
Temples collect devotee names, phone numbers, addresses and PAN for receipts. Credit societies hold KYC, income and loan data for every member. Under the Digital Personal Data Protection Act, 2023, both act as “data fiduciaries” — responsible for how that data is collected, used and protected.
This article is general guidance, not legal advice. Please confirm your obligations with your legal adviser.
The key principles
- Consent: collect personal data for a clear, stated purpose with the person’s consent (or another lawful basis)
- Purpose limitation: use it only for that purpose
- Data minimisation: collect only what you need
- Accuracy and retention: keep it correct, and delete it when no longer needed
- Security safeguards: protect it against breaches
- Rights: let people access, correct and erase their data, and raise grievances
What this means day to day
- Add a short consent notice to donation, booking and membership forms
- Stop collecting fields you never use
- Restrict who can see and export devotee or member lists
- Keep an audit log of who accessed or changed records
- Name a contact for privacy requests and grievances
- Have a plan for reporting and handling a data breach
Penalties are significant
The Act provides for penalties that can run into crores of rupees for failures such as not taking reasonable security safeguards. Beyond the law, a leak of devotee or member data damages the trust that institutions depend on.
Start with three steps this month
- List where personal data is collected and stored — including WhatsApp groups and Excel files
- Remove access for people who no longer need it
- Move records out of shared spreadsheets into a system with access control and backups



