Skip to main content

Sources last verified on 17 August 2026. Methodology

DPDP Rules 2025 · Seventh Schedule

Seventh Schedule: purposes and authorised persons for calling for information

Status
Not yet in force
Commencement
13 May 2027 · computed date, presented as interpretation until officially confirmed (Publication date 13 November 2025 printed on Gazette issue No. 760, plus eighteen months. The corrigendum wording change does not affect this computation.)
Source
Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) · G.S.R. 846(E) · Gazette page 40
Last verified
17 August 2026
Official requirement · verbatim

Seventh Schedule.SEVENTH SCHEDULE [See rule 23(1) and 8(3)] S. no. Purpose Authorised person (1) (2) (3) 1. Use, by the State or any of its instrumentalities, of personal data of a Data Principal in the interest of sovereignty and integrity of India or security of the State. Such officer of the State or of any of its instrumentalities notified under clause (a) of sub-section (2) of section 17 of the Act, as the Central Government or the head of such instrumentality, as the case may be, may designate in this behalf. 2. Use, by the State or any of its instrumentalities, of personal data of a Data Principal for the following purposes, namely: — (i) performance of any function under any law for the time being in force in India; or (ii) disclosure of any information for fulfilling any obligation under any law for the time being in force in India. Person authorised under applicable law. 3. Carrying out assessment for notifying any Data Fiduciary or class of Data Fiduciaries as Significant Data Fiduciary. Such officer of the Central Government, in the Ministry of Electronics and Information Technology, as the Secretary in charge of the said Ministry may designate in this behalf.

Commencement basis · Rules 3, 5 to 16, 22 and 23

Rules 3, 5 to 16, 22 and 23 shall come into force eighteen months after the date of publication in the Official Gazette.

Wording as corrected by corrigenda G.S.R. 892(E).

Sources cited on this page

  1. [1]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), Seventh Schedule Schedule, p. 40. Published 13 November 2025. Official source ↗ · Official requirement · Verified 17 August 2026The Seventh Schedule begins on Gazette page 40 and concludes on page 41. It is printed as a three column table; the Gazette text layer reads each row's purpose and authorised person cells in sequence.
  2. [2]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 1, (4), p. 24. Published 13 November 2025. Official source ↗ · Interpretation, requires judgment · Verified 17 August 2026Rule 1(4) names Rules 8 and 23, which this Schedule serves, in the group due eighteen months after publication and does not name the Schedules. The Seventh Schedule is presented as commencing with those rules (computed 13 May 2027, interpretation until confirmed).
  3. [3]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 1, (4), p. 24. Published 13 November 2025. Official source ↗ · Official requirement · Verified 16 August 2026As printed. Corrigenda G.S.R. 892(E) item (i)(b) corrects the closing words to read in the Official Gazette; the computation is unaffected.
  4. [4]Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)), p. 1. Published 13 November 2025. Official source ↗ · Interpretation, requires judgment · Verified 16 August 2026The calendar date 13 May 2027 is computed from the printed publication date and is presented as interpretation until officially confirmed.