Homeβ€Ί Indiaβ€Ί Ministry of Road Transport and Highwaysβ€Ί Circulation of β€œPolicy for Data Sharing from the National Tr...
Date: 2025-08-18 Category: Not Applicable State: Union Government Country: India

Circulation of β€œPolicy for Data Sharing from the National Transport Repository" (2.19 Mb)

Issued by Ministry of Road Transport and Highways Β· Not Applicable

Research with AI Agent Chat with Document Generate Summary Translate Helpful Share Add to Project Create Task

Executive Summary & Key Takeaways

Executive Summary: This document outlines the "Policy for Data Sharing from the National Transport Repository" (NTR), which includes data from Vahan, Sarathi, eChallan, eDAR, and FASTag. The policy aims to regulate data sharing while ensuring legal compliance and safeguarding personal data. It provides guidelines for various stakeholders, including government bodies, academic institutions, and private agencies, to ensure secure and lawful data sharing practices. Stakeholders are required to bring the contents of this circular to the attention of all concerned within their organization/department. Key Points / Main Content: Data Sharing Policy Overview: - The policy regulates data sharing from the National Transport Repository (NTR), which includes sensitive personal information. - It ensures uniformity and legal compliance in data sharing, aligning with recent legal requirements regarding consent. - The policy supports government functions, academic research, ease of living (EOL), and ease of doing business (EODB). - A detailed framework covers datasets, modes of sharing, and the request and approval process for Vahan, Sarathi, eChallan, eDAR, and FASTag data. Data Sets: - Shareable data parameters are available from Vahan (Vehicle Registration), Sarathi (Driving License), eChallan, eDAR (Accident Report), and NETC FASTag databases. - Agencies must specify the required data with parameter-wise purpose and justification; Personally Identifiable Information (PII) sharing requires approval. Modes of Data Sharing: - API-based sharing is the preferred mode, using NIC API Exchange Gateway (NAPIX) with security measures. - Login-based sharing is available via NTR Portal for government organizations (with secured credentials and two-factor authentication) and for private sector (EODB or EOL, subject to consent of the Data Principal). - Secured and password-protected bulk data sharing is provided on an exceptional basis. - Mobile App-based Access is available to citizen/individuals with limited access to vehicle or driving license information. - Aggregated and anonymized data will be regularly published on data.gov.in for public, academic, and research use. Data Sharing with Specific Data Recipients: - State Governments/UT Administrations: Have read-only access to their own transport data. - Police, Law Enforcement, and National Security Agencies: Have complete access to all data parameters, including Personal Data. - Government Agencies: Provided complete access to data, as required under the applicable law. - Academia and Research: Share aggregated or anonymized data for research, innovation, and business purposes. - Citizen or Individuals: Can access their complete data related to their own vehicle/DL or eChallan. - Transport Service Providing Agencies: Relevant datasets are shared with service providers based on their roles and data needs, with a memorandum of data compliances. Request and Approval Process: - API-based Data Sharing: Requires a request letter, officer contact details, data parameter list, justification, eligibility explanation under Section 7 of DPDP Act, a memorandum of data compliance, and a Website Security Certificate. - Portal-based Data Sharing: Requires a request letter, officer contact details, data parameter list, justification, eligibility explanation under Section 7 of DPDP Act, and a memorandum of data compliance. - Bulk Data Sharing: Requires a request letter, officer contact details, data parameter list, justification, and an undertaking. Data Sharing Security Practices and Procedures: - Data Recipients must comply with the DPDP Act and implement security measures. - These measures include data access controls, security audits, confidentiality agreements, and incident reporting. - Data must be processed and stored on servers located within India. Impact Analysis: State Government/UT Administration: Impact: Access to NTR database limited to state-specific data on a read-only basis. Required to onboard all transport service providing agencies on NTR before commencing of data sharing. Action Required: Ensure compliance with data sharing policies and implement necessary security measures. Police, Law Enforcement Agencies, and National Security Agencies: Impact: Complete access to all data parameters, including Personal Data. Action Required: Ensure data is used in compliance with applicable laws, including DPDP Act, Section 7 and 17. Government Agencies: Impact: Complete access to data, as required under the applicable law. Action Required: Ensure data is used in compliance with applicable laws, including DPDP Act, Section 7 and 17. Implement additional security measures to prevent data breach. Academia and Research: Impact: Access to aggregated or anonymized data for research, innovation, and business purposes. Action Required: Ensure compliance with the National Data Sharing and Accessibility Policy (NDSAP), 2012. Citizen/Individual: Impact: Limited access to information on any Vehicle or Driving license through NTR portal. Action Required: Authenticate through mobile OTP; access is limited to three times per day. Transport Service Providing Agencies: Impact: Access to relevant datasets, subject to data limitation and consent mechanism, as applicable. Action Required: Execute a memorandum of data compliances with MoRTH or the State Government. Comply with the DPDP Act, including Section 6 consent. Onboarding on NTR. Private Sector Entities: Impact: Opportunity to provide authentication services for EOL and EODB. Action Required: Anonymized data fields for authentication may be made available time to time, upon request, subject to approval and compliance with applicable data privacy and security regulations. Execute a memorandum of data compliances with MoRTH or the State Government.

Key Entities Referenced

Policy for Data Sharing from the National Transport Repository: The central policy document outlining guidelines for data sharing from the National Transport Repository. National Transport Repository (NTR): A centralized database for records including Vahan, Sarathi, eChallan, eDAR, and FASTag, maintained by the Ministry of Road Transport and Highways. Vahan: A database within the National Transport Repository containing vehicle registration records. Sarathi: A database within the National Transport Repository containing driving license records. eChallan: A database within the National Transport Repository containing electronic challan records. eDAR (Electronic Detailed Accident Report): A database within the National Transport Repository containing electronic detailed accident reports. FASTag: A database within the National Transport Repository containing National Electronic Toll Collection (NETC) FASTag data. Digital Personal Data Protection Act, 2023 (DPDP Act): The data protection law imposing obligations on Data Fiduciaries regarding personal data processing and sharing.
Official Source Record View Original Source β†’
See Full Document Text
RT-1103 617512022-MVL Government of lndia Ministry of Road Transport & Highways (MVL Section) Transport Bhawar, 1, parliament Street, New Delhi-11OOO1 Dated the lJhugust, 2025 To, 1. The Secretaries of all Ministries/ Departments of Government of lndia 2. The Chief Secretaries/Administrators of all States/Union Territories 3. The Director Generals of Police of all the States and Union Territories 4. The Principal Secretaries/ Secretaries, Department of Transport of all the States/ Union Territories 5. The Transport Commissioners of allthe States/Union Territories. Subject : Circulation of "Policy for Data Sharing from the National Transport Repository". Madam /Sir, The National Transport Repository (NTR) serves as the central database for records including Vahan, Sarathi, eChallan, eDAR, and FASTag. This Ministry received requests for data from States,UTs, Central Government Ministries, academic institutions, and As private agencies. the NTR contains sensitive personal information accessed by various government and enforcement agencies for specific purposes, data sharing must be strictly regulated. 2. A policy has been developed to ensure uniformity and legal compliance in data sharing. This policy provides clear guidelines in line with recent legal requirements regarding consent for sharing personal data.The policy outlines procedures and safeguards to ensure secure and lawful data sharing, supporting government functions, academic research, and promoting ease of living and ease of doing business. A detailed framework covering datasets, modes of sharing, and the request and approval process for Vahan, Sarathi, eChallan, eDAR, and FASTag has been formalized. 3. The policy document titled "Policy for Data Sharing from the National Transport Repository" is enclosed as an annexure. You are requested to bring the contents of this circular to the attention of all concerned within your organization/department. 5. This issues with the approval of the Competent Authority Yours faithfully, Encl:As above vb) rector ( Tel: 011-23718575 Email : ankit.dugarl 986@gov.i nCopy to- i. The Chairman, lnsurance Regulatory and Development Authority and lnsurance lnformation Bureau - for kind information to concerned stakeholders and existing insurance providers ii. Director General, NIC iii. The Chairman, NHAI iv. PPS to AS & FA, MoRTH v. PPS to AS (T,MVL &RS), MoRTH vi. PPS to AS (HighwaysllollllTlLogistics), MoRTH vii. CMD, IHMCL viii. Director (Media), MoRTH ix. Deputy Secretary(Transport), MoFITH x. Deputy Secretary (Road Safety), MoRTH xi. Deputy Secretary(lT), MoRTH xii. Pr.CCA, MoRTH xiii. Shri Joydeep Shome, DDG, NlC, HoD, eTransport - for needful implementation and placing the same on the portalfor information of stakeholders and existing users. xiv. Shri Piyush Gupta, Sr. Technical Director, NIC- to place the same on MoRTH website for information of allstakeholders. xv. All NIC State Coordinator- for needful implementation and informing stakeholders and existing users - HSRP vendors , VLTD implementation agencies , Smart Card Vendors, eChallan third party implementation agencies, Banks etc. xvi. The office of Bharatkosh - for needful implementation and information.POLICY FOR DATA SHARING from the National Transport RepositoryTable of Content 1. Introduction ................................................................................... 3 1.1. Purpose of this Document ............................................................. 3 1.2. Key Objectives .......................................................................... 4 1.3. Key Stakeholders ....................................................................... 4 1.4. Sharing of Personal Data .............................................................. 6 2. Different Data Sets of the Transport Department ....................................... 7 2.1. Vehicle Registration Data Sets (Source: Vahan Database) ........................ 7 2.2. Driving Licence Related Data Sets (Source: Sarathi Database) .................. 8 2.3. e-Challan related datasets (Source: e-Challan Database)........................ 8 2.4. eDAR related datasets (Source: eDAR Database) .................................. 9 2.5. NETC- FASTag related datasets (Source: Toll Database) .......................... 9 3. Modes of Sharing of Data .................................................................. 10 3.1. API based Sharing .................................................................... 10 3.2. Login based Sharing from Portals .................................................. 10 3.3. Secured and password protected bulk data sharing ............................ 11 3.4. Mobile App based Access ............................................................ 12 4. Datasets and the Mode of Sharing specific to the Data Recipients: ................. 14 4.1. Sharing of NTR datasets with the State Government or UT Administration . 14 4.2. Sharing of State-level data with Government Agencies by State Transport Authorities ............................................................................ 14 4.3. Sharing of NTR datasets with Police, Law Enforcement Agencies and National Security Agencies ..................................................................... 14 4.4. Sharing of NTR datasets with Government Agencies etc. ...................... 15 4.5. Sharing of NTR datasets with Academia and Research ......................... 15 4.6. Sharing of NTR datasets with Citizen or Individual.............................. 15 4.7. Sharing of NTR datasets with Transport Service Providing Agencies .......... 15 5. Request and Approval Process ............................................................ 21 5.1. API-based Data Sharing – Process and Prerequisites. ........................... 21 5.2. Portal-based Data Sharing- Process and Prerequisites. ......................... 23 5.3. Bulk Data Sharing – Process and Prerequisites. .................................. 25 16. Data Sharing Security Practices and Procedures ....................................... 27 Annexure I ........................................................................................ 30 Annexure II ........................................................................................ 31 Annexure III ....................................................................................... 32 Annexure IV ....................................................................................... 35 Annexure V........................................................................................ 37 Annexure VI ....................................................................................... 39 Annexure VII ...................................................................................... 40 Annexure VIII ..................................................................................... 41 Data Sets ..................................................................................... 41 Annexure IX ....................................................................................... 50 21. Introduction Ministry of Road Transport and Highways (MoRTH) maintains critical data related to Vehicle Registration Certificates (RCs) and Driver Licenses (DLs) collected through the VAHAN and SARATHI respectively, along-with the data recorded at time of generation of e-Challan or eDAR (Electronic Detailed Accident Report) and National Electronic Toll Collection (NETC)- FASTag data. This data is collectively referred to as the National Transport Repository (NTR). NTR is a centralized repository that holds record of over Thirty-Nine Crore vehicles, TwentyTwo Crore DL and data related to e-Challan, eDAR and NETC- FASTag. The NTR is a unified central data repository maintained by MoRTH, required to be maintained inter alia under Section 25A and Section 62B of the Motor Vehicles Act, 1988 (MV Act). The demand for access from citizens, academics, private sector to this data in various forms continues to grow. Sharing data in a controlled manner can enhance services and benefit research and data driven decision making by government organizations, private sector and academia. Furthermore, State Governments are mandated to ensure electronic monitoring and enforcement of road safety under Section 136A of the MV Act. However, it is important to maintain appropriate safeguards from a security and privacy standpoint to prevent data leakage or breach. MoRTH mandated the use of FASTag for all four-wheelers, irrespective of their date of sale, with effect from January 1st, 2021, through Gazette Notification G.S.R. 690(E) dated September 1st, 2020, amending Rule 138A of the Central Motor Vehicles Rules, 1989 (CMVR). Further, as per G.S.R. 1361(E) dated November 2nd, 2017, all motor vehicles in Category M (used for the carriage of passengers) and Category N (used for the carriage of goods), manufactured on or after July 1st, 2017, are required to be fitted with FASTag. 1.1. Purpose of this Document As mentioned above, NTR serves as the central repository for the aforementioned records. Several government and enforcement agencies access this data for specific purposes. Given that this data includes personal and sensitive information, provision and sharing of data needs to be carefully managed through a governing policy document. The recently enacted Digital Personal Data Protection Act, 2023 (DPDP Act) imposes obligations on the Data Fiduciary holding Personal Data. This policy outlines the procedures for data sharing while ensuring compliance with applicable laws and the implementation of necessary safeguards to benefit government, academia and to promote ease of living (EOL) and ease of doing business (EODB). 31.2. Key Objectives The objective of providing access to data, while ensuring privacy and security of the data, is to enable the following: Smooth and controlled integration of external applications/systems with the Transport National Register, ensuring seamless access to authentic data for stakeholders. Increased operational efficiency by minimizing duplication of work and human intervention along-with furthering digital transformation. Improved services and benefits for citizens, academia/researchers, private sector, government and other stakeholders. Ensuring ease of living and doing business for all stakeholders. Provision of need-based data with user-specific variations. 1.3. Key Stakeholders Data Fiduciary/Provider ο‚· Ministry of Road Transport and Highway: MoRTH is the holder of the data and the primary Data Fiduciary of the NTR data (e.g., Vehicle Registration, Driving Licenses, e-Challan, eDAR, FASTag etc.). It is responsible for formulating the data-sharing policy and ensuring its proper implementation. ο‚· State Government: The Transport Departments and Registering or Licensing Authorities are co-holders and co-Data Fiduciaries of State-level data. The data- sharing policy defined by MoRTH will also apply to States and Union Territories. Data Recipients Organizations that receive data from the NTR, under this policy, are referred to as Data Recipients and shall be implicitly considered as Data Fiduciaries as defined under the DPDP Act, who shall inter alia undergo audits and be liable for any data breach under the applicable law including Chapter VIII of the DPDP Act. These include: 41. Police, Law Enforcement Agencies and National Security Agencies will have complete access to all data parameters, including Personal Data, as required under the applicable law, including Section 7 (certain legitimate uses) and Section 17 (exemptions) of the DPDP Act. 2. State Government or UT Administration: The State Transport Departments will have complete holding of the transport data inter-alia comprising Vahan, Sarathi and e-Challan in respect of the concerned State or Union Territory. Regarding eDAR data, the stakeholders like Police, Transport, Health and Road-owning agencies will be the co-holders of respective data at the State level. The sharing of data with other departments or statutory entities of the State or Union Territory Government shall be approved by them as per the modalities or parameters of this policy. However, for sharing of data pertaining to other State(s) or pan-India data, the approval of MoRTH and consent of the respective State to which the data pertains, shall be mandatory. 3. Government Agencies etc.: Central or State Government Ministries or Departments and statutory entities or organisations owned or controlled by the Central or State Governments specifically mandated for the purpose by MoRTH, Central Government or State Government, as the case may be, will be provided complete access to the data, as required under the applicable law, including Section 7 (certain legitimate uses) and Section 17 (exemptions) of the DPDP Act. The said statutory entities or organisations shall be subjected to additional security measures to prevent data breach, in addition to the measures specified under Clause 6 of this policy. The sharing of data amongst State or Union Territory government entities will be subject to the applicable law including the DPDP Act. 4. Academia and Research: Data in aggregated or anonymized form will be shared with academia and private sector for promoting research, innovation and business purpose. This is in line with the National Data Sharing and Accessibility Policy (NDSAP), 2012. In general, aggregated and anonymized data will be made available on the open Government platform (https://data.gov.in). 5. Citizen or Individuals: Citizens or individuals can access their complete data related to their own vehicle/DL or e-Challan. Additionally, select parameters of these datasets can also be made available to any citizen for the purpose of verification of RC or DL etc. Additionally, aggregated and anonymized data will be accessible to citizen through the open Government platform (https://data.gov.in) and also through public dashboards. 6. Transport Service Providing Agencies: To enable specialized services within the eTransport Ecosystem, relevant datasets will be shared with service providers based on their roles and data needs. Agencies such as insurance providers, banking gateways, HSRP vendors, smart card vendors, third party (TP) sales and Vehicle 5Location Tracking Device (VLTD) vendors receive select data parameters as required for provision of their services. These entities shall execute a memorandum of data compliances (in the template provided in this policy) or an agreement with MoRTH or the State Government, as the case may be, on a case- by-case basis, in furtherance of ensuring compliance with law. These agencies shall be subjected to additional security measures to prevent data breach, in addition to the measures specified under Clause 6 of this policy. 7. Private Sector Entities providing Authentication Services for Ease of Living and Ease of Doing Business: Select data parameters or verification/authentication will be provided depending on specific business requirement in line with promoting EOL or EODB for availing authentication services from MoRTH. For instance, DL as an authentication service on similar lines as Aadhaar Authentication Service. 1.4. Sharing of Personal Data Personal Data, as defined under clause (t) of Section 2 of the DPDP Act, means any data about an individual who is identifiable by or in relation to such data. MoRTH, as the primary Data Fiduciary, is responsible for determining how and when Personal Data is processed or shared. The Personal Data of the DL holders or registered owners of motor vehicle, i.e. Data Principals, who are not in compliance with the provisions of the MV Act or any other rules made thereunder, shall be provided to the law enforcement agencies, transport service providers, insurance companies etc. in un-masked form, with reasonable safeguards. The data shall be shared for ensuring compliance with law or for the performance of functions under law. 62. Different Data Sets of the Transport Department This Clause defines the data sets available for sharing, under this policy. 2.1. Vehicle Registration Data Sets (Source: Vahan Database) A list of shareable data parameters available in the Vahan Database, categorized under the super heads listed below, is provided in Annexure VIII. Vehicle Registration Related Data Set: ο‚· Registration Details ο‚· Purchase Details ο‚· Vehicle Owner Details ο‚· Vehicle Details ο‚· Validity Norms ο‚· Dealer Details ο‚· Used Car Dealer Details ο‚· Permit Details ο‚· Insurance Details ο‚· Hypothecation details ο‚· NOC Details ο‚· Non-use information ο‚· e-Challan details Note 1: Above is a superset of sharable data parameters. Individual agency needs to specify the required data with parameter-wise purpose and justification. The Personally Identifiable Information (PII) or other sensitive data parameters will be shared with the Data Recipients after due approval under this policy. Note 2: The API facilitates search of any registered vehicle record by specifying one of the following input parameters: ο‚· Vehicle Registration Number OR- ο‚· Chassis Number OR- ο‚· Engine Number Note 3: In case of any duplicate record existing for same registration number, chassis number or engine number, the data will not be displayed. Rectification of Duplicate record is facilitated to RTO’S through De-Duplication Module. 72.2. Driving Licence Related Data Sets (Source: Sarathi Database) A list of shareable data parameters available in the Sarathi Database, categorized under the super heads listed below, is provided in Annexure VIII. Driving Licence Related Data Sets ο‚· Driving Licence Details ο‚· DL Holder’s Details ο‚· Validity ο‚· International Driving Permit (IDP) Details ο‚· PSV Details ο‚· Adaptive vehicle Number ο‚· e-Challan details Note 1: Above is a superset of sharable data parameters. Individual agency needs to specify the required data with parameter-wise purpose and justification. The PII or other sensitive data parameters will be shared with the Data Recipients after due approval under this policy. Note 2: Data of Driving License Holders can be searched through following input parameters viz.: ο‚· Driving License Number AND ο‚· Date of Birth 2.3. e-Challan related datasets (Source: e-Challan Database) A list of shareable data parameters available in the e-Challan Database, categorized under the super heads listed below, is provided in Annexure VIII. e-Challan Related Data Sets ο‚· Challan Details ο‚· Vehicle Details ο‚· Challan Recipient Details ο‚· Court Details ο‚· Driving License details 82.4. eDAR related datasets (Source: eDAR Database) A list of shareable data parameters available in the eDAR Database, categorized under the super heads listed below, is provided in Annexure VIII. eDAR Related Data Sets ο‚· Accident Details ο‚· Vehicle and Driver Details ο‚· Vehicle Passenger Details ο‚· Pedestrian Details 2.5. NETC- FASTag related datasets (Source: Toll Database) A list of shareable data parameters available in the NETC database, categorized under the super heads listed below, is provided in Annexure VIII. NETC- FASTag Related Data Sets ο‚· Vehicle Details ο‚· FASTag Details ο‚· General Details ο‚· Bank Details ο‚· Transaction Details 93. Modes of Sharing of Data Under this policy, data sharing can be allowed through various modes depending on the category of users and type of data. The following modes are available: 1 2 3 4 5 API based Login based Secured and Mobile Public Data Sharing Access from Password Application Sharing Portals Protected Bulk Based Access Platform Data Sharing (Mparivahan and Digilocker) 3.1. API based Sharing API-based sharing, which facilitates machine-to-machine data access will be the preferred mode of data sharing. APIs are published via the NIC API Exchange Gateway (NAPIX), and access is granted using security measures such as secret keys, user authentication, and IP whitelisting etc. Organizations desiring access to a specific set of data must submit request in specified form to MoRTH with relevant documentation, purpose for which such data is sought, disclosing their eligibility to process the data under Section 7 of DPDP Act, execution of a memorandum of data compliances, mandate security audit certificate and log records, as outlined in Clause 6 of this policy. In API based access, PII parameters will be masked for data shared with Data Recipient except (a) Police, law enforcement, national security agencies and (b) any entity specifically granted full data access by MoRTH, subject to the provisions of the DPDP Act. 3.2. Login based Sharing from Portals This mode of data sharing shall be applicable to the following: For Government Organizations: These agencies will be given access to the data parameters of Vahan and Sarathi by logging into NTR Portal using secured credentials. Additionally, two-factor authentication will be introduced for additional security. The users will be required to 10make Aadhaar authenticated OTP-based system, in addition to login/password-based access. For Private Sector for EODB or EOL: The data shall be shared with private sector stakeholders to strengthen the transportation ecosystem and to ensure EODB and EOL, thereby strengthening the economy, subject to consent of the Data Principal being obtained through the consent mechanism. Private Sector entities can access datasets from the NTR, subject to approval from MoRTH. MoRTH shall fix a daily data access limit as specified on the concerned portal, from time to time, and specific to the type of Data Recipients. The above services will be subject to data limitation and consent mechanism, if applicable. Such Data Recipient may include insurance companies with valid IRDAI licenses and Scheduled Commercial Banks regulated by the RBI, transporters, State Transport Undertakings, Automobile Manufacturers, Component Manufacturers, motor vehicle aggregators and private sector associations such as ACMA, SIAM etc. Personal Data and PII may be provided under the condition that a Data Recipient obtains user consent through an Aadhaar authenticated OTP-based system linked to the mobile number on the concerned portal. If a mobile number is not available in the records, the user must update it via Aadhaar authentication before giving consent. For Citizen: Citizen/individuals can also have limited access to information on any Vehicle or Driving license through NTR portal. Only select, non-sensitive, non-PII parameters regarding Driving License or Vehicle Registration Certificate of any citizen may be shown. Moreover, user has to authenticate through mobile OTP and number of accesses per day will be restricted limited to three (3). 3.3. Secured and password protected bulk data sharing Bulk data will only be provided on an exceptional basis to select organisations. Full data will be shared on one-time basis, with incremental updates on monthly, quarterly or half-yearly basis, as the case may be. Bulk data will be shared through portable password protected hard disk drive and collected physically by authorised personnel of the concerned organisation. Alternatively, a Secured FTP link may be set up for the Data Recipients to download the incremental data through secured network. For incremental data sharing, this mode shall be preferred. 11The dataset will be provided to agencies as per their specific requirements.The data being shared with such organisations shall be subject to satisfaction of tenets under the DPDP Act, including Section 7 and Section 17 thereof. 3.4. Mobile App based Access Citizen/individuals can also have limited access to information on any Vehicle or Driving license through NTR portal. Only select, non-sensitive, non-PII parameters regarding Driving License or Vehicle Registration Certificate of any citizen may be shown. Moreover, user has to authenticate through mobile OTP and number of accesses per day will be restricted limited to three (3). The following data parameters are provided: A. Registration Certificate β€’ Vehicle number: Non-Masked β€’ Owner number: Masked β€’ Registering Authority: Non-Masked β€’ Vehicle class: Non-Masked β€’ Fuel type: Non-Masked β€’ Emission norm: Non-Masked β€’ Hypothecated: Non-Masked β€’ Registration date: Non-Masked β€’ Insurance valid up to: Non-Masked β€’ PUCC valid up to: Non-Masked β€’ Vehicle status: Non-Masked B. Driving License β€’ DL number: Non-Masked β€’ DL holder’s name: Masked β€’ Issue date: Non-Masked β€’ Licence validity (Non-Transport): Non-Masked β€’ Licence validity (Transport): Non-Masked β€’ Licensing Authority: Non-Masked However, for their own DL or RC, citizens can access complete information/ status through the mParivahan and Digilocker mobile apps. There is a facility to create virtual RC and virtual DL for the concerned user by pulling data from the Vahan/ Sarathi databases through API. MoRTH has already notified the virtual DL and RC available in these two apps as legally valid documents. 12However, MoRTH will make aggregated and anonymised data from its core applications, such as Vahan, Sarathi, e-Challan, eDAR, and FASTag, available through internal and external dashboards. These dashboards will feature key performance indicators, trend analyses, and reports to support informed decision-making. Requests for additional dashboard APIs would be entertained from an academic institution which requires such information for research and analysis purpose, for which a request signed by the designated officer of the academic institution would be necessary. In line with the National Data Sharing and Accessibility Policy 2012 (NDSAP), anonymized datasets will be regularly published on β€˜data.gov.in’ for public, academic, and research use. All internal portals, such Vahan, Sarathi, e-Challan, eDAR, and FASTag, are integrated to ensure seamless data sharing and efficient digital service delivery across platforms. 134. Datasets and the Mode of Sharing specific to the Data Recipients: 4.1. Sharing of NTR datasets with the State Government or UT Administration Every State is the co-holder and co-Data Fiduciary of its own transport related data pertaining to Vahan, Sarathi, e-Challan, eDAR etc. Each State has been provided access to NTR database on read-only basis through secured VPN based access and access credentials are provided for Vahan and Sarathi to Transport Officers as approved by the concerned State Transport Authorities. However, this access is limited only to the State- specific data. This is to facilitate States to have view of their own data and also run ad- hoc reports or queries as per their need. 4.2. Sharing of State-level data with Government Agencies by State Transport Authorities The State Transport Departments will have complete holding of the data pertaining to their jurisdiction and sharing of data with other agencies shall be their prerogative as per the modalities of this policy and subject to the applicable law, including DPDP Act. This access shall be provided preferably through secure API-based systems. However, for sharing of data pertaining to other State(s) or pan-India data, the approval of MoRTH with the consent of the respective State, under this policy, shall be necessary. The Recipient shall execute a memorandum of data compliances or an agreement with the State Government, on a case-by-case basis, in furtherance of ensuring compliance with law. The data will be available in any of the modes mentioned under Clause 3, except for protected bulk data sharing. However, the preferable mode for sharing of data shall be through API access. 4.3. Sharing of NTR datasets with Police, Law Enforcement Agencies and National Security Agencies As stated above, Police, Law Enforcement Agencies and National Security Agencies will have complete access to all data parameters, including Personal Data, as required under the applicable law, including Section 7 (certain legitimate uses) and Section 17 (exceptions) of the DPDP Act. 14The data will be available in any of the modes mentioned under Clause 3. Additionally, when only specific data parameters and/ or from a specific time period, are required, they shall be provided on case-to-case basis. However, the preferable mode for sharing of data shall be through API access. 4.4. Sharing of NTR datasets with Government Agencies etc. As mentioned before, the Central or State Government Ministries or Departments and statutory entities or organisations owned or controlled by the Central or State Governments specifically mandated for the purpose by MoRTH or State Government, as the case may be, will be provided complete access to the data, as required under the applicable law, including Section 7 and Section 17 of the DPDP Act. In view of the same, the data will be available in any of the modes mentioned under Clause 3, except for protected bulk data Sharing. However, the preferable mode for sharing of data shall be through API access. 4.5. Sharing of NTR datasets with Academia and Research As stated before, the aggregated or anonymized data will be shared in with such entities for research innovation and business purposes. In view of the same, the data will be available through Dashboard/Reporting portals and OGD Platform as mentioned in the modes of sharing under Clause 3, except for protected bulk data sharing. Academia and Research entities can request additional select datasets from the NTR, subject to approval from MoRTH. 4.6. Sharing of NTR datasets with Citizen or Individual As stated before, Citizen/ individuals, in addition to complete information of their own vehicle/Driving License details, can also have limited access to information on any Vehicle or Driving license through NTR portal. The user will authenticate through mobile OTP and number of accesses per day will be restricted limited to three (3). 4.7. Sharing of NTR datasets with Transport Service Providing Agencies Transport service providing agencies shall execute a memorandum of data compliances or an agreement with MoRTH or the State Government, as the case may be, on a case- by-case basis, in furtherance of ensuring compliance with law. The provisions of DPDP Act, including Section 6 (consent), shall be applicable to such agencies and the preferred mode of data sharing shall be through API. In addition to the security measures outlined in Clause 6 of this policy, additional security measures to prevent 15data breach will be imposed on these agencies from time to time and on case-to-case basis. Furthermore, Data Recipients shall be liable for any data breach under the applicable law including Chapter VIII of the DPDP Act. Additionally, transport service providing agencies like banks, insurance companies, transporters, OEMs etc. may also be provided anonymised data along-with authentication services to strengthen the transportation ecosystem and facilitate EODB, subject to approval from MoRTH. This access will be subject to data limitation and consent mechanism, as applicable. The State Governments or UT Administration shall onboard all such transport service providing agencies on NTR before commencing of data-sharing. Some of the aforementioned entities are specified below: A. Vehicle registration and Driving License data shared with Card/Smart-card vendors: When a new vehicle is registered or a transaction (such as Renewal, Duplicate, Change of Address etc.) is done on an existing vehicle which necessitates issuance of a Registration Certificate in the form of PVC Card/Smart Card, then data will be made available to the State-authorized Card/Smart-Card vendor through API to issue the DL/RC as a Smart Card. Similarly, when a new Driving License is being issued or a transaction (such as Renewal, Duplicate, Change of Address etc.) is done on an existing DL which necessitates issuance of a Driving License in the form of PVC Card/Smart Card, then data is made available to the State-authorized Card/Smart-Card vendor through API. The approval for such data sharing shall be accorded by concerned State Transport Authority for the authorized agency/vendor. For both aforementioned purposes, complete data for RC or DL (as specified in the relevant forms of CMVR) is made available to the authorized vendor for printing/embedding of the data in the card/smart-card. B. Vehicle registration data shared with HSRP vendors: When vehicle needs to get affixed with HSRP number plates– either during registration of a new vehicle or existing registered vehicle or when a vehicle requires replacement of registration plates, then data is made available to the OEM-authorized (in case of new vehicle) or State-authorised (in case of old vehicle) HSRP vendor through API. The following parameters are shared through API: 16ο‚· Registration number ο‚· Registration date ο‚· State code ο‚· Office code ο‚· Vehicle manufacturer ο‚· Vehicle type ο‚· Vehicle category ο‚· Fuel ο‚· Emission norm ο‚· HSRP front laser code ο‚· HSRP rear laser code C. Vehicle related select parameters shared with IIB & Insurance Companies: Insurance Companies issue third-party insurance policies to every vehicle during registration of a new vehicle and also during renewal of insurance policy. Insurance Information Bureau verifies the issued insurance policy. The following parameters are shared through API: ο‚· Registration Number ο‚· Chassis Number ο‚· Engine Number ο‚· Manufacturer Name ο‚· Model Name ο‚· Vehicle Category ο‚· Vehicle Class D. VLTD Information to the Vehicle Location Tracking System Implementation Agencies in states: The implementation agencies in the States or UTs authorized by concerned State Transport Authorities for setting up and maintaining the Vehicle Location Tracking System back-end system (Command and Control Centres). The following parameters are shared through API: ο‚· VLT Device serial number ο‚· Registration number ο‚· Registration date 17ο‚· Chassis number ο‚· Engine number ο‚· Vehicle class ο‚· Owner name ο‚· Manufacturer name of the VLTD ο‚· Fitment Centre ο‚· IMEI number ο‚· ICC identification ο‚· Type Approval Certificate Number ο‚· Device Activation Status E. Data Sharing with third-party for e-Challan implementations: The Central Government, State Governments and UT Administration have implemented their own version of e-Challan and require select parameters of Vahan, Sarathi and e- Challan data for verification and reconciliation of data, in the interest of prevention, detection, investigation or prosecution of any offence or contravention. The State Governments and UT Administration shall onboard such third-parties on NTR or notify them, before sharing any data with them. Select data parameters will be shared with such third-parties in deference to the principle of data minimization and purpose limitation. F. Data sharing with payment aggregators licensed by the Reserve Bank of India: Payment related data for transactions in NTR and various other applications/ services are exchanged with the concerned payment gateway/ integrator as authorized by concerned authority to collect payment on its behalf for, amongst other things, providing benefit, service, certificate, licence or permit under Section 7(b) of the DPDP Act. States or UTs have assigned their own payment gateways for collection of payments. These are used for collecting all payments for transactions related to transport services w.r.t. NTR. The options adopted by some States or UTs are: i. Banks designated as payment gateway/integrator on behalf of state. ii. Treasury of State. iii. Payment aggregator licensed by Reserve Bank of India for collection of e- Challan payment. 18iv. Prepaid Payment Instruments authorised by the Reserve Bank of India under the provisions of the Payment and Settlement Systems Act, 2007. G. Sharing with NETC-FASTag: NETC-FASTag data is integrated with internal platforms such as VAHAN, e-Detection, and e-Notice portals to enhance enforcement mechanisms. Electronic notices are issued to vehicles that evade toll payments, using integrated data from VAHAN and the National Payments Corporation of India (NPCI). The following parameters are shared: ο‚· Type of vehicle ο‚· Class of vehicle ο‚· Type of ownership ο‚· Registration number ο‚· FASTag identification ο‚· Number of axles ο‚· Axle description ο‚· Axle weight ο‚· Seating/sleeping/standing capacity ο‚· Manufacturer of vehicle ο‚· Model of vehicle ο‚· Color of vehicle ο‚· Fuel type ο‚· Emission norms ο‚· Unladen weight ο‚· Gross vehicle weight ο‚· National Permit ο‚· National Permit valid up to ο‚· National Permit date of issue ο‚· All India Tourist Permit ο‚· All India Tourist Permit valid up to ο‚· All India Tourist Permit date of issue ο‚· Vehicle height, width and length ο‚· Stage Carriage Permit ο‚· Stage Carriage Permit valid up to ο‚· Stage Carriage Permit date of issue 19ο‚· Contract Carriage Permit ο‚· Contract Carriage valid up to ο‚· Contract Carriage date of issue ο‚· Private Service Vehicle Permit ο‚· Private Service valid up to ο‚· Private Service date of issue ο‚· Goods Permit ο‚· Goods Permit valid up to ο‚· Goods Permit date of issue ο‚· Temporary Permit ο‚· Temporary Permit valid up to ο‚· Temporary Permit date of issue ο‚· Special Permit ο‚· Special Permit valid up to ο‚· Special Permit date of issue H. Sharing of NTR datasets with Private Sector Entities providing Authentication Services for EOL and EODB To support EOL and EODB, MoRTH will provide authentication services along-with anonymised data to private sector entities based on specific business needs. For example, DL verification can be offered as an authentication service similar to Aadhaar authentication. Anonymized data fields for authentication may be made available time to time, upon request, subject to approval and compliance with applicable data privacy and security regulations. Such entities can request masked PII datasets from the NTR for authentication purposes, as an exception, subject to approval from MoRTH. Additionally, these entities shall also execute a memorandum of data compliances or an agreement with MoRTH or the State Government, as the case may be, on a case-by-case basis, in furtherance of ensuring compliance with law. 205. Request and Approval Process 5.1. API-based Data Sharing – Process and Prerequisites. If any Government Department/Agency wants access data through API, the following steps shall be followed: a. For Vahan/Sarathi/e-Challan data, the applicant may submit a request letter, on official letterhead, to the Deputy Secretary or Director (MVL), Transport Bhawan, 1 Sansad Marg, New Delhi-110001for accessing the required data through API based Access as per form given in Annexure-I. For eDAR data access, the application has to be submitted to Deputy Secretary or Director (Road Safety) or the concerned Stakeholders at the State level (being co-holder of the data). For FAStag data access, the application shall be submitted to Superintendent Engineer or Director (Toll)/ Member NHAI. b. The request for data access may be made by an officer of rank/position as below: β€’ Govt. of India– Joint Secretary or equivalent. β€’ State Govt.– Administrative Secretary or equivalent. β€’ PSU/ Govt. Undertaking– Director or equivalent. β€’ Enforcement Agencies– Additional Director General of Police or equivalent. c. As per the application form, contact details of one Authorized Government/ PSU Officer and one Authorised Technical Support Head from the requesting agency are to be provided in the form. The Authorised Government Officer will communicate with MoRTH for all administrative purposes, including original request and renewal etc. The Authorised Government Officer will be responsible for the safety and security of the data received through the API. Even if the API is used for an application developed/maintained by any third-party agency, the primary responsibility will still rest with the Government Officer in whose name the API has been approved. If there is any change of officer over the course of time, the same must be informed to MoRTH along with contact details of the new officer. Details of the Technical Support Head also needs to be stated in the application form. The Technical Support Head will coordinate with the NIC for API integration and other technical requirements. If there is any change of the Technical Support Head over the course of time, the same must be informed to MoRTH along with contact details of the new Technical Support Head. d. The form should be accompanied by the required list of data parameters from Vahan/ Sarathi/e-Challan/eDAR/ FASTag with Parameter wise Purpose/ Justification. 21e. The form should be accompanied by explanation for eligibility of such organisations to process the data under Section 7 of DPDP Act. f. The request should be limited to such Personal Data as is necessary for such specified purpose to ensure data minimisation. g. A memorandum of data compliance also needs to be attached regarding safeguards to be ensured regarding the shared data. The format of the Undertaking is attached in the annexure III. h. After submission of the data access request by the applicant agency, MoRTH will examine the details through a due verification process. If approved, same will be communicated to NIC (if necessary, with specific instructions, fur further action and implementation. i. Once approved, Client ID and access credentials will be created by NIC, and information will be communicated to the applicant’s official email ID. The API integration document and other technical details will also be shared. The process will be as below: Allocation of Credential – ο‚· The Client ID will be communicated by NIC to the applicant’s official email ID (same as mentioned on request application form). ο‚· The applicant needs to provide the confirmation email from official email ID of receipt of Client ID to NIC. ο‚· The Security Key will be communicated to the official email ID only after receipt of confirmation email from the user. Testing Phase– ο‚· Initially, only one client IP will be whitelisted for the testing phase and after successful testing, the same will be made live on production. j. The approved Data Recipient or Data Fiduciary needs to submit a Website Security Certificate from CERT-IN empanelled security auditor for the application for which the required data access is being requested. This certificate should cover the application security audit, vulnerability assessment, penetration testing, configuration review and safe hosting clearance. This certificate is also required at the time of annual renewal of the API access. k. After data access is operationalized on the testing platform, log records from the system regarding data access particulars need to be maintained and shared with NIC. (Format attached in Annexure VI). Similar logs need to be maintained in the 22production environment, which may be demanded in case of any security related investigation. l. Once data access is operationalized, it will be valid for one year only. The access must be renewed every year, well in time before end of the tenure, so that there is no discontinuity of services. The same form as used in the initial application will be used for renewal also. Fresh audit of the Data Processor’s system must be made available before the completion of the tenure. Two intimations/alerts will be sent by NIC to the Data Recipient or Data Fiduciary, first after completion of 10 months and second after completion of 11 months. The alerts will be sent to the specified email IDs of the Authorised Government Officer and Technical Support Head. The duly filled application with all pre-requisites will be reviewed and approved by MoRTH and services will be continued. If not renewed or if fresh audit certificate is not furnished, API access will then be blocked automatically at the end of the yearly tenure. m. MoRTH reserves the right to suspend/discontinue the data access for any Data Recipient at any point of time if any data breach or other security incidence is reported. If necessary, MoRTH may also ask for access log and/or other documentation from the Data Recipient. n. The Data Recipient will also be considered as a Data Fiduciary as per DPDP Act and will be liable for legal actions as per the Act in case of any breach or unauthorized disclosure of Personal Data of citizen. 5.2. Portal-based Data Sharing- Process and Prerequisites. If any Government Department/ Agency wants access data through Portal, the following steps maybe followed: a. For Vahan/Sarathi/e-Challan, the applicant may submit a request letter, on official letterhead, to the Deputy Secretary or Director (MVL), Transport Bhawan, 1Sansad Marg, New Delhi-110001 for accessing the required data through Portal based Access as per form given in Annexure-II. For eDAR data access, the application has to be submitted to Director (Road Safety). For FAStag data access, the application has to be submitted to Superintendent Engineer or Director (Toll)/ Member NHAI. b. The request for data access may be made by an officer of rank/position as below: β€’ Govt. of India– Joint Secretary or equivalent. β€’ State Govt.– Administrative Secretary or equivalent. β€’ PSU/ Govt. Undertaking– Director or equivalent. 23β€’ Enforcement Agencies– Additional Director General of Police or equivalent. c. The Authorized Officer may apply for himself/ herself or for any other officer/ staff of the organization working on regular basis not below the L-13 or equivalent pay scale. Further, the access request may be requested for a single user, or for an Admin User. Admin User can create multiple access credentials and allocate them to other users. d. As per the application form, contact details of two representatives from the requesting agency are to be provided in the form. The Authorised Officer will communicate with MoRTH for all administrative purposes, including original request and renewal etc. The Authorised Officer will be responsible for the safety and security of the data received through the portal access. Even if the access is meant for any other officer/ staff of the organization, the primary responsibility will still rest with the Authorized Officer who has submitted the request. If there is any change of officer over the course of time, the same must be informed to MoRTH along with contact details of the new officer. Details of the Actual User – who will be issued the access credentials, also needs to be stated in the application form. This user may communicate with NIC for any technical requirements. If this is an Admin User, then he/she can create other users also. If there is any change of the user over the course of time, the same must be informed to MoRTH along with contact details of the new user. e. The form should be accompanied by the required list of data parameters from Vahan/ Sarathi/e-Challan/eDAR/FASTag with parameter wise Purpose/Justification. f. The form should be accompanied by explanation for eligibility of such organisations to process the data under Section 7 of DPDP Act. g. In case of Personal Data, the request should be limited to such Personal Data as is necessary for such specified purpose to ensure data minimisation. h. An memorandum of data compliance also needs to be attached regarding safeguards to be ensured regarding the shared data. The format of the Undertaking is attached in the annexure IV. i. After submission of the data access request by the applicant agency, MoRTH will examine the details through a due verification process. If approved, same will be communicated to NIC (if necessary, with specific instructions, fur further action and implementation. j. Once data access is operationalized, it will be valid for one year only. The access must be renewed every year, well in time before end of the tenure, so that there is no discontinuity of services. The same form as used in the initial application 24will be used for renewal also. Two intimations/alerts will be sent by NIC to the Data Recipient or Data Fiduciary – two weeks before and 1 week before the end of the yearly tenure. The alerts will be sent to the specified email IDs of the Authorised Government Officer. The duly filled application with all pre-requisites will be reviewed and approved by MoRTH and services will be continued. If not renewed Portal access will then be blocked automatically at the end of the yearly tenure, with intimation to the authorised officer. k. Only one Login ID/password will be issued to an organization. The organization may, in turn, create sub- user IDs and passwords, if required, for its constituents/branches etc. In this case, Admin option should be chosen. However, the Authorised Officer will be responsible for the act/ conduct of all the users created under the admin option. l. The Data Recipient will also be considered as a Data Fiduciary as per DPDP Act and will be liable for legal actions as per the Act in case of any breach or unauthorized disclosure of Personal Data of citizen. 5.3. Bulk Data Sharing – Process and Prerequisites. Bulk data sharing is an exceptional requirement and will be considered by MoRTH on case-by-case basis. So far only five Government agencies have been provided bulk data from Vahan/ Sarathi databases, comprising specified datasets as per user requirements. There is no specified request form or process for this, however, some suggested points are stated as below. Further, the existing bulk data sharing status also may be periodically reviewed by MoRTH and necessary guidelines may be issued to MoRTH. a. For Vahan/Sarathi/e-Challan data, the Applicant may submit a request letter, on official letterhead, to the Director(MVL), Transport Bhawan, 1 Sansad Marg, New Delhi-110001for accessing the required data. For eDAR data access, the application has to be submitted to Deputy Secretary or Director (Road Safety). For FAStag data access, the application has to be submitted to Superintendent Engineer or Director (Toll)/ Member NHAI. b. The request for data access may be made by an officer of rank/position as below: β€’ Govt. of India– Joint Secretary or equivalent. c. Contact details of concerned officials are to be provided in the form. The Authorised Government Officer will communicate with MoRTH for all administrative purposes, including original request and renewal etc. The Authorised Government Officer will be responsible for the safety and security of the data received. Details of the nodal Officer also needs to be stated in the application form. This officer will coordinate with the NIC for operational aspects 25of secure exchange of data and other technical requirements. The Name, Designation, Email ID, Mobile Number and Office Address of both these officers need to be submitted for record purpose. If there is any change of officer over the course of time, the same must be informed to MoRTH along with contact details of the new officer. d. The request should be accompanied by the required list of data parameters from Vahan/ Sarathi/ e-Challan/ eDAR/ FASTag databases with detailed Purpose/Justification. The periodicity of incremental data is also to be specified, which may be in terms of Year/ Quarter/ Month. e. An Undertaking also needs to be attached regarding safeguards to be ensured regarding the shared data. The format of the Undertaking is attached in the annexure V. f. After submission of the data access request by the applicant agency, MoRTH will examine the details through a due verification process. If approved, same will be communicated to NIC (if necessary, with specific instructions, fur further action and implementation. g. Once approved, the data sharing mechanism will be worked out by the Operational Support Officer of the Data Recipient or Data Fiduciary and NIC. If data is to be provided through portable hard disk drive, the agency will provide the same with appropriate capacity to authorized NIC officer/ staff. Required data will be extracted by NIC and copied to the device and handed over to the authorized officer/ staff of the agency as per due security protocol. Alternatively, if the data size permits and the concerned agency agrees, the bulk data can be shared through an SFTP link to be set up by NIC. Access credentials will be created by NIC, and information will be communicated to the applicant’s official email ID. For incremental data also, similar exercise may be undertaken. h. The Data Recipient will also be considered as a Data Fiduciary as per DPDP Act and will be liable for legal actions as per the Act in case of any breach or unauthorized disclosure of Personal Data of citizen. 266. Data Sharing Security Practices and Procedures At present, MoRTH shares data through API and portal-based access with Data Recipients/Fiduciary, such as Government Departments, Enforcement Agencies etc. While, MoRTH and NIC facilitate the provision of data, it is critical to protect sensitive information and ensure compliance with the provisions of the DPDP Act by these Data Recipient or Data Fiduciary. Data Security Guidelines for Government Organisations agencies requesting data: 1. Data access for pan India data will be provided to Government Organizations and Enforcement Agencies upon approval from MoRTH, subject to compliance with all prerequisites. As the data contains sensitive personal information, the designated government officer of the Data Recipient, named in the request application form shall be responsible for safeguarding the data. If the officer of the Data Recipient is transferred, retires, or is replaced, MoRTH must be notified immediately via official letterhead, duly signed and stamped by the Competent Government Officer, to update the records. 2. Data Recipient shall execute a memorandum of data compliances or an agreement with a Data Recipient or Data Fiduciary, on a case-by-case basis, in furtherance of ensuring compliance with law. Data Recipients shall be Data Fiduciaries as defined under the DPDP Act. 3. Where a consent given by the Data Principal is the basis of processing of Personal Data and a question arises in this regard in a proceeding, the Data Recipient i.e. Data Fiduciary shall be obliged to prove that a notice was given by her to the Data Principal and consent was given by such Data Principal in accordance with the provisions of the DPDP Act and the rules made thereunder, as provided under Section 6(10) of the said Act. 4. State-level data sharing may be approved by the respective State Transport Authority, who is the co-holder of the State-specific data. Approval can be granted by the State Transport Secretary or Commissioner, but only for State-specific data. National-level data sharing requires MoRTH approval. 5. A set of prerequisites, such as ensuring its completeness, accuracy and consistency must be met before implementing API-based data sharing. 6. Data Recipient must submit a Security Audit Certificate issued by a CERT-IN empanelled security auditor for the application in which API access is requested. The certificate should cover application security, vulnerability assessment, penetration testing, configuration review, and safe hosting clearance. Details on 27certified consultants are available on the CERT-IN portal (https://cert-in.org.in). Additional audit may be required from time to time and on case-to-case basis. 7. The approval will be granted for only one year at a time and needs to be renewed every year. Further, the Security Audit must be carried out every year, and the certificate needs to be submitted to MoRTH annually. Agencies will receive two alerts or notifications before the renewal date. If the renewal of the data access is not done and updated audit certificate is not submitted to MoRTH in time, service access will be discontinued. 8. API access is granted for a specific application, with a maximum of four IPs (two for Production Servers and two for Development/Testing Servers) whitelisted. Separate approvals are required for each application requesting API access. 9. API credentials must remain confidential and must not be shared with any third party. Sub-granting of the API is not permissible. 10. Data Recipient must implement appropriate access control mechanisms (e.g., secret keys, user-id/password authentication, IP whitelisting, token exchange) to ensure that no third party can access the API through their application. 11. Log records of data access must be maintained, for at least one year, in the production environment and made available upon request for any security investigation. 12. Data Recipient must keep portal access credentials confidential. Passwords must be changed immediately after receipt and regularly thereafter to maintain security. 13. All accessed data must be processed and stored on servers located within India. Data must not be transferred or stored on servers outside India. 14. Data Recipient must specify the required data parameters with a detailed purpose and justification. MoRTH will grant approval based on this justification, ensuring that only necessary data is shared in compliance with the principles of the DPDP Act. 15. Data Recipient are prohibited from disclosing, reproducing, selling, distributing, or transferring any shared data or Personal Data. The data cannot be used for any purpose other than what was originally requested. A fresh application is required for any additional purposes. 16. Data Recipient must maintain up-to-date operating systems, robust cyber security measures, and conduct regular audits to safeguard data and prevent breaches. 2817. Data Recipient must enforce private sector-standard managerial, technical, and physical safeguards to prevent unauthorized data processing or access. 18. Data Recipient Sare advised to implement and enforce strong password policies, including Multi-Factor Authentication (MFA), to enhance security and reduce the risk of unauthorized access. 19. In the event of a data breach involving personal or sensitive information, Data Recipient must immediately notify MoRTH and the affected individuals. Breaches must also be reported in compliance with the DPDP Act. 20. Failure to comply with these guidelines or the DPDP Act may result in debarment from further data sharing, along with legal action or monetary penalties under applicable laws. 21. An Undertaking outlining data protection and privacy responsibilities must be submitted by the Data Recipient prior to data sharing. This undertaking will be reviewed, updated, and renewed annually. 29Annexure I Application Form for API-based Data Sharing Note: A platform for handling requests from all Data Recipient or Data Fiduciary and approval by MoRTH will be developed. It will facilitate Data Recipient or Data Fiduciary to apply online and allow the verifying and approving authorities to carry out the required action online. Until the online application for the request or approval is developed, manual form will be used by the applicant and communicated through eMail. 30Annexure II Application Form for Portal-based Data Sharing Note: A platform for handling requests from all Data Recipient or Data Fiduciary and approval by MoRTH will be developed. It will facilitate Data Recipient or Data Fiduciary to apply online and allow the verifying and approving authorities to carry out the required action online. Until the online application for the request or approval is developed, manual form will be used by the applicant and communicated through eMail. 31Annexure III MEMORANDUM OF DATA COMPLIANCES (For API data sharing) I hereby provide this undertaking in connection with "API based NTR data sharing" As a 'Data Recipient or Data Fiduciary', I am fully aware of the terms and conditions outlined in the Information Technology Act, 2000 and Digital Personal Data Protection Act, 2023 of the Government of India. As a Data Recipient or Data Fiduciary, I hereby undertake the following: 1. I will keep API credentials, Secret Key etc. confidential and not share them with any third party. 2. I understand that API access is granted only for a specific application/app, and a maximum of four IPs (2 IPs for Production Servers and 2 IPs for Development Servers) of the user system are whitelisted for access. 3. I will tightly bind API access to the approved application (Mobile App/Web Application) through appropriate access control mechanisms such as secret keys, user-id/password authentication, IP whitelisting, a token exchange mechanism, etc., ensuring that no third party can access the service through the application/APP. 4. I will submit Security Audit Certificate from CERT-IN empanelled security auditor for the application/app for which the required data access is being requested. 5. I will submit a similar Audit certificate to MoRTH every year at the time of annual renewal. Failure to do so gives MoRTH the right to discontinue the data sharing service. 6. I undertake that after the data access is operationalized on the testing platform, log records from the system regarding data access particulars shall be maintained and shared with NIC. 7. I undertake to be responsible for the safety and security of the data received through access. If I am transferred, retired, or released, the details of the new incumbent on the official letterhead, duly signed, and stamped, shall be shared with MoRTH for updating the records. 8. I undertake to use the shared data only for the purpose justified in the request form. 329. I will not disclose, reproduce, sell, distribute, or transfer any shared data or portion of such data to any third party. 10. I undertake not to use, display, or exchange any shared data in any write-up, paper, presentation, discussion forums, or messaging applications without prior approval from MoRTH. 11. I undertake that all shared data shall be processed and stored on servers or Data Centres residing in India. The data at any point shall not be transferred, processed, or stored on a server outside India. 12. I undertake to develop and maintain strong policies enforcing strong passwords (password management) and the use of multi-factor authentication (MFA). 13. I undertake to always keep up-to-date Operating Systems (OS), robust Cyber- Security systems, including encryption, intrusion detection systems, other application Software, and employee training, to safeguard the systems and data. 14. I undertake that, upon the request of MoRTH, I will stop using/processing the data accessed through this mode and shall erase any Personal Data as per the Digital Personal Data Protection Act, 2023. 15. I undertake that failure to comply with the requirements of these guidelines resulting in any data breach will lead to discontinuation of the service. I undertake to report data breach in accordance to the Digital Personal Data Protection Act, 2023. Further, this may entail legal action and monetary penalties as per Information Technology Act 2000 and Digital Personal Data Protection Act, 2023. 16. The Data Recipient or Data Fiduciary shall comply with the applicable law including Information Technology Act 2000 and Digital Personal Data Protection Act, 2023. 33I have signed and executed this undertaking on this _________ day of ______, 20 at _______________________________. I hereby declare that I have provided this undertaking willingly, without any undue influence or duress, and that the foregoing statement is true and correct. I commit to abiding by and complying with all the terms of this undertaking. Name of Applicant Organisation: …………………………………………………………………………. Name of Authorised Government Officer/ Data Recipient or Data Fiduciary: …………………………………………………………………………. ………………………………………….…………………………………………………..…………………………………………. Designation: …………………………………………………………………………. Department: …………………………………………………………………………. Mobile number: …………………………………………………………………………. Office Phone number: …………………………………………………………………………. Official Email ID: …………………………………………………………………………. Office Address: …………………………………………………………………………. Signature: ____________________ Name: ____________________ Seal 34Annexure IV MEMORANDUM OF DATA COMPLIANCES (For Portal-based data sharing) I hereby provide this undertaking in connection with "Portal based NTR data sharing" As a 'Data Recipient or Data Fiduciary', I am fully aware of the terms and conditions outlined in the Information Technology Act 2000 and Digital Personal Data Protection Act, 2023 of the Government of India. As a Data Requester/ Data Recipient or Data Fiduciary, I hereby undertake the following: 1. I undertake to keep the Portal credentials confidential and not share them with any third party. 2. I undertake to change the password immediately after receiving it and thereafter, update the password as frequently as possible. 3. I undertake to be responsible for the safety and security of the data received through the Portal access. If I am transferred, retired, or released, the details of the new incumbent on the official letterhead, duly signed, and stamped, shall be shared with MoRTH for updating the records. 4. I undertake to use the shared data only for the purpose justified in the request form. 5. I will not disclose, reproduce, sell, distribute, or transfer any shared data or portion of such data to any third party. 6. I undertake not to use, display, or exchange any shared data in any write-up, paper, presentation, discussion forums, or messaging applications without prior approval from MoRTH. 7. I undertake to comply with password policy and guidelines of the portal and the use multi-factor authentication (MFA). 8. I undertake to always keep up-to-date Operating Systems (OS), robust Cyber- Security systems, including encryption, intrusion detection systems, other application Software, and employee training, to safeguard the systems and data. 9. I undertake that, upon the request of MoRTH, I will stop using/processing the data accessed through this mode and shall erase any Personal Data as per the Digital Personal Data Protection Act, 2023. 10. I undertake that failure to comply with the requirements of these guidelines resulting in any data breach will lead to discontinuation of the service. I undertake 35to report data breach in accordance to the Digital Personal Data Protection Act, 2023. Further, this may entail legal action and monetary penalties as per Information Technology Act 2000 and Digital Personal Data Protection Act, 2023. 11. The Data Recipient or Data Fiduciary shall comply with the Information Technology Act 2000 and Digital Personal Data Protection Act, 2023. This undertaking has been signed and executed by me on this _______________ day of ______________, 20 at ____________________________. I do hereby declare that this undertaking has been given by me of my own volition without any undue influence or duress and that the foregoing statement is true and correct. I undertake to abide by and comply with all the terms of this undertaking. Name of Applicant Organisation: …………………………………………………………………………. Name of Authorised Government Officer/ Data Recipient or Data Fiduciary: …………………………………………………………………………. ………………………………………….………………………………………………………………………………………………. Designation: …………………………………………………………………………. Department: …………………………………………………………………………. Mobile number: …………………………………………………………………………. Office Phone number: …………………………………………………………………………. Official Email ID: …………………………………………………………………………. Office Address: …………………………………………………………………………. Signature: ____________________ Name: ____________________ Seal 36Annexure V MEMORANDUM OF DATA COMPLIANCES (For Bulk data sharing) I hereby provide this undertaking in connection with "Bulk NTR data sharing" As a 'Data Requester/ Data Recipient or Data Fiduciary', I am fully aware of the terms and conditions outlined in the Information Technology Act 2000 and Digital Personal Data Protection Act, 2023 of the Government of India. As a Data Requester/ Data Recipient or Data Fiduciary, I hereby undertake the following: 1. I undertake the responsibility for the safety and security of the NTR bulk data received through a portable hard disk drive or Secured FTP (SFTP) link. 2. I commit to using the Shared Bulk Data only for the Purpose/Justification mentioned at the time of data requisition and shall not disclose, reproduce, sell, distribute, or transfer any Shared Data or portion of such data to any third party for any other purpose, without the prior written consent of the MoRTH. 3. I commit not to use, display, or exchange any Shared Bulk Data in any write-up, paper, presentation, discussion forums, or messaging applications without prior approval from the MoRTH. 4. I commit that all Shared Bulk Data shall be processed and stored on servers or Data Centres residing in India. The data at any point shall not be transferred, processed, or stored on a server outside India. 5. I commit to always keep up-to-date Operating Systems (OS), robust Cyber-Security systems, including encryption, intrusion detection systems, other application Software, and employee training, to safeguard the systems and data. 6. I commit that, upon the request of MoRTH, I will stop using/processing the data accessed through this mode and shall erase any personal as per the Digital Personal Data Protection Act, 2023. 7. I undertake that failure to comply with the requirements of these guidelines resulting in any data breach will lead to discontinuation of the service. I undertake to report data breach in accordance to the Digital Personal Data Protection Act, 2023. Further, this may entail legal action and monetary penalties as per Information Technology Act 2000 and Digital Personal Data Protection Act, 2023. 8. The Data Recipient or Data Fiduciary shall comply with the Information Technology Act 2000 and Digital Personal Data Protection Act, 2023. 37This undertaking has been signed and executed by me on this _______________ day of __________, 20 at _______________________. I hereby declare that this undertaking has been given by me of my own volition without any undue influence or duress and that the foregoing statement is true and correct. I undertake to abide by and comply with all the terms of this undertaking. Name of Applicant Organisation: …………………………………………………………………………. Name of Authorised Government Officer/ Data Recipient or Data Fiduciary: …………………………………………………………………………. ………………………………………….………………………………………………………………………………………………. Designation: …………………………………………………………………………. Department: …………………………………………………………………………. Mobile number: …………………………………………………………………………. Office Phone number: …………………………………………………………………………. Official Email ID: …………………………………………………………………………. Office Address: …………………………………………………………………………. Signature: ____________________ Name: ____________________ Seal 38Annexure VI MEMORANDUM OF DATA COMPLIANCES (For Citizen sharing) I hereby provide this undertaking in connection with NTR data sharing. As a 'Data Recipient or Data Fiduciary', I am fully aware of the terms and conditions outlined in the Information Technology Act, 2000 and Digital Personal Data Protection Act, 2023 of the Government of India. As a Data Requester/ Data Recipient or Data Fiduciary, I hereby undertake the following: 1. I undertake to keep the Portal credentials confidential and not share them with any third party, (if applicable). 2. I undertake to change the password immediately after receiving it and thereafter, update the password as frequently as possible (if applicable). 3. I undertake to be responsible for the safety and security of the data received. 4. I will not disclose, reproduce, sell, distribute, or transfer any shared data or portion of such data to any third party. 5. I undertake that, upon the request of MoRTH, I will stop using/processing the data accessed through this mode and shall erase any Personal Data as per the Digital Personal Data Protection Act, 2023. 6. I undertake that failure to comply with the requirements of these guidelines resulting in any data breach will lead to discontinuation of the service. I undertake to report data breach in accordance to the Digital Personal Data Protection Act, 2023. Further, this may entail legal action and monetary penalties as per Information Technology Act, 2000 and Digital Personal Data Protection Act, 2023. 7. The Data Recipient or Data Fiduciary shall comply with the Information Technology Act 2000 and Digital Personal Data Protection Act, 2023. This undertaking has been signed and executed by me on this____________________ day of ______________, 20 at ___________________________. I do hereby declare that this undertaking has been given by me of my own volition without any undue influence or duress and that the foregoing statement is true and correct. I undertake to abide by and comply with all the terms of this undertaking. Signature:____________________ Name: _______________________ 39Annexure VII Log Record Format API audit logs are critical for tracking and recording actions and events related to API usage, ensuring security, compliance, and monitoring. All agencies granted API-based data access are required to maintain detailed logs for every API access. These logs must be preserved for a minimum of one year and provided to MoRTH either annually or upon request. 40 pmatsemiT tseuqeR dohteM tseuqeR LRU tseuqeR sredaeH tseuqeR ydoB tseuqeR edoC sutatS esnopseR sredaeH esnopseR ydoB esnopseR emiT esnopseR sserddA PI tneilC sserddA PI revreS tnegA resUAnnexure VIII Data Sets A. Vahan Data Sets ο‚· Registration Details β€’ Registration Number β€’ Registration Date β€’ Registering Authority β€’ Vehicle Status β€’ Vehicle Blacklist Status ο‚· Purchase Details β€’ Purchase Date β€’ Sale Amount ο‚· Vehicle Owner Details β€’ Owner’s Name β€’ Ownership Serial Number β€’ Owner’s Address β€’ Permanent Address β€’ Present Address β€’ Owner’s Father Name β€’ Owner Mobile Number β€’ Vehicle Owner History β€’ Owner Category β€’ Ownership Type ο‚· Vehicle Details β€’ Maker Name β€’ Model Name β€’ Chassis Number β€’ Engine Number β€’ Vehicle Colour β€’ Vehicle Body Type β€’ Wheelbase 41β€’ Vehicle Manufacturing Month/Year β€’ Vehicle Class β€’ Vehicle Category β€’ Vehicle Type(T/NT) β€’ Fuel Type β€’ Emission Norms β€’ Unladen Weight β€’ Laden Weight β€’ Number of Cylinders β€’ Vehicle Cubic Capacity β€’ Seating Capacity β€’ Sleeper Capacity β€’ Standing Capacity ο‚· Validity Norms β€’ Registration Validity β€’ Fitness Validity β€’ PUCC Validity β€’ MV Tax Validity β€’ Passenger tax validity β€’ Goods tax validity ο‚· Dealer Details β€’ Dealer Name β€’ Trade Certificate Number β€’ Dealer Address ο‚· Used Car Dealer Details β€’ Dealer Code β€’ Dealer Name ο‚· Permit Details β€’ Type β€’ Number β€’ Validity β€’ Issuing Authority 42ο‚· Insurance Details β€’ Validity β€’ Company Name β€’ Policy Number ο‚· Hypothecation details β€’ Financer Name β€’ Financer Address β€’ Hypothecation type ο‚· NOC Details β€’ Reference Number β€’ Date β€’ State To β€’ Transport Office To ο‚· Non-use information β€’ From Date β€’ To Date β€’ Reason ο‚· e-Challan details β€’ Date & Time β€’ Place β€’ Offence β€’ Challan Number β€’ Challan Amount B. Sarathi Data Sets ο‚· Driving License Details β€’ Driving License Number β€’ DL Issue Date β€’ Issuing Authority β€’ DL Category β€’ Type of License β€’ Class of Vehicle details o Description 43o Category o Issue date β€’ Old Driving License Number β€’ Last Endorsement Authority β€’ Last Endorsement Date β€’ Last Completed Transaction β€’ Current License Status ο‚· DL Holder’s Details β€’ License Holder’s Name β€’ Date of Birth β€’ Photograph β€’ Gender β€’ Address β€’ Permanent Address β€’ Present Address β€’ Previous addresses (if any) β€’ Blood Group β€’ Organ Donor Consent β€’ Educational Qualification β€’ Contact Number β€’ E-Mail ID β€’ Identification Marks β€’ Son/Wife/Daughter of* ο‚· Validity β€’ Non-Transport Validity β€’ Transport Validity β€’ Hazardous Validity β€’ Hill Validity ο‚· International Driving Permit (IDP) Details β€’ IDP Number β€’ Issuing Authority β€’ Issue Date β€’ Validity 44ο‚· PSV Details β€’ Badge Number β€’ Issue Date β€’ Issued By ο‚· Adaptive vehicle Number ο‚· Challan details β€’ Challan Number β€’ Challan Source Type β€’ Enforcement From Date β€’ Enforcement End Date β€’ Enforcement Remark β€’ DL Intermediate Stage β€’ RTO Action C. e-Challan Datasets ο‚· Challan’s Details β€’ Challan Number β€’ Challan Date Time β€’ Challan Location β€’ Challan Location Lat-Long β€’ State Name/Code β€’ Circle/Area/Police Station β€’ Challaning Authority Office β€’ Challaning Officer Name β€’ Department Code (TRAFFIC/TRANSPORT) β€’ List of Offences β€’ Challan Amount β€’ Challan Status β€’ Receipt No of Disposed Challan β€’ List of Impounded Documents ο‚· Vehicle Details β€’ Vehicle Registration Number β€’ Class of Vehicle 45ο‚· Challan Recipient Details β€’ Name (Challan recipient Name) β€’ Father Name (Challan recipient Father Name) β€’ Vehicle Owner Name β€’ Vehicle Owner’s Father Name β€’ Driver Name β€’ Driving Licence Number ο‚· Court Details β€’ Sent to Court Date-Time β€’ Court Name β€’ Court Address β€’ Court Status of Challan β€’ Date of Proceeding in Virtual Court β€’ Fine Imposed in Virtual Court ο‚· Driving license Details β€’ Driving License Number D. eDar datasets ο‚· Accident Basic Details β€’ Accident Id β€’ Accident Date and Time β€’ Accident Location β€’ Point of Interest β€’ Landmark Name β€’ Severity of the Accident β€’ Number of Vehicles Involved β€’ Police Station β€’ District β€’ State β€’ Driver β€’ Passengers β€’ Pedestrian β€’ Road Classification β€’ Road Name 46β€’ Collision Type β€’ Collision Nature β€’ Weather Condition β€’ Light Condition β€’ Visibility β€’ Initial Observation of Accident Scene β€’ Traffic Violation β€’ Accident Description ο‚· Vehicle and Driver Details β€’ Accident ID β€’ Vehicle Damage β€’ Vehicle Id β€’ Vehicle Category β€’ Hit and Run β€’ Accused or Victim β€’ Vehicle Type β€’ Load Category β€’ Skid Mark β€’ Education β€’ Occupation β€’ Cellphone while driving β€’ Severity β€’ Injury Type β€’ Seatbelt/Helmet β€’ Drunk and Drive β€’ Pedestrian Action ο‚· Vehicle Passenger Details β€’ Accident Id β€’ Vehicle Id β€’ Gender β€’ Education β€’ Occupation β€’ Severity β€’ Injury Type 47β€’ Mode of Hospitalisation β€’ Hospitalisation Delay β€’ Passenger Position β€’ Passenger Action β€’ Helmet/Seatbelt ο‚· Vehicle Pedestrian Details β€’ Accident Id β€’ Vehicle Id β€’ Gender β€’ Education β€’ Occupation β€’ Severity β€’ Injury Type β€’ Mode of Hospitalisation β€’ Hospitalisation Delay β€’ Pedestrian Position E. FASTag Datasets ο‚· Vehicle Details β€’ Vehicle Classes (VC1, VC2 etc) β€’ Vehicle registration number β€’ Vehicle exemption code β€’ Commercial vehicle β€’ Automatic vehicle class ο‚· FASTag Details β€’ FASTag id β€’ Unique number printed on tag β€’ TagCode ο‚· General Details β€’ Weight in motion β€’ Lane Id β€’ Lane Direction β€’ Unregistered Flag (F/T)(1/0) 48β€’ Financial Year ο‚· Bank Details β€’ Merchant NETC code β€’ Merchant Type (TOLL/Parking etc) we only receive plaza data β€’ Merchant Sub Type (National/State) β€’ Issuer Bank id in the NPCI system β€’ Acquired bank id ο‚· Transaction Details β€’ Transaction seq. no. generated by NPCI for each txn. β€’ Transaction no./id generated by acquirer bank β€’ Transaction id generated by merchant/toll. β€’ Transaction time captured by acquirer bank β€’ Transaction type (Credit/Debit/Non-fin) β€’ Original transaction id β€’ Time at which the transaction was captured by reader β€’ Transaction status: o Accepted, o Deemed Accepted, o Declined, o Pending. β€’ Transaction Amount β€’ Final settlement amount β€’ Time at which transaction was received by NPCI β€’ Transaction last updated at NPCI β€’ Month of Transaction 49Annexure IX Abbreviation Full Form MORTH Ministry of Road Transport and Highways NIC National Informatics Center RC Registration Certificate DL Driving License eDAR Electronic Detailed Accident Report DPDP Digital Personal Data Protection NR National Register NTR National Transport Repository EODB Ease of Doing Business POI Proof of Identity NDSAP National data Sharing Accessibility Policy CAG Comptroller and Auditor General of India IRDAI Insurance Regulatory and Development Authority of India IIB Insurance Information Bureau GSTN Goods and Services Tax Network CBI Central Bureau of Investigation IB Intelligence Bureau NIA National Investigation Agency NATGRID National Intelligence Grid CBIC Central Board of Indirect Taxes SPG Special Protection Group OTP One time password API Application Programming Interface NGO Non-Government Organisation 50Abbreviation Full Form PII Personally Identifiable Information PUCC Pollution under control certificate MV Tax Motor Vehicle Tax T/ NT Transport/ Non-Transport NCRB National Crime Record Bureau NOC No Objection Certificate RTO Regional Transport Office IDP International Driving Permit PSV Public Service Vehicle PVC Polyvinyl Chloride Card OEM Original Equipment Manufacturer HSRP High Security Registration Plate VLTD Vehicle location tracking Device ICCC Integrated Command Control Centre VLTS Vehicle location tracking system IMEI International Mobile Equipment Identity CSC Common Service Centre DGQI Data Governance Quality Index NAPIX NIC API Exchange Gateway IIT Indian Institute of Technology MFA Multi factor Authentication IP Internet Protocol CERT-IN Computer Emergency Response Team OS Operating System 51

Continue your research