Skip to content
BharatScope

Parliament takes up a sweeping data governance bill

The draft legislation would rewrite how public institutions collect, share and retain citizen data — consolidating a patchwork of departmental rules into a single accountability standard, and forcing a reckoning over who answers when records leak.

BharatScope Newsroom

Published Today, 06:10 IST · Updated Today, 09:42 IST · 8 min read

Journalists and officials outside a parliament building at golden hour
Journalists and officials outside a parliament building at golden hour

In 30 seconds

  • A comprehensive data governance bill has been listed for discussion this session.
  • It proposes a single accountability standard across central and state bodies.
  • Civil society groups are pressing for narrower exemptions for security and state agencies.
  • A committee referral is expected before any floor vote.

The story

For nearly a decade, India's approach to citizen data has been governed by a scattered set of departmental circulars, sectoral rules and court-mandated safeguards rather than a single statute. The bill introduced this session is an attempt to close that gap, replacing overlapping frameworks with one accountability standard that applies uniformly to central ministries, state departments and the public bodies that sit beneath them.

At its core, the draft requires every public authority that holds citizen data to publish a register disclosing what it collects, the legal basis for collecting it, and how long it intends to keep it. Officials involved in drafting the bill say the register requirement is meant to end the practice of departments holding records indefinitely simply because no rule forced them to specify a retention period.

The breach-notification provisions have drawn the most scrutiny from technologists and privacy lawyers. The draft sets a 90-day outer limit for public authorities to disclose a data breach to an oversight body, a window that supporters call workable and critics call generous relative to global norms, where 72-hour disclosure windows are increasingly standard.

Supporters argue that a single statute reduces the compliance confusion that has dogged both citizens seeking redress and administrators trying to interpret conflicting departmental rules. "A single standard is only meaningful if the exemptions are narrow and reviewable," said a senior fellow at a Delhi-based public policy research centre who has studied earlier drafts of the framework. "Otherwise you've just centralised the ambiguity instead of removing it."

The sharpest disagreement concerns the carve-outs available to security and intelligence-linked agencies, which under the current text can seek broad exemptions from disclosure and retention limits on national-security grounds. Opposition members and several civil society coalitions argue the exemption clause, as worded, could swallow the rule itself; the government maintains such carve-outs mirror standard practice in comparable democracies.

A parallel concern, raised largely by state government representatives, is administrative capacity. Several states have told the joint committee examining the bill that meeting the register and retention requirements within the proposed implementation timeline would require hiring and training data officers at a scale few state IT departments currently have budgeted for.

Key numbers

48

Clauses in the draft bill

As tabled this session

12

Central ministries directly in scope

Per the bill's schedule of covered authorities

90 days

Proposed outer limit for breach disclosure

From date of detection, per draft text

Timeline

  1. 3 weeks ago

    Drafting

    Cabinet clears the draft bill for introduction after inter-ministerial consultations.

  2. 10 days ago

    Circulation

    Draft circulated to members ahead of the session, along with an explanatory memorandum.

  3. 6 days ago

    Response

    Departments submit written comments on the scope of covered authorities.

  4. 4 days ago

    Listing

    Business advisory committee lists the bill for debate this session.

  5. 2 days ago

    Reaction

    A coalition of civil society groups publishes a joint note flagging the security exemption clause.

  6. Today

    Debate opens

    Floor debate begins; a committee referral is widely expected before any vote.

What they said

A single standard is only meaningful if the exemptions are narrow and reviewable.

Senior fellow · Public policy research centre, New Delhi

We support the register requirement in principle, but the compliance timeline assumes a level of staffing most state departments simply do not have.

State IT department official · Member, state coordination committee on data governance

What we know

  • The draft has been formally listed for discussion and applies to both central and state public bodies.
  • A dataset register and defined retention limits are core requirements of the text as tabled.
  • The breach-notification window proposed is 90 days from detection.

The Scope

What happened · Why it matters · What's next

What happened

A comprehensive data governance bill was listed for discussion in Parliament this session, proposing one accountability standard for how public institutions collect, hold and disclose citizen data.

Why it matters

Data rules decide who can see your records, how long they are kept, and what recourse exists when they leak. A single statutory standard would change day-to-day administration in every department that touches citizen data, from ration cards to health records.

What we know

  • The draft has been formally listed for discussion and applies to both central and state public bodies.
  • A dataset register and defined retention limits are core requirements of the text as tabled.
  • The breach-notification window proposed is 90 days from detection.

What's disputed

  • The width of security-agency exemptions: the government characterises them as standard practice, while critics call the drafting open-ended.
  • Whether state governments have the administrative capacity to comply within the proposed implementation timeline.
  • Whether the 90-day breach window is adequate compared with international disclosure norms.

What's next

  1. 01Committee stage referral is expected within the week.
  2. 02A written-submissions window will open for state governments to flag implementation concerns.
  3. 03Any revised draft would need to return to the floor before a vote is scheduled.

Sources

  • Primary documentMinistry briefing note circulated to reportersDistributed at the post-meeting press briefing.
  • Official statementOfficial spokesperson statementDelivered on the record to the press pool.
  • ReportingBharatScope field reportingOriginal interviews and on-the-ground verification by BharatScope correspondents.

Scope modules are editorial context written by the newsroom. AI-assisted summaries, where used, are labelled and based on cited reporting.

Coverage Lens

We compare claims, evidence and emphasis — not political labels.

BharatScope

A comprehensive data governance bill was listed for discussion in Parliament this session, proposing one accountability standard for how public institutions collect, hold and disclose citizen data.

Other coverage

  • A leading national dailyLeads on the administrative burden the bill places on state governments.
  • A business and markets wire serviceFocuses on compliance costs for private contractors handling government data.
  • A legal affairs journalExamines the precise drafting of the exemption clause against comparable statutes abroad.

What sources agree on

  • The bill has been listed for discussion this session.
  • It covers both central and state public bodies.

What is disputed

  • How broad the exemptions for security agencies actually are in practice.
  • Whether the compliance timeline given to states is realistic.

Sources

  • Primary documentMinistry briefing note circulated to reportersDistributed at the post-meeting press briefing.
  • Official statementOfficial spokesperson statementDelivered on the record to the press pool.
  • ReportingBharatScope field reportingOriginal interviews and on-the-ground verification by BharatScope correspondents.

Corrections: none recorded for this story. Original reporting is distinguished from AI-assisted context throughout.