SCHEDULE III - THIRD SCHEDULE - CLASS OF DATA FIDUCIARIES, PURPOSES AND TIME PERIODS

Third Schedule - Class of Data Fiduciaries, purposes and time periods

Official text

See rule 8(1)

S. no.(1)Class of Data Fiduciaries(2)Purposes(3)Time period(4)
1.Data Fiduciary who is an e-commerce entity having not less than two crore registered users in India.
For all purposes, except for the following:
(a)Enabling the Data Principal to access her user account; and
(b)Enabling the Data Principal to access any virtual token that is issued by or on behalf of the Data Fiduciary, is stored on the digital facility or platform of such Data Fiduciary, and may be used to get money, goods or services.
Three years from the date on which the Data Principal last approached the Data Fiduciary for the performance of the specified purpose or exercise of her rights, or the commencement of the Digital Personal Data Protection Rules, 2025, whichever is latest.
2.Data Fiduciary who is an online gaming intermediary having not less than fifty lakh registered users in India.
For all purposes, except for the following:
(a)Enabling the Data Principal to access her user account; and
(b)Enabling the Data Principal to access any virtual token that is issued by or on behalf of the Data Fiduciary, is stored on the digital facility or platform of such Data Fiduciary, and may be used to get money, goods or services.
Three years from the date on which the Data Principal last approached the Data Fiduciary for the performance of the specified purpose or exercise of her rights, or the commencement of the Digital Personal Data Protection Rules, 2025, whichever is latest.
3.Data Fiduciary who is a social media intermediary having not less than two crore registered users in India.
For all purposes, except for the following:
(a)Enabling the Data Principal to access her user account; and
(b)Enabling the Data Principal to access any virtual token that is issued by or on behalf of the Data Fiduciary, is stored on the digital facility or platform of such Data Fiduciary, and may be used to get money, goods or services.
Three years from the date on which the Data Principal last approached the Data Fiduciary for the performance of the specified purpose or exercise of her rights, or the commencement of the Digital Personal Data Protection Rules, 2025, whichever is latest.

S. no. 1.

Class of Data Fiduciaries (2)Data Fiduciary who is an e-commerce entity having not less than two crore registered users in India.
Purposes (3)
For all purposes, except for the following:
(a)Enabling the Data Principal to access her user account; and
(b)Enabling the Data Principal to access any virtual token that is issued by or on behalf of the Data Fiduciary, is stored on the digital facility or platform of such Data Fiduciary, and may be used to get money, goods or services.
Time period (4)Three years from the date on which the Data Principal last approached the Data Fiduciary for the performance of the specified purpose or exercise of her rights, or the commencement of the Digital Personal Data Protection Rules, 2025, whichever is latest.

S. no. 2.

Class of Data Fiduciaries (2)Data Fiduciary who is an online gaming intermediary having not less than fifty lakh registered users in India.
Purposes (3)
For all purposes, except for the following:
(a)Enabling the Data Principal to access her user account; and
(b)Enabling the Data Principal to access any virtual token that is issued by or on behalf of the Data Fiduciary, is stored on the digital facility or platform of such Data Fiduciary, and may be used to get money, goods or services.
Time period (4)Three years from the date on which the Data Principal last approached the Data Fiduciary for the performance of the specified purpose or exercise of her rights, or the commencement of the Digital Personal Data Protection Rules, 2025, whichever is latest.

S. no. 3.

Class of Data Fiduciaries (2)Data Fiduciary who is a social media intermediary having not less than two crore registered users in India.
Purposes (3)
For all purposes, except for the following:
(a)Enabling the Data Principal to access her user account; and
(b)Enabling the Data Principal to access any virtual token that is issued by or on behalf of the Data Fiduciary, is stored on the digital facility or platform of such Data Fiduciary, and may be used to get money, goods or services.
Time period (4)Three years from the date on which the Data Principal last approached the Data Fiduciary for the performance of the specified purpose or exercise of her rights, or the commencement of the Digital Personal Data Protection Rules, 2025, whichever is latest.

Note

In this Schedule, -

(a)“e-commerce entity” means any person who owns, operates or manages a digital facility or platform for e-commerce as defined in the Consumer Protection Act, 2019 (35 of 2019), but does not include a seller offering her goods or services for sale on a marketplace e-commerce entity as defined in the said Act;
(b)“online gaming intermediary” means any intermediary who enables the users of its computer resource to access one or more online games;
(c)“social media intermediary” means an intermediary as defined in clause (w) of sub-rule (1) of rule 2 of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021; and
(d)“user”, in relation to -
(i)an e-commerce entity, means any person who accesses or avails any computer resource of an e-commerce entity; and
(ii)an online gaming intermediary or a social media intermediary, means any person who accesses or avails of any computer resource of an intermediary for the purpose of hosting, publishing, sharing, transacting, viewing, displaying, downloading or uploading information.

Cross-references

Third Schedule

Commentary

The Third Schedule, read with Rule 8, creates a time-based mechanism for determining when certain processing purposes are deemed no longer to be served by specified large digital platforms. It applies to large e-commerce entities, online gaming intermediaries and social media intermediaries that cross the prescribed registered-user thresholds in India.

The Schedule does not establish a general three-year retention period for all Data Fiduciaries or all personal data. It applies only to the listed classes and operates through the specific mechanism in Rule 8. Its effect is that, after three years of inactivity measured in the prescribed manner, the listed Data Fiduciary must treat most purposes associated with the personal data as no longer being served and erase the data, unless retention is required by law or the data remains necessary for one of the two purposes expressly preserved by the Schedule.

Rule 8 and the Third Schedule are scheduled to come into force on 13 May 2027, eighteen months after publication of the final Rules. The final text was notified under G.S.R. 846(E) dated 13 November 2025.

1.1 Scope and rationale

The Schedule applies only to:

  • an e-commerce entity having at least two crore registered users in India;

  • an online gaming intermediary having at least fifty lakh registered users in India; and

  • a social media intermediary having at least two crore registered users in India.

These thresholds focus the deemed-purpose mechanism on large platforms likely to hold personal data at significant scale. Smaller entities remain subject to the general erasure framework in the Act, but they are not brought within this particular three-year deeming rule merely because they operate in e-commerce, online gaming or social media.

The Schedule addresses a recurring problem with digital accounts. A person may stop using a platform while her personal data continues to remain active across account, marketing, behavioural, recommendation, advertising, analytics and operational systems for an indefinite period. The account may remain technically open, allowing the platform to argue that the initial service purpose still continues even though the individual has had no meaningful interaction with it for years.

The Third Schedule prevents that position from continuing indefinitely for the specified large platforms. Once the relevant three-year period expires, most processing purposes are deemed no longer to be served. Rule 8 then requires the Data Fiduciary to erase the personal data unless its retention remains necessary for compliance with law.

The Schedule therefore supplements, rather than replaces, the Act’s general rule that personal data must be erased when consent is withdrawn or when it is reasonable to assume that the specified purpose is no longer being served, whichever is earlier, unless legal retention remains necessary. A Data Principal’s withdrawal of consent or erasure request may require action before three years. The Schedule does not authorise a platform to retain personal data for the entire three-year period where the purpose has already ended under the ordinary statutory test.

1.2 Determining whether the Schedule applies

The relevant threshold is based on registered users in India. The Data Fiduciary must therefore be capable of determining whether it falls within the prescribed class.

This may require clarity regarding:

  • which legal entity owns, operates or manages the platform;

  • whether user accounts relate to India;

  • whether multiple services are operated through the same Data Fiduciary;

  • whether duplicate or dormant accounts are counted;

  • and whether an entity acts within the statutory definition of e-commerce entity, online gaming intermediary or social media intermediary.

The Schedule excludes a seller merely offering goods or services through a marketplace from the definition of an e-commerce entity for this purpose. The marketplace operator may be covered if it owns, operates or manages the relevant digital facility and satisfies the threshold, while an individual seller using that marketplace does not become a Schedule-covered e-commerce entity solely because it lists products there.

An online gaming intermediary is covered where it enables users of its computer resource to access one or more online games and has at least fifty lakh registered users in India. A social media intermediary is covered where it primarily or solely facilitates online interaction among users and allows them to create, upload, share, disseminate, modify or access information, subject to the two-crore threshold.

A platform offering several combined services should examine its actual functions. Calling a service “social,” “community,” “commerce” or “gaming” is not determinative if its real operation falls within a statutory category. Equally, a conventional business website does not become a social media intermediary merely because it allows customer reviews or limited interaction.

The Schedule applies according to the actual class and threshold, not according to whether the Data Fiduciary has been designated a Significant Data Fiduciary. SDF designation and the Third Schedule are separate frameworks. A platform may fall within the Third Schedule without being notified as an SDF, while an SDF operating in another sector may fall outside the Schedule.

1.3 The three-year inactivity period

The prescribed period runs from the later of:

  • the date on which the Data Principal last approached the Data Fiduciary for performance of the specified purpose or exercise of her rights; and

  • the commencement of the DPDP Rules, 2025.

The use of the later date creates a transition period for personal data already held when the relevant provisions commence. The three-year inactivity period for legacy accounts cannot expire before three years from commencement merely because the Data Principal’s last interaction occurred many years earlier.

The expression “approached the Data Fiduciary” should be applied to a meaningful act by the Data Principal. It may include a request for performance of the service or exercise of a statutory right. Depending on the nature of the platform, this may include placing an order, initiating a gaming interaction, posting or otherwise using a social media function, contacting the Data Fiduciary for the service, or submitting an access, correction, erasure or grievance request.

The platform should not reset the three-year period through its own unilateral activity. Sending an advertisement, push notification, automated reminder or promotional email does not amount to the Data Principal approaching the Data Fiduciary. Similarly, passive background processing by the platform should not convert an inactive individual into an active user.

The difficult issue will be distinguishing genuine engagement from incidental technical activity. Automatic app updates, background refreshes, security pings, cookie transmission or device-level telemetry may occur without a conscious request by the Data Principal. Treating every such event as renewed approach would frustrate the Schedule by allowing the period to be reset indefinitely through platform-controlled technology.

The platform should therefore use an inactivity methodology that reflects genuine interaction connected with the specified purpose or exercise of rights. The methodology should be consistently applied, technically reliable and capable of audit.

The filing of a rights request resets the period because the Schedule expressly includes exercise of rights. This does not mean that the platform may retain all ordinary service and marketing data for another three years regardless of the substance of the request. A request to erase personal data must still be handled under Section 12 and the general erasure obligations. Section 12 requires erasure upon request unless retention is necessary for the specified purpose or compliance with law.

1.4 Effect of the deemed cessation

After the prescribed period, the Schedule treats all purposes as no longer being served except the two purposes specifically preserved. Rule 8 then requires erasure of the personal data associated with those expired purposes, subject to legally required retention.

The mechanism is broader than simply closing a dormant account. Personal data may exist in several systems, including:

  • marketing databases;

  • recommendation systems;

  • behavioural profiles;

  • advertising segments;

  • customer-support tools;

  • analytics environments;

  • fraud systems;

  • data warehouses;

  • development or testing environments;

  • and systems operated by Data Processors.

The platform must determine which personal data remains necessary for the preserved account-access or virtual-token purpose and which data relates only to purposes that are deemed to have ended.

An inactivity rule implemented only in the customer-facing application would be incomplete if the individual’s marketing and behavioural information remains active elsewhere. Erasure must correspond to the real processing environment, including processing undertaken on the Data Fiduciary’s behalf.

The Schedule also does not require erasure of information that another law requires to be retained. An e-commerce platform may need to retain specified invoices, payment records, tax information, transaction evidence, fraud records or complaint documentation for an applicable statutory period. Such retention does not permit continued use for advertising, recommendations, profiling or unrelated analytics. Records retained solely for legal compliance should be segregated or access-restricted so that the expired operational purpose is not effectively continued.

1.5 The two preserved purposes

The Schedule excludes two purposes from the three-year deemed cessation:

  1. enabling the Data Principal to access her user account; and

  2. enabling the Data Principal to access a qualifying virtual token stored on the platform that may be used to obtain money, goods or services.

These exclusions prevent the automatic three-year rule from destroying the basic mechanism through which a dormant user may regain access to an account or retrieve stored digital value.

The account-access exception should be interpreted according to its limited function. It permits retention of personal data necessary to recognise the account, authenticate the user, preserve essential security and restore account access. It should not be treated as permission to retain every historical activity record, advertising profile, recommendation history or inferred interest merely because the account remains technically capable of login.

A Data Fiduciary may therefore retain identifiers, authentication records and proportionate security information needed to preserve access, while erasing or deactivating personal data connected only with purposes deemed to have ended.

The virtual-token exception protects digital value associated with the account. Depending on the platform, the relevant token might represent stored credit, a redeemable voucher, reward value, digital entitlement or another platform-issued instrument that can be used to obtain money, goods or services.

This exception prevents an inactive user from losing access to value merely because she has not used the platform for three years. However, it does not authorise the platform to preserve all surrounding behavioural and commercial information. Retention should remain limited to what is necessary to authenticate the Data Principal, preserve the token, prevent fraud and permit lawful redemption.

Whether a particular loyalty point, game item, coupon or digital entitlement qualifies will depend on whether it falls within the Schedule’s description and may be used to obtain money, goods or services. The exception should not be expanded to every internal score, badge or non-redeemable engagement indicator merely because the platform calls it a virtual token.

1.6 Notice before erasure

Rule 8 requires the affected Data Principal to be informed at least forty-eight hours before erasure under the deemed-purpose mechanism. The communication should explain that the prescribed inactivity period has expired and that the personal data will be erased unless the Data Principal logs into her account or otherwise initiates contact for performance of the specified purpose or exercise of her rights.

The notice should reach the Data Principal through an appropriate communication channel available to the Data Fiduciary. It should not be designed merely to satisfy a formal dispatch requirement through an obsolete or inaccessible channel where another current channel is available.

The forty-eight-hour period provides a final opportunity for the Data Principal to preserve an active service relationship. It should not be used to obtain fresh consent through pressure or misleading design. The Data Principal should be able to understand:

  • which account or service is affected;

  • when erasure is expected;

  • what action will prevent erasure;

  • what information may still be retained for legal compliance;

  • and what account-access or virtual-token information will remain.

If the Data Principal meaningfully re-engages with the service, the Schedule’s timer may restart from that interaction. However, the platform should not require the person to consent to unrelated processing as the price of preventing account erasure. Continued service and optional advertising or profiling purposes should remain legally distinguishable.

The three-year period is not a minimum retention entitlement.

If the Data Principal withdraws consent, processing based on that consent must cease within a reasonable time, subject to any separate lawful basis. If she requests erasure, the Data Fiduciary must erase the personal data unless retention remains necessary for the specified purpose or compliance with law.

Accordingly, the platform cannot respond to an erasure request by stating that it is entitled to retain the information until the Third Schedule period expires. The Schedule addresses when specified purposes are automatically deemed no longer to be served in the absence of earlier events. It does not suspend rights or override earlier cessation of purpose.

The correct relationship is:

  • purpose may end factually before three years;

  • consent may be withdrawn before three years;

  • erasure may be requested before three years;

  • another law may require selected records to be retained beyond three years;

  • and the Schedule supplies an outer inactivity-based deeming mechanism for the covered purposes.

1.8 Application across Processors and group systems

Large platforms commonly distribute personal data across group entities, vendors and shared infrastructure. Compliance with the Third Schedule requires an end-to-end view.

A Data Processor holding information solely on behalf of the platform should receive an instruction to erase or restrict the relevant data when the Schedule applies. The platform cannot satisfy Rule 8 by deleting the visible profile while leaving full copies with advertising, analytics, customer-service or cloud providers.

Where an overseas affiliate or group company uses the information for its own purposes, its role must be analysed separately. The covered Data Fiduciary cannot assume that group sharing removes the data from the Schedule. It must determine whether it remains responsible for operations conducted on its behalf and whether another entity has independently determined a new purpose that requires its own lawful basis.

Backups also require a controlled approach. Immediate deletion from every immutable backup may not always be technically feasible, but erased data should not return to active processing through restoration. Backup retention should follow a defined cycle, be protected against ordinary use and ensure that any restored data is subjected again to the applicable erasure instruction.

1.9 Legacy data and commencement

For accounts already inactive when Rule 8 commences, the “whichever is latest” formula means the transition period begins no earlier than commencement.

On the currently notified timeline, Rule 8 commences on 13 May 2027. Therefore, even where an individual last used the covered platform before that date, the Schedule’s three-year period would not expire before 13 May 2030, unless the person later approaches the platform, in which case the later interaction becomes relevant.

This transitional protection gives covered platforms time to:

  • identify dormant users;

  • map associated personal data;

  • distinguish preserved from expired purposes;

  • update Processor arrangements;

  • build the forty-eight-hour notice mechanism;

  • and implement reliable erasure across systems.

It does not authorise indefinite retention during the transition. The general statutory erasure obligation may still require earlier deletion where consent is withdrawn, an erasure request is made or the specified purpose has already ended under the ordinary test.

1.10 Coverage changes and threshold management

A platform may cross the prescribed threshold after the Rules commence. From that point, it should assess how Rule 8 and the Third Schedule apply to its registered-user base and legacy records.

The Schedule does not expressly provide a separate grace period for a platform that later becomes covered. The Data Fiduciary should therefore monitor user thresholds rather than wait for an external declaration.

A platform may also fall below the threshold after previously being covered. The Schedule does not expressly state that obligations already triggered disappear immediately. Avoiding manipulation requires a stable and clearly documented approach to threshold measurement. An entity should not be able to escape erasure simply through temporary fluctuations, account reclassification or artificial distribution of users among related services.

Where services are reorganised among legal entities, the actual identity of the Data Fiduciary and the purposes and means it determines remain relevant. Corporate restructuring should not be used to defeat the Schedule’s threshold-based protection.

1.11 Governance and evidence

Compliance requires reliable evidence of:

  • whether the Data Fiduciary falls within a listed class;

  • the number of registered users in India;

  • the Data Principal’s last qualifying interaction;

  • the purposes for which each category of personal data remains processed;

  • the information retained for account or virtual-token access;

  • legal-retention exceptions;

  • the forty-eight-hour communication;

  • erasure from active and Processor systems;

  • and the treatment of backups and restricted archives.

The inactivity date should not be inferred through an opaque or undocumented algorithm. Nor should all historical processing be retained on the assumption that some part may be needed for account security.

The Data Fiduciary should maintain a purpose-based data map capable of separating:

  • account-access information;

  • virtual-token information;

  • transaction records subject to law;

  • and personal data linked only to purposes deemed to have ended.

This is especially important because a single database may contain fields serving several purposes. Complete deletion of the account may be inappropriate where a redeemable token remains, while retention of the entire database may be excessive. The system must support selective erasure or effective restriction.

1.12 Enforcement implications

A covered Data Fiduciary that continues processing personal data after the specified purpose is deemed no longer to be served may breach the erasure obligations under the Act and Rule 8. Failure may arise not only from refusing to delete data but also from defective implementation, such as retaining active advertising profiles, failing to notify Processors, using automated platform messages to reset inactivity or omitting the prescribed advance notice.

The applicable penalty will depend on the legal provision breached and the facts established through the statutory inquiry. The residual Schedule entry may apply to a significant breach for which no separate penalty category is specified, while associated security or breach-notification failures may attract their own penalty treatment.

The seriousness of non-compliance would likely be greater where the platform:

  • knowingly retains large volumes of dormant-user data;

  • continues advertising or behavioural profiling;

  • treats passive technical activity as renewed user engagement;

  • conceals the upcoming erasure;

  • retains data through Processors after deleting the customer-facing account;

  • or represents that law requires retention when no such requirement exists.

1.13 Concluding interpretation

The Third Schedule creates a targeted dormancy rule for large e-commerce, gaming and social media platforms. Its purpose is to prevent long-inactive accounts from justifying indefinite processing of personal data across the platform’s wider commercial and technical ecosystem.

The three-year period is measured from the Data Principal’s last meaningful approach for performance of the specified purpose or exercise of rights, subject to the commencement date being the minimum starting point for legacy data. Once the period expires, most purposes are deemed no longer to be served. Personal data must then be erased unless legal retention applies or the information remains necessary to preserve access to the user account or a qualifying virtual token.

Those exceptions are narrow. Keeping an account technically accessible does not justify permanent retention of behavioural profiles, marketing records, recommendations, advertising segments or unrelated analytics. Similarly, preserving a redeemable token does not authorise retention of every record connected with the user.

The Schedule must also be read as an outer deeming mechanism, not a guaranteed three-year retention entitlement. Consent withdrawal, an erasure request or earlier factual cessation of purpose may require deletion sooner. Conversely, a specific legal obligation may justify limited retention beyond three years, but only for that legal purpose.

In substance, the Third Schedule requires covered platforms to distinguish continuing user access and stored value from the wider data economy built around an account. After prolonged inactivity, the account may remain recoverable, but the platform cannot treat that dormant relationship as indefinite permission to continue every form of personal-data processing.

Reproduced from official sources for reference. Not legal advice. In case of any discrepancy, the text published in the Gazette of India prevails.