Version 1.0 • CURRENT
DPDP Rules 2025 Processing of Personal Data by State
RULE 5

Processing of personal data by State and its instrumentalities

Official Statutory Text MeitY Gazette Notified Section 40 Delegated Authority
Plain-Language Compliance Breakdown (Editorial Analysis)

What this means: Even when the government collects your data without explicit consent (to give you a subsidy or license), they are not completely free from the rules. They must still follow basic security standards and delete your data when the purpose is fulfilled.

Key Practical Takeaways for Compliance Teams

  • Delegated Specificity: This rule provides concrete operational criteria that must be reflected in technical architectures and compliance records.
  • Audit Readiness: Ensure written SOPs, consent logs, and security controls correspond directly to the statutory wording of Rule 5.
  • Statutory Traceability: In any legal interpretation, the exact Gazette text above takes precedence over internal summaries.
← PREVIOUS RULE Rule 4: Registration and obligations of Consent Manager NEXT RULE → Rule 6: Reasonable security safeguards
Statutory text reproduced under open access public domain principles. This reader is designed for educational and compliance decision support.