
Introduction
The Digital Personal Data Protection Act, 2023 (“Act“) establishes a comprehensive framework for the protection of personal data in commercial processing including through the requirement of consent, while preserving carve-outs for the processing for legitimate uses, inter alia, by the State in the discharge of public functions. Yet, between these two ends of the spectrum lies an important category of organizations whose role is neither purely commercial nor governmental: non-governmental organizations (“NGOs“).
Whether engaged in education, healthcare, legal aid, or social welfare, NGOs routinely collect and process extensive amounts of personal data to identify beneficiaries, collect resources, deliver services, and report to government bodies and funding agencies. Often, this processing enables individuals to access benefits, assistance or entitlements that may otherwise remain out of reach. However, despite a clear public interest underlying NGO activities, the Act does not adequately address the distinct position that NGOs occupy.
Practical Challenges for NGOs
Under the Act, NGOs may qualify either as a ‘data fiduciary’ or a ‘data processor’, depending on the role they play in relation to the processing of personal data. This distinction is critical because the primary responsibility for compliance under the Act rests with the data fiduciary. Thus, where an NGO determines the purpose and means of processing personal data, it assumes the role of a data fiduciary and the burden of compliance with the Act, including the obligation to obtain consent that lies with it. However, where an NGO processes personal data only on behalf of another entity that determines the purpose and means of such processing (i.e., a data fiduciary), such NGO will be treated as a data processor for the purposes of the Act, and the liability will fall squarely on the data fiduciary. It is a reasonable presumption that NGOs, which often have financial constraints, might opt to act as a data processor and no longer be the primary decision-maker.
In addition to the financial implications, consent-related challenges may pose a host of difficulties for NGOs. Beneficiaries may lack formal education, reside in inaccessible areas, have incomplete or unclear records, lack adequate identification details, or have limited access to the internet, all of which may affect the quality of ‘informed’ consent and an NGO’s ability to demonstrate that valid consent was obtained. This issue will become even more acute where NGOs work with children or persons with disabilities (“PWDs“). Section 9 of the Act generally requires a data fiduciary to obtain verifiable consent from a parent or lawful guardian before processing children’s or PWDs’ personal data. For NGOs working with abandoned children and PWDs, trafficked minors, or children and PWDs rescued from abusive environments, obtaining consent from a lawful guardian may be impossible or even contrary to their best interests. In the absence of specific provisions for welfare organizations, including NGOs, the Act offers limited guidance on how such organizations should navigate consent requirements in these circumstances.
No Clear Exemption in the Act
A possible basis for exempting certain NGO activities may lie in Section 17(2)(b) of the Act, which excludes processing undertaken for research, archiving or statistical purposes, provided that such processing is not used to make decisions relating to data principals and complies with prescribed standards. At first glance, this provision could cover several NGO activities involving the systematic collection and analysis of data. However, neither the Act nor the underlying rules define the scope of ‘research, archiving or statistical purposes’, leaving considerable uncertainty around its application.
This uncertainty is significant because NGO work often combines operational and analytical functions. Data initially collected for research or statistical purposes may later be used to identify beneficiaries, provide benefits or implement a welfare scheme. Once the data is used to make decisions concerning data principals, the Section 17(2)(b) exemption would no longer apply. As a result, an NGO may need to obtain specific consent before relying on such data, even where the subsequent use serves a welfare-oriented purpose.
Accordingly, the research exemption offers only limited assistance to NGOs. Given the uncertainty surrounding its scope, it is unlikely to provide a reliable basis for core NGO functions such as beneficiary management or welfare service delivery.
The EU GDPR’s More Flexible Approach
A useful comparison may be drawn with the European Union’s General Data Protection Regulation (“EU GDPR“). Article 6 of the EU GDPR recognizes circumstances in which processing personal data without consent will be lawful. However, Article 6(1)(f) also permits processing where it is necessary for the legitimate interests pursued by a data fiduciary (referred to as a ‘controller’ in the EU GDPR) or by a third party, provided those interests are not overridden by the rights and freedoms of the data principal. This balancing mechanism recognizes that socially beneficial processing cannot always depend solely on consent or express statutory authorization.
Article 6(1)(f) therefore gives organizations, including NGOs, a degree of flexibility not available under the Act, where the purpose of processing is legitimate and beneficial. Instead of relying on an exhaustive list of permitted purposes, the EU GDPR allows a contextual assessment of necessity, legitimacy and competing rights.
By contrast, the Act currently contains no comparable lawful basis for non-State organizations to independently undertake legitimate processing without consent. Section 7 of the Act permits processing without consent in limited circumstances described as ‘certain legitimate uses’. However, Section 7(b) allows only the State and its instrumentalities to process personal data without consent for providing subsidies, benefits, services, certificates, licenses or permits to data principals, subject to compliance with prescribed standards. The provision recognizes that, in the context of welfare delivery, insisting on consent in every case may be impractical and may delay the implementation of welfare schemes. Yet, this carve-out is confined to the State and its instrumentalities and does not extend to other organizations acting in public interest, including NGOs.
This creates another practical difficulty. NGOs frequently process personal data while implementing welfare programs, including by conducting surveys, identifying beneficiaries and collecting information required to facilitate access to benefits by data principals. Where an NGO acts as a data fiduciary, it would generally be required to obtain consent from beneficiaries before processing their personal data. In contexts involving vulnerable or hard-to-reach communities, this requirement may hamper timely welfare delivery.
This issue is particularly significant because modern welfare delivery is rarely undertaken by the State alone. Government agencies often rely on NGOs as implementation partners for welfare schemes. In such collaborations, the cleanest legal route under Section 7(b) is for the State to remain the data fiduciary by determining the purpose and means of processing, while the NGO acts only as a data processor on the State’s behalf.
In practice, however, NGO-State collaborations do not always fit neatly within this outsourcing model. While the State may define the broad objective of the processing, NGOs often make key operational decisions such as survey methodology, questionnaire design, sampling approach and field-level data collection. For example, in Saharanpur’s Mission Sunehra Kal, Pratham Foundation (the NGO) was not confined to collecting data on the State’s instructions but helped in preparing and implementing the baseline and the endline surveys, exercising significant influence over the survey design[1].
These operational decisions, when left to NGOs, may amount to determining the means of processing. In such cases, both the State and the NGO would be treated as data fiduciaries under the Act. The result is an uneven position: the State may rely on Section 7(b) to process data without consent, while the NGO, despite acting in furtherance of the same welfare objective, may still be required to obtain consent.
Conclusion
The Act clearly brings NGOs within India’s data protection framework, but it does not adequately account for their distinctive role in processing personal data to deliver public welfare rather than pursue commercial gain. Section 7(b) recognizes the State’s need to process personal data without consent for welfare delivery but offers no similar accommodation for NGOs. The research exemption, while potentially relevant, remains too narrow and uncertain to support core NGO functions. The framework for children’s data also leaves critical questions unresolved for NGOs working with vulnerable children.
The solution is not to exempt NGOs from data protection obligations. Organizations that handle sensitive and personal data must remain subject to strong privacy safeguards. What is needed instead is clearer recognition of legitimate social-interest processing, more precise guidance on the research exemption, and a practical framework for child-welfare situations where ordinary consent requirements may be difficult or inappropriate to apply.
Until such clarification is provided, NGOs will need to navigate the Act by carefully defining their roles as data fiduciaries or data processors, identifying an appropriate lawful basis for each processing activity, and adopting privacy practices that balance compliance with the realities of welfare delivery. As India’s data protection regime evolves, the way these issues are resolved will determine not only how NGOs comply with the law, but also how effectively they can continue delivering essential public welfare services.
[1] NITI for States, Mission Sunehra Kal – Poshan Bhi Padhai Bhi: Saharanpur District, Uttar Pradesh (State Support Mission, NITI Aayog 2025) <https://www.nitiforstates.gov.in/public-assets/images/20250428_071949_mission-sunehra-kal-final.pdf> accessed 20 July 2026.













