/The Rules · Schedules
Seventh Schedule: Purposes for which the State may call for information, and authorised persons
[See rule 23(1) and 8(3)] The Gazette prints no descriptive heading for this Schedule; the title above is editorial. Printed headings: Purpose, Authorised person.
- Part of
- The Digital Personal Data Protection Rules, 2025
- Referred to by
- Rule 8Rule 23
- Source
- Ministry of Electronics and Information Technology · G.S.R. 846(E) · 13 November 2025 · Official PDF
| S. no. | Purpose | Authorised person |
|---|---|---|
| 1. | Use, by the State or any of its instrumentalities, of personal data of a Data Principal in the interest of sovereignty and integrity of India or security of the State. | Such officer of the State or of any of its instrumentalities notified under clause (a) of sub-section (2) of section 17 of the Act, as the Central Government or the head of such instrumentality, as the case may be, may designate in this behalf. |
| 2. | Use, by the State or any of its instrumentalities, of personal data of a Data Principal for the following purposes, namely: — (i) performance of any function under any law for the time being in force in India; or (ii) disclosure of any information for fulfilling any obligation under any law for the time being in force in India. | Person authorised under applicable law. |
| 3. | Carrying out assessment for notifying any Data Fiduciary or class of Data Fiduciaries as Significant Data Fiduciary. | Such officer of the Central Government, in the Ministry of Electronics and Information Technology, as the Secretary in charge of the said Ministry may designate in this behalf. [F. No. AA-11038/1/2025-CLandES] AJIT KUMAR, Jt. Secy. |
This schedule lists specific purposes for which personal data can be used by the government, and identifies exactly who is authorized to carry out those actions. It acts as a reference table for rules regarding state use of data and the assessment of major data-handling entities. First, the State or its agencies can use the personal data of a Data Principal (the individual to whom the data relates) to protect the sovereignty, integrity, or security of India. The authorized person for this task is a specific officer designated by the Central Government or the head of the relevant state agency. Second, the State can use personal data to perform functions or disclose information required by any existing Indian law. In this case, the authorized person is whoever is permitted under that specific law. Finally, the schedule covers the process of evaluating a Data Fiduciary (an entity that decides how and why data is processed) to see if it should be classified as a Significant Data Fiduciary. This assessment must be carried out by an officer within the Ministry of Electronics and Information Technology, specifically designated by the Secretary of that Ministry.
Key points
- The State can use personal data for India's sovereignty, integrity, or security, carried out by a designated officer [Item 1].
- The State can use personal data to perform legal functions or fulfill legal disclosure obligations, carried out by a person authorized under the relevant law [Item 2].
- The Central Government can assess Data Fiduciaries to classify them as Significant Data Fiduciaries [Item 3].
- This assessment must be done by a designated officer in the Ministry of Electronics and Information Technology [Item 3].
Common misreadings
- Readers might think any government employee can access data for national security, but the schedule requires a specifically designated officer to be the authorized person.
- Readers might assume the Board assesses entities to become Significant Data Fiduciaries, but the schedule assigns this task to a designated officer in the Ministry of Electronics and Information Technology.
Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.
/MYND · DPDP practice
Putting this into practice?
MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.