Blogs

CSC operators cannot store Aadhaar data under DPDP Act: MeitY


Key Points

  • Data Protection Board recruitment advertisement published in Employment News on 6 June 2026
  • Village Level Entrepreneurs at 5.8 lakh CSCs not authorised to store citizen data
  • Consent Manager registration to begin from 13 November 2026 under Phase 2

Village Level Entrepreneurs operating India’s network of over 5.8 lakh are not authorised to collect or store any citizen data, including Aadhaar, and health records, the government has told Parliament.

Jitin Prasada, minister of state for electronics and information technology, made the clarification in response to a question on whether CSC operators, who process sensitive citizen data daily, qualify as Data Fiduciaries under the Act, 2023. A Data Fiduciary is any person or entity that determines the purpose and means of processing personal data, carrying significant compliance obligations under the law.

Advertisement


EVENT

Infosec Reimagined

Infosec Reimagined

Infosec Reimagined 2026 is the premier information security summit where top leaders—CISOs, CROs, CIOs, CTOs and risk executives—converge to redefine cyber resilience.


Register Now →

EVENT

Digital SenateDigital Senate

Digital Senate

Digital Senate is a premier conference uniting government leaders, technologists and innovators to share ideas, success stories and strategies on digital governance, public sector transformation, cybersecurity and emerging technologies in India.


Register Now →

EVENT

CIO PrismCIO Prism

CIO Prism

CIO Prism unites forward-thinking technology leaders to exchange transformative insights, shape digital strategies, and foster innovation, empowering enterprises to excel in an era of rapid technological change.


Register Now →

EVENT

National DefTech SummitNational DefTech Summit

National DefTech Summit

Featuring keynotes, expert panels, live tech demos and strategic networking, the summit will drive actionable insights for defence sector.


Register Now →

EVENT

Future-Ready DefenceFuture-Ready Defence

Future-Ready Defence

A Leadership Dialogue on sovereign, trusted data infrastructure, AI readiness and mission resilience for Defence Forces.


Register Now →

The minister’s response in the Lok Sabha on Wednesday (12 August), confirmed that CSC VLEs provide assisted access to digital services but operate under restrictions that prevent them from retaining the data they handle on behalf of citizens.

Board recruitment

The government also provided an update on the phased implementation of the DPDP Rules, 2025, which were notified on 13 November 2025. The Rules establish an eighteen-month transition period for full compliance, divided into three phases.

Under Phase 1, the Data Protection Board of India is being established. The Board, which will handle citizen grievances and adjudicate data protection disputes, is to comprise a Chairperson and four Members appointed through a Search-cum-Selection Committee. The recruitment advertisement for these posts was published in the Employment News on 6 June 2026.

Phase 2, to be completed within one year of the Rules’ notification, covers the registration and functioning of Consent Managers. These are entities that will help citizens manage their data consent across multiple platforms and services. Registration is scheduled to begin from 13 November 2026.

Phase 3, due within eighteen months, will bring into force the full compliance obligations for Data Fiduciaries. These include providing valid notices in 22 Indian languages, obtaining consent where required, implementing security safeguards, responding to data principal requests within specified timelines, facilitating correction and erasure of personal data and establishing grievance redressal mechanisms that must resolve complaints within ninety days.

Rural awareness

Responding to concerns about whether a dedicated rural awareness programme on data principal rights would be conducted through the CSC network, particularly in aspirational districts such as Gonda in Uttar Pradesh, the minister outlined the government’s existing capacity building initiatives.

Advertisement

Training programmes are being conducted across sectors to strengthen IT security capabilities, according to the response. Public awareness initiatives include Security Awareness Month, Safer Internet Day, workshops, conferences, expert sessions and digital outreach campaigns. These programmes aim to educate citizens on online safety, secure digital transactions, their rights and responsibilities under the DPDP Act and responsible use of digital services.

By the numbers

5.8 lakh
Common Service Centres across India
22
Indian languages for mandatory DPDP notices
90 days
Maximum grievance resolution timeline

The question had specifically raised concerns about vernacular and simplified grievance redressal mechanisms for rural citizens with limited digital literacy, noting that most CSC users in districts like Gonda lack access to formal written consent processes.

The government stated that citizens can access grievance redressal support through the CSC Helpdesk at 14599, the Digital Seva Portal and the State and District CSC network. The DPDP Act requires Data Fiduciaries to provide notices accessible in 22 Indian languages, addressing the vernacular access concern.

Compliance obligations

The minister’s response detailed the full range of obligations that will apply to Data Fiduciaries once Phase 3 comes into force. These entities must maintain valid contracts with any Data Processors they engage. A Data Processor is an entity that processes personal data on behalf of a Data Fiduciary and must process data only as directed, ensure reasonable security safeguards and comply with contractual requirements.

Data Fiduciaries must also report personal data breaches to the Data Protection Board and affected individuals within prescribed timelines. The Board is mandated to function in a digital manner, suggesting online filing and resolution of complaints.

CSC e-Governance Services India Limited, which operates the CSC network, provides the platform through which VLEs support citizens in understanding and accessing government services.

The clarification that VLEs cannot store citizen data places the data protection compliance obligation on the government departments and agencies whose services are accessed through the CSC network, rather than on the individual entrepreneurs operating the centres.

Your Questions, Answered

Can CSC operators store my Aadhaar or banking data?

No. The government has clarified that Village Level Entrepreneurs operating Common Service Centres are not authorised to collect or store any citizen data. They provide assisted access to digital services but cannot retain Aadhaar, banking or health records.

When will the Data Protection Board of India become operational?

The Board is in Phase 1 of establishment. Recruitment advertisements for the Chairperson and four Members were published on 6 June 2026. The Board will function digitally to handle citizen grievances and adjudicate data protection disputes.

What is a Consent Manager under the DPDP Act?

A Consent Manager is an entity that helps citizens manage their data consent across multiple platforms and services. Registration for Consent Managers is scheduled to begin from 13 November 2026 under Phase 2 of the DPDP Rules implementation.

How can rural citizens file data protection grievances?

Citizens can access grievance support through the CSC Helpdesk at 14599, the Digital Seva Portal and State or District CSC networks. Data Fiduciaries must also provide notices in 22 Indian languages and resolve grievances within ninety days.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *