The Seventh Schedule performs two connected but legally distinct functions under the Digital Personal Data Protection Rules, 2025. First, it defines the purposes for which the Central Government may require a Data Fiduciary or intermediary to furnish information under Rule 23 and identifies the official authorised to issue each category of request. Second, through its express cross-reference to Rule 8(3), it identifies the purposes for which certain personal data, associated traffic data and processing logs must be retained for at least one year.
The Schedule therefore operates at the intersection of governmental access, State functions, national security, regulatory assessment, mandatory retention and confidentiality. It should not be interpreted as a general power for every government official to obtain any personal data from any private organisation, nor as a universal requirement that every Data Fiduciary must preserve every item of personal data for one year. Its operation depends on the precise purpose identified in the Schedule, the authority of the requesting official, the scope of the information required and the connection between the information and the specified purpose.
The final DPDP Rules and subsequent corrigendum are published by MeitY. The provisions to which the Seventh Schedule relates are scheduled to become operational on 13 May 2027.