Cabinet Secretary Directs Ministries

Cabinet Secretary Directs Ministries and States to Prepare for DPDP Compliance

Cabinet Secretary directs ministries and states to prepare for DPDP compliance, strengthening data protection and privacy measures across India.

Cabinet Secretary T. V. Somanathan has directed Central ministries, State governments and Union Territory administrations to begin preparations for compliance with the Digital Personal Data Protection Act, 2023. In a letter dated 20 August 2026, government authorities were asked to designate senior officials to oversee implementation, appoint nodal officers to coordinate with the Ministry of Electronics and Information Technology (MeitY), and prepare phased implementation plans with defined responsibilities and timelines. The directive marks a significant step towards operationalising India’s data protection framework across government bodies. 

As part of the exercise, ministries and States have been asked to identify and document their personal data processing activities, review existing privacy notices, and incorporate privacy-by-design principles into the development, enhancement and operation of digital government services. Legacy systems are also expected to undergo phased, risk-based reviews to assess their alignment with the DPDPA framework. 

The directive is particularly significant given the scale and sensitivity of personal data processed by government authorities across areas such as welfare delivery, taxation, healthcare, education and public administration. Bringing these systems within a structured compliance exercise places greater emphasis on internal accountability, data governance and security safeguards within the public sector. 

The development signals a shift from the enactment of the DPDPA towards its practical implementation, with government entities now required to establish institutional responsibility and systematically review their data-processing practices. It also underscores the importance of embedding privacy considerations into the design of digital public services rather than treating data protection as a post-deployment compliance exercise. 

Read More: Cabinet Secretary Directs Ministries and States to Prepare for DPDP Compliance.  

📰 MINI HEADLINES 

  • Australia Unveils Second Wave of Privacy Act Reforms 

Australia has published initial proposals for the second wave of reforms to its Privacy Act, signalling a further expansion of individual privacy rights and organisational accountability. The proposals include a proposed “fair and reasonable” test for personal data handling, requiring organisations to assess whether the collection, use and disclosure of personal information is objectively justified in the circumstances. The reforms would also strengthen consent requirements and introduce a broader right to erasure, allowing individuals to seek deletion of certain personal information held by digital platforms. 

The proposals also focus on strengthening protections against identity misuse and modernising privacy law for emerging technologies. The Australian Government has linked the reforms to growing concerns surrounding digital platforms, AI-enabled technologies and connected devices, reflecting an effort to ensure that privacy obligations remain effective in an increasingly data-driven environment. 

READ MORE - Australia Unveils Second Wave of Privacy Act Reforms 

  • Indonesia Issues Long-Awaited Rules to Implement Its Personal Data Protection Law 

Indonesia has published the long-awaited implementing regulation for its Personal Data Protection Law, providing greater clarity on the operational framework governing personal data processing in the country. Government Regulation No. 33 of 2026 (GR 33/2026) was enacted on 16 July 2026, but reportedly began circulating publicly only in late August, ahead of a formal government announcement. 

The regulation is significant because Indonesia’s Personal Data Protection Law (Law No. 27 of 2022) established the country’s overarching data protection framework while leaving several practical aspects to be addressed through implementing rules. The issuance of GR 33/2026 therefore represents an important step towards operationalising Indonesia’s privacy regime and providing organisations with greater clarity on their compliance obligations. 

READ MORE - Indonesia Issues Long-Awaited Rules to Implement Its Personal Data Protection Law

  • Morocco Orders Political Parties to Follow Data Protection Rules and Label AI Content 

Morocco’s National Commission for the Control of Personal Data Protection (CNDP) has issued guidance requiring political parties to comply with data protection obligations during the country’s legislative elections scheduled for 23 September 2026. Parties have been reminded to declare personal-data processing to the CNDP before commencing such processing, comply with purpose and retention limitations, and ensure that political opinions are not processed without explicit consent. The regulator also cautioned against direct outreach or marketing without prior consent. 

The guidance also introduces a significant AI governance dimension to Morocco’s electoral framework. Political parties have been directed to clearly flag AI-generated content, while broadcasters face restrictions on airing AI-generated or altered election material that could mislead the public. Such content may be used for informational, explanatory or verification purposes where its artificial nature is clearly disclosed. 

READ MORE - Morocco Orders Political Parties to Follow Data Protection Rules and Label AI Content 

© 2024-26 GoTrust

India

Noida

303, Tower C, ATS Bouquet, Noida Sector 132, U.P.

mumbai

1st Floor, Raheja Platinum, WeWork, K, Marol, Andheri East, Mumbai, Maharashtra 400059

Bengaluru

Workden Exucutive 2, Address: 372, 100 Feet Road, HAL 2nd Stage, Indiranagar, Bengaluru, Karnataka 560008

UAE

DIFC Innovation Hub, Gate Avenue, Zone D, Co-working Space Level 1 Al Mustaqbal St, Dubai

Netherlands

Cuserpark Amsterdam, De Cuserstraat 91, 1081CN, Amsterdam, Netherlands

© 2024-26 GoTrust

India

Noida

303, Tower C, ATS Bouquet, Noida Sector 132, U.P.

mumbai

1st Floor, Raheja Platinum, WeWork, K, Marol, Andheri East, Mumbai, Maharashtra 400059

Bengaluru

Workden Exucutive 2, Address: 372, 100 Feet Road, HAL 2nd Stage, Indiranagar, Bengaluru, Karnataka 560008

UAE

DIFC Innovation Hub, Gate Avenue, Zone D, Co-working Space Level 1 Al Mustaqbal St, Dubai

Netherlands

Cuserpark Amsterdam, De Cuserstraat 91, 1081CN, Amsterdam, Netherlands

© 2024-26 GoTrust

India

Noida

303, Tower C, ATS Bouquet, Noida Sector 132, U.P.

mumbai

1st Floor, Raheja Platinum, WeWork, K, Marol, Andheri East, Mumbai, Maharashtra 400059

Bengaluru

Workden Exucutive 2, Address: 372, 100 Feet Road, HAL 2nd Stage, Indiranagar, Bengaluru, Karnataka 560008

UAE

DIFC Innovation Hub, Gate Avenue, Zone D, Co-working Space Level 1 Al Mustaqbal St, Dubai

Netherlands

Cuserpark Amsterdam, De Cuserstraat 91, 1081CN, Amsterdam, Netherlands