Skip to Content
Skip to main content

Purpose, choice and accountability

Privacy & DPDP Centre

A detailed implementation-ready explanation of personal-data handling under India’s Digital Personal Data Protection framework. Each live service still needs its own exact, approved notice.

1. Who is responsible

Website / service brand: eSetu Kendra.

Operating legal entity / proposed Data Fiduciary: NewGenEra AI Technologies Private Limited.

Privacy contact or DPO: info@newgenera.in · +91 93598 05849.

Grievance contact: info@newgenera.in · +91 93598 05849.

The role can change by service. A government department, Kendra operator, platform operator, regulated partner or payment provider may act as a separate Data Fiduciary, joint participant or Data Processor depending on law, contract and actual decision-making. The service-specific notice must name the parties and roles; this page does not silently assign them.

2. DPDP framework and commencement

The Digital Personal Data Protection Act, 2023 governs digital personal data processed in India and certain processing outside India connected with offering goods or services to Data Principals in India. The Digital Personal Data Protection Rules, 2025 and the commencement notification use phased effective dates.

Position reviewed on 21 September 2026: only the first phase below is in force. The phases scheduled for 13 November 2026 and 13 May 2027 are not yet in force. eSetu nevertheless treats the later duties as implementation-readiness requirements; the responsible operator must recheck the Gazette and obtain legal approval before production launch.
DPDP commencement schedule notified on 13 November 2025
Effective dateAct provisionsRulesStatus on 21 September 2026
13 November 2025 Section 1(2), section 2, sections 18–26, section 35, sections 38–43, and section 44(1) and (3) Rules 1, 2 and 17–21 In force
13 November 2026 Section 6(9) and section 27(1)(d) Rule 4 Not yet in force
13 May 2027 Sections 3–5; section 6(1)–(8) and (10); sections 7–17; the remaining provisions of section 27; sections 28–34, 36 and 37; and section 44(2) Rules 3, 5–16, 22 and 23 Not yet in force

Digital Personal Data Protection Act, 2023, Act No. 22 of 2023, assented 11 August 2023 (official PDF opens in a new tab) · Digital Personal Data Protection Rules, 2025, G.S.R. 846(E), 13 November 2025 (official PDF opens in a new tab) · DPDP Act commencement notification, G.S.R. 843(E), 13 November 2025 (official PDF opens in a new tab)

This page is an operational transparency notice, not legal advice and not a substitute for the Act, Rules, notifications, sectoral law or service-specific government terms.

3. Personal data that a configured service may use

Only data necessary for the stated purpose should be requested. The exact fields must appear in the notice shown before or with collection.

Illustrative categories; each live collection notice must list the actual data requested
CategoryExamplesTypical purpose
Account and contactName, mobile number, email, preferred language, login/session evidenceAuthentication, communication and account security
Identity and demographicDate of birth, gender, category, masked identity referencesEligibility and applicant identification where lawfully required
Address and geographyAddress, district, taluka, village, ward and PIN codeJurisdiction, domicile, delivery and nearby Kendra
Household and relationshipFamily members, guardian, nominee or dependent relationshipFamily-based services, child/guardian workflows and nomination
Documents and application answersUploaded proofs, form answers, declarations, signatures and query responsesPrepare, submit, verify and decide the requested service
FinancialFee, transaction reference, bank-account metadata, income or benefit informationPayment, refund, benefit, finance or statutory processing
Agriculture and businessLand, crop, enterprise, tax, licence, project and subsidy factsRelevant agriculture or enterprise service
Education and employmentQualifications, enrolment, attendance, CV and application statusTraining or job-assistance journey
Health or insurance disclosuresOnly the proposal or claim information expressly requiredInsurance or regulated service processing
Device and securityIP address, timestamps, browser/session, security events and audit evidencePrevent abuse, secure accounts and demonstrate compliance
Support and grievanceMessages, call or case notes, evidence and resolutionRespond to help, complaint, appeal or rights request

Passwords, OTPs, UPI PINs, card PINs and CVVs are not service-application data and must never be requested or recorded by a Kendra operator.

4. Purpose and lawful processing path

The system must record a specific purpose and distinguish consent from processing for a use permitted by the Act or required under another law. Consent must not be used as a blanket label for every government-service activity.

Illustrative processing paths that still require service-specific legal and governance approval
ActivityExpected processing pathControl
Citizen requests a serviceConsent where applicable, or a service-specific permitted/legal basis identified by the responsible authorityStandalone notice, necessary fields and submission evidence
Department routing and decisionNecessary sharing with the named authority under the disclosed service purposeRecipient, dataset, timestamp and response audit
Payment and statutory recordsTransaction performance and applicable legal/accounting dutiesMinimise data, separate fee components and retain by schedule
Security and fraud preventionReasonable security safeguards and permitted/legal uses as applicableProportionate logging, restricted access and review
Marketing or cross-sellingSeparate optional consentNo pre-tick, channel choice and easy withdrawal
Optional analytics/cookiesSeparate preference/consent where requiredEssential operation remains available without optional tracking

Certain legitimate uses

The Act identifies circumstances in which processing may occur without relying on consent, including specified voluntary provision, State functions/benefits and other statutory circumstances. These are not a general exception. The exact clause, responsible Data Fiduciary, necessity and safeguards must be documented for the service. Consent withdrawal does not erase processing independently required or permitted by law.

5. What a collection notice must contain

Before or with each collection, the citizen should receive a clear, standalone, plain-language notice that can be accessed independently of general terms. It should state:

  • the accountable Data Fiduciary and contact mechanism;
  • an itemised description of personal data requested;
  • each specific purpose and what service or feature it enables;
  • whether providing an item is required, optional or conditional;
  • the processing basis, named recipient categories and material processors;
  • consequences of providing, refusing or later withdrawing optional consent;
  • retention criteria, security approach and relevant cross-border processing;
  • how to withdraw consent and exercise access, correction, erasure, grievance and nomination rights;
  • how to complain to the Board after using the internal grievance mechanism; and
  • the notice version, effective date and available languages.

The notice and consent evidence should preserve the exact text/version presented, language, affirmative action, time, channel, purpose and withdrawal history.

7. Sharing, processors and transfers

Depending on the chosen service, necessary data may be shared with the named government department, authorised Kendra/operator, hosting and document processor, payment provider, communications provider, identity/eSign/DigiLocker provider, regulated lender/insurer/professional, training provider, employer or marketplace provider. A live notice must identify the actual recipients or meaningful categories, not this entire possible list.

  • Processors act only on documented instructions and appropriate contracts.
  • Access is role-based, purpose-bound and logged.
  • Only the minimum dataset needed for the recipient task is shared.
  • Onward sharing, retention, deletion, incident and audit duties are contractual.
  • Cross-border processing is reviewed against restrictions notified by the Central Government and relevant sectoral rules.
  • A citizen-facing sharing history should show material disclosures where legally and operationally appropriate.

8. Retention, erasure and legal holds

Records should be retained only for the service purpose and the applicable statutory, audit, accounting, limitation, fraud-prevention or government-record schedule. A single indefinite retention period is not appropriate for every service.

  1. Each data purpose receives a documented retention rule and owner.
  2. Inactivity or purpose completion triggers review and any required advance notice.
  3. Data is erased or irreversibly anonymised when purpose and legal retention end.
  4. Backups age out under a documented cycle and remain protected until deletion.
  5. A legal hold records its authority, scope, reviewer and release date.
  6. Erasure requests are fulfilled unless a lawful retention reason applies; any refusal must be explained.

9. Data Principal rights

Subject to the applicable provisions and lawful limitations, a Data Principal can use the published mechanism to:

  • obtain a summary of personal data being processed and processing activities;
  • obtain identities or categories of other Data Fiduciaries and Processors with whom data was shared, as applicable;
  • correct inaccurate or misleading data;
  • complete incomplete data and update changed data;
  • request erasure where retention is not legally necessary;
  • withdraw consent for consent-based future processing;
  • use the readily available grievance-redressal mechanism; and
  • nominate another individual to exercise rights in the event of death or incapacity.

How a request should work

  1. Use the secure privacy centre when enabled, or the verified privacy contact shown above.
  2. Describe the account/service, right requested and relevant date range; do not send excess identity data.
  3. Complete proportionate identity/authority verification through the secure method offered.
  4. Receive an acknowledgement and reference number.
  5. The responsible team locates data across systems/processors, records exemptions or legal holds, approves the response and communicates the outcome.
  6. If dissatisfied, use the internal grievance mechanism before approaching the Data Protection Board as required by the Act.

Privacy request contact: info@newgenera.in · +91 93598 05849.

Data Principal duties

Citizens must comply with applicable law, not impersonate another person, not suppress material information when providing data for a State document or identifier, not file false or frivolous grievances, and provide verifiably authentic information when seeking correction or erasure.

10. Children and persons represented by a lawful guardian

Before processing a child’s personal data on a consent basis, the responsible Data Fiduciary must obtain verifiable consent from a parent. Where a person with disability is represented by a lawful guardian for the relevant decision, guardian authority must be verified. Applicable exemptions must be documented, not assumed.

  • Use age-appropriate, clear notices for the child and the parent/guardian.
  • Collect the minimum evidence needed to verify adulthood, parenthood or lawful guardianship.
  • Do not undertake tracking or behavioural monitoring of children, or targeted advertising directed at children, except as lawfully permitted.
  • Do not process in a manner likely to cause a detrimental effect on the well-being of a child.
  • Reassess authority and consent when circumstances or age change.

11. Security safeguards

Reasonable safeguards should include encryption or equivalent protection in transit and at rest where appropriate, access control, multi-factor protection for privileged access, secure session/token handling, data masking, malware scanning, logging and monitoring, vulnerability management, tested backups, business continuity, processor controls and periodic security assessment.

Operational controls include separation of duties, least privilege, record-level citizen ownership, signed/idempotent callbacks, document download authorisation, log redaction, retention controls and training for operators who handle citizen documents.

Personal-data breach response

  1. Contain the event, preserve evidence and assess affected data, people and likely harm.
  2. Notify affected Data Principals in clear language as required, including nature, likely consequences, mitigation and contact information.
  3. Notify the Data Protection Board in the form and timeframe required by the Rules, including immediate intimation and the required detailed information within the prescribed period.
  4. Coordinate processor facts, remediate root cause, document decisions and track follow-up.

Report a suspected privacy or security incident through the verified privacy/grievance contact. For immediate financial fraud, also contact the relevant bank/payment provider and official cybercrime channel.

12. Additional duties if designated a Significant Data Fiduciary

If the Central Government designates an involved entity as a Significant Data Fiduciary, the applicable additional measures include appointing a Data Protection Officer based in India, appointing an independent data auditor, periodic Data Protection Impact Assessments, audits and other prescribed due diligence. The website does not claim such a designation or exemption unless formally recorded.

13. Grievance, Board and penalties

Use the published internal grievance mechanism first and retain its reference. Eligible unresolved matters may then be taken to the Data Protection Board of India through the notified process. Board orders are appealable through the statutory appellate mechanism. The Act’s Schedule provides potentially substantial monetary penalties, including the highest bands for failures to take reasonable security safeguards and notify breaches; the Board determines any penalty under the statutory factors.

Open the grievance routing guide.

14. Changes and service-specific notices

Material changes to purpose, data, recipient, retention or consent require a new notice/version and, where applicable, fresh consent. Previous notice and consent evidence must remain auditable. Service-specific notice text overrides this general explanation only for that named journey and must not reduce statutory rights.

Was this page helpful?

No

Do not enter Aadhaar, bank, phone or application numbers here. For help with your own case, use Contact & support.