---
title: "Second Schedule: Standards for processing of personal data by State and its instrumentalities under clause (b) of section 7 and for processing of personal data necessary for the purposes specified in clause (b) of sub-section (2) of section 17"
url: https://dpdp.myndsolution.com/wiki/rules/schedule-2-standards-for-processing-of-personal-data-by-state-and-its/
description: "Second Schedule to the DPDP Rules, 2025 (Standards for processing of personal data by State and its instrumentalities under clause (b) of section 7 and for…"
kind: rules-schedule
updated: 2026-09-09
official_source: https://egazette.gov.in/WriteReadData/2025/267650.pdf
text_type: official-text-plus-interpretation
publisher: MYND Integrated Solutions
license: Official Government of India texts are reproduced verbatim (public domain / open government data). Interpretation is CC BY 4.0, MYND Integrated Solutions.
disclaimer: Not legal advice. Official text prevails over any interpretation.
html_version: https://dpdp.myndsolution.com/wiki/rules/schedule-2-standards-for-processing-of-personal-data-by-state-and-its/
---
# Second Schedule: Standards for processing of personal data by State and its instrumentalities under clause (b) of section 7 and for processing of personal data necessary for the purposes specified in clause (b) of sub-section (2) of section 17

*[See rules 5(1) and 16]*

## Official text

Implementation of appropriate technical and organisational measures to ensure effective observance of the following, in accordance with applicable law, for the processing of personal data, namely: —

- **(a)** Processing is carried out in a lawful manner;

- **(b)** Processing is done for the uses specified in clause (b) of section 7 of the Act or for the purposes specified in clause (b) of sub-section (2) of section 17 of the Act, as the case may be;

- **(c)** Processing is limited to such personal data as is necessary for such uses or achieving such purposes, as the case may be;

- **(d)** Processing is done while making reasonable efforts to ensure the completeness, accuracy and consistency of personal data;

- **(e)** Personal data is retained till required for such uses or achieving such purposes, as the case may be, or for compliance with any law for the time being in force;

- **(f)** Reasonable security safeguards to prevent personal data breach to protect personal data in the possession or under control of the Data Fiduciary, including in respect of any processing undertaken by it or on its behalf by a Data Processor;

- **(g)** Where processing is to be done under clause (b) of section 7 of the Act, the same is undertaken while giving the Data Principal an intimation in respect of the same and—
  - **(i)** giving the business contact information of a person who is able to answer on behalf of the Data Fiduciary the questions of the Data Principal about the processing of her personal data;
  - **(ii)** specifying the particular communication link for accessing the website or app, or both, of such Data Fiduciary, and a description of other means, if any, using which such Data Principal may exercise her rights under the Act; and
  - **(iii)** is carried on in a manner consistent with such other standards as may be applicable to the processing of such personal data under policy issued by the Central Government or any law for the time being in force; and

- **(h)** Accountability of the person who alone or in conjunction with other persons determines the purpose and means of processing of personal data, for effective observance of these standards.



## Interpretation in plain English (not legal advice)

> This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation.

Schedule II of the rules sets out the standards that the State and its instrumentalities must follow when processing personal data for certain specific purposes. These purposes include providing state services or benefits, or processing necessary for state security and public order. The entity processing the data must put in place appropriate technical and organizational measures to meet these standards.\n\nThe standards require that all processing is lawful, limited to the specific permitted uses, and restricted to only the personal data necessary for those uses. The entity must make reasonable efforts to keep the data complete, accurate, and consistent. It must also delete the data when it is no longer needed for the purpose or for complying with any law, and it must use reasonable security safeguards to prevent data breaches, even if a Data Processor (an entity processing data on its behalf) is used.\n\nWhen the State processes data to provide services or benefits, it must notify the Data Principal (the individual to whom the data relates). This notice must include the contact information of someone who can answer questions, a link or method for the Data Principal to exercise their rights, and it must follow any other applicable government policies. Finally, the person deciding how and why the data is processed remains fully accountable for following these rules.

### Key points

- Processing must be lawful, limited to permitted uses, and restricted to necessary personal data [(a), (b), (c)].
- The entity must make reasonable efforts to ensure data is complete, accurate, and consistent [(d)].
- Personal data can only be retained as long as required for the purpose or for legal compliance [(e)].
- Reasonable security safeguards must be implemented to prevent data breaches, covering both the Data Fiduciary and any Data Processor [(f)].
- When processing for certain state services, the Data Fiduciary must notify the Data Principal, provide contact details for questions, and explain how to exercise their rights [(g)].
- The person determining the purpose and means of processing is accountable for observing these standards [(h)].

### Common misreadings

- Assuming the State is completely exempt from data security rules when processing for state security; the rules still require reasonable security safeguards to prevent data breaches.
- Believing that using a Data Processor shifts the responsibility for security; the Data Fiduciary must ensure safeguards cover processing done on its behalf.

*Interpretation prepared 2026-09-09 from the official text only; the official text prevails.*
