Key Points
- Data Protection Board recruitment advertisement published in Employment News on 6 June 2026
- Village Level Entrepreneurs at 5.8 lakh CSCs not authorised to store citizen data
- Consent Manager registration to begin from 13 November 2026 under Phase 2
Village Level Entrepreneurs operating India’s network of over 5.8 lakh Common Service Centres are not authorised to collect or store any citizen data, including Aadhaar, banking and health records, the government has told Parliament.
Jitin Prasada, minister of state for electronics and information technology, made the clarification in response to a question on whether CSC operators, who process sensitive citizen data daily, qualify as Data Fiduciaries under the Digital Personal Data Protection Act, 2023. A Data Fiduciary is any person or entity that determines the purpose and means of processing personal data, carrying significant compliance obligations under the law.
The minister’s response in the Lok Sabha on Wednesday (12 August), confirmed that CSC VLEs provide assisted access to digital services but operate under restrictions that prevent them from retaining the data they handle on behalf of citizens.
Board recruitment
The government also provided an update on the phased implementation of the DPDP Rules, 2025, which were notified on 13 November 2025. The Rules establish an eighteen-month transition period for full compliance, divided into three phases.
Under Phase 1, the Data Protection Board of India is being established. The Board, which will handle citizen grievances and adjudicate data protection disputes, is to comprise a Chairperson and four Members appointed through a Search-cum-Selection Committee. The recruitment advertisement for these posts was published in the Employment News on 6 June 2026.
Phase 2, to be completed within one year of the Rules’ notification, covers the registration and functioning of Consent Managers. These are entities that will help citizens manage their data consent across multiple platforms and services. Registration is scheduled to begin from 13 November 2026.
Phase 3, due within eighteen months, will bring into force the full compliance obligations for Data Fiduciaries. These include providing valid notices in 22 Indian languages, obtaining consent where required, implementing security safeguards, responding to data principal requests within specified timelines, facilitating correction and erasure of personal data and establishing grievance redressal mechanisms that must resolve complaints within ninety days.
Rural awareness
Responding to concerns about whether a dedicated rural awareness programme on data principal rights would be conducted through the CSC network, particularly in aspirational districts such as Gonda in Uttar Pradesh, the minister outlined the government’s existing capacity building initiatives.
Advertisement
Training programmes are being conducted across sectors to strengthen IT security capabilities, according to the response. Public awareness initiatives include Cyber Security Awareness Month, Safer Internet Day, workshops, conferences, expert sessions and digital outreach campaigns. These programmes aim to educate citizens on online safety, secure digital transactions, their rights and responsibilities under the DPDP Act and responsible use of digital services.
By the numbers
- 5.8 lakh
- Common Service Centres across India
- 22
- Indian languages for mandatory DPDP notices
- 90 days
- Maximum grievance resolution timeline
The question had specifically raised concerns about vernacular and simplified grievance redressal mechanisms for rural citizens with limited digital literacy, noting that most CSC users in districts like Gonda lack access to formal written consent processes.
The government stated that citizens can access grievance redressal support through the CSC Helpdesk at 14599, the Digital Seva Portal and the State and District CSC network. The DPDP Act requires Data Fiduciaries to provide notices accessible in 22 Indian languages, addressing the vernacular access concern.
Compliance obligations
The minister’s response detailed the full range of obligations that will apply to Data Fiduciaries once Phase 3 comes into force. These entities must maintain valid contracts with any Data Processors they engage. A Data Processor is an entity that processes personal data on behalf of a Data Fiduciary and must process data only as directed, ensure reasonable security safeguards and comply with contractual requirements.
Data Fiduciaries must also report personal data breaches to the Data Protection Board and affected individuals within prescribed timelines. The Board is mandated to function in a digital manner, suggesting online filing and resolution of complaints.
CSC e-Governance Services India Limited, which operates the CSC network, provides the platform through which VLEs support citizens in understanding and accessing government services.
The clarification that VLEs cannot store citizen data places the data protection compliance obligation on the government departments and agencies whose services are accessed through the CSC network, rather than on the individual entrepreneurs operating the centres.
Your Questions, Answered
Can CSC operators store my Aadhaar or banking data?
No. The government has clarified that Village Level Entrepreneurs operating Common Service Centres are not authorised to collect or store any citizen data. They provide assisted access to digital services but cannot retain Aadhaar, banking or health records.
When will the Data Protection Board of India become operational?
The Board is in Phase 1 of establishment. Recruitment advertisements for the Chairperson and four Members were published on 6 June 2026. The Board will function digitally to handle citizen grievances and adjudicate data protection disputes.
What is a Consent Manager under the DPDP Act?
A Consent Manager is an entity that helps citizens manage their data consent across multiple platforms and services. Registration for Consent Managers is scheduled to begin from 13 November 2026 under Phase 2 of the DPDP Rules implementation.
How can rural citizens file data protection grievances?
Citizens can access grievance support through the CSC Helpdesk at 14599, the Digital Seva Portal and State or District CSC networks. Data Fiduciaries must also provide notices in 22 Indian languages and resolve grievances within ninety days.




