Skip to main content

Sources last verified on 24 August 2026. Methodology

Section 17 of the DPDP Act: what the exemptions actually switch off

Applicability

By Abhijeet Singh · Primary sources verified by dpdprules.orgPublished · Last reviewed 18 min read

The short answer

Section 17(1) disapplies Chapter II, except sections 8(1) and 8(5), Chapter III and section 16 in 6 named situations: enforcing a legal right or claim, judicial and regulatory functions, offence prevention and investigation, offshore contracts for Data Principals outside India, court approved mergers and loan default checks. Section 17(2) removes the whole Act for notified State instrumentalities and for research, archiving or statistical purposes on Second Schedule standards. Section 17(3) and section 17(5) add relief that waits on a Central Government notification, while section 17(4) applies to State processing by force of the text. Section 17 commences on the computed date 13 May 2027, interpretation until officially confirmed.

Search for DPDP exemptions and you will find claims that section 17 lets whole categories of organisation out of the Act. It does not. Section 17 is a narrow instrument built in 5 parts: 1 subsection switches off named chapters in 6 named situations while expressly keeping 2 duties alive, another removes the Act entirely for 2 cases, and the last 3 create relief that either applies only to the State or waits on a Central Government notification that does not exist. This article maps every clause against the Gazette text, states which duties survive which exemption, and marks the 1 clause and 1 subsection now before the Supreme Court.

All of section 17 in 1 table

SubsectionWho or what it reachesWhat stops applyingHow it switches on
17(1)any person, in 6 named situations, clauses (a) to (f)Chapter II except sections 8(1) and 8(5), all of Chapter III, and section 16by force of the text, when the situation is made out
17(2)(a)a notified instrumentality of the State, plus the Central Government's processing of data that instrumentality furnishes to itthe whole ActCentral Government notification, on 5 grounds named in the text
17(2)(b)processing necessary for research, archiving or statistical purposesthe whole Actby force of the text, subject to 2 conditions, now supplied by Rule 16 and the Second Schedule
17(3)Data Fiduciaries or classes that the Central Government notifies, "including startups"section 5, sections 8(3) and 8(7), sections 10 and 11, and nothing elseCentral Government notification, having regard to the volume and nature of personal data processed
17(4)the State or any instrumentality of the Statesection 8(7) and section 12(3) always, section 12(2) conditionallyby force of the text, with no notification
17(5)any Data Fiduciary or class the Central Government declaresany provision of the Act, for the period the notification specifiesnotification, exercisable before expiry of 5 years from commencement

3 things stand out from that shape. Only section 17(2) removes the Act as a whole. Only sections 17(1), 17(2)(b) and 17(4) operate without a notification. And section 17(1), the one most organisations will actually meet, never removes the security duty.

Section 17(1): 6 situations, and what they switch off

The opening words do the work:

Official requirement · verbatim

"The provisions of Chapter II, except sub-sections (1) and (5) of section 8, and those of Chapter III and section 16 shall not apply where—"

Chapter II is Obligations of Data Fiduciary, sections 4 to 10. Chapter III is Rights and Duties of Data Principal, sections 11 to 15. Section 16 is the power to restrict transfers to notified countries. That is the full extent of the disapplication: 3 named targets, with 2 subsections carved back out of the first.

ClauseWho or what is exemptedThe condition in the text
17(1)(a)anyone processing personal data to enforce a legal right or claimthe processing must be "necessary for enforcing any legal right or claim"
17(1)(b)a court, tribunal or other body in India entrusted by law with a judicial, quasi judicial, regulatory or supervisory functionthe processing must be necessary for the performance of that function
17(1)(c)anyone processing in the interest of prevention, detection, investigation or prosecution of any offence or contravention of law in force in Indiathe named interest must be the reason for the processing; this clause is under Supreme Court challenge
17(1)(d)a person based in India processing personal data of Data Principals not within Indiathe processing must be pursuant to a contract entered into with a person outside India
17(1)(e)processing necessary for a scheme of compromise, arrangement, merger or amalgamation of 2 or more companies, or a reconstruction of a company by demerger or otherwise, or a transfer of undertaking or division of companiesthe scheme must be approved by a court, tribunal or other authority competent to do so under a law in force
17(1)(f)anyone ascertaining the financial information, assets and liabilities of a person who has defaulted on a loan or advance from a financial institutionthe processing must accord with the disclosure provisions of other law in force; default and financial institution take their Insolvency and Bankruptcy Code, 2016 meanings

Clause (f) is the only one the Act illustrates, and the illustration is worth reading because it shows how narrow a section 17(1) exemption is in practice:

Official requirement · verbatim

"X, an individual, takes a loan from Y, a bank. X defaults in paying her monthly loan repayment instalment on the date on which it falls due. Y may process the personal data of X for ascertaining her financial information and assets and liabilities."

The bank does not become exempt. 1 activity, on 1 customer, for 1 purpose, steps outside Chapter II and Chapter III. Everything else the bank does with personal data continues under the full framework.

What survives a section 17(1) exemption

This is the part most summaries get wrong. Section 17(1) does not disapply the Act. It disapplies 2 chapters and 1 section, and it expressly preserves 2 subsections inside the chapter it targets.

DutyWhere it livesUnder a section 17(1) exemption
Responsibility for compliance irrespective of any agreement to the contrarysection 8(1)stands
Reasonable security safeguards to prevent personal data breachsection 8(5)stands
Definitions and the application of the Actsections 2 and 3, Chapter Istands
Section 17 itselfChapter IVstands
Data Protection Board, inquiry, penalties, appealsChapters V to IXstands
Lawful grounds for processingsection 4falls away
Notice before consentsection 5falls away
Consent and its withdrawalsection 6falls away
Certain legitimate usessection 7falls away
Data Processor contractsection 8(2)falls away
Completeness, accuracy and consistencysection 8(3)falls away
Technical and organisational measures for observancesection 8(4)falls away
Breach intimation to the Board and to affected Data Principalssection 8(6)falls away
Erasure on withdrawal or purpose servedsections 8(7) and 8(8)falls away
Published contact for questionssection 8(9)falls away
Grievance redressal mechanismsection 8(10)falls away
Children's duties: parental consent, no detrimental processing, no tracking or targeted advertisingsection 9falls away
Significant Data Fiduciary duties: DPO, independent auditor, DPIAsection 10falls away
Data Principal rights: access, correction, erasure, grievance redressal, nominationsections 11 to 14, Chapter IIIfalls away
Duties of a Data Principalsection 15, Chapter IIIfalls away
Restriction on transfer to a notified country or territorysection 16falls away

Read the 2 survivors together and a clear rule emerges: an exemption under section 17(1) never becomes an exemption from securing the data. Section 8(5) stands and section 8(6) does not, which is the single most consequential asymmetry in section 17 and easy to miss because the 2 duties usually travel together. That much is the printed text. What follows for the Rules is this site's interpretation, because section 17(1) disapplies provisions of the Act and says nothing about the Rules. Rule 6 states the security minimum, encryption, access control and logs among it, in the same terms as section 8(5), and on this site's reading it continues to apply to exempt processing, whether because the surviving duty carries it or because section 17(1) never reached the Rules at all. Rule 7 answers clause (f) of section 40(2), a power expressly tied to the form and manner of intimation of a breach under section 8(6), so on this site's reading it has nothing left to attach to once section 8(6) is disapplied for that processing. Neither of those 2 readings is settled by the text, and both are marked interpretation in the sources below.

1 practical warning before leaving the point: section 38(1) says the provisions of the Act are in addition to and not in derogation of any other law in force, so an exemption under section 17 does nothing to a reporting duty that lives outside the DPDP framework. The CERT-In directions of 28 April 2022 under section 70B(6) of the Information Technology Act, 2000 require covered organisations to report the incidents listed in their Annexure I, which include data breach and data leak, within 6 hours. Section 17 does not touch them.

Section 8(1) surviving matters for a different reason. It is the anti contracting out provision: you remain responsible for compliance in respect of processing undertaken by you or on your behalf by a Data Processor, whatever your agreements say. An exemption you hold does not transfer responsibility down the chain, and the parts of your processing outside the exempt situation stay yours.

1 consequence deserves flagging because it runs against a common assumption. Section 9, the children's provision, sits in Chapter II. A section 17(1) situation can therefore disapply parental consent, the tracking and targeted advertising ban, and even the prohibition on processing likely to cause a detrimental effect on a child's wellbeing. That is wider than the child specific route in Rule 12 and the Fourth Schedule, which lifts only sections 9(1) and 9(3) and never reaches section 9(2). The children's data guide sets out that separate regime.

Section 17(2): the 2 exemptions from the whole Act

Section 17(2) opens differently, and the difference is the point: "The provisions of this Act shall not apply in respect of the processing of personal data—". Not a chapter, the Act.

Clause (a), notified instrumentalities of the State. The exemption covers processing "by such instrumentality of the State as the Central Government may notify, in the interests of sovereignty and integrity of India, security of the State, friendly relations with foreign States, maintenance of public order or preventing incitement to any cognizable offence relating to any of these, and the processing by the Central Government of any personal data that such instrumentality may furnish to it". 3 features of that wording carry weight. It works only by notification, so no body exempts itself. The 5 grounds are named in the text and are the grounds on which the notification must rest. And the exemption extends downstream: the Central Government's own processing of personal data furnished to it by an exempt instrumentality is covered too. The Act defines State by reference to article 12 of the Constitution, in section 2(zb), but the narrower expression instrumentality of the State is defined nowhere in the Act or in the Rules, on a check of both definition provisions, section 2 of the Act and Rule 2 of the Rules, verified on 24 August 2026.

Clause (b), research, archiving and statistical purposes. This one needs no notification. It applies to processing "necessary for research, archiving or statistical purposes if the personal data is not to be used to take any decision specific to a Data Principal and such processing is carried on in accordance with such standards as may be prescribed". 2 conditions, both mandatory: no decision specific to a Data Principal, and compliance with prescribed standards. Until the standards existed the clause was unusable. They now exist in print, though like section 17 itself they are not yet in force.

Rule 16 and the Second Schedule: the research standards

Rule 16 of the DPDP Rules 2025 is 1 sentence:

Official requirement · verbatim

"The provisions of the Act shall not apply to the processing of personal data necessary for research, archiving or statistical purposes if it is carried on in accordance with the standards specified in Second Schedule."

The Second Schedule, which the same Rules print under the reference "[See rules 5(1) and 16]", carries 8 standards. It is a shared Schedule: it also supplies the standards for State processing under clause (b) of section 7, and 1 of its items is written to apply only to that other track.

ItemThe standardAttaches to research, archiving or statistical processing?
(a)processing carried out in a lawful manneryes
(b)processing done for the purposes specified in section 17(2)(b), or the section 7(b) uses, as the case may beyes
(c)processing limited to the personal data necessary for those purposesyes
(d)reasonable efforts to ensure completeness, accuracy and consistencyyes
(e)retention only till required for those purposes or for compliance with lawyes
(f)reasonable security safeguards to prevent personal data breach, including for processing by a Data Processoryes
(g)intimation to the Data Principal, business contact information and a link for exercising rightsno: item (g) is expressed to apply only "Where processing is to be done under clause (b) of section 7 of the Act"
(h)accountability of the person who determines the purpose and means of processingyes

So the research exemption is not a licence. It replaces the Act with a compressed version of it: lawfulness, purpose limitation, data minimisation, accuracy efforts, retention limits, security safeguards and accountability, all of it self administered because the Act's enforcement machinery no longer applies to that processing.

2 cautions on this route. First, Rule 16 restates the exemption without repeating the Act's condition that the personal data is not to be used to take any decision specific to a Data Principal. That condition sits in section 17(2)(b), and the rulemaking power the clause engages is a power to prescribe standards, not to widen the exemption, so on this site's reading the condition continues to apply in full. It is a reading, not text. Second, corrigenda G.S.R. 892(E) corrected 5 pages of the Rules gazette but touched neither Rule 16 nor the Second Schedule, so the text above is the text as published.

Section 17(3): what it actually says about startups

Startups appear exactly once in section 17, and not as a class that is exempt. The subsection reads:

Official requirement · verbatim

"The Central Government may, having regard to the volume and nature of personal data processed, notify certain Data Fiduciaries or class of Data Fiduciaries, including startups, as Data Fiduciaries to whom the provisions of section 5, sub-sections (3) and (7) of section 8 and sections 10 and 11 shall not apply."

3 precise limits, all in that sentence:

  1. It is a power, not an exemption. Nothing happens until the Central Government notifies. No notification under section 17(3) exists, and as of 24 August 2026 none could: section 17 is not yet in force.
  2. The relief is a fixed list of 5 provisions. Notice under section 5, accuracy and completeness under section 8(3), erasure and retention under section 8(7), Significant Data Fiduciary duties under section 10, and the right to access information under section 11. Consent, security safeguards, breach intimation, grievance redressal, children's duties, correction and erasure rights and cross border restrictions are all outside the list and would continue to apply to a notified startup.
  3. The test is the data, not the company. The power is exercised "having regard to the volume and nature of personal data processed". Being small is not the criterion in the text.

The Explanation defines a startup as a private limited company, partnership firm or limited liability partnership incorporated in India that is eligible to be and is recognised as such under the criteria and process notified by the department to which matters relating to startups are allocated in the Central Government. So recognition is external, and even a recognised startup gets nothing from section 17(3) until it is named or its class is notified. Does the DPDP Act apply to startups works the same question from the applicability end.

Section 17(4): the State's automatic relief, and how narrow it is

Section 17(4) is the only exemption in section 17 that operates with neither a notification nor a situational trigger. It simply applies:

Official requirement · verbatim

"In respect of processing by the State or any instrumentality of the State, the provisions of sub-section (7) of section 8 and sub-section (3) of section 12 and, where such processing is for a purpose that does not include making of a decision that affects the Data Principal, sub-section (2) of section 12 shall not apply."

Unpacked: for State processing, the erasure duties in section 8(7) and section 12(3) never apply, and the correction, completion and updating duty in section 12(2) does not apply where the purpose does not include making a decision that affects the Data Principal. Where the purpose does include such a decision, section 12(2) applies to the State like anyone else.

Note what is absent. Section 12(1), the Data Principal's right itself, is not named; only the Data Fiduciary's response duties in 12(2) and 12(3) are. And notice, consent and legitimate use grounds, security safeguards, breach intimation, access, grievance redressal and nomination all continue to apply to State processing unless a section 17(2)(a) notification covers it. Section 17(4) is a retention and correction provision, not a general exemption for government.

Section 17(5): a power with a 5 year window

The last subsection is the widest and the shortest lived:

Official requirement · verbatim

"The Central Government may, before expiry of five years from the date of commencement of this Act, by notification, declare that any provision of this Act shall not apply to such Data Fiduciary or classes of Data Fiduciaries for such period as may be specified in the notification."

The mechanism has 4 moving parts. The instrument is a notification. Its reach is any provision of the Act, with no fixed list. Its beneficiaries are a Data Fiduciary or classes of Data Fiduciaries. And the exemption lasts for the period the notification specifies, which the subsection does not cap.

The time limit bites on the power, not on the exemption: the declaration must be made before expiry of 5 years from the date of commencement of the Act. When does that window close? Section 1(2) answers it, and the answer matters because the Act commenced in groups: "any reference in any such provision to the commencement of this Act shall be construed as a reference to the coming into force of that provision". Read with section 1(2), the 5 years run from the day section 17 itself comes into force. No official document states when that window closes. Adding 5 years to the computed commencement date of 13 May 2027 gives 13 May 2032, a computation built on another computation that itself turns on the publication date printed on the Gazette, so both steps are interpretation rather than official text. On the competing reading, that the phrase points at the first appointed date of 13 November 2025, the window would close in November 2030. Treat neither date as a deadline until the Government states one. Either way the power is transitional by design, and no notification under it exists.

What section 17 does not exempt

Stated only as far as the text supports:

  • Nothing, as things stand. Section 17 sits in the 18 month commencement group under paragraph (c) of notification G.S.R. 843(E), which names "sections 11 to 17". It is not in the group that commenced on publication. It comes into force on the computed date of 13 May 2027, interpretation until officially confirmed. Rule 1(4) puts Rule 16 in the same 18 month group, so it arrives on the same computed date; Rule 1 assigns commencement to rules rather than to Schedules, so the Second Schedule is presented as commencing with the rules it serves.
  • No organisation, only processing. Every exemption in section 17 attaches to processing, a situation or a notification. None attaches to an entity as such. Even a notified instrumentality under section 17(2)(a) is exempt in respect of the processing the notification covers.
  • Not the security duty, under section 17(1). Sections 8(1) and 8(5) are carved back out of the exemption by name.
  • Not the Board or the penalties, under section 17(1). Chapters V to IX are untouched, so the Data Protection Board keeps jurisdiction over the duties that survive. Under a section 17(2) exemption there is nothing left to enforce for that processing, which is precisely why that route is drawn so narrowly.
  • No size, revenue or sector threshold anywhere. Section 17 contains none. The only route that could ever turn on company type is section 17(3), and only if the Central Government notifies.
  • Not by self declaration. Sections 17(2)(a), 17(3) and 17(5) all require a Central Government notification. No such notification exists as of 24 August 2026.

1 drafting point in the interest of honesty: clauses (a) to (f) of section 17(1) are printed with a semicolon and the word and before the last clause. This article reads each clause as a self standing situation, because a cumulative reading would require all 6 to be satisfied at once and leave the subsection with no practical operation. That reading is interpretation.

The Supreme Court challenge to sections 17(1)(c) and 17(2)

2 parts of section 17 are before the Supreme Court. Per the petition synopsis hosted by the Supreme Court Observer, the writ petitions led by Venkatesh Nayak v Union of India, W.P.(C) 177/2026, ask the court to declare sections 17(1)(c) and 17(2) of the DPDP Act, along with sections 33(1), 36 and 44(3) and Rules 17 and 23(2), unconstitutional on grounds under Articles 14, 19(1)(a) and 21. The petition numbers and the pendency of the stay applications come from the court's own cause list of 23 March 2026.

No stay was granted. LiveLaw reported that at the first hearing on 16 February 2026 the bench led by Chief Justice Surya Kant issued notice and refused an interim stay, the Chief Justice saying there was no question of stay. As of 24 August 2026 no provision has been struck down or suspended, so sections 17(1)(c) and 17(2) stand exactly as notified and commence with the rest of section 17. Litigation facts in this paragraph are secondary reporting, labelled explanation; the challenge tracker carries the full hearing log and the position on every challenged provision.

What to do with this

Offered as this site's recommendation, not as law. Build your programme on the assumption that no section 17 exemption applies to you, because sections 17(3) and 17(5) and clause (a) of section 17(2) need a notification that does not exist, section 17(4) reaches only the State, and what is left, section 17(1) and the research route in section 17(2)(b), attaches to situations and standards rather than to organisations. Then, where you do rely on section 17(1), record it the way the text is written: which clause, which processing activity, which purpose, and the date the situation began and ended. An exemption that cannot be tied to a clause and an activity is not an exemption you can show anyone.

Settle applicability first with the applicability check, then build the obligation set with the company compliance plan. The official texts live at section 17, Rule 16 and the Second Schedule, each with its Gazette citation.

Section 17, official textRule 16, official textThe Second Schedule, official textSupreme Court challenge to the DPDP Act: what stands todayChildren's data under the DPDP ActDoes the DPDP Act apply to startups?

section 17exemptionsresearch exemptionrule 16state instrumentality

Share this: