DPDP
DPDP
ON
Data Protection Platform (DPP) for Individual Users and
Organizations as per DPDP Act, India
∼ November, 2024 ∼
SUBMITTED BY:
In the digital age, data is a critical asset for individuals and organizations alike. As the use of
personal data grows, so do concerns about privacy, misuse, and the protection of sensitive infor-
mation. The Government of India has introduced the Data Protection and Digital Privacy
(DPDP) Act to address these concerns and provide a legal framework to regulate the collection,
storage, and processing of personal data.
The project aims to develop a platform that facilitates organizations’ compliance with the
DPDP Act and empowers individual users by ensuring transparency and control over their per-
sonal data. The platform will enable organizations to manage personal data in accordance with
legal requirements while giving individuals the power to see how their data is being used and to
exercise their rights under the DPDP Act.
SUMMARY SHEET
1 Title of Project
Data Protection Platform (DPP) for Individual Users and Organizations as per DPDP Act, India
2 Organization(s)
A.
a) Name: Centre for Development of Advanced Computing (CDAC), Kolkata
b) Address: Plot-E2/1, Block-GP, Sector-V, Salt Lake, Kolkata – 700 091
c) Legal Status: Govt. Society R&D Institute under MeitY, Government of India, C-DAC is
a scientific society, under the Department of Electronics & Information Technology, Ministry
of Communications and Information Technology, Government of India.
3 Chief Investigator
A.
a) Name: Ritesh Mukherjee
b) Designation: Scientist F
c) Department: Advanced Signal Processing Group (ASPG)
d) Address: Plot-E2/1, Block-GP, Sector-V, Salt Lake, Kolkata – 700 091
B.
a) Name: Sayak Bhowal
b) Designation: Project Engineer
c) Department: Advanced Signal Processing Group (ASPG)
d) Address: Plot-E2/1, Block-GP, Sector-V, Salt Lake, Kolkata – 700 091
C.
a) Name: Ahindra Kumar Das
b) Designation: Project Engineer
c) Department: Advanced Signal Processing Group (ASPG)
d) Address: Plot-E2/1, Block-GP, Sector-V, Salt Lake, Kolkata – 700 091
1
4 Nature of Project (Check one)
a) Research, Development & Engineering (R, D & E) leading to production capability
b) Application oriented Research, Design and Development (R, D & D) having production poten-
tial □
✓
c) Basic R & D
• Data Sovereignty: Assures individuals and organizations that data is stored and processed
within the legal boundaries defined by the DPDP Act.
Compliance with the DPDP Act is crucial for organizations that collect, process, and store per-
sonal data. This law defines strict guidelines for how personal data must be handled to protect the
privacy and rights of individuals. The platform aims to help organizations meet these guidelines
by providing the tools and systems necessary to manage user data responsibly.
Accountability is a key principle of data protection laws, requiring organizations to take respon-
sibility for how they collect, store, process, and share personal data. The platform will help ensure
that organizations can track, log, and report on their data usage, demonstrating their adherence
to the DPDP Act.
Data sovereignty refers to the principle that personal data is subject to the laws and governance
structures of the country where it is collected. The DPDP Act mandates that certain categories of
data, particularly sensitive and critical personal data, must be stored and processed within India.
The platform ensures that both organizations and individuals are confident that their data remains
within the legal boundaries defined by the DPDP Act.
2
Figure 1: Aadhaar validation by Service Provider
Expected Outcomes:
1. Web API for Aadhaar validation.
2. Mobile Apps Aadhaar information Fetching.
Proposed Technology:
The technology includes several interdisciplinary techniques with an emphasis on
• React.js
• Python/Django
• PostgreSQL
• Role-based access control (RBAC)
• Cloud Computing
• RESTful API
3
7 Expected outcome in physical terms (as applicable)
a. Development outcome
• Web API for Aadhaar Validation.
• Mobile Application for Aadhaar Detail Fetching
• User Portal for allowing them to monitor the processing of their data and identify who is
handling it.
• Integration Support
2nd Year
• Training Support
4
13 Total Budget outlay
(Rs. in lakhs)
Years
Head 1st 2nd Total
14
5
Additional Information Required
There are several cases in India where the proposed solution can be enforced to implement to
maintain DPDP act properly. Few examples are given below,
• When a guest checks into a hotel, the receptionist requests a government-issued ID. Most
often, guests submit a photocopy of their Aadhaar card, which contains unnecessary personal
information, such as their photo and address that does not need to be stored. If the pro-
posed arrangement is implemented, the Aadhaar number will be verified against the Aadhaar
database, and the hotel authority will not access the guest’s personal information. Only a
generated QR code needs to be stored for that guest. If law enforcement agencies require
information about a specific guest for investigation, they can retrieve it by scanning the QR
code with proper authorization.
• The same procedure for purchasing a SIM card can be applied, allowing the service provider
to verify the customer’s identity using biometric data. However, they should not retain this
biometric information. If this arrangement is established, the service provider can confirm
the customer’s identity without storing personal information.
• A similar arrangement can prevent the misuse of hospital patient records by implementing a
QR code system that allows only authorized personnel to access the records.
6
DETAILS OF THE PROPOSAL
1 Title of Project
Data Protection Platform (DPP) for Individual Users and Organizations as per DPDP Act, India
2 Chief Investigator
(i)
a) Name: Ritesh Mukherjee
b) Designation: Scientist F
c) Department: Advanced Signal Processing Group (ASPG)
d) Address: Plot-E2/1, Block-GP, Sector-V, Salt Lake, Kolkata – 700 091
e) Email: [email protected]
f) Contact: 9433493563
7
b) Designation: Project Engineer
c) Department: Advanced Signal Processing Group (ASPG)
d) Address: Plot-E2/1, Block-GP, Sector-V, Salt Lake, Kolkata – 700 091
e) Email: [email protected]
f) Contact: 9038629749
8
b) Existing manpower and other personnel with names available for the project on
full-time basis.
• Sayak Bhowal, Project Engineer
• Ahindra Kumar Das, Project Engineer
9
PART II: TECHNICAL INFORMATION
Task
Challenges
Proposed Approach
The proposed approach consists of fewer interrelated components that together ensure compliance
with the DPDP Act, 2023. The components are described below and a related block diagram is
presented in Figure 3.
Components
Web API The web API validates Aadhar numbers for organizations using biometric support,
returning a binary True/False result. Upon successful validation, it generates an encrypted
QR code for the organization and stores 28 Aadhar-related information in the database for
future reference. CDAC, Kolkata, will develop this Web API.
10
Mobile Apps The mobile app serves as the main interface for authorized agencies, including
law enforcement, to scan QR codes and access user details retrieved from previously stored
Aadhar verification data. CDAC, Kolkata, will develop this Mobile Apps.
User Portal The user portal serves as the main interface for individuals to engage with the
platform, allowing them to monitor the processing of their data and identify who is handling
it. CDAC, Kolkata, will develop this User Portal.
Database The database stored users’ Aadhar information along with the organizations that val-
idated it. The database is the integral part of Web API, Mobile Apps and User Portal.
CDAC, Kolkata, will design this database and maintain the database under AMC period.
Organization portal The organization portal is a third-party web or mobile application that
allows organizations to collect users’ Aadhaar numbers and biometric information for valida-
tion. It should be connected to the CDAC-developed web API for Aadhaar data validation
services.
Cloud The entire system is deployed in the cloud, providing organizations with a web API service
for implementation.
Table 1: Caption
11
3 Need, forecast and urgency for the technology proposed
to be developed with justification such as importance of
know-how, import substitution role, pay off w.r.t. pur-
chase of know-how or development of technology com-
petitiveness, technology exports, international alliances
possibilities etc.
4 Specific manner in which know-how generated here is en-
visaged to be translated into production, details regarding
5
a) Name of production agencies willing to productionise/use and market surveys if
any made by them regarding demand for for the product Not yet identified.
12
l) Telecom Billing & Payment Accounting Solution was a commercial project funded
by “Calcutta Telephones”
m) Cryptographic Component for P&T, Govt. of India
n) Ekalavya (An Editor and Player based vernacular LCMS product) used in several projects
including “Sarbasiksha Misson”, “Computer aided design”, “Computer aided learning”
o) JharWeather (Mobile application for Daily or Hourly basis micro level weather information
dissemination for the state of Jharkhand) is a part if Digital India initiative
p) Development of Integrated Electronic Warfare system for DLRL, Hyderabad. Act as “DBA”
for the activity
b) Currently in progress
• A prototype for railways is already completed (URL:- https://rail-saathi-cdac.vercel.app)
c) Abandoned
• NA
10
a) Specific problems, hold-ups and difficulties foreseen in the implementation of the
project.
•
•
•
b) If the answer is not Nil to 10(a), how does Chief Investigator propose to overcome
them?
•
13
12 Details of possible alternative arrangements if the Chief
Investigator leaves institution or is unable for any other
reason to continue on this project.
In case present chief investigator is not available for any reason to continue work following person
will take the charge of this project:
14
PART III: FINANCIAL DETAILS
15
1.3 Participant: C-DAC, Kolkata (Rs. In Lakhs)
16
PART IV
3. In case the project is approved, I undertake to make available facilities to carry it out, to
arrange for the submission of periodic progress reports, utilization certificates and other
information that may be required by the Ministry of Electronics and Information Technology
and In general to ensure that the conditions attached to the award of such grant are fulfilled
by my institution/organisation.
4. I certify that in case present chief investigator is not available for any reason to continue work
5. I certify that the facilities mentioned in the body of this report are available at my institution.
6. I certify that I shall ensure that accounts will be ept of the funds received and spent andmade
available on demand, as specified and required by the Ministry of Communications and
Information Technology.
7. I certify that I am the competent authority, the virtue of the administrative and financial
powers vested in me by to undertake the above stated commitments on behalf of my institu-
tion.
Designation
Date
17
ANNEXURE-I
18
j) Automated performance audit of the “Directory Enquiry System” users was a commercial
project funded by “Calcutta Telephones”
k) Barcode Based File Tracking System was a commercial project funded by “Small Scale
Industries” department of West Bengal Government
l) Telecom Billing & Payment Accounting Solution was a commercial project funded by
“Calcutta Telephones”
m) Cryptographic Component for P&T, Govt. of India
n) Ekalavya (An Editor and Player based vernacular LCMS product) used in several projects
including “Sarbasiksha Misson”, “Computer aided design”, “Computer aided learning”
o) JharWeather (Mobile application for Daily or Hourly basis micro level weather information
dissemination for the state of Jharkhand) is a part if Digital India initiative
p) Development of Integrated Electronic Warfare system for DLRL, Hyderabad. Act as “DBA”
for the activity
◦ Copyrights:
• Krishi Sandesh (Registration Number :SW-8123/2014 Dtd. 01/10/2014): A
SMS-based System for dissemination of 3 information pertaining to Agriculture, Livestock
and Forestry in English, Hindi and 5 local languages of Jharkhand
• Krishi Barta (Registration Number :SW-8122/2014 Dtd. 01/10/2014): A Web-
based Player Editor System for creation of portal to disseminate content in the domain of
Agriculture, Livestock and Forestry in English, Hindi and 5 local languages of Jharkhand
• Krishi Vani (Registration Number: SW-8121/2014 Dtd. 01/10/2014): An Inter-
active Voice Response System for dissemination of information pertaining to Agriculture in
hindi language
• Advanced face recognition system (mobile application) (Registration Number:
SW-17561/2023 Dtd. 13/11/2023): Mobile based solution for finding criminal an-
tecedent of a person using face recognition
List of publications
1. Mukherjee R, Goswami A, Chowdhury S, and Ghoshal N. INNOVATIVE LOW-COST PERIME-
TER SECURITY GADGET WITH IN-BUILT MECHANISM TO ENSURE CONFIDEN-
TIALITY, AUTHENTICITY AND NON-REPUDIATION
2. Goswami A, Mukherjee R, Chowdhury S, and Ghoshal N. Digital signature protocol for visual
authentication. Int. Arab J. Inf. Technol. 2019; 16:712–9
3. Goswami A, Mukherjee R, and Ghoshal N. Robust Fabrication of Share to Assure Error Free
Dissemination of Secret Data (RFSAEFDSD). 2018 International Conference on Wireless
Communications, Signal Processing and Networking (WiSPNET). IEEE. 2018 :1–5
19
4. Chowdhury S, Ray A, Mukherjee R, and Ghoshal N. Dynamical Digital Authentication for
Wireless Domain With Randomized Dispersing of Multiple Secret Signatures. 2018 Interna-
tional Conference on Wireless Communications, Signal Processing and Networking (WiSP-
NET). IEEE. 2018 :1–8
5. Goswami A, Chowdhury S, Mukherjee R, and Ghoshal N. Digitized data validation using dual
color images with improved robustness and error correction facility. Sādhanā 2021; 46:116
6. Goswami A, Mukherjee R, and Ghoshal N. Chaotic visual cryptography based digitized doc-
ument authentication. Wireless Personal Communications 2017; 96:3585–605
7. Chowdhury S, Mukherjee R, and Ghoshal N. Dynamic authentication protocol using multiple
signatures. Wireless Personal Communications 2017; 96:3607–38
8. Mukherjee R. Access of Agricultural Information over Mobile Devices in Vernacular. IT-
Mediated and Technology-driven Agricultural Development. 2017
9. Jha BK, Jha SK, Mukherjee R, and Basak D. Development of guided SMS solution in lo-
cal languages for demand-driven access of agricultural information. 2015 7th International
Conference on Communication Systems and Networks (COMSNETS). IEEE. 2015 :1–5
10. Jha B, Mukherjee R, and Basak D. Off line dissemination of agricultural information in
vernacular. Interaction 2016; 34:19–24
11. Mukherjee R and Ghoshal N. Steganography based visual cryptography (SBVC). Proceedings
of the International Conference on Frontiers of Intelligent Computing: Theory and Applica-
tions (FICTA). Springer. 2013 :559–66
12. Mukherjee R and Basak D. Assessment, Development and Validation of Web-based Informa-
tion Dissemination System in Local Languages for Agricultural Development. INFORMATION-
An International Interdisciplinary Journal
20
Resume of Sonali Dhali Mustafi, Co-CI, CDAC, Kolkata
Experience
20 Years Industrial Experience in Software Development in the areas of Image Processing, Steganog-
raphy & Steganalysis,, Pattern Recognition and Computer Vision. Expertise in File Format Anal-
ysis(Image, Video, Audio etc), Steganography and Steganalysis, Computational Genomics,HPC
etc.
c) Development of Face Recognition System for Handling large database and devel-
opment of Advanced Techniques for Video Enhancement funded by MeitY
d) Development of analysis tools for videos and other steganographed objects funded
by PANCDAC
e) Development of a fast, flexible, high performance computing framework to accel-
erate NGS omics-data analysis funded by MeitY
f) Feature Augmented Password cracking for cryptographically strong steganography
tools using high performance computing funded by MeitY
21
List of publications
1. Mazumdar D, Mitra S, Dhali S, and Pal SK. A chosen plaintext steganalysis of hide4pgp v
2.0. Pattern Recognition and Machine Intelligence: First International Conference, PReMI
2005, Kolkata, India, December 20-22, 2005. Proceedings 1. Springer. 2005 :459–64
22
Resume of Sayak Bhowal, Co-CI, CDAC, Kolkata
List of publications
1. Bhowal S. A case study of low-noise amplifier design for 2.65 GHz wireless system using
MOSFET BSIM4 series and CNTFET. 2014 First International Conference on Automa-
tion, Control, Energy and Systems (ACES). IEEE. 2014 :1–6
2. Bhowal S. Transformation of ACS module to CSA module of low-power Viterbi decoder for
digital wireless communication applications. 2013 International Conference on Advances
in Computing, Communications and Informatics (ICACCI). IEEE. 2013 :266–70
3. Bhowal S, Dutta SR, and Mitra S. An efficient reduced set brute force attack technique
for a particular steganographic tool using vername algorithm. 2017 Fourth International
Conference on Image Information Processing (ICIIP). IEEE. 2017 :1–4
4. Bhowal S. Speed, Noise Immunity, Power Consumption and Area Comparison between
Different Approaches of Low-Power Viterbi Decoder for Digital Wireless Communication
Applications. Netw. Protoc. Algorithms 2014; 6:19–36
23
5. Bhowal S and Maji S. A case study of illumination robust face and finger print merging
identification technique using cross correlation. 2013 International Conference on Emerg-
ing Trends in Communication, Control, Signal Processing and Computing Applications
(C2SPCA). IEEE. 2013 :1–4
24
Resume of Ankur Ghoshal, Co-CI, CDAC, Kolkata
List of publications
25
ANNEXURE-II
Ongoing Projects
Completed Projects
26
ANNEXURE-III
Gantt Chart
Year1 Year2 Year3
Q1 Q2 Q3 Q4 Q1 Q2 Q3 Q4 Q1 Q2 Q3 Q4
Preparation of
0% complete
Software Design Document
Identification of Domain Work &
0% complete
Preparation of vocabulary
Preparation of Sign Corpus 0% complete
Identification of tools
0% complete
& techniques for the ’Area of Interest’
3D mascot creation 0% complete
27
web application
Development of
0% complete
desktop application
Development of
0% complete
mobile application
Development of
0% complete
text and audio input parsing module
Development of
0% complete
sign detection module
Development of
0% complete
language translator module
Integration of 0% complete
LLM with the 3D mascot
Implementation of
0% complete
the simplex version for pilot testing
Implementation of
0% complete
the half duplex version for pilot testing
UAT of the system 0% complete