Startup Exemptions Under the DPDP Act: What's Actually Been Notified
Founders often assume a blanket startup exemption exists. The Act only creates a power for the government to grant one. Here is the honest state of play.
The statutory hook
The reference point for a start-up exemption is the Section 17 government exemption power, under which the central government may notify that some or all of the Act's provisions do not apply to specified classes of Data Fiduciaries, including start-ups, for such period as may be specified, having regard to factors such as the volume and nature of personal data processed. It is important to be precise: this is an enabling power the government may use, not a self-executing exemption that automatically applies to any company that qualifies as a start-up under, say, a DPIIT recognition scheme.
Nothing in the Act itself defines exactly which start-ups would qualify, which obligations would be eased, or for how long; all of that is left to the specific notification the government would need to issue to activate the exemption for any given class.
What has, and has not, been confirmed
At the time of writing, a comprehensive, finalised notification specifically operationalising a start-up exemption under Section 17, with defined eligibility criteria and a clear list of eased obligations, had not been established with enough certainty to describe precisely here. Public discussion around the Rules and government statements have referenced the possibility of lighter-touch treatment for smaller entities, but founders should not treat this as confirmed policy until an actual notification is published and verified against MeitY's official channels.
This is a genuinely moving area, and the honest, responsible answer for any founder asking exactly what relief they currently qualify for is that it depends on notifications that may not yet exist in final form, rather than on a settled rule that can be summarised confidently today.
Why founders should plan for full compliance regardless
Building a compliance program on the assumption that a favourable exemption will eventually arrive carries real risk: the notification, if and when it comes, may be narrower than hoped, may apply only to specific obligations rather than the whole Act, may be time-limited, or may exclude companies handling data types the government considers sensitive regardless of company size. A start-up that has already built reasonable consent, notice, and security practices is far better positioned either way, whether or not a specific exemption eventually applies to it.
There is also a practical growth consideration: a start-up that scales quickly may outgrow whatever volume or nature-of-data thresholds a future exemption notification sets, at which point full compliance becomes necessary regardless. Treating any exemption as a temporary grace period to build toward compliance, rather than a permanent carve-out, is the more resilient posture.
Where to go next
See the companion guide on the Section 17 government exemption for the fuller mechanics of how these notifications work, and use the Applicability Checker to understand your baseline obligations independent of any exemption that may or may not eventually apply to your company.