
DPDPA Rule 5: Government and it’s Agencies
The government didn’t write itself a blank check. Discover how DPDP Act Rule 5 regulates state data processing for DPDP subsidies and public benefits.
Written by
Sahil Pugalia
Date
Read time
5 min

People assume the government wrote itself a blank check for data collection. It didn’t. It wrote DPDP Act Rule 5.
The rule governs how the State and its instrumentalities process personal data to deliver DPDP subsidies and benefits, as well as services, certificates, licences, or permits. It authorizes processing for public service delivery, but with a catch: strict adherence to the standards specified in the Second Schedule.
This article explains what the rule actually says, how to interpret it correctly, and what changes in practice for the agencies and teams executing public programs.
Scope and Authority
Rule 5 applies the moment the State or its instrumentalities process personal data to provide or issue a subsidy, benefit, service, certificate, licence, or permit.
Operating under Section 7(b) of the Act, it frames a lawful basis for government processing tied directly to specific public programs.
The takeaway is clear. If an agency is delivering a defined public entitlement or document, it may process the personal data necessary to do so,provided it meets the standards set out in the Second Schedule.
It is an authorization. It is not an exemption from accountability.
What Counts as Under Law, Under Policy, and Using Public Funds
Bureaucracy thrives on ambiguity. Rule 5 attempts to eliminate it by providing precise, functional definitions to avoid confusion across programs and authorities:
- Under law means the State or its instrumentalities are exercising powers or performing functions under any law in force. Example: Processing personal data to issue a driving licence under the Motor Vehicles Act.
- Under policy means the Central or State Government is acting under executive policy or instruction. Example: Processing personal data to allocate benefits under a rural employment scheme implemented through a State government policy.
- Using public funds means the program is financed from public finances. For the Central or State Government, this includes the Consolidated Fund of India, the Consolidated Fund of the State, or the public account of India or of the State. For local or other authorities under government control, this includes their own funds. Example: A municipality processing data to grant property tax rebates funded through its own revenues.

These definitions are functional. They confirm that public programs delivered under statute, executive policy, or through public financing are firmly within scope.
Standards in the Second Schedule
Rule 5 requires that all processing under this rule follows the standards in the Second Schedule.
The text indicates these standards likely cover transparency and security,such as informing individuals about data use and implementing safeguards against unauthorized access.
The operational message is non-negotiable. Before processing data, agencies must identify and implement the specific controls and procedures set out in the Second Schedule.
Teams cannot assume compliance just because they are a government entity. They must review the schedule and evidence their adherence.
What This Means in Practice
Public bodies and their instrumentalities must move from theoretical compliance to operational reality. Execution should align with three core ideas drawn from the rule and its interpretation:
1) Tie processing to a defined public program
- Link each data element collected to a specific subsidy, benefit, service, certificate, licence, or permit.
- Confirm whether the program is under law, under policy, or using public funds. Record this basis.
2) Implement Second Schedule standards as a working system
- Establish clear notices to individuals where required, explaining purpose and use.
- Apply security measures proportionate to the sensitivity and scale of data processed.
- Maintain traceability for how data flows through the program and where it is stored.
3) Embed purpose limitation and transparency
- Use personal data only for the defined program purpose.
- Do not repurpose or share the data beyond what the law or policy contemplates without a clear basis.
- Provide clarity to individuals about the purpose and processing activities.
These are not theoretical steps. They are the execution guardrails that align with the rule’s requirements.
Boundaries and Accountability
Let’s be clear: Rule 5 is not a blanket waiver. When discussing DPDP government exemptions, the State does not get carte blanche to collect and use personal data however it sees fit.
The rule authorizes processing only for delivering a defined public entitlement or document, and binds that processing to the Second Schedule standards.

The interpretation emphasizes strict accountability measures:
- Purpose limitation. Data must be processed only for the specific program or entitlement.
- Transparency. Individuals should know what data is processed and why.
- Auditable compliance. Expect to evidence exactly how controls meet the Second Schedule.
These principles help prevent overreach. They reinforce the State’s duty as a custodian of personal data while executing welfare and service delivery.
Interpretation Boundaries You Should Not Cross
Compliance fails when boundaries blur. Here are the lines you should not cross:
- Do not extend Rule 5 beyond its mandate. General analytics or unrelated administrative uses do not fit unless justified under another provision. It must link to a subsidy, benefit, service, certificate, licence, or permit.
- Do not treat executive policies casually. “Under policy” has a defined meaning tied strictly to policies or instructions issued by the Central or State Government under executive power.
- Do not overlook funding structure. “Using public funds” includes more than central or state treasuries. It can include the funds of local or other authorities under government control. Map the finance source correctly.
- Do not skip the Second Schedule. Compliance is not implied. Teams must implement the standards it prescribes and be prepared to demonstrate that implementation.
Practical Examples Aligned With Rule 5
To ground this in reality, here is what Rule 5 looks like in action:
- Under law: Processing data to verify identity, eligibility, and records to issue a driving licence under a statute.
- Under policy: Processing data to disburse benefits under a State’s employment or social protection program issued through executive instructions.
- Using public funds: Processing data to apply a municipal property tax rebate funded from the municipality’s own revenues.
Notice the pattern. Each example is anchored in a defined program, a clear authority or funding source, and a direct service or entitlement outcome.
Closing Thoughts
Rule 5 enables government programs to function without compromising the individual’s right to data protection.
The path is straightforward. Identify the program authority or funding basis. Limit data use to that purpose. Implement the Second Schedule standards in a way you can evidence. That is how you stay compliant and keep services moving.
But execution is where teams struggle. Mapping data fields to purposes, validating authority, and operationalizing the Second Schedule often exposes massive process gaps. A framework on paper is not a capability in practice.
At Regodit, we provide a structured way to organize obligations, controls, and evidence across programs. Because moving from policy to proof shouldn’t require friction,it just requires the right system.
Disclaimer: The views and explanations shared in this blog are based on our team's understanding of the relevant compliance frameworks. While every effort has been made to ensure accuracy, readers are encouraged to refer to the original legal provisions and official notifications for authoritative guidance. Please reach out to us at connect@solsphere.ai.
Keep reading
All blogs →DPDPA Rule 23: Government Requests for Information from Data Fiduciaries and Intermediaries
Handling a notice under DPDP Act Rule 23 requires strict confidentiality. Discover how to respond to government data requests and ensure full compliance.
DPDPA Rule 22: Appeals to the Appellate Tribunal
Lost at the Data Protection Board? DPDPA Rule 22 governs the digital-first appeals process. Read our complete guide to filing an appeal with the Tribunal.
DPDPA Rule 21: The Machinery Behind the Data Protection Board of India
Ensure your business meets DPDP Act compliance requirements. Discover key obligations for data fiduciaries, penalty risks, and steps to protect user privacy.
