DPDP NavigatorAct 2023 · Rules 2025
All guides
Legal Intelligence

The Government Exemption Under Section 17(2): What It Covers and What It Doesn't

25 Jul 20269 min read

Section 17 lets the government carve out entire categories of Data Fiduciaries from parts of the Act. Here is what that power can and cannot reasonably be used for.

The structure of the exemption power

Section 17 of the DPDP Act sets out several distinct exemption pathways rather than a single blanket carve-out. One strand exempts processing necessary for enforcing legal rights or claims, and for judicial or quasi-judicial functions. Another, commonly referred to as the Section 17 government exemption, allows the central government to notify that provisions of the Act shall not apply to specified classes of Data Fiduciaries, including start-ups, for such period as may be specified, having regard to the volume and nature of personal data processed.

A separate strand addresses research, archiving, and statistical purposes, recognising that processing for these ends often does not fit neatly within the Act's consent-and-purpose-limitation framework. State instrumentalities can also be exempted from specific provisions on grounds connected to sovereignty and integrity of India, security of the state, friendly relations with foreign states, maintenance of public order, or preventing incitement to certain offences, a strand discussed in more detail in a separate guide because of how much debate it has generated.

What the start-up-style exemption is meant to address

The evident policy rationale behind the government's power to exempt classes of Data Fiduciaries, including start-ups, is that a small, early-stage company processing a modest volume of personal data may not have the resources to meet the same compliance bar as a large, established fiduciary, and that a rigid one-size-fits-all obligation set could disproportionately burden smaller players relative to the actual privacy risk they present.

Exactly which obligations would be eased, and for which class of entities, depends on the specific notification the government issues, since Section 17 empowers the government to specify this rather than setting the parameters in the Act itself. At the time of writing, the details of any such notification specifically calibrated for start-ups had not been finally settled in a way that can be described with confidence, and organisations should treat this as an evolving area rather than a fixed dispensation.

What the exemption does not do

It is worth being precise about the limits. Section 17 exemptions are notified by the government for defined classes and purposes; they are not a general opt-out that any company can claim for itself by virtue of being small or new. A start-up processing large volumes of sensitive personal data, or one designated a Significant Data Fiduciary, would not automatically fall within a start-up carve-out simply because of its corporate age or funding stage.

The exemption also does not touch the core recognition of privacy as a value the Act protects; even exempted classes generally remain subject to the Act's foundational framework, with the exemption operating on specific obligations rather than repealing the statute's application altogether for that class.

Practical implications for founders

Because the precise scope of any start-up exemption is set by notification rather than by the Act's text, the safest planning assumption for an early-stage company is to build toward full compliance and treat any eventual relief as upside rather than something to rely on from day one. Notifications can be narrower than expected, time-limited, or conditioned on facts, like data volume, that change quickly as a company scales.

Where to go next

See the companion guide on startup exemptions for what has actually been notified as of this writing, and use the Applicability Checker to see how your organisation's current profile maps onto the Act's general obligations before assuming an exemption will apply.