Concept Page
Data Governance and Protection Standard of India (DGPSI)
The Data Governance and Protection Standard of India (DGPSI) is a government‑issued framework that prescribes uniform rules for collecting, storing, processing, and sharing data across public and private sectors. It requires, for instance, that any entity handling personal information encrypt data at rest and submit to periodic audits by the Data Protection Authority, thereby boosting security and public trust.
The Data Governance and Protection Standard of India (DGPSI) is a unified normative framework issued by the Government of India to govern how digital data is collected, stored, processed, transmitted, and shared across both government departments and private enterprises operating within Indian jurisdiction. Its defining ambition is to replace the patchwork of sector-specific rules — each ministry had its own data practices, and the private sector operated under loosely interpreted contractual terms — with a single, auditable standard modelled on the architecture of the Digital Personal Data Protection Act, 2023, but extending beyond personal data to cover operational, transactional, and non-personal datasets handled by public bodies. The framework is administered by the Data Protection Board (constituted under Sections 18–22 of the 2023 Act) in coordination with the National Data Management Office under the Ministry of Electronics and Information Technology (MeitY).
Origins and Institutional Context
The DGPSI emerged from the recognition that the Digital Personal Data Protection Act, 2023 — which received presidential assent on 11 August 2023 and came into force in stages from 13 September 2023 onwards — established rights and obligations but left the technical and procedural details of compliance to subordinate rulemaking. To operationalise those obligations, MeitY circulated the DGPSI as an overarching standard that translates statutory principles (consent, data minimisation, purpose limitation, storage limitation) into measurable technical and organisational controls. The standard draws additionally on the Information Technology (Reasonable Security Practices and Procedures) Rules, 2011, the National Data Sharing and Accessibility Policy (NDSAP) of 2012, and the India Data Management Office framework announced in the 2022–23 Union Budget.
Key Provisions and Mandatory Controls
The DGPSI is organised into nine control families covering governance, consent management, data inventory and classification, storage and localisation, encryption, access control, breach notification, audit, and cross-border transfer. Personal data of Indian citizens must be processed only on servers located within India, with mirrors permitted abroad solely for redundancy. Encryption at rest is mandated using algorithms cleared by the Centre for Development of Advanced Computing (C-DAC), and encryption in transit must conform to TLS 1.2 or higher. Every Data Fiduciary, as defined under Section 2(i) of the 2023 Act, is required to appoint a Data Protection Officer accessible to the Data Protection Board, maintain a Record of Processing Activities (RoPA), and conduct an independent audit every twenty-four months by a CERT-In empanelled auditor. Breach notification to affected principals must occur within seventy-two hours of discovery, mirroring the timeline in the General Data Protection Regulation (GDPR) of the European Union.
Implementation Status
Adoption is being phased, beginning with Union Ministries, public-sector banks, and companies classified as Significant Data Fiduciaries under Section 10 of the parent Act. The framework is enforced alongside CERT-In's Directions of 28 April 2022, which separately require cybersecurity incident reporting within six hours. Voluntary compliance certifications, issued by the National Accreditation Board for Certification Bodies (NABCB), are operational, and the government has signalled that procurement eligibility for large digital contracts will increasingly require DGPSI certification. As of late 2024, however, the standard remains a MeitY notification rather than a Parliamentary statute, leaving its long-term legal durability tied to amendments likely under consideration to the 2023 framework.