THE RULES

Rule 5 - Processing for provision or issue of subsidy, benefit, service, certificate, licence or permit by State

Official text

(1)Processing the personal data of a Data Principal under this rule shall be done following the standards specified in Second Schedule.

(2)In this rule and the Second Schedule, the reference to any subsidy, benefit, service, certificate, licence or permit that is provided or issued—

(a)under law shall be construed as a reference to provision or issuance of such subsidy, benefit, service, certificate, licence or permit in exercise of any power of or the performance of any function by the State or any of its instrumentalities under any law for the time being in force;

(b)under policy shall be construed as a reference to provision or issuance of such subsidy, benefit, service, certificate, licence or permit under any policy or instruction issued by the Central Government or a State Government in exercise of its executive power; and

(c)using public funds shall be construed as a reference to provision or issuance of such subsidy, benefit, service, certificate, licence or permit by incurring expenditure on the same from, or with accrual of receipts to, —

(i)in case of the Central Government or a State Government, the Consolidated Fund of India or the Consolidated Fund of the State or the public account of India or the public account of the State; or

(ii)in case of any local or other authority within the territory of India or under the control of the Government of India or of any State, the fund or funds of such authority.

Cross-references

Rule 5

Commentary

Rule 5 operationalises the standards applicable when the State or its instrumentalities process personal data under Section 7(b) of the DPDPA for providing or issuing a subsidy, benefit, service, certificate, licence or permit. It also clarifies when such provision or issuance is treated as occurring under law, under government policy or instruction, or through public funds.

Rule 5 must be read with the Second Schedule, which establishes the substantive safeguards governing such processing. The Second Schedule also applies separately to processing necessary for research, archiving or statistical purposes under Section 17(2)(b). Accordingly, the Schedule performs two distinct functions, even though Rule 5 itself is principally concerned with State processing under Section 7(b).

Commencement position: Rule 5, Section 7 and the relevant substantive obligations are scheduled to come into force on13 May 2027. Rule 5 is therefore final and available for implementation planning, but is not yet operational as of 1 September 2026.

1.1 Relationship with Section 7(b)

Section 7 identifies certain legitimate uses for which personal data may be processed without relying on consent as the immediate legal ground for that particular processing. Section 7(b) applies where the State or one of its instrumentalities processes personal data to provide or issue a subsidy, benefit, service, certificate, licence or permit.

The provision broadly contemplates two situations:

  • the Data Principal has previously consented to processing of her personal data by the State or its instrumentality for another qualifying subsidy, benefit, service, certificate, licence or permit; or

  • the relevant personal data is already available in digital form in a database, register, book or other document maintained by the State or its instrumentality, or is available in a non-digital government record that is subsequently digitised.

The use of previously provided or government-held personal data is subject to the standards prescribed under the Rules and must remain connected to a qualifying State benefit, service or authorisation. Rule 5 and the Second Schedule provide those standards.

This means Section 7(b) does not create a general authority for governmental reuse of personal data. The processing must remain connected to the provision or issuance of the relevant subsidy, benefit, service, certificate, licence or permit and must satisfy the requirements concerning lawfulness, necessity, accuracy, retention, security, transparency and accountability.

1.2 Illustration: Reuse of existing government data

A State Government already holds an individual’s identity and residential information in connection with a previously issued ration card. It later introduces a housing-support benefit and proposes to use the existing information to determine or facilitate eligibility.

The State may examine whether Section 7(b) applies instead of obtaining fresh consent merely to retrieve the same information. If it relies on Section 7(b), it must still:

  • establish that the housing support is a qualifying subsidy, benefit or service;

  • use only the personal data necessary for the housing-support purpose;

  • take reasonable steps to check accuracy;

  • inform the individual about the processing;

  • provide privacy contact and rights-access mechanisms;

  • protect the data against breach; and

  • stop retaining it when it is no longer required, subject to applicable law.

The fact that the Government already possesses the information does not permit unlimited reuse for unrelated governmental or commercial purposes.

1.3 Scope of qualifying government activity

Rule 5 recognises that State programmes may be created and administered through different legal and financial mechanisms. A subsidy, benefit, service, certificate, licence or permit may qualify where it is provided or issued:

  • under law;

  • under a government policy or executive instruction; or

  • using public funds.

This prevents Section 7(b) from being limited only to programmes expressly created by an Act of Parliament or State Legislature.

Provision or issuance under law

A programme is provided or issued under law where it is connected with the exercise of a statutory power or performance of a statutory function by the State or its instrumentality.

This may include, depending on the governing legislation:

  • statutory licences;

  • registrations;

  • permits;

  • certificates;

  • social-security benefits;

  • welfare entitlements;

  • regulatory approvals; or

  • public services delivered under legislation.

The authority should be able to identify the applicable legal power or function. It should not describe a programme as being “under law” merely because the organisation administering it is a public authority.

Provision or issuance under policy

A qualifying programme may also arise under a policy or instruction issued by the Central Government or a State Government in exercise of executive power.

This recognises that many government schemes are introduced through:

  • policies;

  • executive orders;

  • administrative instructions;

  • government resolutions; or

  • scheme guidelines, rather than through a separate enactment.

A policy-based programme must still have a proper governmental foundation. An informal departmental practice or an official’s internal preference should not automatically be treated as a policy or instruction issued in exercise of governmental executive power.

Provision or issuance using public funds

Rule 5 also covers programmes financed through constitutionally or legally recognised public funds.

For the Central Government or a State Government, this includes expenditure from, or accrual of receipts to:

  • the Consolidated Fund of India;

  • the relevant State Consolidated Fund;

  • the Public Account of India; or

  • the relevant State Public Account.

For a local or other governmental authority, the programme may qualify where expenditure is incurred from, or receipts accrue to, the authority’s own fund or funds.

This may cover programmes administered by:

  • municipal authorities;

  • development authorities;

  • statutory boards;

  • public educational bodies;

  • welfare boards; or

  • other authorities under Central or State control.

Public funding alone should not be interpreted as authority for any form of personal-data processing. The processing must still concern the actual provision or issuance of the qualifying subsidy, benefit, service, certificate, licence or permit and satisfy the Second Schedule.

1.4 Standards under the Second Schedule

The Second Schedule ensures that reliance on Section 7(b) does not remove basic data-protection safeguards merely because the processing is undertaken by the State.

The State or instrumentality acting as Data Fiduciary must implement appropriate technical and organisational measures to ensure effective compliance with the prescribed standards.

1.5 Lawfulness

The processing must be carried out lawfully. Section 7(b) does not legitimise an activity prohibited by another law or undertaken without proper governmental authority.

The Data Fiduciary must establish:

  • the governmental programme involved;

  • its statutory, policy or public-funding foundation;

  • the function being performed;

  • the relevance of the personal data; and

  • the authority of the State body conducting the processing.

The provision cannot be used to bypass legal restrictions governing confidentiality, protected records, surveillance, discrimination or sector-specific data use.

1.6 Purpose limitation

Personal data processed under Rule 5 must be used for the qualifying purpose for which Section 7(b) permits it.

Example

For example, personal data collected or retrieved to determine eligibility for an educational scholarship should not automatically be used for:

  • unrelated law-enforcement profiling;

  • political communication;

  • commercial advertising;

  • sale to private businesses;

  • unrelated population analytics; or

  • assessment for another programme having no proper connection with the original use.

Where another use is proposed, the State must identify an independent legal basis and satisfy the applicable requirements for that processing.

1.7 Illustration: Scholarship information

A State department processes a student’s identity, educational and income information to assess scholarship eligibility.

The information may be used for:

  • verifying the application;

  • determining eligibility;

  • disbursing the scholarship;

  • preventing duplicate claims;

  • conducting legally authorised audits; and

  • maintaining records required by law.

It should not automatically be passed to a private education company for targeted advertising merely because the company provides technology to the department.

1.8 Necessity and data minimisation

Processing must be limited to personal data necessary for providing or issuing the relevant subsidy, benefit, service, certificate, licence or permit.

This requires the State body to examine each data field rather than collecting information merely because it might be useful later.

Example

For example, an authority issuing a residential parking permit may require:

  • identity details;

  • address;

  • vehicle registration;

  • proof of residence; and

  • contact information.

It should not ordinarily require:

  • medical history;

  • complete bank statements;

  • family members’ identity records;

  • employment appraisals; or

  • unrelated travel history, unless the authority can establish why such information is genuinely necessary under the applicable programme.

Digitisation of an entire historical record does not make every field necessary for the new use. Systems should be designed to retrieve, display and disclose only the data needed for the relevant function.

1.9 Accuracy

The State or its instrumentality must make reasonable efforts to ensure that personal data is accurate.

Accuracy is especially important where processing determines whether an individual receives or is denied:

  • financial assistance;

  • food support;

  • healthcare;

  • education;

  • pension;

  • employment-related benefits;

  • a licence;

  • a certificate; or

  • another essential public service.

The appropriate measures may include:

  • verification against reliable sources;

  • allowing individuals to correct outdated information;

  • recording the source and date of data;

  • checking identity matching;

  • preventing incorrect merging of records;

  • identifying unresolved discrepancies; and

  • providing human review where an automated match produces an adverse result.

1.10 Illustration: Outdated income information

A welfare database records an individual’s income using information several years old. The individual has since lost employment and applies for financial assistance.

The department should not reject the application solely because the older database classifies her as above the income threshold. Reasonable accuracy measures should permit updated information, correction and review before an adverse decision is finalised.

The Second Schedule requires reasonable efforts, not absolute perfection. However, the nature and consequences of the decision affect what will count as reasonable. A higher degree of verification may be required where inaccurate data could deprive a person of an essential benefit.

1.11 Retention limitation

Personal data may be retained while it is required for:

  • providing or issuing the relevant benefit, service or authorisation;

  • administering that programme;

  • achieving the permitted purpose; or

  • complying with another applicable law.

The State body should not retain personal data indefinitely merely because storage is inexpensive or the information might be useful for an unspecified future programme.

A compliant retention framework should identify:

  • the purpose served by each record;

  • the duration of the programme;

  • audit and limitation requirements;

  • statutory retention periods;

  • pending claims or disputes;

  • archival requirements;

  • deletion or anonymisation triggers; and

  • authorised exceptions.

Expiry of a licence or completion of a benefit does not always require immediate deletion. Records may need to be preserved for audit, fraud investigation, appeals, public-accounting obligations or another legal requirement. However, retention should remain connected to an identified purpose or legal obligation.

1.12 Security safeguards

The State or its instrumentality must maintain reasonable security safeguards for personal data in its possession or control, including processing undertaken through Data Processors.

The obligation therefore extends to:

  • departmental systems;

  • government databases;

  • cloud environments;

  • programme portals;

  • mobile applications;

  • outsourced service providers;

  • payment processors;

  • call centres;

  • enrolment agencies; and

  • other vendors processing data on behalf of the State.

Appropriate safeguards may include:

  • role-based access controls;

  • encryption or comparable protection;

  • logging and monitoring;

  • multifactor authentication;

  • segregation of programme databases;

  • vulnerability management;

  • backups;

  • incident detection;

  • secure transfer mechanisms;

  • processor contracts;

  • periodic access reviews;

  • employee training; and

  • breach-response procedures.

The use of a private technology provider does not transfer the State Data Fiduciary’s statutory accountability to that provider.

1.13 Illustration: Municipal benefits portal

A municipality appoints a vendor to operate an online portal for a public-health benefit. The vendor stores identity, address and health-related information.

The municipality must ensure that its contract and oversight arrangements address:

  • permitted processing;

  • access restrictions;

  • security safeguards;

  • incident reporting;

  • deletion;

  • subcontractors;

  • return of information;

  • audit; and

  • assistance with Data Principal rights.

It cannot avoid responsibility by stating that the breach occurred in the vendor’s infrastructure.

1.14 Intimation and Data Principal control

Where processing is undertaken under Section 7(b), the Data Principal must receive an intimation concerning that processing.

The intimation requirement is important because Section 7(b) processing does not depend on fresh consent for the particular use. The individual must nevertheless be informed that the State or its instrumentality is processing her data and must be given practical access to privacy assistance and statutory rights.

The intimation should communicate, in a clear and accessible form:

  • the State body responsible for processing;

  • the qualifying benefit, service, certificate, licence or permit;

  • the personal data being processed;

  • the permitted purpose;

  • the source of the data, where relevant;

  • how to ask questions;

  • how to exercise statutory rights; and

  • how to raise a grievance.

The Second Schedule specifically requires:

  • business contact information for a person capable of answering questions on behalf of the Data Fiduciary; and

  • a particular communication link to the Data Fiduciary’s website or application, together with any other available means for exercising rights.

This is not necessarily the same as the consent notice under Section 5 and Rule 3. Rule 3 supports an informed consent request. The Second Schedule intimation explains processing carried out under Section 7(b), where the State is relying on a certain legitimate use rather than requesting consent.

The intimation should therefore not misleadingly ask the Data Principal to “consent” to processing that the State intends to undertake under Section 7(b). The legal basis and the individual’s available rights should be described accurately.

1.15 Exercise of rights

Reliance on Section 7(b) does not generally extinguish the Data Principal’s rights under the Act.

Subject to the applicable statutory provisions, the individual may seek:

  • information about processing;

  • correction, completion or updating;

  • erasure where retention is no longer authorised;

  • grievance redressal; and

  • nomination.

However, erasure may be refused where continued retention is required by law or remains necessary for the qualifying purpose. Similarly, correction should not allow an individual to rewrite an official finding, but should permit correction of inaccurate personal data on which the finding relies.

1.16 Accountability

The person who determines the purpose and means of processing remains accountable for effective observance of the Second Schedule.

This prevents responsibility from becoming unclear where several public bodies and vendors participate in a scheme.

For each programme, the State should identify:

  • the Data Fiduciary determining the processing;

  • any other persons jointly determining purposes or essential means;

  • Data Processors acting on instructions;

  • the department responsible for privacy governance;

  • the person answering Data Principal questions;

  • the grievance channel;

  • the owner of accuracy and correction processes;

  • the authority responsible for retention; and

  • the official responsible for security oversight.

A technology vendor does not become the responsible Data Fiduciary merely because it operates the portal. Conversely, a department cannot avoid responsibility where it determines the purpose and essential means but delegates technical implementation to another agency.

1.17 Illustration: Joint government scheme

The Central Government designs a benefit, a State department verifies eligibility, and a local authority disburses it.

The parties should determine their respective roles by examining who decides:

  • eligibility criteria;

  • personal data required;

  • verification sources;

  • recipients;

  • retention periods;

  • processing systems; and

  • purposes of further use.

Calling every participant a “Processor” does not resolve the issue if several bodies actually exercise determinative authority over the processing.

1.18 Relationship with Section 17(2)(b)

The title of the Second Schedule also refers to processing necessary for research, archiving or statistical purposes under Section 17(2)(b).

Section 17(2)(b) provides a conditional exemption for processing necessary for such purposes where:

  • the personal data is not used to take a decision specifically concerning the Data Principal; and

  • the processing is carried out according to prescribed standards.

The Second Schedule supplies those prescribed standards. Consequently, the standards concerning lawfulness, purpose limitation, necessity, accuracy, retention, security and accountability are relevant not only to Rule 5 State-benefit processing, but also to reliance on the research, archiving and statistical exemption.

The two applications should not be confused.

1.19 Under Section 7(b)

The State processes personal data to provide or issue a subsidy, benefit, service, certificate, licence or permit. The processing may directly affect the named individual’s entitlement or application. The additional intimation requirements in paragraph (g) of the Second Schedule expressly apply.

1.20 Under Section 17(2)(b)

Personal data is processed for research, archiving or statistical purposes and must not be used to take a decision specifically concerning the particular Data Principal if the exemption is relied upon.

Example

For example, a department may analyse de-identified or suitably protected records to measure overall utilisation of a welfare scheme. It cannot rely on the research or statistical exemption to use that analysis to deny a named person’s individual claim. Once the processing is used for a decision specifically affecting the individual, the conditions for the exemption may no longer be satisfied.

Section 7(b) is a certain legitimate use, not consent.

This distinction has practical consequences:

  • the State need not manufacture a consent request where Section 7(b) lawfully applies;

  • refusal or withdrawal of consent does not necessarily stop processing independently authorised under Section 7(b);

  • the State must still provide the prescribed intimation;

  • processing must remain necessary and purpose-bound; and

  • Data Principal rights and safeguards continue to apply subject to the Act.

Previous consent may form part of the factual condition allowing reuse under Section 7(b), but the later processing is undertaken on the statutory footing of certain legitimate use. This should be reflected correctly in records and public-facing communications.

Where Section 7(b) does not apply, the State must identify another valid ground under the DPDPA. Rule 5 cannot be used as a general fallback for every public-sector processing activity.

1.22 Practical implementation

Before relying on Rule 5, a State body should document:

  1. the qualifying subsidy, benefit, service, certificate, licence or permit;

  2. whether it is provided under law, policy or executive instruction, or using public funds;

  3. the relevant authority and programme documents;

  4. how the conditions of Section 7(b) are satisfied;

  5. the personal data required;

  6. why each category is necessary;

  7. the source and accuracy of the data;

  8. the purpose and permitted uses;

  9. participating Data Fiduciaries and Processors;

  10. security safeguards;

  11. the retention period;

  12. the prescribed intimation;

  13. privacy and rights channels;

  14. correction and grievance workflows; and

  15. governance and accountability.

This should be supported by:

  • data inventories;

  • process maps;

  • access-control records;

  • processor contracts;

  • information-security assessments;

  • retention schedules;

  • accuracy-verification procedures;

  • notices or intimations;

  • incident-response plans; and

  • periodic compliance reviews.

1.23 Enforcement consequences

A significant breach of Rule 5 or the Second Schedule may fall within the residual penalty category in the DPDPA Schedule for breach of another provision of the Act or Rules, potentially attracting a monetary penalty of up to ₹50 crore.

Where the same incident also involves failure to maintain reasonable security safeguards or failure to notify a personal data breach, the more specific Schedule entries may also become relevant.

The maximum penalty is not automatic. The Board must follow the procedure under Sections 27, 28 and 33, determine that a significant breach occurred, provide an opportunity of hearing and apply the statutory penalty factors.

1.24 Concluding commentary

Rule 5 enables the State and its instrumentalities to use qualifying personal data for delivering legally or publicly supported subsidies, benefits, services, certificates, licences and permits without requiring fresh consent for every processing operation where Section 7(b) properly applies.

That facilitation is balanced by the Second Schedule. State processing must remain:

  • lawful;

  • connected with the qualifying public purpose;

  • limited to necessary data;

  • reasonably accurate;

  • time-bound;

  • securely managed;

  • transparent to the Data Principal; and

  • attributable to an accountable Data Fiduciary.

The provision should therefore not be understood as a broad governmental-data exemption. It permits defined public-service processing while imposing a structured responsibility framework.

Key point

Rule 5 allows personal data to follow the administration of a qualifying public benefit or service, but not to become unrestricted government data. The Second Schedule preserves necessity, accuracy, security, transparency, retention discipline and accountability throughout that processing.

Reproduced from official sources for reference. Not legal advice. In case of any discrepancy, the text published in the Gazette of India prevails.