Purpose, choice and accountability
Privacy & DPDP Centre
A detailed implementation-ready explanation of personal-data handling under India’s Digital Personal Data Protection framework. Each live service still needs its own exact, approved notice.
1. Who is responsible
Website / service brand: eSetu Kendra.
Operating legal entity / proposed Data Fiduciary: NewGenEra AI Technologies Private Limited.
Privacy contact or DPO: info@newgenera.in · +91 93598 05849.
Grievance contact: info@newgenera.in · +91 93598 05849.
The role can change by service. A government department, Kendra operator, platform operator, regulated partner or payment provider may act as a separate Data Fiduciary, joint participant or Data Processor depending on law, contract and actual decision-making. The service-specific notice must name the parties and roles; this page does not silently assign them.
2. DPDP framework and commencement
The Digital Personal Data Protection Act, 2023 governs digital personal data processed in India and certain processing outside India connected with offering goods or services to Data Principals in India. The Digital Personal Data Protection Rules, 2025 and the commencement notification use phased effective dates.
| Effective date | Act provisions | Rules | Status on 21 September 2026 |
|---|---|---|---|
| 13 November 2025 | Section 1(2), section 2, sections 18–26, section 35, sections 38–43, and section 44(1) and (3) | Rules 1, 2 and 17–21 | In force |
| 13 November 2026 | Section 6(9) and section 27(1)(d) | Rule 4 | Not yet in force |
| 13 May 2027 | Sections 3–5; section 6(1)–(8) and (10); sections 7–17; the remaining provisions of section 27; sections 28–34, 36 and 37; and section 44(2) | Rules 3, 5–16, 22 and 23 | Not yet in force |
Digital Personal Data Protection Act, 2023, Act No. 22 of 2023, assented 11 August 2023 (official PDF opens in a new tab) · Digital Personal Data Protection Rules, 2025, G.S.R. 846(E), 13 November 2025 (official PDF opens in a new tab) · DPDP Act commencement notification, G.S.R. 843(E), 13 November 2025 (official PDF opens in a new tab)
This page is an operational transparency notice, not legal advice and not a substitute for the Act, Rules, notifications, sectoral law or service-specific government terms.
3. Personal data that a configured service may use
Only data necessary for the stated purpose should be requested. The exact fields must appear in the notice shown before or with collection.
| Category | Examples | Typical purpose |
|---|---|---|
| Account and contact | Name, mobile number, email, preferred language, login/session evidence | Authentication, communication and account security |
| Identity and demographic | Date of birth, gender, category, masked identity references | Eligibility and applicant identification where lawfully required |
| Address and geography | Address, district, taluka, village, ward and PIN code | Jurisdiction, domicile, delivery and nearby Kendra |
| Household and relationship | Family members, guardian, nominee or dependent relationship | Family-based services, child/guardian workflows and nomination |
| Documents and application answers | Uploaded proofs, form answers, declarations, signatures and query responses | Prepare, submit, verify and decide the requested service |
| Financial | Fee, transaction reference, bank-account metadata, income or benefit information | Payment, refund, benefit, finance or statutory processing |
| Agriculture and business | Land, crop, enterprise, tax, licence, project and subsidy facts | Relevant agriculture or enterprise service |
| Education and employment | Qualifications, enrolment, attendance, CV and application status | Training or job-assistance journey |
| Health or insurance disclosures | Only the proposal or claim information expressly required | Insurance or regulated service processing |
| Device and security | IP address, timestamps, browser/session, security events and audit evidence | Prevent abuse, secure accounts and demonstrate compliance |
| Support and grievance | Messages, call or case notes, evidence and resolution | Respond to help, complaint, appeal or rights request |
Passwords, OTPs, UPI PINs, card PINs and CVVs are not service-application data and must never be requested or recorded by a Kendra operator.
4. Purpose and lawful processing path
The system must record a specific purpose and distinguish consent from processing for a use permitted by the Act or required under another law. Consent must not be used as a blanket label for every government-service activity.
| Activity | Expected processing path | Control |
|---|---|---|
| Citizen requests a service | Consent where applicable, or a service-specific permitted/legal basis identified by the responsible authority | Standalone notice, necessary fields and submission evidence |
| Department routing and decision | Necessary sharing with the named authority under the disclosed service purpose | Recipient, dataset, timestamp and response audit |
| Payment and statutory records | Transaction performance and applicable legal/accounting duties | Minimise data, separate fee components and retain by schedule |
| Security and fraud prevention | Reasonable security safeguards and permitted/legal uses as applicable | Proportionate logging, restricted access and review |
| Marketing or cross-selling | Separate optional consent | No pre-tick, channel choice and easy withdrawal |
| Optional analytics/cookies | Separate preference/consent where required | Essential operation remains available without optional tracking |
Certain legitimate uses
The Act identifies circumstances in which processing may occur without relying on consent, including specified voluntary provision, State functions/benefits and other statutory circumstances. These are not a general exception. The exact clause, responsible Data Fiduciary, necessity and safeguards must be documented for the service. Consent withdrawal does not erase processing independently required or permitted by law.
5. What a collection notice must contain
Before or with each collection, the citizen should receive a clear, standalone, plain-language notice that can be accessed independently of general terms. It should state:
- the accountable Data Fiduciary and contact mechanism;
- an itemised description of personal data requested;
- each specific purpose and what service or feature it enables;
- whether providing an item is required, optional or conditional;
- the processing basis, named recipient categories and material processors;
- consequences of providing, refusing or later withdrawing optional consent;
- retention criteria, security approach and relevant cross-border processing;
- how to withdraw consent and exercise access, correction, erasure, grievance and nomination rights;
- how to complain to the Board after using the internal grievance mechanism; and
- the notice version, effective date and available languages.
The notice and consent evidence should preserve the exact text/version presented, language, affirmative action, time, channel, purpose and withdrawal history.
6. Consent and preference matrix
Consent must be free, specific, informed, unconditional and unambiguous, expressed by clear affirmative action, limited to data necessary for the stated purpose, and capable of withdrawal with comparable ease. Terms acceptance, notice delivery and consent are separate records.
| Purpose | How it must be handled | Default |
|---|---|---|
| Account creation and secure portal operation | Account-specific notice; collect only authentication/contact evidence needed | Required only to use the account feature |
| Requested service and service documents | Service-specific, itemised notice; do not bundle unrelated services | Context-dependent |
| Sharing with responsible government authority | Name or clearly identify the authority/category and exact service purpose | Context-dependent |
| Aadhaar authentication or offline verification | Use only an authorised method; explain alternative where applicable; never expose the full number unnecessarily | Off until the journey requires and authorises it |
| DigiLocker access | Request only the named document(s), issuer and purpose | Off |
| eSign or biometric processing | Separate just-in-time explanation and authorised provider hand-off | Off |
| Payment processing | Identify gateway/recipient and transaction fields; never collect a PIN or CVV in eSetu records | Only at payment |
| External OCR or AI | Identify purpose, provider category, human review and data minimisation; avoid model training unless separately justified | Off unless explicitly enabled |
| Transactional SMS, email or WhatsApp | Choose necessary service channels and distinguish them from promotions | Only configured service updates |
| Marketing and cross-sell | Separate by channel and purpose; no effect on core service | Off |
| Precise geolocation | Request only while locating a Kendra; offer manual district/PIN search | Off |
| Marketplace or regulated-partner referral | Name recipient or category and share the minimum referral dataset | Off |
| Employer or training-provider sharing | Per application/enrolment; no blanket future sharing | Off |
| Optional analytics and non-essential cookies | Granular preference with reject/withdraw control | Off |
| Research or statistics | Use anonymised data where possible; document the applicable exemption or consent | Off unless justified |
| Parent/guardian action | Verifiably establish adult/guardian authority before child or represented-person processing | Required when applicable |
Withdrawal
Withdrawing optional consent should be as easy as giving it. The citizen must be told the forward-looking operational consequence before confirmation. Withdrawal does not invalidate processing already lawfully completed and may not stop retention or processing required by law. Every downstream processor receiving the affected instruction must be handled through an auditable propagation workflow.
Consent Managers
Where a registered Consent Manager is used, the citizen may give, manage, review or withdraw consent through that interoperable platform. The system must verify registration and integration scope rather than describing itself as a Consent Manager without approval.
7. Sharing, processors and transfers
Depending on the chosen service, necessary data may be shared with the named government department, authorised Kendra/operator, hosting and document processor, payment provider, communications provider, identity/eSign/DigiLocker provider, regulated lender/insurer/professional, training provider, employer or marketplace provider. A live notice must identify the actual recipients or meaningful categories, not this entire possible list.
- Processors act only on documented instructions and appropriate contracts.
- Access is role-based, purpose-bound and logged.
- Only the minimum dataset needed for the recipient task is shared.
- Onward sharing, retention, deletion, incident and audit duties are contractual.
- Cross-border processing is reviewed against restrictions notified by the Central Government and relevant sectoral rules.
- A citizen-facing sharing history should show material disclosures where legally and operationally appropriate.
8. Retention, erasure and legal holds
Records should be retained only for the service purpose and the applicable statutory, audit, accounting, limitation, fraud-prevention or government-record schedule. A single indefinite retention period is not appropriate for every service.
- Each data purpose receives a documented retention rule and owner.
- Inactivity or purpose completion triggers review and any required advance notice.
- Data is erased or irreversibly anonymised when purpose and legal retention end.
- Backups age out under a documented cycle and remain protected until deletion.
- A legal hold records its authority, scope, reviewer and release date.
- Erasure requests are fulfilled unless a lawful retention reason applies; any refusal must be explained.
9. Data Principal rights
Subject to the applicable provisions and lawful limitations, a Data Principal can use the published mechanism to:
- obtain a summary of personal data being processed and processing activities;
- obtain identities or categories of other Data Fiduciaries and Processors with whom data was shared, as applicable;
- correct inaccurate or misleading data;
- complete incomplete data and update changed data;
- request erasure where retention is not legally necessary;
- withdraw consent for consent-based future processing;
- use the readily available grievance-redressal mechanism; and
- nominate another individual to exercise rights in the event of death or incapacity.
How a request should work
- Use the secure privacy centre when enabled, or the verified privacy contact shown above.
- Describe the account/service, right requested and relevant date range; do not send excess identity data.
- Complete proportionate identity/authority verification through the secure method offered.
- Receive an acknowledgement and reference number.
- The responsible team locates data across systems/processors, records exemptions or legal holds, approves the response and communicates the outcome.
- If dissatisfied, use the internal grievance mechanism before approaching the Data Protection Board as required by the Act.
Privacy request contact: info@newgenera.in · +91 93598 05849.
Data Principal duties
Citizens must comply with applicable law, not impersonate another person, not suppress material information when providing data for a State document or identifier, not file false or frivolous grievances, and provide verifiably authentic information when seeking correction or erasure.
10. Children and persons represented by a lawful guardian
Before processing a child’s personal data on a consent basis, the responsible Data Fiduciary must obtain verifiable consent from a parent. Where a person with disability is represented by a lawful guardian for the relevant decision, guardian authority must be verified. Applicable exemptions must be documented, not assumed.
- Use age-appropriate, clear notices for the child and the parent/guardian.
- Collect the minimum evidence needed to verify adulthood, parenthood or lawful guardianship.
- Do not undertake tracking or behavioural monitoring of children, or targeted advertising directed at children, except as lawfully permitted.
- Do not process in a manner likely to cause a detrimental effect on the well-being of a child.
- Reassess authority and consent when circumstances or age change.
11. Security safeguards
Reasonable safeguards should include encryption or equivalent protection in transit and at rest where appropriate, access control, multi-factor protection for privileged access, secure session/token handling, data masking, malware scanning, logging and monitoring, vulnerability management, tested backups, business continuity, processor controls and periodic security assessment.
Operational controls include separation of duties, least privilege, record-level citizen ownership, signed/idempotent callbacks, document download authorisation, log redaction, retention controls and training for operators who handle citizen documents.
Personal-data breach response
- Contain the event, preserve evidence and assess affected data, people and likely harm.
- Notify affected Data Principals in clear language as required, including nature, likely consequences, mitigation and contact information.
- Notify the Data Protection Board in the form and timeframe required by the Rules, including immediate intimation and the required detailed information within the prescribed period.
- Coordinate processor facts, remediate root cause, document decisions and track follow-up.
Report a suspected privacy or security incident through the verified privacy/grievance contact. For immediate financial fraud, also contact the relevant bank/payment provider and official cybercrime channel.
12. Additional duties if designated a Significant Data Fiduciary
If the Central Government designates an involved entity as a Significant Data Fiduciary, the applicable additional measures include appointing a Data Protection Officer based in India, appointing an independent data auditor, periodic Data Protection Impact Assessments, audits and other prescribed due diligence. The website does not claim such a designation or exemption unless formally recorded.
13. Grievance, Board and penalties
Use the published internal grievance mechanism first and retain its reference. Eligible unresolved matters may then be taken to the Data Protection Board of India through the notified process. Board orders are appealable through the statutory appellate mechanism. The Act’s Schedule provides potentially substantial monetary penalties, including the highest bands for failures to take reasonable security safeguards and notify breaches; the Board determines any penalty under the statutory factors.
14. Changes and service-specific notices
Material changes to purpose, data, recipient, retention or consent require a new notice/version and, where applicable, fresh consent. Previous notice and consent evidence must remain auditable. Service-specific notice text overrides this general explanation only for that named journey and must not reduce statutory rights.