Key point
Clause-by-clause commentary on the exemption architecture of Section 17, the clause-specific derogations in Section 17(1), State and research exemptions, notified exemptions and the constitutional limits on delegated exemption powers
CHAPTER IV - SPECIAL PROVISIONS
Section 17 - Exemptions
Official text
(1)The provisions of Chapter II, except sub-sections (1) and (5) of section 8, and those of Chapter III and section 16 shall not apply where—
(a)the processing of personal data is necessary for enforcing any legal right or claim;
(b)the processing of personal data by any court or tribunal or any other body in India which is entrusted by law with the performance of any judicial or quasi-judicial or regulatory or supervisory function, where such processing is necessary for the performance of such function;
(c)personal data is processed in the interest of prevention, detection, investigation or prosecution of any offence or contravention of any law for the time being in force in India;
(d)personal data of Data Principals not within the territory of India is processed pursuant to any contract entered into with any person outside the territory of India by any person based in India;
(e)the processing is necessary for a scheme of compromise or arrangement or merger or amalgamation of two or more companies or a reconstruction by way of demerger or otherwise of a company, or transfer of undertaking of one or more company to another company, or involving division of one or more companies, approved by a court or tribunal or other authority competent to do so by any law for the time being in force; and
(f)the processing is for the purpose of ascertaining the financial information and assets and liabilities of any person who has defaulted in payment due on account of a loan or advance taken from a financial institution, subject to such processing being in accordance with the provisions regarding disclosure of information or data in any other law for the time being in force.
Explanation.—For the purposes of this clause, the expressions “default” and “financial institution” shall have the meanings respectively assigned to them in sub-sections (12) and (14) of section 3 of the Insolvency and Bankruptcy Code, 2016.
Illustration.X, an individual, takes a loan from Y, a bank. X defaults in paying her monthly loan repayment instalment on the date on which it falls due. Y may process the personal data of X for ascertaining her financial information and assets and liabilities.
(2)The provisions of this Act shall not apply in respect of the processing of personal data—
(a)by such instrumentality of the State as the Central Government may notify, in the interests of sovereignty and integrity of India, security of the State, friendly relations with foreign States, maintenance of public order or preventing incitement to any cognizable offence relating to any of these, and the processing by the Central Government of any personal data that such instrumentality may furnish to it; and
(b)necessary for research, archiving or statistical purposes if the personal data is not to be used to take any decision specific to a Data Principal and such processing is carried on in accordance with such standards as may be prescribed.
(3)The Central Government may, having regard to the volume and nature of personal data processed, notify certain Data Fiduciaries or class of Data Fiduciaries, including startups, as Data Fiduciaries to whom the provisions of section 5, sub-sections (3) and (7) of section 8 and sections 10 and 11 shall not apply.
Explanation.—For the purposes of this sub-section, the term “startup” means a private limited company or a partnership firm or a limited liability partnership incorporated in India, which is eligible to be and is recognised as such in accordance with the criteria and process notified by the department to which matters relating to startups are allocated in the Central Government.
(4)In respect of processing by the State or any instrumentality of the State, the provisions of sub-section (7) of section 8 and sub-section (3) of section 12 and, where such processing is for a purpose that does not include making of a decision that affects the Data Principal, sub-section (2) of section 12 shall not apply.
(5)The Central Government may, before expiry of five years from the date of commencement of this Act, by notification, declare that any provision of this Act shall not apply to such Data Fiduciary or classes of Data Fiduciaries for such period as may be specified in the notification.
Cross-references
Section 17
Commentary
1. What is the function of Section 17 within the architecture of the DPDP Act?
Section 17 is placed in Chapter IV, Special Provisions, immediately after Section 16, which concerns the processing of personal data outside India. Its location is significant. The substantive framework of the Digital Personal Data Protection Act, 2023 (“DPDP Act” or “Act”) proceeds on the premise that a Data Fiduciary must process personal data only for a lawful purpose, generally founded upon consent or a statutorily recognised legitimate use, and must thereafter comply with a series of obligations concerning notice, security, retention, children's data, accountability and the rights of Data Principals. Section 17 identifies circumstances in which that framework, in whole or in part, will not operate.
The provision should therefore not be approached by asking the deceptively simple question:
“Is this organisation exempt from the DPDP Act?”
The legally relevant question is considerably narrower:
“Is this particular processing activity covered by one of the exemptions in Section 17, and, if so, precisely which provisions of the Act cease to apply?”
That distinction is fundamental because Section 17 contains several different kinds of exemptions. Section 17(1), for instance, does not remove the Act in its entirety. It disapplies Chapter II, subject to the express preservation of Sections 8(1) and 8(5), together with Chapter III and Section 16, when processing falls within one of six specified circumstances. Section 17(2), by contrast, provides that the Act shall not apply to two specified categories of processing, subject to the conditions prescribed in the provision. Sections 17(3) and 17(5) confer notification-based exemption powers upon the Central Government, while Section 17(4) provides a narrower, statutory exemption for certain State processing.
The provision is consequently better understood as a derogation architecture rather than a blanket exemption clause.
That architecture is necessary. A data protection statute cannot reasonably require a court to obtain consent before processing evidence, prevent an investigating authority from processing information necessary for an investigation, or require a company to erase information necessary for a court-approved merger. At the same time, however, the more extensive the exemption, the greater the risk that the exemption itself may become the mechanism through which the protection promised by the statute is displaced.
That tension lies at the heart of Section 17.
2. When does Section 17 become operative?
The temporal question is particularly important because Section 17 forms part of the third commencement phase.
The commencement framework divides the operation of the DPDP Act into three principal stages. Section 17 does not become enforceable merely because the Act received Presidential assent or because the Rules have been notified. Its enforceability depends upon the specific commencement notification issued under Section 1(2).
The commencement notification provides that the provisions comprising Section 17 come into force eighteen months after the date of publication of the notification.
Accordingly, where the notification was published on 13 November 2025, Section 17 becomes operative on:
13 May 2027.
This is important because the existence of an enacted exemption and the commencement of that exemption are two different legal propositions.
Until the relevant commencement date, one cannot treat Section 17 as an operative statutory basis for excluding processing from the Act.
Once it commences, however, the analysis becomes activity-specific: the Data Fiduciary must determine whether the processing satisfies the conditions of the relevant clause and which provisions are thereby disapplied.
3. Why does Section 17(1) preserve Sections 8(1) and 8(5)?
Section 17(1) contains one of its most important drafting choices in the opening words:
“The provisions of Chapter II, except sub-sections (1) and (5) of section 8…”
The exception is deliberate.
Section 8(1) makes the Data Fiduciary responsible for compliance with the Act and Rules in respect of processing undertaken by it or on its behalf by a Data Processor, irrespective of an agreement to the contrary or failure of the Data Principal to perform her duties.
Section 8(5), meanwhile, requires the Data Fiduciary to protect personal data by taking reasonable security safeguards to prevent personal data breach.
Therefore, where Section 17(1) applies, the Data Fiduciary does not emerge from the provision with a complete regulatory immunity.
The distinction may be illustrated as follows.
Illustration
Suppose a Data Fiduciary processes personal data for the purpose of enforcing a legal claim under Section 17(1)(a). Chapter III rights may be displaced and the ordinary Chapter II obligations may largely cease to apply. But Section 8(1) continues to attach responsibility to the Data Fiduciary, and Section 8(5) continues to require reasonable security safeguards.
The architecture is therefore:
Exemption from specified substantive obligations ≠ exemption from accountability and security.
This is an important limitation upon Section 17(1), and it should not be overlooked when the provision is described simply as an “exemption”.
It also produces an important contrast with Section 17(2). Section 17(2) says that the provisions of the Act shall not apply to the specified processing. Unlike Section 17(1), it does not expressly preserve Sections 8(1) and 8(5). For research processing, however, safeguards are reintroduced through the prescribed standards.
This difference in drafting becomes significant when assessing the precise legal consequences of each exemption.
4. Section 17(1)(a): How far should the legal-claim exemption extend?
Section 17(1)(a) applies where:
“the processing of personal data is necessary for enforcing any legal right or claim”.
The first critical expression is “necessary”.
The provision does not exempt processing merely because it is useful, convenient, or connected with a legal claim.
There must be a relationship between the processing and enforcement of the right or claim.
Consider a company involved in commercial litigation. It may need to process:
- correspondence with the opposing party;
- employee information contained in relevant records;
- customer information;
- invoices;
- contractual documents;
- communications;
- transaction histories; and
- other evidence.
Where such processing is genuinely necessary for enforcing a legal claim, Section 17(1)(a) provides a rational basis for disapplying the ordinary rights and obligations that could otherwise obstruct the litigation process.
But the critical issue is scope.
A legal dispute should not become a convenient justification for processing every item of personal data held by an organisation.
The exemption should therefore be construed activity-by-activity and purpose-by-purpose, rather than entity-by-entity.
A company is not “exempt because it is litigating”. Only the processing necessary for enforcing the relevant legal right or claim falls within the language of the clause.
This is particularly important because Chapter III contains rights of the Data Principal. A litigant could otherwise seek erasure or other rights concerning information that constitutes evidence necessary for the litigation. Section 17 recognises that such rights may have to yield to the administration of justice.
The difficulty, however, is that the Act provides no detailed test for determining how much processing is “necessary”. That interpretive burden will ultimately fall upon Data Fiduciaries, the Board and courts.
5. Section 17(1)(b): Why are judicial and regulatory functions treated differently?
Clause (b) extends the exemption to processing by:
- a court;
- a tribunal; or
- another body in India entrusted by law with judicial, quasi-judicial, regulatory or supervisory functions,
where the processing is necessary for the performance of that function.
The justification is straightforward.
A court cannot adjudicate a dispute without processing personal data. A regulator cannot investigate regulatory compliance without processing information relating to individuals. A tribunal cannot determine rights and liabilities without receiving evidence that may contain personal information.
The ordinary data-protection regime therefore cannot be mechanically applied to adjudicatory functions.
But the wording contains two safeguards.
First, the body must be “entrusted by law” with the relevant function.
Secondly, the processing must be “necessary for the performance of such function.”
These requirements prevent every government office from claiming regulatory exemption merely because it performs some public task.
The clause consequently reflects a functional principle:
The exemption follows the function being performed, not merely the identity of the institution performing it.
That is a sound legislative approach.
The problem is that Section 17 does not explain what happens at the boundaries.
For example, a regulator may perform both statutory regulatory functions and unrelated administrative or commercial activities. The exemption should logically attach only to the processing connected with the statutory function. Otherwise, institutional status could become a substitute for functional necessity.
6. Section 17(1)(c): The most consequential exemption for criminal investigations
Clause (c) provides an exemption where personal data is processed:
“in the interest of prevention, detection, investigation or prosecution of any offence or contravention of any law for the time being in force in India”.
This is arguably the most consequential of the Section 17(1) exemptions.
The justification is compelling. Criminal investigation frequently requires the processing of information without the knowledge or cooperation of the person concerned. If an investigating authority were required to provide notice, obtain consent, facilitate immediate erasure, or otherwise comply with ordinary Data Principal rights, the statutory privacy regime could frustrate the investigation it is supposed to regulate.
Yet the drafting here is materially broader than clauses (a), (b) and (e).
Those clauses expressly use the word “necessary”.
Clause (c) does not.
Instead, it uses:
“in the interest of”
That is a significantly less constrained formulation.
The processing need not expressly be described as “necessary” for the investigation. The statutory language asks whether it is processed in the interest of prevention, detection, investigation or prosecution.
This creates an important interpretive problem.
Illustration
Suppose an enforcement authority possesses a very large dataset. Only a small portion is relevant to a particular investigation. Is processing the entire dataset permissible because doing so might facilitate detection of offences?
A rights-protective interpretation should reject such an approach. Otherwise, the phrase “in the interest of” could convert a targeted law-enforcement exception into a general authorisation for broad data collection.
The provision would have been considerably stronger if Parliament had expressly incorporated a necessity and proportionality limitation.
This is not merely an academic concern. Section 17(1)(c) raises an important constitutional question concerning the relationship between privacy and legitimate law-enforcement objectives.
The question is therefore not whether crime prevention is a legitimate State objective. It plainly is.
The harder question is:
How much privacy protection may be displaced, by what process, and subject to what safeguards, merely because processing is said to be in the interest of crime prevention or investigation?
7. Section 17(1)(d): Why does the Act withdraw protection from certain foreign Data Principals?
Clause (d) applies where personal data of Data Principals not within the territory of India is processed pursuant to a contract entered into with a person outside India by a person based in India.
The provision is commercially significant for Indian businesses performing services for foreign clients.
Consider an Indian technology company processing the personal data of customers of a foreign enterprise under a services agreement.
If the statutory conditions are satisfied, the processing falls within Section 17(1)(d), and the provisions identified in Section 17(1) cease to apply.
The policy justification is obvious: the Indian legislature does not necessarily seek to impose its entire domestic data-rights architecture upon foreign individuals whose relationship is primarily with an overseas entity.
Yet the provision raises a difficult territorial question.
The test depends upon where the Data Principal is situated.
A person may be outside India when data is collected and subsequently enter India. Does the exemption disappear immediately?
Conversely, if a person is in India temporarily while the processing occurs, does that mean the exemption is unavailable?
The Act does not provide a detailed territorial rule for such situations.
This can become particularly difficult in global digital services where location is fluid rather than permanent.
There is also a broader policy question. If India seeks to become a major destination for global data processing and digital services, removing Indian statutory protections from foreign individuals may facilitate business. But it may also create difficulties in demonstrating that India's data-protection framework provides sufficiently robust protections in cross-border contractual ecosystems.
The exemption therefore reflects a deliberate business-facilitation choice, but one that requires careful territorial interpretation.
8. Section 17(1)(e): The M&A exemption and its temporal problem
Clause (e) applies where processing is necessary for specified corporate restructuring transactions, including:
- compromise or arrangement;
- merger;
- amalgamation;
- reconstruction;
- demerger;
- transfer of undertaking; and
- division of companies,
provided the relevant scheme is approved by the competent court, tribunal or authority.
The rationale is strong.
M&A transactions necessarily require due diligence. The buyer may need access to employee, customer, contractual, litigation and financial information. Requiring every disclosure within a transaction to comply with the entire data-rights architecture could materially interfere with corporate restructuring.
The difficulty lies in the requirement that the scheme be approved.
A substantial amount of data processing often occurs before approval:
initial due diligence → data room → valuation → negotiations → transaction documents → regulatory filing → court/tribunal approval → closing → integration.
Section 17(1)(e) expressly connects the exemption to a scheme that has been approved. This creates uncertainty regarding the pre-approval stage.
A narrow reading would mean that the exemption cannot automatically be invoked for all pre-approval due diligence.
That creates a practical compliance problem because the period during which the greatest volume of personal information may be exchanged is precisely the period before formal approval.
The provision could therefore have been more precisely drafted by expressly addressing the entire transaction lifecycle while limiting the exemption to processing genuinely necessary for the transaction.
9. Section 17(1)(f): Why does loan-default processing receive special treatment?
Clause (f) concerns processing for ascertaining the financial information and assets and liabilities of a person who has defaulted on a loan or advance from a financial institution.
The provision is supported by a clear economic rationale.
A financial institution attempting to recover a defaulted loan may need to identify:
- the borrower's financial position;
- assets;
- liabilities;
- sources of income; and
- other information relevant to recovery.
Without such processing, the creditor's ability to enforce the debt could be substantially impaired.
The clause, however, contains an important external-law limitation:
processing must be in accordance with provisions regarding disclosure of information or data under any other law for the time being in force.
Thus, Section 17(1)(f) does not override other legal restrictions on disclosure.
This is particularly important in regulated financial sectors, where banking, insolvency, credit reporting and confidentiality obligations may operate simultaneously.
The provision also incorporates the definitions of “default” and “financial institution” from the Insolvency and Bankruptcy Code, 2016.
The statutory illustration confirms the intended operation: where an individual defaults on a bank loan, the bank may process her personal data to ascertain her financial information and assets and liabilities.
The critical question will be whether institutions attempt to extend the exemption from genuine default assessment to broader customer profiling or debt-management activities. The wording should be confined to the specified purpose.
10. The central structural distinction: Section 17(1) is not a blanket exemption
The six clauses under Section 17(1) have one common feature: the exemption is connected to particular processing.
The following matrix captures the distinction:
| Clause | Processing context | Principal justification | Critical limiting factor |
|---|---|---|---|
| 17(1)(a) | Legal right/claim | Legal enforcement | Necessary for enforcement |
| 17(1)(b) | Court/tribunal/regulatory function | Administration/regulation | Necessary for function |
| 17(1)(c) | Crime/contravention | Law enforcement | “In the interest of”, comparatively broader |
| 17(1)(d) | Foreign Data Principals | Cross-border contractual processing | Territorial + contractual conditions |
| 17(1)(e) | M&A/restructuring | Transactional necessity | Approved scheme requirement |
| 17(1)(f) | Loan default | Debt recovery | Other-law disclosure requirements |
The practical implication is that a Data Fiduciary cannot place an organisation into an exempt category and stop there.
The exemption must be mapped to:
data → processing activity → purpose → statutory clause → provisions disapplied.
That is the proper compliance analysis.
11. Section 17(2)(a): Where does the State exemption become constitutionally difficult?
The most controversial portion of Section 17 is arguably Section 17(2)(a).
It provides that the Act shall not apply to processing by such instrumentality of the State as the Central Government may notify, where the processing is undertaken in the interests of:
- sovereignty and integrity of India;
- security of the State;
- friendly relations with foreign States;
- maintenance of public order; or
- preventing incitement to any cognizable offence relating to those matters.
It additionally covers processing by the Central Government of personal data furnished by such instrumentality.
There is an obvious and legitimate reason for a State-security exemption.
A government cannot reasonably be required to obtain an individual's consent before processing intelligence information relevant to national security. Nor can an individual demand erasure of intelligence data simply because the ordinary data-protection regime would otherwise confer such a right.
The problem is not therefore the existence of a national-security exemption.
The problem is the breadth and architecture of the exemption.
12. What is missing from Section 17(2)(a)?
The provision does not expressly require that the exempted processing be:
- necessary;
- proportionate;
- limited to a specific category of data;
- limited to a defined period;
- subject to periodic review;
- approved by a court;
- independently audited; or
- accompanied by a statutory reporting mechanism.
Nor does the provision itself require the notification to contain detailed reasons explaining why each particular obligation under the Act must be displaced.
This creates a sharp contrast with the constitutional privacy framework.
The Supreme Court has recognised privacy as a fundamental right and developed a structured approach requiring legality, a legitimate State aim and proportionality where State action infringes privacy.
The constitutional question is therefore not whether national security constitutes a legitimate State objective. It does.
The harder question is:
How far may the legislature permit the executive to displace statutory privacy protections in pursuit of that objective?
This is particularly significant because the State is not an ordinary Data Fiduciary.
The government can possess:
- identity databases;
- welfare information;
- tax information;
- health information;
- education records;
- location information;
- law-enforcement data;
- financial information; and
- information generated by multiple public authorities.
An exemption from the principal privacy framework therefore has consequences affecting a potentially enormous population.
The concern becomes particularly acute if the exemption is interpreted as institution-wide rather than processing-specific.
13. Section 17(2)(a) and the constitutional proportionality problem
The constitutional analysis should not be reduced to saying:
“Section 17(2)(a) is unconstitutional because it permits exemptions.”
That proposition is too broad.
The State undoubtedly possesses legitimate interests capable of justifying restrictions upon privacy.
The real constitutional inquiry is whether the means adopted are appropriately calibrated.
The proportionality framework asks whether there is:
- legality;
- a legitimate State aim;
- a rational relationship between the measure and objective;
- necessity in the sense that a less restrictive but equally effective measure is unavailable; and
- an appropriate balance between the competing interests.
Section 17(2)(a) expressly identifies legitimate State interests, but it does not itself articulate the entire proportionality discipline that should govern the resulting intrusion into informational privacy.
This creates a potential structural weakness.
Why should an agency be removed from the entire Act rather than only from the particular obligations that conflict with its security function?
Why should an exemption necessarily continue without a statutory duration or periodic review requirement?
Why should the executive alone determine the breadth of the exemption?
These are questions of institutional calibration, not questions about whether national security matters.
The constitutional vulnerability therefore lies principally in the possibility that a legitimate objective is being pursued through a measure that is broader than necessary.
14. Section 17(2)(b): Is the research exemption necessary?
The second limb of Section 17(2) concerns processing necessary for:
- research;
- archiving; or
- statistical purposes,
provided that the personal data is not used to take a decision specific to a Data Principal and the processing follows prescribed standards.
The exemption is defensible.
Research often requires historical datasets, longitudinal information and large-scale statistical analysis. Requiring fresh consent for every secondary research use could make important scientific and social research difficult.
The problem is not the principle.
The problem is scope.
The Act does not define “research”, “archiving” or “statistical purposes” in Section 2.
That creates uncertainty over the boundaries of the exemption.
For example:
- Does commercial market research qualify?
- Does pharmaceutical research qualify?
- Does academic research qualify?
- Does AI model training qualify?
- Does product-development experimentation qualify?
- When does analytics become “statistical” processing?
- When does a historical database become an “archive”?
These questions matter because an exemption from the entire Act is materially different from a narrowly tailored research derogation.
The answer cannot be that every processing activity labelled “research” automatically qualifies.
The purpose and actual use of the information must remain relevant.
15. Can Rule 16 expand the Section 17(2)(b) exemption?
Rule 16 provides standards for processing undertaken for research, archiving or statistical purposes under Section 17(2)(b).
The Rules introduce a standards-based framework including requirements concerning matters such as:
- lawful processing;
- purpose limitation;
- processing limited to necessary personal data;
- reasonable efforts concerning completeness, accuracy and consistency;
- retention only for the relevant purpose or legal compliance;
- security safeguards; and
- accountability.
These requirements are important because they demonstrate that the research exemption was not intended to create a completely uncontrolled processing environment.
There is, however, an important drafting difference.
Section 17(2)(b) expressly states that the exemption applies where the personal data is not to be used to take any decision specific to a Data Principal.
The Rules must therefore be interpreted consistently with that statutory condition.
If a rule were interpreted as allowing processing that Parliament expressly excluded from the exemption, the rule would exceed the scope of delegated legislation.
The correct hierarchy is:
Act → Rule → Schedule.
The Rules operationalise the Act; they cannot amend its substantive limits.
Accordingly, Rule 16 should not be interpreted as silently removing the statutory condition relating to decisions specific to a Data Principal.
16. Section 17(3): Does the Act automatically exempt startups?
No.
This is an important point.
Section 17(3) provides that the Central Government may, having regard to the volume and nature of personal data processed, notify certain Data Fiduciaries or classes of Data Fiduciaries,including startups, to whom specified provisions shall not apply.
A startup is therefore not automatically exempt merely because it satisfies the statutory description of a startup.
Section 17(3) is an enabling power, not a self-executing exemption.
The provisions capable of being excluded are:
- Section 5;
- Section 8(3);
- Section 8(7);
- Section 10; and
- Section 11.
The relief is therefore narrower than the phrase “startup exemption” might suggest.
Notably, Section 17(3) does not automatically remove:
- Section 6 consent requirements;
- Section 8(5) security;
- Section 8(6) breach notification;
- Section 9 children's data protections;
- Section 12 correction and erasure rights;
- Section 13 grievance redressal; or
- the penalty framework.
This demonstrates that Parliament did not intend to create a general “small business exemption”.
It created the possibility of targeted regulatory relief.
17. Is “volume and nature” a sufficient standard for startup exemptions?
There is nevertheless a significant policy concern.
Section 17(3) directs the Government to have regard to:
“the volume and nature of personal data processed.”
But those factors may not be sufficient to measure privacy risk.
Two companies may process the same volume of data while creating radically different risks.
A health-tech startup processing 100,000 health records may pose greater privacy risks than a company processing several million ordinary transactional records.
Likewise, a company processing children's data, biometric identifiers or detailed behavioural profiles may present heightened risks even at relatively modest volumes.
A more sophisticated exemption framework could consider:
- sensitivity;
- vulnerability of Data Principals;
- consequences of misuse;
- scale;
- duration;
- nature of processing;
- automated decision-making;
- cross-border processing; and
- security risks.
The risk-based approach is particularly relevant because the DPDP Act itself recognises that different Data Fiduciaries may warrant different levels of regulatory treatment.
Section 17(3), however, leaves substantial discretion to the Central Government in deciding when that differentiation should occur.
18. Section 17(4): Why does the State receive a second layer of exemptions?
Section 17(4) provides that, in respect of processing by the State or an instrumentality of the State:
- Section 8(7) does not apply;
- Section 12(3) does not apply; and
- where the processing does not involve making a decision affecting the Data Principal, Section 12(2) does not apply.
This provision is different from Section 17(2)(a).
Section 17(2)(a) allows a notified State instrumentality to escape the Act altogether for specified national-interest processing.
Section 17(4) applies more generally to State processing but removes only specified obligations.
This distinction is important because the State may undertake ordinary administrative processing that has nothing to do with national security.
For example, public administration inevitably requires the collection and retention of information. Parliament has therefore created specific exceptions to deletion and correction mechanisms in defined circumstances.
The problem, however, is the interaction with the right to erasure.
Section 8(7) ordinarily requires erasure where consent is withdrawn or the specified purpose is no longer served, subject to legal retention requirements. Section 17(4) removes that obligation for State processing.
This creates a structural asymmetry:
The State may retain personal data in circumstances where a private Data Fiduciary would otherwise be required to erase it.
Such asymmetry may be justified by the special nature of State functions. But the statute provides comparatively little detail concerning how long such information may be retained or how the individual can challenge unnecessary retention.
The concern becomes more serious where the data is aggregated across multiple State databases.
19. Section 17(5): How broad is the Government's residual exemption power?
Section 17(5) provides that the Central Government may, before expiry of five years from the date of commencement of the Act, by notification, declare thatany provision of the Act shall not apply to a Data Fiduciary or class of Data Fiduciaries for a specified period.
This is an extraordinarily flexible delegated power.
Unlike Section 17(3), it is not restricted to five specified provisions.
Unlike Section 17(1), it is not tied to six specified processing circumstances.
Unlike Section 17(2)(a), it is not limited to State instrumentalities.
The Government may potentially exempt a Data Fiduciary or class from any provision.
There is nevertheless an important temporal limitation: the power must be exercised before the expiry of five years from the date of commencement of the Act.
But the provision raises a fundamental delegation question.
How much legislative policy has Parliament itself supplied?
The Government is given considerable discretion to determine:
- who receives the exemption;
- which provision is removed; and
- the duration of the exemption.
The statutory standard for exercising the power is comparatively thin.
This creates a risk that the substantive architecture of the Act could gradually be modified through exemption notifications rather than legislative amendment.
That is especially important in a statute whose central promise is to establish a stable and predictable framework for informational privacy.
20. Section 17 and delegated legislation: where is the constitutional line?
The deeper issue running through Section 17 is therefore not simply government discretion.
It is the distinction between:
legislative policy andexecutive implementation.
Parliament may legitimately delegate the task of identifying technical details or implementing a statutory policy.
But where an exemption can remove significant statutory protections, the more important question becomes whether Parliament has provided sufficient standards, boundaries and safeguards to guide that discretion.
This is particularly acute under Sections 17(2)(a) and 17(5).
A notification may have enormous consequences for informational privacy while remaining an executive instrument.
The constitutional concern is therefore not necessarily that delegation itself is impermissible. It is whether the delegation has been accompanied by sufficient legislative guidance to prevent arbitrary or disproportionate exercise.
The more fundamental the right being affected, the greater the importance of carefully articulated statutory standards.
21. Section 17 and the GDPR: why Article 23 provides an important contrast
The comparison with Article 23 of the GDPR is particularly instructive.
Article 23 permits Union or Member State law to restrict specified data-subject rights and controller obligations where the restriction:
- respects the essence of fundamental rights and freedoms; and
- is a necessary and proportionate measure in a democratic society.
Article 23 also identifies legitimate objectives, including national security, defence, public security and the prevention, investigation, detection or prosecution of criminal offences.
The contrast is significant.
The GDPR expressly embeds:
essence + necessity + proportionality + legislative measure
into its restriction framework.
Section 17 contains several of these ideas indirectly, and certain clauses expressly use “necessary”, but the Indian legislation does not establish a comparable general proportionality discipline within the text of the exemption provision itself.
This difference becomes especially significant in relation to Section 17(2)(a).
The Indian Constitution independently supplies constitutional review. Therefore, the absence of an express proportionality clause in Section 17 does not mean that proportionality disappears from constitutional scrutiny.
But from a legislative-drafting perspective, Parliament could have made the framework considerably stronger by expressly requiring exemptions affecting privacy to be necessary and proportionate to the identified objective.
22. Does Section 17 undermine the right to privacy?
The answer should be qualified.
Section 17 does not, by its mere existence, undermine privacy.
A functioning data-protection statute necessarily requires carefully designed exceptions.
The real concern is that some of the exceptions are insufficiently calibrated.
There is a fundamental difference between:
“The government may disregard a particular obligation because compliance would frustrate a specific statutory function”
and:
“The government may exempt an entire instrumentality from the Act.”
The first is targeted.
The second is structural.
Section 17 contains both approaches.
That is why it cannot fairly be characterised either as an entirely necessary provision or as an entirely illegitimate one.
Its validity will depend heavily upon how its powers are exercised and, where challenged, how courts interpret their constitutional limits.
23. What should be the proper interpretive approach to Section 17?
A rights-protective interpretation should adopt at least five principles.
First, exemptions should be construed according to their text
An exemption should not be expanded merely because the underlying activity appears socially desirable.
Secondly, processing should be distinguished from the entity
The fact that a company is litigating, restructuring or recovering a debt does not make the company generally exempt.
Thirdly, “necessary” should have substantive meaning
Where Parliament has used “necessary”, processing that is merely convenient should not qualify.
Fourthly, the Rules cannot enlarge the Act
Rule 16 cannot remove the statutory limitation in Section 17(2)(b).
Fifthly, constitutional proportionality remains relevant
A statutory exemption affecting fundamental privacy interests cannot be insulated from constitutional review merely because the provision is framed as an “exemption”.
These principles are particularly important because Section 17 operates at the boundary between individual autonomy and institutional necessity.
24. What is ultimately missing from Section 17?
The most significant weakness is not the existence of exemptions but the relative absence of procedural safeguards accompanying the most intrusive ones.
A stronger framework could have required, particularly for State exemptions:
- reasoned notifications;
- identification of the specific processing covered;
- limitation to specified categories of data;
- necessity and proportionality assessment;
- periodic review;
- sunset provisions;
- independent oversight;
- security obligations;
- retention controls;
- audit requirements; and
- a mechanism for challenging excessive processing.
Some of these safeguards may arise elsewhere in Indian law or constitutional review. But they are not sufficiently integrated into Section 17 itself.
This matters because privacy protection is not merely about whether the State has a legitimate reason to process information.
It is also about how much information is collected, for how long, for what purpose, who can access it, whether it can be repurposed, and what happens when the original justification disappears.
An exemption that answers only the first question leaves the remainder unresolved.
25. Final assessment: Is Section 17 a necessary exception or a structural weakness?
Section 17 should ultimately be understood as containing three different legislative philosophies.
The first is functional necessity.
This is represented by Sections 17(1)(a), (f). Litigation, adjudication, law enforcement, foreign contractual processing, corporate restructuring and debt recovery can all require processing that would otherwise collide with ordinary data-protection rights.
The second is institutional and public-interest exemption.
This appears principally in Section 17(2). Here, the legislature accepts that certain State-security and research activities may require the Act to stand aside.
The third is executive flexibility.
This appears in Sections 17(3) and 17(5), where the Government is given power to exempt particular Data Fiduciaries or classes of Data Fiduciaries.
The first category is comparatively easier to justify because the exemption is tied to a defined function.
The second is substantially more sensitive because it can remove the Act from entire categories of State processing.
The third raises questions concerning the permissible limits of delegated legislative power.
The most important conceptual distinction is therefore between a narrow exemption from a conflicting obligation anda broad exemption from the regulatory framework itself.
Section 17(1) largely adopts the former model. Section 17(2)(a) adopts the latter.
That is where the provision becomes constitutionally significant.
The recognition of informational privacy as part of Article 21 means that the State cannot simply invoke “security”, “public order” or another legitimate objective and treat the resulting privacy intrusion as conclusively justified. The legality of the objective and the proportionality of the means remain separate questions.
Accordingly, the strongest criticism of Section 17 is not that national security should never justify an exemption, nor thatcriminal investigations should be subjected to ordinary consent requirements. Such propositions would misunderstand the necessity of exemptions in a functioning privacy statute.
The more persuasive criticism is narrower:
Where Parliament creates an exemption capable of removing fundamental privacy protections, the exemption itself must be sufficiently structured to ensure that the exception does not become the rule.
Section 17 comes closest to that standard in Section 17(1), where particular purposes trigger a partial exemption and Sections 8(1) and 8(5) remain applicable. It is considerably less precise in Section 17(2)(a), where a notified State instrumentality may be taken outside the Act on broad grounds without an express statutory requirement of necessity, proportionality, temporal limitation or independent review.
The research exemption under Section 17(2)(b) occupies an intermediate position. Its objective is legitimate and the prescribed standards introduce meaningful safeguards concerning lawfulness, purpose limitation, necessity, accuracy, retention and security. But the absence of clear statutory definitions and the uncertainty concerning the operation and enforcement of those standards remain important weaknesses.
Finally, Sections 17(3) and 17(5) demonstrate that the DPDP Act deliberately leaves room for regulatory differentiation. That is defensible from the standpoint of innovation and administrative flexibility, but such flexibility must not become a mechanism through which the executive can selectively rewrite the level of privacy protection owed by particular classes of Data Fiduciaries.
The ultimate character of Section 17 will therefore depend on interpretation as much as implementation.
If construed narrowly, its exemptions can perform their legitimate function: allowing courts to adjudicate, regulators to regulate, investigators to investigate, creditors to recover, companies to restructure and researchers to conduct socially valuable work without allowing ordinary data rights to frustrate those activities.
If construed expansively, however, particularly in relation to State processing, Section 17 risks producing an uncomfortable inversion of the DPDP Act's central premise: the State that possesses some of the largest concentrations of personal data could potentially place substantial portions of that processing outside the very framework designed to govern personal data.
That is the central legal tension within Section 17.
And it is ultimately the question that any constitutional analysis of the provision must confront:
Does the exemption merely make the right workable in circumstances where competing legal interests require limited derogation, or does it permit the executive to determine, with insufficient statutory safeguards, when the right itself will cease to operate?
Section 17 is therefore best understood neither as a mere list of exceptions nor as a wholesale suspension of data protection. It is the boundary-setting provision of the DPDP Act: the provision that determines where the statutory protection of personal data yields to competing claims of justice, investigation, security, administration, commerce and public interest.
Its greatest strength is that it recognises that privacy cannot operate in isolation from these competing legal interests.
Its greatest weakness is that, in some of the most consequential situations, particularly State-security processing and executive exemption powers, it leaves too much of the boundary to be determined after the fact.
The interpretive task will consequently be to ensure that Section 17 remains an exception to the protection created by the Act, rather than becoming an alternative route around that protection.
26. Corresponding Rules and Schedules
| Section 17 provision | Rules and Schedules connection |
|---|---|
| Section 17(1)(a) to (f), clause-specific exemptions | No separate Rule. The clauses operate directly, subject to Sections 8(1) and 8(5) |
| Section 17(2)(a), State processing for subsidies, benefits, services, certificates, licences and permits | Rule 5, read with the Second Schedule, and Rule 5 read with the Seventh Schedule for the purpose and authorised person |
| Section 17(2)(b), research, archiving and statistical purposes | Rule 16, read with the Second Schedule standards |
| Section 17(3), classes of Data Fiduciaries including startups | Rule 12, read with the Fourth Schedule exemptions from Section 9(1) and 9(3) |
| Section 17(4) and 17(5), notified exemptions | Exercised by notification. Rule 16 and the Second Schedule remain the outer limits of the standards that apply |
| Commencement of Section 17 | Section 1(2), Phase III, 13 May 2027, and Rule 1(4) |
The Schedules matter here because an exemption under Section 17(2) does not leave processing entirely unregulated. Where the Second Schedule standards apply, they continue to govern the manner of processing, and the Fourth Schedule identifies the classes of Data Fiduciary and the purposes for which the child-related obligations in Section 9(1) and 9(3) are relaxed.
Reproduced from official sources for reference. Not legal advice. In case of any discrepancy, the text published in the Gazette of India prevails.