/The Act · Chapter IV · Special Provisions
Section 17: Exemptions
DPDP Act, 2023 (No. 22 of 2023). Comes into force on 13 May 2027.
- Provision
- Section 17 of The Digital Personal Data Protection Act, 2023
- Status
- Comes into force on 13 May 2027 (phase 3) G.S.R. 843(E)
- Rules made under it
- Rule 16
- Source
- Ministry of Law and Justice (Legislative Department) · 11 August 2023 · Official PDF
The provisions of Chapter II, except sub-sections (1) and (5) of section 8, and those of Chapter III and section 16 shall not apply where—
the processing of personal data by any court or tribunal or any other body in India which is entrusted by law with the performance of any judicial or quasi-judicial or regulatory or supervisory function, where such processing is necessary for the performance of such function;
personal data is processed in the interest of prevention, detection, investigation or prosecution of any offence or contravention of any law for the time being in force in India;
personal data of Data Principals not within the territory of India is processed pursuant to any contract entered into with any person outside the territory of India by any person based in India;
the processing is necessary for a scheme of compromise or arrangement or merger or amalgamation of two or more companies or a reconstruction by way of demerger or otherwise of a company, or transfer of undertaking of one or more company to another company, or involving division of one or more companies, approved by a court or tribunal or other authority competent to do so by any law for the time being in force; and
the processing is for the purpose of ascertaining the financial information and assets and liabilities of any person who has defaulted in payment due on account of a loan or advance taken from a financial institution, subject to such processing being in accordance with the provisions regarding disclosure of information or data in any other law for the time being in force.
For the purposes of this clause, the expressions “default” and “financial institution” shall have the meanings respectively assigned to them in sub-sections (12) and (14) of section 3 of the Insolvency and Bankruptcy Code, 2016.
The provisions of this Act shall not apply in respect of the processing of personal data—
by such instrumentality of the State as the Central Government may notify, in the interests of sovereignty and integrity of India, security of the State, friendly relations with foreign States, maintenance of public order or preventing incitement to any cognizable offence relating to any of these, and the processing by the Central Government of any personal data that such instrumentality may furnish to it; and
necessary for research, archiving or statistical purposes if the personal data is not to be used to take any decision specific to a Data Principal and such processing is carried on in accordance with such standards as may be prescribed.
The Central Government may, having regard to the volume and nature of personal data processed, notify certain Data Fiduciaries or class of Data Fiduciaries, including startups, as Data Fiduciaries to whom the provisions of section 5, sub-sections (3) and (7) of section 8 and sections 10 and 11 shall not apply.
For the purposes of this sub-section, the term “startup” means a private limited company or a partnership firm or a limited liability partnership incorporated in India, which is eligible to be and is recognised as such in accordance with the criteria and process notified by the department to which matters relating to startups are allocated in the Central Government.
In respect of processing by the State or any instrumentality of the State, the provisions of sub-section (7) of section 8 and sub-section (3) of section 12 and, where such processing is for a purpose that does not include making of a decision that affects the Data Principal, sub-section (2) of section 12 shall not apply.
The Central Government may, before expiry of five years from the date of commencement of this Act, by notification, declare that any provision of this Act shall not apply to such Data Fiduciary or classes of Data Fiduciaries for such period as may be specified in the notification.
Section 17 lists situations where many of the standard obligations for a Data Fiduciary (a person or entity determining the purpose and means of processing data) and rights of a Data Principal (the individual to whom the data relates) do not apply. These exemptions include processing data to enforce a legal claim, perform judicial or regulatory functions, or investigate and prosecute offences. It also exempts processing related to court-approved corporate mergers, tracking the assets of loan defaulters, and processing the data of individuals outside India under a foreign contract. In these cases, most rules about consent and individual rights are paused, though basic duties like keeping data secure still apply.
The entire Act does not apply in two specific scenarios. First, the Central Government can notify certain State agencies as exempt to protect national security, sovereignty, public order, or friendly relations with foreign states. Second, processing for research, archiving, or statistical purposes is completely exempt, provided the data is not used to make decisions about a specific Data Principal and follows standards that may be prescribed.
The Central Government can exempt certain Data Fiduciaries, including recognized startups, from specific rules like notice requirements and data retention limits, depending on the volume and nature of the data they process. Additionally, the State and its agencies are permanently exempt from rules requiring them to delete data when its purpose is served or upon request. They are also exempt from correcting data if they are not making a decision that affects the Data Principal.
Finally, for the first five years after the Act commences, the Central Government has the power to issue notifications exempting any Data Fiduciary or class of Data Fiduciaries from any provision of the Act for a specified period.
Key points
- Processing for legal claims, judicial functions, investigating offences, corporate mergers, and loan defaults is exempt from most consent and Data Principal rights. [(1)]
- Processing data of individuals outside India under a foreign contract is exempt from most obligations. [(1)(d)]
- The entire Act does not apply to notified State agencies acting for national security or to processing for research and statistics that does not target specific individuals. [(2)]
- The Central Government can exempt certain Data Fiduciaries, including startups, from specific notice and retention rules based on data volume and nature. [(3)]
- The State and its agencies are exempt from obligations to erase personal data. [(4)]
- The Central Government can exempt any Data Fiduciary from any provision of the Act for a specified period, if notified within five years of the Act's commencement. [(5)]
Common misreadings
- Assuming that all processing by startups is automatically exempt from the Act, when they are only exempt from specific provisions if the Central Government explicitly notifies them.
- Believing that research data can be used to make decisions about the individuals involved, whereas the exemption only applies if the data is not used to take any decision specific to a Data Principal.
- Thinking the State must delete personal data once its purpose is served, when the State and its instrumentalities are explicitly exempt from data retention limits and erasure requests.
Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.
/MYND · DPDP practice
Putting this into practice?
MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.