India - Data Governance Framework
Draft National Data Governance Framework Policy / India Data Accessibility and Use Policy (drafts)
India
RAI-IN-NA-DNDGIXX-2022The Ministry of Electronics & Information Technology (MeitY) released two related draft instruments in 2022: the Draft India Data Accessibility and Use Policy (Feb 2022) and a revised Draft National Data Governance Framework Policy (May 2022). The revised draft focuses on creating an institutional architecture (an India Data Management Office and India Datasets programme) to enable safe access to anonymized non‑personal government data for research and innovation while excluding controversial monetisation proposals from the earlier draft.
Summary
Background and Purpose: In 2022 the Government of India, through the Ministry of Electronics & Information Technology (MeitY), released two public consultation drafts addressing public-sector data access and non-personal data governance. The earlier Draft India Data Accessibility and Use Policy (published February 21, 2022) proposed a comprehensive institutional architecture for public-sector data management (including an India Data Office and India Data Council) and controversially included provisions permitting pricing/licensing of certain government datasets. Following widespread stakeholder criticism, MeitY released a revised Draft National Data Governance Framework Policy (published May 26, 2022) that removed explicit monetisation provisions and refocused on safely enabling access to anonymized non-personal datasets for Indian researchers, startups and government-to-government use. Institutional architecture: The May draft proposes creation of an India Data Management Office (IDMO) under the Digital India Corporation to develop rules, standards, toolkits and platforms for secure sharing of anonymized non-personal government datasets and to operate an "India Datasets" platform. It further envisages Data Management Units and designated Chief Data Officers (CDOs) in ministries/departments and encourages state adoption and coordination with line ministries. Scope and data types: The drafts are primarily targeted at non-personal and anonymized datasets held by Central government entities; state adoption is encouraged. The May draft clarifies that data sharing will be subject to anonymisation standards and other safeguards and that designated IDMO platforms will process dataset requests. Standards, APIs and toolkits: Both drafts emphasize standardized metadata, quality, interoperability and APIs for "whole-of-government" data management. They propose a data‑sharing toolkit (risk assessment, anonymisation guidance, restricted-access mechanisms) and technical standards to support safe reuse. Access model and negative list: The draft framework adopts an "open by default" posture for government data with exceptions captured via a negative list or restricted access categories defined by ministries. The India Datasets programme is intended to give researchers and startups prioritized access to curated anonymized datasets through IDMO-designated platforms. Private sector engagement: The May draft removes compulsory monetisation and instead proposes to "encourage" voluntary contributions of non-personal datasets by private entities and to accelerate inclusion of private datasets into the India Datasets programme under IDMO guidelines. Privacy and legal alignment: MeitY stresses that anonymisation, privacy-by-design and compliance with India’s legal framework (including the IT Act and any data protection laws) are prerequisites for sharing; the draft anticipates future harmonisation with data protection legislation and international norms. Consultation and next steps: Both drafts were published for public consultation; the May draft was open for inputs with a consultation deadline in June 2022, and MeitY indicated the NDGFP was under finalization in official responses to Parliament. Primary official materials include the MeitY draft documents and Press Information Bureau statements outlining objectives and institutional proposals. (Primary sources: MeitY draft documents and the Government of India press release.)
Full article
Read full text ↗Overview
The Draft India Data Accessibility and Use Policy (published 21 February 2022) and the subsequent Draft National Data Governance Framework Policy (published 26 May 2022) represent MeitY's iterative policy effort to make government-held non-personal and anonymized datasets more discoverable and usable for research, startups and intragovernmental purposes. The May 2022 draft reframes and narrows the earlier approach by removing explicit market‑pricing/monetisation provisions and by proposing a governance and implementation architecture centered on an India Data Management Office (IDMO) and an "India Datasets" platform. The drafts aim to standardize metadata, APIs, anonymisation and risk assessment tools to support a "whole-of-government" data ecosystem, while preserving privacy, security and legal compliance as core principles. See the MeitY draft and official government statement for the authoritative text and status updates: Draft National Data Governance Framework Policy (MeitY, May 2022) and Press Information Bureau release (27 Jul 2022).
Definitions
The drafts distinguish: (a) non-personal data — datasets that do not permit identification of an individual; (b) anonymized data — data that has undergone techniques intended to prevent re-identification; (c) India Datasets programme — a curated repository of anonymized non-personal data for research and startups; and (d) IDMO — the central coordinating office proposed under Digital India Corporation for rule‑making, standards and platform management. The drafts propose domain‑specific metadata, "high-value datasets" classification, a negative list (non-shareable datasets) and restricted access categories to govern release and reuse.
Governance and Institutional Framework
The central institutional design in the May 2022 draft places the IDMO within the Digital India Corporation under MeitY with responsibilities to design the India Datasets platform, issue technical rules/standards (metadata, anonymisation, retention), operate a dataset request processing mechanism and coordinate with line ministries, states and industry. Every ministry/department is expected to create Data Management Units (DMUs) led by Chief Data Officers (CDOs) to operationalize standards, prepare datasets for inclusion, and manage intra‑governmental sharing. Consultative bodies and periodic multi‑stakeholder consultations are foreseen to refine guidelines and maintain dialogue with industry and states; the IDMO is required to consult ministries and stakeholders semi‑annually according to the draft. The proposal anticipates rule‑making powers delegated to IDMO for operational standards, though primary statutory enforcement remains with central law and future data protection legislation. (Official statement: Press Information Bureau; draft text: MeitY draft.)
Key Focus Areas
The drafts emphasize multiple programmatic priorities: (1) Open-by-default government data with defined exceptions; (2) Standardisation — metadata schemas, APIs and interoperability across ministries to enable "whole-of-government" integration; (3) Privacy and anonymisation — mandatory application of anonymisation techniques and risk-assessment toolkits prior to dataset release; (4) India Datasets programme — creation of curated anonymized datasets available via IDMO-authorized platforms for Indian researchers, startups and government users; (5) Risk-managed access — a tiered access model with open, restricted and negative-list categories, plus secure processing environments for sensitive analytics; (6) Capacity building — DMUs, training and national standards to strengthen data stewardship across departments; (7) Voluntary private-sector contribution — an encouragement model (not mandatory) for private actors to onboard non-personal datasets into the India Datasets programme; and (8) Alignment with legal frameworks — ensuring that data sharing occurs within existing national laws and in anticipation of future data protection rules.
Implementation Framework
Operationalisation in the May draft centers on IDMO tasks: build and operate the India Datasets platform, publish rulebooks and toolkits (anonymisation, data quality, retention), define APIs and technical standards, process dataset requests (including researcher/startup access), and coordinate DMUs/State Data Officers. Ministries are expected to inventory datasets, classify them against the negative/restricted lists, implement metadata and API endpoints, and channel dataset requests through the IDMO platform. The draft also envisages technical controls including secure enclaves, audit trails, licensing/terms-of-use templates and citation/attribution obligations for dataset users. For G2G access, a separate standard mechanism is to be developed by IDMO to streamline inter‑departmental exchange.
Monitoring and Evaluation
The draft proposes periodic reporting by IDMO on dataset inclusions, requests processed, usage patterns, anonymisation audits and compliance checks. IDMO is expected to publish performance scorecards and hold semi‑annual stakeholder consultations to review standards and operational friction points. Data quality indicators, timeliness, API uptimes and request turnaround times form part of monitoring metrics. The draft recommends independent audits of anonymisation processes and an escalation mechanism for suspected re‑identification or misuse to ensure trust and continual improvement.
Penalties, Liability, and Appeals
The May 2022 draft focuses on governance, standards and access procedures but does not establish a broad novel penal code for data misuse; instead it contemplates administrative sanctions, revocation of platform access, contractual remedies under dataset license terms and escalation to existing law enforcement or regulator frameworks (e.g., actions under the IT Act or future data protection law). The draft envisages that IDMO will define compliance obligations and remedial processes, while determinations of criminal liability or regulatory fines will remain governed by applicable national statutes and sectoral rules until specific enforcement rules are prescribed.
Relationship to Other Instruments
The drafts are explicitly designed to complement existing Indian instruments: the National Data Sharing and Accessibility Policy (NDSAP 2012), Open Government Data initiatives, the Information Technology Act 2000 and ongoing discussions on data protection and digital personal data laws. The May draft also references the 2020 Expert Committee report on Non‑Personal Data (Kris Gopalakrishnan Committee) and seeks to operationalize several recommendations while removing some contested provisions (notably monetisation) present in the February draft. The framework envisions harmonisation with sectoral data regimes and international guidelines as implementation proceeds.
International Alignment
MeitY's drafts seek to align technical and governance standards with international best practice on anonymisation, data interoperability and cross‑border legal obligations, while prioritizing a domestic repository of India‑specific datasets for research. The policy signals intent to coordinate with international frameworks for privacy-preserving analytics and with multilateral digital economy initiatives, but it also emphasizes national data sovereignty and domestic researcher/startup access as primary objectives. Implementation design includes compatibility with internationally recognized anonymisation and security standards to facilitate potential future cross‑jurisdictional collaboration.
Implementation Timeline
| Milestone | Target / Actual Date |
|---|---|
| Draft India Data Accessibility & Use Policy published for consultation | 2022-02-21 |
| Draft National Data Governance Framework Policy published for consultation | 2022-05-26 |
| Public consultation / inputs deadline (May draft) | 2022-06-11 |
| PIB public statement / Lok Sabha written reply noting draft under finalisation | 2022-07-27 |
Sources and References
| Source | Type |
|---|---|
| Draft National Data Governance Framework Policy (MeitY, 26 May 2022) | Primary Source |
| Draft India Data Accessibility and Use Policy (e-Gov Standards portal; Feb 2022 listing) | Primary Source (government-hosted consultation) |
| Press Information Bureau: National Data Governance Framework Policy (27 Jul 2022) | Primary Source (official statement) |
Requirements for a company
What an organisation has to do under India - Data Governance Framework, at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Not yet in force (Draft). These requirements apply once the instrument takes effect and may change before then.
Must do
12- Establish and maintain a Data Management Unit within your ministry or department.Every Indian government ministry or department.
- Designate a Chief Data Officer to lead the Data Management Unit.Every Indian government ministry or department.
- Build and operate the India Datasets platform and associated request processing mechanisms.India Data Management Office (IDMO).
- Publish rulebooks, toolkits, APIs, and technical standards for data quality and anonymisation.India Data Management Office (IDMO).
- Inventory all datasets and classify them into open, restricted, or negative list categories.Indian government ministries and departments.
- Mandatorily apply anonymisation techniques and risk assessment toolkits before releasing datasets.Indian government ministries and departments releasing datasets.
- +6 more in the table below
Must not do
0Nothing in this category.
Should do
2- Encourage private sector actors to voluntarily contribute non-personal datasets to the programme.India Data Management Office (IDMO).
- Conduct independent audits of anonymisation processes and establish an escalation mechanism.India Data Management Office (IDMO).
Should not do
0Nothing in this category.
Who must do what
The obligations under India - Data Governance Framework, most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Every Indian government ministry or department. | Establish and maintain a Data Management Unit within your ministry or department. “Every ministry/department is expected to create Data Management Units (DMUs) led by Chief Data Officers (CDOs).” | — | Governance and Institutional Framework | Critical |
| 2 | Every Indian government ministry or department. | Designate a Chief Data Officer to lead the Data Management Unit. “Every ministry/department is expected to create Data Management Units (DMUs) led by Chief Data Officers (CDOs).” | — | Governance and Institutional Framework | Critical |
| 3 | India Data Management Office (IDMO). | Build and operate the India Datasets platform and associated request processing mechanisms. “Operationalisation in the May draft centers on IDMO tasks: build and operate the India Datasets platform...” | — | Implementation Framework | Critical |
| 4 | India Data Management Office (IDMO). | Publish rulebooks, toolkits, APIs, and technical standards for data quality and anonymisation. “IDMO tasks: ...publish rulebooks and toolkits (anonymisation, data quality, retention), define APIs and technical standards...” | — | Implementation Framework | Critical |
| 5 | Indian government ministries and departments. | Inventory all datasets and classify them into open, restricted, or negative list categories. “Ministries are expected to inventory datasets, classify them against the negative/restricted lists...” | — | Implementation Framework | Critical |
| 6 | Indian government ministries and departments releasing datasets. | Mandatorily apply anonymisation techniques and risk assessment toolkits before releasing datasets. “mandatory application of anonymisation techniques and risk-assessment toolkits prior to dataset release” | Before dataset release | Key Focus Areas | Critical |
| 7 | Indian government ministries and departments. | Implement metadata schemas and API endpoints compliant with IDMO technical standards. “Ministries are expected to... implement metadata and API endpoints...” | — | Implementation Framework | Important |
| 8 | Indian government ministries and departments. | Channel all dataset requests through the India Data Management Office (IDMO) platform. “Ministries are expected to... channel dataset requests through the IDMO platform.” | — | Implementation Framework | Important |
| 9 | Entities providing access to restricted datasets. | Utilize secure processing environments and audit trails for sensitive or restricted datasets. “The draft also envisages technical controls including secure enclaves, audit trails...” | — | Implementation Framework | Important |
| 10 | Users of datasets from the India Datasets programme. | Cite and attribute source data according to licensing and terms of use. “licensing/terms-of-use templates and citation/attribution obligations for dataset users.” | Upon use or publication | Implementation Framework | Important |
| 11 | India Data Management Office (IDMO). | Consult ministries and stakeholders semi-annually to refine guidelines and maintain dialogue. “the IDMO is required to consult ministries and stakeholders semi‑annually according to the draft.” | Semi-annually | Governance and Institutional Framework | Important |
| 12 | India Data Management Office (IDMO). | Report periodically on dataset inclusions, requests processed, usage patterns, and compliance checks. “The draft proposes periodic reporting by IDMO on dataset inclusions, requests processed, usage patterns...” | Periodically | Monitoring and Evaluation | Important |
| 13 | India Data Management Office (IDMO). | Encourage private sector actors to voluntarily contribute non-personal datasets to the programme. “Voluntary private-sector contribution — an encouragement model (not mandatory) for private actors to onboard non-personal datasets” | — | Key Focus Areas | Recommended |
| 14 | India Data Management Office (IDMO). | Conduct independent audits of anonymisation processes and establish an escalation mechanism. “The draft recommends independent audits of anonymisation processes and an escalation mechanism...” | — | Monitoring and Evaluation | Recommended |
Related Regulations
Report by the Committee of Experts on Non-Personal Data Governance Framework (Gopalakrishnan Committee)
India92% similar
Report of the Committee on Platforms and Data on Artificial Intelligence (MeitY report)
India90% similar
India AI Governance Guidelines: Enabling Safe and Trusted AI Innovation
India89% similar
National Data Governance Strategy (Nacionālā datu pārvaldības stratēģija) - (in development)
Latvia88% similar
AIRAWAT (AI Research, Analytics and Knowledge Assimilation platform) - Approach Paper
India88% similar
© Regulations.AI · updated on 13-Jun-2026