Dispatch #002

State as the Largest Data Fiduciary

The Digital Personal Data Protection Act places strict obligations on data fiduciaries. But while commercial firms race to comply, the state remains the single largest custodian of citizen identities.

Keshav Bhardwaj 02 Sep 2026 8 min read Governance · DPDP · Digital Public Infrastructure
Archival record room
Public documentation, archival records, and statutory registries Photo: Keshav Bhardwaj
"The state does not merely administer the law; in its routine procedures and record-keeping, it defines what is legible, visible, and trusted."
— Public Administration Review
Did you know? You can print this as PDF, and make annotations and remarks. Take this dispatch offline with a curated, annotation-friendly print edition. Open this page on your PC to export the PDF.
Note:This is a test page with AI generated content.

Introduction

The Digital Personal Data Protection (DPDP) Act and DPDP Rules place solemn statutory responsibilities on Data Fiduciaries—any entity determining the purpose and means of processing personal data collected from individuals. Violations can entail severe financial consequences, with penalties extending up to ₹250 crore.

As implementation deadlines draw nearer, industry consultations and corporate compliance audits dominate the headlines. Yet commercial platforms, fintech applications, and e-commerce companies constitute only a fraction of the digital footprint that defines everyday life.

In modern India, it is state institutions that function as the single largest and most pervasive custodians of personal data.

The Scale of Public Custodianship

Consider the architecture of contemporary public administration:

  • Municipal Corporations: Birth and death registries, property ownership records, civic tax payments, water and sewage billings.
  • District Administrations: Land registries (Jamabandi, land records digitization), revenue disputes, social welfare beneficiary rolls.
  • State Governments: Civil supplies databases (PDS ration distribution), student scholarships, public transport smart cards.
  • Central Ministries: Income tax portals, healthcare identifier schemes, pension management architectures, and Digital Public Infrastructure (DPI) rails.

Unlike private platforms where consumer consent is theoretically optional (even if practically constrained), citizen interaction with state registries is mandatory. You cannot opt out of municipal birth certificates, property registries, or national identification databases without severe civic disenfranchisement.

The Electoral Roll and Public Visibility

Take the Election Commission of India as an instructive archetype. It maintains granular personal details on nearly one billion adult citizens. Historically, the bedrock of democratic transparency mandated public posting of the Electoral Roll on notice boards in local administrative wards.

In the digital era, however, these records transitioned into freely downloadable PDF rolls containing:

  1. Full names and age
  2. Exact residential addresses
  3. Guardian / Parental names
  4. Photographs and polling precinct identifiers

While transparency in voter registration prevents electoral fraud, unfettered bulk-scraping of unredacted PDF rolls enables weaponized profiling, unsolicited commercial marketing, and privacy degradation.

Transparency must protect the integrity of democratic processes without sacrificing the personal security of the voter.

State as the Exemplar

The transition under the DPDP framework presents India with a historic opportunity. Rather than seeking blanket exemptions under sovereign prerogative, the state must establish gold-standard institutional benchmarks:

  • Purpose Limitation & Data Minimization: Restricting bureaucratic data collection strictly to what is necessary for the statutory delivery of the public service.
  • Granular Redaction for Public Disclosures: Employing cryptographic proofs and anonymized hashes for public scrutiny without publishing raw identifying credentials.
  • Strict Intra-Departmental Access Controls: Instituting tiered role-based security clearances for outsourced contractors, consultants, and administrative staff handling state databases.

When the sovereign demonstrates rigorous custodial discipline over the data it holds, it establishes the moral and legal authority required to enforce compliance across the entire private digital economy.

References, Sources & Further Reading
  1. Ministry of Electronics and Information Technology (MeitY). (2023). The Digital Personal Data Protection Act, 2023. The Gazette of India. New Delhi.
  2. Election Commission of India. (2024). Handbook on Electoral Rolls and Citizen Registry Practices. Nirvachan Sadan, New Delhi.
  3. Unique Identification Authority of India (UIDAI). (2025). Aadhaar Authentication Regulations and Data Fiduciary Guidelines. Government of India.

Keshav Bhardwaj

Dispatches · Essay #002

Disclaimer: Views expressed are solely those of the author and do not necessarily reflect those of any affiliated institution.

Looking to print and make annotations? Open this dispatch on your PC to export the print edition.
Link copied to clipboard