The Second Schedule establishes a common accountability framework for two distinct categories of processing under the Digital Personal Data Protection Act, 2023. The first is processing by the State or its instrumentalities under Section 7(b) for providing or issuing a subsidy, benefit, service, certificate, licence or permit. The second is processing necessary for research, archiving or statistical purposes under Section 17(2)(b), where the personal data is not used to take a decision specific to a Data Principal.
The Schedule does not create either statutory authority by itself. Section 7(b) and Section 17(2)(b) establish the relevant legal routes, while Rules 5 and 16 make compliance with the Second Schedule central to their operation. The Schedule then prescribes the standards that must govern the processing. It was notified as part of the final DPDP Rules, 2025 under G.S.R. 846(E) dated 13 November 2025.
Its legal effect is particularly important because both contexts involve processing that may proceed without ordinary reliance on consent. The absence of a consent requirement does not leave the processing uncontrolled. Instead, the Schedule requires the person determining the purpose and means of processing to implement appropriate technical and organisational measures ensuring that the processing remains lawful, necessary, accurate, secure, purpose-bound, appropriately retained and accountable.