DPDP Wiki Talk to us

/The Rules · Schedules

Second Schedule: Standards for processing of personal data by State and its instrumentalities under clause (b) of section 7 and for processing of personal data necessary for the purposes specified in clause (b) of sub-section (2) of section 17

[See rules 5(1) and 16]

Official text
Part of
The Digital Personal Data Protection Rules, 2025
Referred to by
Rule 5Rule 16
Source
Ministry of Electronics and Information Technology · G.S.R. 846(E) · 13 November 2025 · Official PDF

SECOND SCHEDULE [See rules 5(1) and 16]

Verbatim from the Gazette of India

Implementation of appropriate technical and organisational measures to ensure effective observance of the following, in accordance with applicable law, for the processing of personal data, namely: —

(a)

Processing is carried out in a lawful manner;

(b)

Processing is done for the uses specified in clause (b) of section 7 of the Act or for the purposes specified in clause (b) of sub-section (2) of section 17 of the Act, as the case may be;

(c)

Processing is limited to such personal data as is necessary for such uses or achieving such purposes, as the case may be;

(d)

Processing is done while making reasonable efforts to ensure the completeness, accuracy and consistency of personal data;

(e)

Personal data is retained till required for such uses or achieving such purposes, as the case may be, or for compliance with any law for the time being in force;

(f)

Reasonable security safeguards to prevent personal data breach to protect personal data in the possession or under control of the Data Fiduciary, including in respect of any processing undertaken by it or on its behalf by a Data Processor;

(g)

Where processing is to be done under clause (b) of section 7 of the Act, the same is undertaken while giving the Data Principal an intimation in respect of the same and—

(i)

giving the business contact information of a person who is able to answer on behalf of the Data Fiduciary the questions of the Data Principal about the processing of her personal data;

(ii)

specifying the particular communication link for accessing the website or app, or both, of such Data Fiduciary, and a description of other means, if any, using which such Data Principal may exercise her rights under the Act; and

(iii)

is carried on in a manner consistent with such other standards as may be applicable to the processing of such personal data under policy issued by the Central Government or any law for the time being in force; and

(h)

Accountability of the person who alone or in conjunction with other persons determines the purpose and means of processing of personal data, for effective observance of these standards.

Interpretation in plain English

Interpretation · not legal advice
Interpretation, not legal advice. This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation.
Data FiduciaryData PrincipalData ProcessorCentral Government

Schedule II of the rules sets out the standards that the State and its instrumentalities must follow when processing personal data for certain specific purposes. These purposes include providing state services or benefits, or processing necessary for state security and public order. The entity processing the data must put in place appropriate technical and organizational measures to meet these standards.\n\nThe standards require that all processing is lawful, limited to the specific permitted uses, and restricted to only the personal data necessary for those uses. The entity must make reasonable efforts to keep the data complete, accurate, and consistent. It must also delete the data when it is no longer needed for the purpose or for complying with any law, and it must use reasonable security safeguards to prevent data breaches, even if a Data Processor (an entity processing data on its behalf) is used.\n\nWhen the State processes data to provide services or benefits, it must notify the Data Principal (the individual to whom the data relates). This notice must include the contact information of someone who can answer questions, a link or method for the Data Principal to exercise their rights, and it must follow any other applicable government policies. Finally, the person deciding how and why the data is processed remains fully accountable for following these rules.

Key points

  • Processing must be lawful, limited to permitted uses, and restricted to necessary personal data [(a), (b), (c)].
  • The entity must make reasonable efforts to ensure data is complete, accurate, and consistent [(d)].
  • Personal data can only be retained as long as required for the purpose or for legal compliance [(e)].
  • Reasonable security safeguards must be implemented to prevent data breaches, covering both the Data Fiduciary and any Data Processor [(f)].
  • When processing for certain state services, the Data Fiduciary must notify the Data Principal, provide contact details for questions, and explain how to exercise their rights [(g)].
  • The person determining the purpose and means of processing is accountable for observing these standards [(h)].

Common misreadings

  • Assuming the State is completely exempt from data security rules when processing for state security; the rules still require reasonable security safeguards to prevent data breaches.
  • Believing that using a Data Processor shifts the responsibility for security; the Data Fiduciary must ensure safeguards cover processing done on its behalf.

Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.

/MYND · DPDP practice

Putting this into practice?

MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.

How we use these details: only to respond to you. Withdraw any time by writing to sales@myndsol.com. This form is protected against automated submissions.