SCHEDULE II - SECOND SCHEDULE - STANDARDS FOR PROCESSING BY STATE

Second Schedule - Standards for processing by State

Official text

See rules 5(1) and 16

Standards for processing of personal data by State and its instrumentalities under clause (b) of section 7 and for processing of personal data necessary for the purposes specified in clause (b) of sub-section (2) of section 17

Implementation of appropriate technical and organisational measures to ensure effective observance of the following, in accordance with applicable law, for the processing of personal data, namely: -

(a)Processing is carried out in a lawful manner;
(b)Processing is done for the uses specified in clause (b) of section 7 of the Act or for the purposes specified in clause (b) of sub-section (2) of section 17 of the Act, as the case may be;
(c)Processing is limited to such personal data as is necessary for such uses or achieving such purposes, as the case may be;
(d)Processing is done while making reasonable efforts to ensure the completeness, accuracy and consistency of personal data;
(e)Personal data is retained till required for such uses or achieving such purposes, as the case may be, or for compliance with any law for the time being in force;
(f)Reasonable security safeguards to prevent personal data breach to protect personal data in the possession or under control of the Data Fiduciary, including in respect of any processing undertaken by it or on its behalf by a Data Processor;
(g)Where processing is to be done under clause (b) of section 7 of the Act, the same is undertaken while giving the Data Principal an intimation in respect of the same and -
(i)giving the business contact information of a person who is able to answer on behalf of the Data Fiduciary the questions of the Data Principal about the processing of her personal data;
(ii)specifying the particular communication link for accessing the website or app, or both, of such Data Fiduciary, and a description of other means, if any, using which such Data Principal may exercise her rights under the Act; and
(iii)is carried on in a manner consistent with such other standards as may be applicable to the processing of such personal data under policy issued by the Central Government or any law for the time being in force; and
(h)Accountability of the person who alone or in conjunction with other persons determines the purpose and means of processing of personal data, for effective observance of these standards.

Cross-references

Second Schedule

Commentary

The Second Schedule establishes a common accountability framework for two distinct categories of processing under the Digital Personal Data Protection Act, 2023. The first is processing by the State or its instrumentalities under Section 7(b) for providing or issuing a subsidy, benefit, service, certificate, licence or permit. The second is processing necessary for research, archiving or statistical purposes under Section 17(2)(b), where the personal data is not used to take a decision specific to a Data Principal.

The Schedule does not create either statutory authority by itself. Section 7(b) and Section 17(2)(b) establish the relevant legal routes, while Rules 5 and 16 make compliance with the Second Schedule central to their operation. The Schedule then prescribes the standards that must govern the processing. It was notified as part of the final DPDP Rules, 2025 under G.S.R. 846(E) dated 13 November 2025.

Its legal effect is particularly important because both contexts involve processing that may proceed without ordinary reliance on consent. The absence of a consent requirement does not leave the processing uncontrolled. Instead, the Schedule requires the person determining the purpose and means of processing to implement appropriate technical and organisational measures ensuring that the processing remains lawful, necessary, accurate, secure, purpose-bound, appropriately retained and accountable.

1.1 Integrated operation of the Schedule

The two statutory contexts covered by the Schedule must remain distinct.

Under Section 7(b), the State or its instrumentality may process personal data to provide or issue a prescribed subsidy, benefit, service, certificate, licence or permit. The detailed eligibility conditions governing this route appear in Rule 5. The Second Schedule governs how such processing must occur once Section 7(b) applies.

Under Section 17(2)(b), personal data may be processed for research, archiving or statistical purposes without application of the ordinary provisions of the Act where the information is not used to take a decision specific to a Data Principal. Rule 16 makes compliance with the Second Schedule a condition of that exemption.

The Schedule should not be used to enlarge either statutory route. A State instrumentality cannot rely on it to process personal data for any public or administrative objective merely because the processing is lawful in a general sense. The activity must first fall within Section 7(b) and Rule 5. Similarly, an organisation cannot classify customer profiling, individual risk scoring or personalised commercial decision-making as statistical processing simply because statistical methods are used. It must first satisfy Section 17(2)(b) and Rule 16.

Compliance with the Second Schedule is therefore necessary but not independently sufficient. The underlying processing must fall within the statutory provision relied upon.

1.2 Lawful and purpose-bound processing

The Schedule requires the processing to be lawful and confined to the applicable statutory use or purpose. This prevents Section 7(b) and Section 17(2)(b) from becoming open-ended authorities for secondary use.

For State processing, the personal data must be used for the provision or issuance of the relevant subsidy, benefit, service, certificate, licence or permit. Information collected for one programme cannot automatically be combined with other government databases or used for unrelated enforcement, profiling or commercial activity merely because both functions are undertaken by the State.

If a public authority collects identity, educational and financial information to determine eligibility for a scholarship, the Second Schedule permits processing necessary for that scholarship process. It does not automatically authorise the authority to use the same information for unrelated advertising, commercial analytics or another administrative purpose having no proper connection with the benefit.

The position is similar for research, archiving and statistical processing. Data processed for a qualifying study must remain within that study or another purpose that independently satisfies the exemption. A workforce dataset used to produce aggregate attrition statistics cannot later be used to rank named employees for termination while continuing to claim the research or statistical exemption. Once the processing becomes connected with a decision specific to an identifiable person, it moves outside Section 17(2)(b).

Lawfulness also requires compliance with the wider body of applicable Indian law. The Second Schedule cannot legitimise personal data acquired through unauthorised access, deception, breach of confidence, violation of a court order or disregard of sector-specific confidentiality requirements. A valuable research objective does not cure unlawful acquisition of medical records. Likewise, a public-benefit purpose does not authorise a department to disregard statutory restrictions governing the source, disclosure or use of the information.

1.3 Necessity and proportionality

The Schedule limits processing to personal data necessary for the statutory use or exempt purpose. This is a substantive limitation on the nature and quantity of personal data that may be processed.

Necessity does not mean that every potentially useful field may be collected. The responsible person should be able to explain why the particular data is required and whether the purpose can reasonably be achieved through less personal data, less granular information, pseudonymous records or anonymous statistics.

In a State-benefit programme, necessity applies across the entire processing chain. The authority must consider not only what information is required to assess eligibility, but also what must be shared with verification agencies, payment providers, service-delivery partners and other instrumentalities. An application form may not collect unrelated family, financial or identity information merely because it could become administratively convenient in the future.

The same discipline applies to exempt research. A public-health study may need age bands, district, diagnosis, treatment and outcome information. It may not need names, exact addresses, complete identification numbers or unrelated medical history. If direct identifiers are temporarily necessary to link records, they should not remain available throughout the study after that linkage has been completed.

Necessity also governs duration, frequency and access. Information necessary for a single eligibility check may not need to be continuously collected. Identifiable research data required by a small linkage team may not need to be accessible to every researcher. An archive may validly retain identifiable records for their enduring historical value, but that does not make unrestricted publication or universal internal access necessary.

1.4 Accuracy and the consequences of unreliable data

The Schedule requires reasonable efforts to ensure the accuracy of personal data. This obligation is important in both statutory contexts, although the consequences of inaccuracy may differ.

In State processing, inaccurate information may deny a person a benefit, issue a certificate containing incorrect particulars, direct a subsidy to the wrong account or incorrectly classify an eligible individual as ineligible. The authority should therefore apply accuracy controls before relying on the data, particularly where the information is likely to affect the Data Principal or be disclosed to another entity.

The obligation is one of reasonable effort, not absolute perfection. The appropriate level of verification depends on the source, purpose, consequences and available correction mechanisms. An authority should not reject reliable information solely because its internal database has not been updated, nor should it treat a legacy government record as conclusively accurate where the Data Principal provides credible evidence of correction.

In research and statistical processing, inaccurate or inconsistent personal data can distort findings, reduce scientific validity and create misleading policy conclusions. Relevant safeguards may include verification of sources, consistent definitions, treatment of missing values, deduplication, maintenance of provenance and documentation of known limitations.

For archival processing, accuracy must be reconciled with authenticity. An archive should ordinarily preserve an original historical record even where it contains an error. Rather than rewriting the source document, the archive may attach an explanatory note, correction or contextual metadata. The objective is to preserve both the original record and the accurate context necessary to understand it.

1.5 Retention and transition out of active use

The Schedule permits retention only while the personal data is required for the applicable use or exempt purpose, or where another Indian law requires continued retention.

This prevents indefinite preservation based solely on the possibility that information may become useful later.

For State-benefit processing, retention should reflect the actual programme lifecycle. Personal data may be needed during application, eligibility assessment, provision of the benefit, audit, grievance handling and any applicable statutory record period. Different records may justify different periods. A payment record may need to be retained under financial law even after an unsuccessful application or a temporary verification document no longer serves any operational purpose.

The end of the underlying use does not necessarily require immediate deletion of every record where a legal-retention requirement applies. However, information retained only for legal compliance should not remain available for ordinary operational, analytical or commercial use. Its access and use should be restricted to the continuing legal purpose.

Research data may need to be retained through collection, validation, analysis, peer review and a justified reproducibility period. Once identifiable information is no longer necessary, it should be removed, separated, anonymised or placed under stronger restriction.

Archiving is different because long-term or permanent preservation may itself constitute the continuing purpose. Even then, preservation does not imply unrestricted use. Access limitations, closure periods, controlled research access and protection of information concerning living individuals may remain necessary.

Statistical source data should be reconsidered once reliable aggregate or anonymous outputs have been produced. Keeping named source records for unrelated future marketing would no longer be retention for the statistical purpose.

1.6 Security and Processor accountability

The Schedule expressly requires reasonable security safeguards for personal data in the possession or control of the Data Fiduciary, including processing carried out on its behalf by a Data Processor.

The responsible Data Fiduciary cannot avoid this obligation by outsourcing eligibility checks, payment administration, cloud hosting, archival digitisation or statistical analysis. The safeguards must extend through the complete processing arrangement.

For State processing, the service-delivery chain may include technology providers, authentication services, banks, payment intermediaries, field agencies and cloud providers. Contracts, access controls and technical architecture should ensure that each participant receives only the information required for its role and does not independently use the data for unrelated purposes.

Research arrangements may involve universities, hospitals, sponsors, laboratories, statistical consultants and cloud providers. The allocation of responsibility should reflect who actually determines the purpose and means of processing. A service provider acting only on instructions may be a Data Processor, while a collaborating institution that determines its own research objectives may be a separate or joint Data Fiduciary for relevant operations.

Security must correspond to the nature of the information and the consequences of compromise. Government-benefit systems may contain identity, household, financial and eligibility information. Research datasets may combine health, employment, behavioural or socioeconomic records from several sources. Appropriate safeguards may therefore require controlled access, encryption, segregation of identifiers, pseudonymisation, secure transmission, activity logging, restrictions on downloading and reliable deletion.

The reference to Processor activity reinforces the continuing accountability of the Data Fiduciary. A Processor’s security failure, excessive retention or unauthorised secondary use cannot be dismissed as an independent vendor matter where the processing was undertaken on the Data Fiduciary’s behalf.

1.7 Transparency and rights in State processing

The additional requirements concerning intimation, contact information and rights channels apply specifically where processing occurs under Section 7(b).

The State or its instrumentality must inform the Data Principal about the processing and provide the business contact information of a person capable of answering questions on the Data Fiduciary’s behalf. It must also identify the website, application or other means through which the Data Principal may exercise rights under the Act.

This requirement is important because Section 7(b) processing does not depend on consent. The Data Principal may not be presented with a consent request and may have limited practical choice if the processing is necessary to obtain a public benefit or service. Transparency, accessible contact and rights mechanisms therefore become the principal means through which the individual can understand and challenge the processing.

The intimation should enable the Data Principal to understand the responsible authority, benefit or service involved, relevant personal data, purpose, material disclosures and available rights. A generic government privacy statement that does not identify the particular programme or processing may not provide meaningful transparency.

The authority should also avoid presenting the processing as optional consent where it is actually relying on Section 7(b). If processing will proceed under the statutory legitimate-use provision, the communication should describe that legal position accurately rather than obtaining a nominal consent that the Data Principal cannot meaningfully refuse.

State processing must additionally remain consistent with standards imposed by applicable Central Government policy or other law. The Second Schedule therefore establishes a baseline, not a ceiling. A public authority may be subject to stricter requirements under the governing scheme, sectoral law, information-security policy, record-management rules or another statutory framework.

The specific intimation requirements in paragraph (g) are directed to Section 7(b) processing and should not automatically be transplanted as identical conditions for research, archiving or statistical processing. For the latter category, the applicable requirements arise from Section 17(2)(b), Rule 16 and the other generally applicable legal or ethical framework governing the project.

1.8 Accountability as the unifying obligation

The final standard places accountability on the person who, alone or with others, determines the purpose and means of processing. This prevents responsibility from disappearing across departments, agencies, research partners and vendors.

For State processing, the accountable person must be able to establish that the programme falls within Section 7(b), the information is necessary, the Data Principal has received the required intimation, Processors are controlled, security measures operate and retention is justified.

For exempt research, archiving and statistical processing, the accountable person must be able to demonstrate that the purpose genuinely qualifies under Section 17(2)(b), identifiable personal data is necessary, no decision specific to a Data Principal is taken, safeguards are effective and later use has not moved outside the exemption.

Accountability should be supported by evidence rather than a conclusory statement that the Schedule has been followed. The processing record should explain the purpose, data categories, sources, recipients, Processors, security measures, accuracy controls, retention periods and responsibility for review.

Where processing changes materially, the legal assessment should be revisited. An exempt research model that is later deployed to make decisions about identifiable individuals cannot remain under the Schedule merely because its original development qualified. A benefits database that is later integrated with an enforcement system requires assessment of whether the new use has an independent lawful basis.

1.9 Consequence of failing the standards

Failure to observe the Second Schedule has different consequences depending on the statutory route relied upon.

For Section 7(b), failure may mean that the State processing does not satisfy the standards prescribed for that legitimate use. The authority may then face questions concerning lawfulness, necessity, accuracy, security, retention, transparency and rights enablement.

For Section 17(2)(b), the consequences may be more fundamental. Rule 16 makes compliance with the Second Schedule a condition of the exemption. If the processing does not satisfy the Schedule, the organisation may be unable to claim that the provisions of the DPDPA do not apply. Its activity would then have to be justified under the ordinary framework of the Act.

An organisation cannot safely rely on Rule 16 while ignoring data minimisation, security or retention on the assumption that the Act is already inapplicable. Compliance with the Schedule is what supports the exemption in the first place.

1.10 Concluding interpretation

The Second Schedule creates a principle-based alternative to ordinary consent-driven processing in two defined statutory contexts. It recognises that the State may need to process personal data to deliver legally authorised benefits and services, and that society benefits from genuine research, preservation of historically valuable records and reliable statistical analysis. At the same time, it prevents those purposes from becoming unrestricted gateways to the collection, retention and reuse of personal data.

Its central effect is that processing must remain connected to legal authority and demonstrated necessity. Personal data cannot be collected merely because it is available, retained merely because storage is inexpensive, shared merely because another public body or research partner may find it useful, or repurposed merely because the original collection was lawful.

For Section 7(b) processing, the Data Principal must also receive meaningful intimation, an accountable contact and a usable route for exercising rights. For Section 17(2)(b) processing, the information must remain outside decisions specific to identifiable Data Principals and the processing must continue satisfying Rule 16.

The standards operate together rather than in isolation. Lawful authority does not excuse excessive collection. Necessity does not excuse inaccurate data. Accuracy does not excuse indefinite retention. Security does not authorise a new purpose. Outsourcing does not remove responsibility. Transparency does not cure processing that never fell within the statutory provision.

Ultimately, the Second Schedule requires the State, research bodies, archives, statistical organisations and other responsible persons to demonstrate disciplined stewardship of personal data even where ordinary consent requirements or other provisions of the DPDPA do not apply in the usual manner.

Reproduced from official sources for reference. Not legal advice. In case of any discrepancy, the text published in the Gazette of India prevails.