SCHEDULE VII - SEVENTH SCHEDULE - PURPOSE AND AUTHORISED PERSON

Seventh Schedule - Purpose and authorised person

Official text

See rule 23(1) and 8(3)

S. no.(1)Purpose(2)Authorised person(3)
1.Use, by the State or any of its instrumentalities, of personal data of a Data Principal in the interest of sovereignty and integrity of India or security of the State.Such officer of the State or of any of its instrumentalities notified under clause (a) of sub-section (2) of section 17 of the Act, as the Central Government or the head of such instrumentality, as the case may be, may designate in this behalf.
2.
Use, by the State or any of its instrumentalities, of personal data of a Data Principal for the following purposes, namely: -
(i)performance of any function under any law for the time being in force in India; or
(ii)disclosure of any information for fulfilling any obligation under any law for the time being in force in India.
Person authorised under applicable law.
3.Carrying out assessment for notifying any Data Fiduciary or class of Data Fiduciaries as Significant Data Fiduciary.Such officer of the Central Government, in the Ministry of Electronics and Information Technology, as the Secretary in charge of the said Ministry may designate in this behalf.

S. no. 1.

Purpose (2)Use, by the State or any of its instrumentalities, of personal data of a Data Principal in the interest of sovereignty and integrity of India or security of the State.
Authorised person (3)Such officer of the State or of any of its instrumentalities notified under clause (a) of sub-section (2) of section 17 of the Act, as the Central Government or the head of such instrumentality, as the case may be, may designate in this behalf.

S. no. 2.

Purpose (2)
Use, by the State or any of its instrumentalities, of personal data of a Data Principal for the following purposes, namely: -
(i)performance of any function under any law for the time being in force in India; or
(ii)disclosure of any information for fulfilling any obligation under any law for the time being in force in India.
Authorised person (3)Person authorised under applicable law.

S. no. 3.

Purpose (2)Carrying out assessment for notifying any Data Fiduciary or class of Data Fiduciaries as Significant Data Fiduciary.
Authorised person (3)Such officer of the Central Government, in the Ministry of Electronics and Information Technology, as the Secretary in charge of the said Ministry may designate in this behalf.

Cross-references

Seventh Schedule

Commentary

The Seventh Schedule performs two connected but legally distinct functions under the Digital Personal Data Protection Rules, 2025. First, it defines the purposes for which the Central Government may require a Data Fiduciary or intermediary to furnish information under Rule 23 and identifies the official authorised to issue each category of request. Second, through its express cross-reference to Rule 8(3), it identifies the purposes for which certain personal data, associated traffic data and processing logs must be retained for at least one year.

The Schedule therefore operates at the intersection of governmental access, State functions, national security, regulatory assessment, mandatory retention and confidentiality. It should not be interpreted as a general power for every government official to obtain any personal data from any private organisation, nor as a universal requirement that every Data Fiduciary must preserve every item of personal data for one year. Its operation depends on the precise purpose identified in the Schedule, the authority of the requesting official, the scope of the information required and the connection between the information and the specified purpose.

The final DPDP Rules and subsequent corrigendum are published by MeitY. The provisions to which the Seventh Schedule relates are scheduled to become operational on 13 May 2027.

Rule 23 permits the Central Government, acting through the corresponding authorised person identified in the Seventh Schedule, to require a Data Fiduciary or intermediary to furnish information for a purpose listed in that Schedule. The request must specify the information required and the period within which it must be furnished.

Rule 8(3) separately requires a Data Fiduciary to retain, in relation to processing undertaken by it or on its behalf by a Data Processor:

  • such personal data;

  • associated traffic data; and

  • other processing logs, for at least one year from the date of processing, for the purposes identified in the Seventh Schedule. After that period, the Data Fiduciary must cause those records to be erased unless longer retention is required by another law or notified by the Government.

The combined framework means that the Schedule does not merely identify circumstances in which the Government may ask for information. It also supports preservation of records that may be necessary for those governmental and regulatory purposes.

The three purposes are:

  1. State use of personal data in the interests of the sovereignty and integrity of India or security of the State;

  2. State use of personal data for performing a function under Indian law or disclosing information to fulfil an obligation under Indian law; and

  3. assessment of whether a Data Fiduciary or class of Data Fiduciaries should be notified as a Significant Data Fiduciary.

These purposes cover materially different forms of governmental action. The first concerns national and State security. The second concerns ordinary statutory functions and legally required disclosures. The third concerns administration of the DPDPA’s enhanced regulatory framework for Significant Data Fiduciaries.

The Seventh Schedule must be interpreted separately for each purpose. Authority under one entry does not automatically confer authority under the others.

1.2 Purpose-bound governmental access

The Schedule is designed around a combination of purpose and authority. A valid Rule 23 request must arise from one of the specified purposes and must be issued through the person identified for that purpose.

This structure prevents the Schedule from becoming a free-standing information-demand power for public officials generally. A request should be capable of demonstrating:

  • the relevant Schedule entry;

  • the statutory or governmental purpose;

  • the authorised official;

  • the Data Fiduciary or intermediary to whom it is directed;

  • the information required; and

  • the period for compliance.

A recipient should not disclose personal data merely because a communication appears to come from a government department. It should verify that the request has been made by the appropriate authorised person and falls within the purpose for which that person is authorised.

Equally, the recipient should not obstruct a valid request by imposing requirements that are not found in the applicable framework. Once authority, purpose and scope are established, the Data Fiduciary or intermediary must furnish the information within the period specified in the request.

The Schedule does not expressly prescribe one standard form or one uniform response period. The form and time allowed may therefore differ according to urgency, volume, technical complexity and the statutory purpose. A national-security request may require faster action than an extensive information request undertaken to assess whether a class of organisations should be designated as SDFs.

1.3 State use in the interests of sovereignty, integrity and security

The first entry concerns use by the State or its instrumentalities of a Data Principal’s personal data in the interests of the sovereignty and integrity of India or security of the State.

This entry must be read with Section 17(2)(a), which empowers the Central Government to notify instrumentalities of the State for specified sovereign, security and public-order interests. Section 17(2)(a) refers more broadly to sovereignty and integrity, State security, friendly relations with foreign States, maintenance of public order and prevention of incitement to cognizable offences connected with those matters. The Seventh Schedule’s first entry expressly identifies sovereignty, integrity and State security for its information and retention framework.

The authorised person is an officer of the State or the relevant instrumentality notified under Section 17(2)(a), designated by the Central Government or by the head of that instrumentality, as applicable.

The involvement of a notified instrumentality is important. An entity does not obtain authority under this entry merely because it is government-owned, performs a public function or considers its work relevant to security. The request must be tied to the statutory notification and an officer designated by the competent authority.

The designation should also be understood institutionally. The officer acts through the authority assigned by the State or notified instrumentality, not in a personal capacity. The recipient should verify the officer’s designation, official communication channel and the relationship between the information demanded and the specified sovereign or security purpose.

This entry may support requests concerning information needed to understand, prevent or respond to risks affecting India’s sovereignty, integrity or State security. However, the language should not be treated as authorising unrestricted collection of every record held by the recipient. The information called for should have a rational and credible connection with the stated purpose.

Where only specified account, access, transaction or communication records are required, the Data Fiduciary should not ordinarily furnish unrelated customer databases merely because they are technically accessible. The request should be implemented accurately rather than either resisted without basis or answered through indiscriminate overproduction.

1.4 Statutory functions and legally required disclosures

The second entry covers State use of personal data for:

  • performance of a function under Indian law; or

  • disclosure of information for fulfilling an obligation under Indian law.

The authorised person is the person authorised under the applicable law.

This entry is broad in subject matter but not unlimited in authority. The State function or disclosure obligation must have an identifiable foundation in law, and the officer or person issuing the requirement must possess authority under that law.

Potentially relevant legal functions may concern regulation, licensing, taxation, financial supervision, public administration, law enforcement, welfare administration or another statutory responsibility. The validity and scope of the request depend on the underlying legislation.

The Schedule does not itself create every power required to perform those functions. Rather, it recognises the person authorised under the applicable law and allows the Rule 23 mechanism to operate in relation to the stated DPDPA purpose.

The recipient should therefore assess the request by reference to:

  • the law under which the function or disclosure obligation arises;

  • the authority of the person issuing it;

  • the information reasonably connected with that function;

  • the period and form required;

  • and any confidentiality, secrecy or procedural conditions under the underlying law.

A person authorised to obtain specified financial records under one statute does not automatically gain authority under the Schedule to obtain unrelated health, employee or communication information. The underlying law continues to define the substantive boundary.

This entry also explains why Rule 8(3) is not concerned only with cybersecurity or personal data breaches. Processing records may need to remain available for legally authorised governmental functions or disclosures even after the immediate commercial transaction has ended.

Example

For example, an online service may complete a transaction and no longer require certain information for ordinary service delivery. Nevertheless, selected transaction and processing records may need to remain available during the one-year Rule 8(3) period so that lawful public functions and disclosure requirements can be fulfilled. Any longer preservation still requires an independent legal basis or governmental notification.

1.5 Assessment for designation as a Significant Data Fiduciary

The third entry enables information to be obtained for assessing whether a particular Data Fiduciary or class of Data Fiduciaries should be notified as Significant Data Fiduciaries under Section 10.

The authorised person is an officer of the Central Government in MeitY designated by the Secretary in charge of the Ministry.

This entry supports the Government’s ability to make an evidence-based SDF designation. Section 10 requires consideration of factors such as:

  • volume and sensitivity of personal data;

  • risk to Data Principal rights;

  • potential impact on sovereignty and integrity;

  • risk to electoral democracy;

  • State security;

  • and public order.

An SDF assessment may therefore require information concerning the scale and nature of the processing, the number and categories of Data Principals, important technical systems, algorithmic processing, cross-border data flows, security arrangements, Processor dependencies, history of breaches and other matters relevant to the statutory criteria.

The information sought must remain connected to the SDF assessment. This entry should not be interpreted as a general authorisation for the designated MeitY officer to demand information for unrelated enforcement, taxation, security or commercial purposes.

Receipt of an information request does not itself make the recipient an SDF. Designation requires a separate Central Government notification under Section 10. Until such notification applies, the organisation does not acquire SDF status merely because it supplied information or was being assessed.

Conversely, where a class is later notified and the organisation falls within that class, the additional obligations apply according to the terms of the notification even if its corporate name is not individually reproduced.

1.6 Meaning of the one-year retention requirement

The cross-reference from Rule 8(3) makes the Seventh Schedule central to the mandatory retention framework.

The Rule requires retention for a minimum of one year from the date of the relevant processing. This suggests that the retention period is linked to the processing event rather than solely to account creation, account closure or the most recent interaction with the Data Principal.

The requirement does not necessarily mean that every field in every system must be preserved for one year. Rule 8(3) refers to “such personal data, associated traffic data and other logs of the processing” for the Schedule purposes. The retention should therefore be connected with the records reasonably required for those purposes.

A defensible implementation should distinguish among:

  • the substantive personal data processed;

  • metadata concerning access, routing or communication;

  • transaction records;

  • authentication and security logs;

  • records of sharing or disclosure;

  • and operational data having no reasonable connection with a Schedule purpose.

The provision should not be used to justify wholesale retention of every customer profile, behavioural inference, marketing segment, uploaded document and communication merely because the organisation processes personal data.

At the same time, the Data Fiduciary should not erase essential transaction or processing records prematurely where Rule 8(3) requires their preservation.

The correct question is not whether a record contains personal data in the abstract. It is whether the record falls within the personal data, associated traffic data or processing logs that must remain available for a Seventh Schedule purpose.

1.7 Associated traffic data and processing logs

Associated traffic data may include metadata concerning how personal data moved through or was accessed within a system. Depending on the service and architecture, this may include:

  • source and destination identifiers;

  • IP addresses;

  • timestamps;

  • device or session identifiers;

  • routing information;

  • transfer events;

  • log-in activity;

  • API communication records;

  • and system endpoints.

Processing logs may record events such as collection, access, alteration, transmission, sharing, delivery, deletion, consent status or system operations affecting personal data.

Traffic data and logs may themselves be personal data. They can reveal when an individual used a service, from which device or approximate location, which organisations received information and what type of activity occurred.

Their retention must therefore remain subject to appropriate security and access controls. A record retained for governmental or regulatory purposes must not automatically be reused for employee monitoring, marketing, commercial profiling or AI development.

The one-year rule also does not necessarily require logging the full content of every communication or transaction. Where event metadata is sufficient for the permitted purpose, recording complete content may be excessive. Rule 8(3) should not be transformed into an authority for continuous and indiscriminate content surveillance.

1.8 Relationship with the Third Schedule and general erasure

The Seventh Schedule retention requirement should not be confused with the Third Schedule’s three-year inactivity-based erasure mechanism.

The Third Schedule determines when most processing purposes of specified large e-commerce, online gaming and social media platforms are deemed no longer to be served after prolonged inactivity.

The Seventh Schedule, through Rule 8(3), concerns minimum retention of relevant personal data, traffic data and processing logs for specified governmental and regulatory purposes.

The two can operate simultaneously.

A large e-commerce platform may erase dormant-user information when the Third Schedule period expires but still retain selected legally required transaction or processing records if another law or applicable requirement supports continued retention. Similarly, even where a commercial purpose ends immediately after a transaction, Rule 8(3) may require relevant data and logs to remain available for one year.

The distinction is between:

  • continued active use for the original commercial or service purpose; and

  • restricted preservation for a statutory governmental or regulatory purpose.

Retained records should not remain available for ordinary advertising, recommendation or behavioural profiling merely because they are preserved under Rule 8(3).

1.9 Starting point and recurring processing

The Rule 8(3) period begins from the date of the relevant processing. This creates practical complexity where processing is continuous or repeated.

A single transaction may involve several events:

  • account authentication;

  • order placement;

  • payment;

  • confirmation;

  • delivery;

  • complaint handling;

  • refund;

  • and erasure.

Each event may generate its own records and processing date.

The Data Fiduciary should develop a principled method for grouping related events without either erasing required records prematurely or resetting the retention clock indefinitely through routine system activity.

Automatic backups, security scans, system pings or internal migration should not necessarily restart the one-year period for the entire substantive dataset. Otherwise, ordinary technical operations could make erasure impossible.

The retention model should identify meaningful processing events and the corresponding records required for the Seventh Schedule purposes. The methodology should be documented and technically enforceable.

1.10 Longer retention and the duty to erase

Rule 8(3) describes one year as a minimum period. It also states that after the period, the Data Fiduciary must cause the personal data and logs to be erased unless:

  • further retention is required by another law; or

  • further retention is notified by the Government.

The one-year period is therefore neither a universal maximum nor an automatic authority for indefinite storage.

A tax, financial, corporate, employment, telecommunications or sectoral law may require specified records to be retained for longer. In that case, the longer legal period governs those records.

The legal basis must be record-specific. A requirement to retain an invoice does not necessarily justify continued retention of an unrelated advertising profile, precise location history or abandoned identity document.

After the final applicable retention period expires, erasure must extend to processing undertaken by Data Processors. The Data Fiduciary must therefore ensure that its contracts and technical systems allow it to preserve required records for the applicable period and erase them afterward.

1.11 Data Processors and outsourced systems

Rule 8(3) expressly applies to processing undertaken by the Data Fiduciary or on its behalf by a Data Processor.

The Data Fiduciary remains responsible for ensuring that Processors:

  • retain the relevant information for the required period;

  • protect it through reasonable security safeguards;

  • make it available when the Data Fiduciary must respond to a lawful request;

  • restrict it from unrelated use;

  • erase it when the retention requirement ends;

  • and apply corresponding controls to authorised subprocessors.

A vendor’s standard deletion schedule cannot override a mandatory one-year preservation requirement. Conversely, a vendor’s global policy of retaining all data for several years cannot override the Data Fiduciary’s obligation to erase when the lawful period ends.

Contractual arrangements should address retention at service termination. If a Processor contract ends six months after a relevant transaction, the Data Fiduciary must determine how records required for the remaining period will be preserved. This may require secure export, restricted archival retention or migration to another controlled environment.

The Data Fiduciary should not require the Processor to keep the entire active platform merely because selected logs remain subject to preservation.

1.12 Secure preservation and restricted use

Information retained for Seventh Schedule purposes may include highly consequential records. Security protections should correspond to the nature and volume of the data.

Restricted retention should ordinarily mean that the data is:

  • separated from ordinary commercial systems where practicable;

  • accessible only to authorised personnel;

  • protected against alteration and deletion;

  • logged when accessed;

  • unavailable for advertising or profiling;

  • and subject to automatic erasure or review at expiry.

This is particularly important where the original service relationship has ended. A Data Principal may delete an account while selected transaction and processing evidence remains in a restricted legal or compliance archive. The organisation should not treat that limited retention as authority to continue the former service or commercial relationship.

1.13 Confidentiality under Rule 23

Rule 23 permits the Central Government to direct a Data Fiduciary or intermediary not to disclose the furnishing of information where disclosure is likely to prejudicially affect India’s sovereignty and integrity or State security.

Such a direction may prevent disclosure to the affected Data Principal or any other person unless the authorised person grants prior written permission.

This is not an automatic secrecy rule for every Seventh Schedule request. The confidentiality power depends on the stated prejudice and a requirement imposed by the Central Government.

Where the direction applies, the recipient must restrict knowledge of the request internally. Personnel handling Data Principal rights, transparency reporting, legal response and customer support should not inadvertently disclose the protected furnishing.

The restriction does not mean that the organisation may give a knowingly false answer. It may mean that the organisation cannot reveal the existence or details of the information request and must handle the response according to the applicable legal restriction.

A Data Fiduciary cannot invent its own Rule 23 secrecy restriction merely because it prefers not to disclose governmental access. The non-disclosure obligation must arise through the statutory mechanism.

1.14 Relationship with other governmental powers

The Seventh Schedule does not replace separate powers under criminal procedure, taxation, financial regulation, telecommunications law, the Information Technology Act or another statute.

A governmental request should be assessed under the law through which it is actually issued. Different powers may have different authorised officers, procedures, secrecy rules, response periods and consequences.

A valid demand under another law does not become invalid merely because it is not issued under Rule 23. Likewise, a communication described as a Rule 23 request cannot exceed the purpose and authority provided by the Seventh Schedule simply because another governmental power might potentially exist.

The recipient should identify the legal basis accurately because that basis determines:

  • what may be demanded;

  • who may demand it;

  • how the response should be made;

  • whether disclosure to the Data Principal is restricted;

  • and for how long the relevant records must be preserved.

1.15 Accountability and demonstrability

A Data Fiduciary or intermediary responding to a Seventh Schedule request should maintain a reliable internal record of:

  • the requesting authority;

  • the officer’s designation;

  • the Schedule purpose;

  • the legal basis;

  • information requested;

  • applicable period;

  • clarification or extension;

  • systems searched;

  • Processors involved;

  • information furnished;

  • security controls used;

  • confidentiality directions;

  • and the persons who approved the response.

The record should be access-restricted, particularly where national-security information or a non-disclosure direction is involved.

The Data Fiduciary should also be capable of demonstrating why particular data and logs were retained under Rule 8(3). It should not merely cite the Seventh Schedule across its entire data inventory without connecting the retained record to a Schedule purpose.

The retention schedule should identify the processing event, record category, one-year period, any longer law, responsible system, Processor, access limitation and final erasure action.

1.16 The interpretive significance of the dual cross-reference

The explicit heading of the Seventh Schedule refers to both Rule 23(1) and Rule 8(3). This resolves the concern that the Rule 8(3) cross-reference might be accidental or mistakenly intended to refer to the Third Schedule.

The two references serve different but connected functions:

  • Rule 23 uses the Schedule to identify the purposes and persons through whom information may be required.

  • Rule 8(3) uses the Schedule to identify the purposes for which relevant data and processing logs must remain available for at least one year.

This means that the statutory illustrations under Rule 8(3), such as retention of e-book transaction details and cloud-hosted records, should be understood through the need to preserve relevant processing evidence for the Seventh Schedule purposes. The illustration does not mean that the complete customer account or every unrelated dataset must be retained.

The Data Fiduciary should preserve a proportionate, reliable and secure evidentiary record of the processing, rather than use the rule as justification for retaining all information generated by the service.

1.17 Enforcement implications

Failure to furnish information under a valid Rule 23 request, breach of an applicable confidentiality requirement or failure to retain and erase records in accordance with Rule 8(3) may constitute non-compliance with the Act or Rules.

Depending on the facts, a significant breach may fall within the residual penalty category, which permits a monetary penalty of up to ₹50 crore. Other penalty categories may apply where the conduct also involves inadequate security safeguards or failure to notify a personal data breach.

Serious non-compliance may include:

  • knowingly ignoring a valid request;

  • furnishing materially false information;

  • concealing responsive records;

  • disclosing a protected request contrary to a valid Rule 23 direction;

  • deleting relevant records before expiry of the one-year period;

  • retaining them indefinitely without legal basis;

  • allowing Processors to erase required records prematurely;

  • continuing commercial use of records supposedly retained only for statutory purposes;

  • or furnishing information to a person whose authority was not verified.

The maximum penalty is not automatic. The applicable procedure and Section 33 factors must be followed before a monetary penalty is imposed.

1.18 Concluding interpretation

The Seventh Schedule creates a controlled institutional bridge between personal-data processing by Data Fiduciaries and specified governmental purposes.

It permits information to be required only where:

  • the purpose falls within one of its three entries;

  • the request is issued by the corresponding authorised person;

  • the information sought is connected with that purpose;

  • and the recipient is given a period for compliance.

It also supports preservation of relevant personal data, traffic data and processing logs for at least one year so that those governmental and regulatory functions are not frustrated by premature deletion.

The Schedule does not justify indiscriminate governmental access or indiscriminate business retention. Information gathering must remain purpose-bound and authorised. Retention must remain connected to the Schedule, restricted from unrelated use, extended only where another law or notification requires it, and followed by erasure when the final legal period ends.

The three entries also remain separate. A national-security officer does not automatically acquire SDF-assessment authority. A MeitY officer designated for SDF assessment does not automatically obtain authority to demand information for an unrelated statutory function. A person authorised under another law cannot use that authority beyond the scope of that law.

In substance, the Seventh Schedule requires disciplined governance on both sides. The Government must act through the authorised person and for the listed purpose. The Data Fiduciary or intermediary must preserve relevant records, verify the request, furnish responsive information securely, comply with any lawful secrecy direction and erase retained data when the legal justification ends.

Reproduced from official sources for reference. Not legal advice. In case of any discrepancy, the text published in the Gazette of India prevails.