Parliament takes up a sweeping data governance bill
The draft legislation would rewrite how public institutions collect, share and retain citizen data — consolidating a patchwork of departmental rules into a single accountability standard, and forcing a reckoning over who answers when records leak.
Published Today, 06:10 IST · Updated Today, 09:42 IST · 8 min read

In 30 seconds
- A comprehensive data governance bill has been listed for discussion this session.
- It proposes a single accountability standard across central and state bodies.
- Civil society groups are pressing for narrower exemptions for security and state agencies.
- A committee referral is expected before any floor vote.
The story
For nearly a decade, India's approach to citizen data has been governed by a scattered set of departmental circulars, sectoral rules and court-mandated safeguards rather than a single statute. The bill introduced this session is an attempt to close that gap, replacing overlapping frameworks with one accountability standard that applies uniformly to central ministries, state departments and the public bodies that sit beneath them.
At its core, the draft requires every public authority that holds citizen data to publish a register disclosing what it collects, the legal basis for collecting it, and how long it intends to keep it. Officials involved in drafting the bill say the register requirement is meant to end the practice of departments holding records indefinitely simply because no rule forced them to specify a retention period.
The breach-notification provisions have drawn the most scrutiny from technologists and privacy lawyers. The draft sets a 90-day outer limit for public authorities to disclose a data breach to an oversight body, a window that supporters call workable and critics call generous relative to global norms, where 72-hour disclosure windows are increasingly standard.
Supporters argue that a single statute reduces the compliance confusion that has dogged both citizens seeking redress and administrators trying to interpret conflicting departmental rules. "A single standard is only meaningful if the exemptions are narrow and reviewable," said a senior fellow at a Delhi-based public policy research centre who has studied earlier drafts of the framework. "Otherwise you've just centralised the ambiguity instead of removing it."
The sharpest disagreement concerns the carve-outs available to security and intelligence-linked agencies, which under the current text can seek broad exemptions from disclosure and retention limits on national-security grounds. Opposition members and several civil society coalitions argue the exemption clause, as worded, could swallow the rule itself; the government maintains such carve-outs mirror standard practice in comparable democracies.
A parallel concern, raised largely by state government representatives, is administrative capacity. Several states have told the joint committee examining the bill that meeting the register and retention requirements within the proposed implementation timeline would require hiring and training data officers at a scale few state IT departments currently have budgeted for.
Key numbers
48
Clauses in the draft bill
As tabled this session
12
Central ministries directly in scope
Per the bill's schedule of covered authorities
90 days
Proposed outer limit for breach disclosure
From date of detection, per draft text
Timeline
- 3 weeks ago
Drafting
Cabinet clears the draft bill for introduction after inter-ministerial consultations.
- 10 days ago
Circulation
Draft circulated to members ahead of the session, along with an explanatory memorandum.
- 6 days ago
Response
Departments submit written comments on the scope of covered authorities.
- 4 days ago
Listing
Business advisory committee lists the bill for debate this session.
- 2 days ago
Reaction
A coalition of civil society groups publishes a joint note flagging the security exemption clause.
- Today
Debate opens
Floor debate begins; a committee referral is widely expected before any vote.
What they said
“A single standard is only meaningful if the exemptions are narrow and reviewable.”
“We support the register requirement in principle, but the compliance timeline assumes a level of staffing most state departments simply do not have.”
What we know
- The draft has been formally listed for discussion and applies to both central and state public bodies.
- A dataset register and defined retention limits are core requirements of the text as tabled.
- The breach-notification window proposed is 90 days from detection.
The Scope
What happened · Why it matters · What's nextWhat happened
A comprehensive data governance bill was listed for discussion in Parliament this session, proposing one accountability standard for how public institutions collect, hold and disclose citizen data.
Why it matters
Data rules decide who can see your records, how long they are kept, and what recourse exists when they leak. A single statutory standard would change day-to-day administration in every department that touches citizen data, from ration cards to health records.
What we know
- The draft has been formally listed for discussion and applies to both central and state public bodies.
- A dataset register and defined retention limits are core requirements of the text as tabled.
- The breach-notification window proposed is 90 days from detection.
What's disputed
- The width of security-agency exemptions: the government characterises them as standard practice, while critics call the drafting open-ended.
- Whether state governments have the administrative capacity to comply within the proposed implementation timeline.
- Whether the 90-day breach window is adequate compared with international disclosure norms.
What's next
- 01Committee stage referral is expected within the week.
- 02A written-submissions window will open for state governments to flag implementation concerns.
- 03Any revised draft would need to return to the floor before a vote is scheduled.
Sources
- Primary documentMinistry briefing note circulated to reportersDistributed at the post-meeting press briefing.
- Official statementOfficial spokesperson statementDelivered on the record to the press pool.
- ReportingBharatScope field reportingOriginal interviews and on-the-ground verification by BharatScope correspondents.
Scope modules are editorial context written by the newsroom. AI-assisted summaries, where used, are labelled and based on cited reporting.
Coverage Lens
We compare claims, evidence and emphasis — not political labels.
BharatScope
A comprehensive data governance bill was listed for discussion in Parliament this session, proposing one accountability standard for how public institutions collect, hold and disclose citizen data.
Other coverage
- A leading national daily — Leads on the administrative burden the bill places on state governments.
- A business and markets wire service — Focuses on compliance costs for private contractors handling government data.
- A legal affairs journal — Examines the precise drafting of the exemption clause against comparable statutes abroad.
What sources agree on
- — The bill has been listed for discussion this session.
- — It covers both central and state public bodies.
What is disputed
- ≠ How broad the exemptions for security agencies actually are in practice.
- ≠ Whether the compliance timeline given to states is realistic.
Sources
- Primary documentMinistry briefing note circulated to reportersDistributed at the post-meeting press briefing.
- Official statementOfficial spokesperson statementDelivered on the record to the press pool.
- ReportingBharatScope field reportingOriginal interviews and on-the-ground verification by BharatScope correspondents.
Corrections: none recorded for this story. Original reporting is distinguished from AI-assisted context throughout.