Disclaimer: This article is educational and does not constitute legal advice. State-level requirements referenced here are general and illustrative of the kinds of additional obligations that exist — always confirm the current, specific requirements for your state and sector with your institutional ethics board, legal counsel, and the relevant state department before fieldwork.
Most compliance guidance written for Indian field researchers treats the Digital Personal Data Protection Act 2023 as the whole picture. It's the national floor — the minimum baseline that applies everywhere in India. But it is not the ceiling. Depending on your survey's subject matter, your funding source, and which state (or states) you're working in, there are often additional layers of requirement sitting on top of DPDP that a purely national-law reading of your compliance obligations will miss entirely.
This matters because the layers aren't always obvious from the DPDP Act text itself. A team that gets DPDP consent right — proper privacy notice, specific purpose, withdrawal mechanism — can still be non-compliant with a state Health Department's ethics clearance requirement, or in breach of a state tender's data-hosting mandate, simply because those requirements live in a different regulatory document entirely.
Layer 1: DPDP Act — The National Floor
Every organisation collecting personal data anywhere in India must comply with the DPDP Act regardless of state: valid consent, a privacy notice, data minimisation, and respect for Data Principal rights (correction, erasure, grievance redressal). This is covered in depth in our companion article on DPDP Act 2023 for Field Researchers. Everything below assumes you've already got this layer right — it's a prerequisite, not an alternative.
Layer 2: State Health Department Ethics/IRB Clearance
Many state Health Departments, and the institutional review structures connected to them, require ethics clearance for any survey that touches health indicators — even when the survey isn't a clinical study. This commonly applies to nutrition surveys, maternal and child health assessments, disability studies, and any research collecting biometric, medical history, or health-status data from respondents.
The practical trigger is usually the content of your questionnaire, not the identity of your organisation. A livelihoods survey that includes a handful of health-screening questions (child immunisation status, recent illness, disability indicators) can cross into ethics-review territory even though the survey's primary purpose is economic. Teams frequently miss this because they design the survey instrument first and think about ethics clearance only when a funder specifically asks for it — by which point fieldwork planning is already underway and a retroactive clearance process can delay data collection by weeks.
If your form includes any health, disability, or biometric question — even a small number embedded in a broader survey — confirm with your state Health Department or your institution's ethics committee whether IRB-style clearance is required before you finalise fieldwork timelines. Retrofitting ethics clearance after enumerator training has begun is a common and avoidable cause of schedule slippage.
Layer 3: State Tender Vendor and Hosting Mandates
State government tenders for survey, monitoring, or data collection work frequently specify vendor and infrastructure requirements beyond what DPDP requires nationally. Common patterns include a requirement that the software vendor be empanelled with NIC (National Informatics Centre) or listed on GeM (Government e-Marketplace), a requirement that data be hosted exclusively on India-based infrastructure, and sometimes a requirement that the vendor be an India-registered entity with a specified minimum operating history.
This is distinct from — and additional to — the general data-residency considerations covered in our article on data residency and sovereignty for survey software. A state tender can make India hosting a hard, disqualifying requirement rather than a general best practice, and the specific empanelment or registration criteria vary by state and by department. If your organisation regularly bids on or partners with state government-linked survey work, confirm current empanelment requirements directly with the procuring department each time — these lists and criteria are updated periodically and a stale assumption can disqualify a bid late in the process.
Layer 4: State-Specific Survey Protocols
Large state-run socioeconomic and household-listing programmes — the kind of work implied by a state Socioeconomic and Caste Census-style household listing exercise, or a state-run socioeconomic survey conducted in partnership with implementing NGOs — often come with their own detailed survey protocol layered on top of both DPDP and any sector-specific ethics requirement. These protocols typically specify things generic DPDP guidance won't cover: exact consent script wording approved by the state department, specific enumerator identification and verification procedures, designated local-language versions of consent and survey materials, and data-handling procedures specific to that programme (e.g., how household IDs must be structured, how data is transmitted to the state's own systems, and retention periods tied to the programme rather than your organisation's general policy).
When your organisation is implementing a state-commissioned survey rather than running your own independent research, the state's protocol document — not your organisation's standard consent template — is usually the controlling document for exactly how consent and data handling must be executed in the field. Treating your organisation's generic DPDP-compliant consent flow as automatically sufficient for a state-commissioned programme is a common gap; always request and review the specific programme protocol first.
| Layer | Applies When | What to Confirm |
|---|---|---|
| DPDP Act (national) | Always, every survey collecting personal data | Consent flow, privacy notice, data minimisation, DPA with vendor |
| State Health Dept ethics/IRB | Survey touches health, disability, or biometric indicators | Whether ethics clearance is required before fieldwork begins |
| State tender vendor mandates | Government-commissioned or PSU-funded survey work | NIC/GeM empanelment status, India-hosting requirement |
| State-specific survey protocol | Implementing a state-run census/household-listing programme | Approved consent script, local-language materials, ID/data-handling rules |
How This Shows Up for CSR and Donor-Funded Programmes
Corporate social responsibility (CSR) funded programmes and donor-funded NGO work add a fifth practical wrinkle: even when no formal state mandate applies, funders increasingly build their own version of these requirements into grant agreements — sometimes explicitly, sometimes as an implicit expectation raised only at audit time. A CSR-funded health programme may require IRB-style ethics review as a funding condition even in a state where it isn't independently mandated, simply because the corporate funder's own governance policy requires it for anything touching health data. A donor agreement may require India-based data hosting as a grant condition, layered on top of (and sometimes stricter than) what DPDP itself requires. The practical lesson is the same either way: read the funding agreement's data and ethics clauses as carefully as you read the state regulatory requirements, because a funder can impose a stricter bar than the law does.
What Happens When a Layer Gets Missed
The consequences of missing one of these layers are rarely dramatic — it's uncommon for a missed state-level requirement to result in a penalty in the way a DPDP breach might. The more common, and more disruptive, outcome is a mid-fieldwork stoppage: a state department official visits a survey site, asks for ethics clearance documentation the team doesn't have, and fieldwork pauses while the team scrambles to secure retroactive approval — often losing days or weeks of a tightly scheduled data collection window, and sometimes requiring the affected respondents to be re-consented under a corrected protocol. For a state-commissioned programme specifically, a protocol mismatch discovered after data collection has started can mean the state department rejects submitted data outright, requiring re-fieldwork at the implementing organisation's cost. These are schedule and budget risks, not just legal ones — which is precisely why the pre-fieldwork check matters more than a reactive fix.
Pre-Fieldwork Compliance Checklist
Before enumerator training begins for any new survey, work through this checklist alongside your standard DPDP preparation:
Why This Layering Trips Teams Up
The core reason these layers get missed isn't carelessness — it's that they live in different places. DPDP is a single national statute your legal team can read once. State ethics requirements, tender mandates, and programme-specific protocols are scattered across department circulars, tender documents, and programme guidelines that aren't centrally indexed anywhere. A team that has genuinely done its DPDP homework can reasonably believe it has covered "compliance" without realising a second, state-specific layer applies to this particular survey.
The practical fix isn't memorising every state's rules in advance — it's building the four-question check above into your standard pre-fieldwork process, every time, for every new survey, regardless of how similar it looks to your last one. A programme running in one state with one set of health indicators may have entirely different requirements from a superficially similar programme next door.
Building This Into a Repeatable Process
The most reliable teams handle this not by researching each survey's compliance landscape from scratch, but by maintaining a short standing document — a one-page pre-fieldwork compliance brief, refreshed for every new programme — that walks through the four layers above and records the answer, the source (which department or person confirmed it), and the date. This turns a research task into a five-minute lookup for programmes similar to ones the organisation has run before, while still forcing a fresh check for anything genuinely new (a new state, a new health indicator, a new government partner). It also produces exactly the kind of documentation a funder or auditor asks for after the fact — evidence that compliance was actively confirmed, not assumed.
Where FieldGovern Fits
FieldGovern doesn't replace the ethics-clearance or protocol-confirmation steps above — those are institutional and departmental processes, not something software can automate away. What it does provide is the technical layer that makes compliance defensible once you've done that homework: timestamped, local-language consent capture built directly into the form, an audit log of exactly what was shown to and agreed by each respondent, India-hosted data with a signed DPA, and export formats (CSV, Stata .dta, SPSS) that match the data-handling requirements state programmes typically specify.
Consent and Audit Trails Built for Indian Fieldwork
Local-language consent capture, timestamped audit logs, and India-hosted data — the technical layer under your compliance process. See it in a free trial.
Start Free Trial