DPDPA Exemptions Under Section 17: Who Is Covered and Who Is Not?
Section 17 of the DPDPA creates several exemptions from the Act's obligations. Understanding their precise scope prevents both over-reliance and unnecessary non-compliance.

Section 17 comes up often in conversations about India's data protection law, usually framed as a possible way out of DPDPA obligations. The provision is narrower than that framing suggests. It covers five specific situations: legal and judicial processing, government-notified national security activities, non-commercial research, certain cross-border contracts, and government-notified startups. Banks, e-commerce platforms, fintechs, healthcare services, and HR tech companies fall outside all five categories and remain fully within the DPDPA's scope.
This article walks through what Section 17 covers, and where its boundaries sit.
What Section 17 Actually Covers
Section 17 of the DPDPA creates a layered set of exemptions from the Act's obligations. The provision is structured across several sub-sections, each addressing a different category of processing.
Section 17(1) exempts processing necessary for enforcing legal rights or claims, processing by courts and tribunals for judicial or quasi-judicial functions, processing for prevention and investigation of offences, and processing related to mergers, amalgamations, and financial default assessments.
Section 17(2)(a) allows the Central Government to notify certain state instrumentalities as exempt from the Act's provisions, where processing serves the interests of sovereignty, security of the State, friendly relations with foreign States, maintenance of public order, or preventing incitement to any cognizable offence.
Section 17(2)(b) provides that the Act shall not apply to processing necessary for research, archiving, or statistical purposes, provided the personal data is not used to take any decision specific to a Data Principal and the processing follows standards that may be prescribed.
A separate exemption applies to processing personal data of Data Principals not within the territory of India, where such processing follows a contract entered into with a person outside India by a person based in India.
Section 17(3) empowers the Central Government to notify certain Data Fiduciaries, including startups, as exempt from specific provisions of the Act.
That covers the full set. Each category carries defined boundaries built around a specific institutional context, and few of them align with what a typical private company does day to day.
The Government Exemption Applies Within a Narrow Frame
Section 17(2)(a) is sometimes read as a broad carve-out for government bodies. The exemption applies within a narrower frame than that reading suggests.
The exemption activates only when the Central Government issues a specific notification designating a particular instrumentality as exempt, and even then, only for processing tied to sovereignty, security, public order, or the prevention of incitement to offences. A government department processing tax returns, distributing welfare benefits, or issuing licences continues to fall under the DPDPA the same way a private company does, since these are routine administrative functions rather than the narrow category the exemption addresses.
The exemption comes into play for the specific slice of activity where following standard rules would work against something like national security. Everything outside that slice stays within the Act's scope.
The Research Exemption Comes With Conditions
The exemption for research, archiving, and statistical processing sounds broadly applicable to organizations doing data-heavy work. The conditions attached to it narrow that scope considerably.
Three things need to line up together for this exemption to apply:
1. The personal data is not used to take any decision specific to a Data Principal
2. The processing follows prescribed standards
3. The processing serves the purposes of research, archiving, or statistics.
The exemption remains partially dependent on those standards existing.
This exemption is built for academic institutions, journalists doing public-interest work, and researchers operating in the public domain, and it is worth evaluating carefully against that scope. A private company running data analysis for product development, market insights, or internal business intelligence sits outside the intent of this exemption, since it was designed around public-interest and academic research rather than commercial data processing.
Businesses That Fall Outside Section 17
Organizations running a bank, an e-commerce platform, a fintech app, a healthcare service, a loyalty program, or an HR tech tool remain outside Section 17's exemptions. The DPDPA's obligations apply to these businesses in full: consent requirements, notice obligations, and data principal rights all continue to apply.
A category in Section 17 can sound similar to a business activity on the surface, which makes a closer legal read worth doing before treating any exemption as applicable. These exemptions were drafted with narrow, specific contexts in mind. Confirming applicability through a proper legal review, specific to the business in question, is a useful step before building compliance plans around any of them.
The Extraterritorial Exemption Is Easy to Misread
The exemption in Section 17(1)(d) addresses processing personal data of Data Principals outside the territory of India, under a contract entered into with a person outside India by a person based in India. Read on its own, this can seem to cover any cross-border data processing arrangement.
A nuance is worth flagging here. The DPDPA carries extraterritorial application and covers processing that occurs outside India when it connects to offering goods or services to individuals in India. An Indian citizen travelling abroad for work, a holiday, or a temporary stay retains their status as a Data Principal under the DPDPA regardless of location. The exemption in Section 17(1)(d) applies to individuals who are genuinely outside India's Data Principal base, not Indian citizens who happen to be abroad temporarily.
Where This Leaves Most Businesses
Section 17 exemptions serve the specific entities and situations they were designed for, and they carry real weight within those boundaries. Treating them as a general compliance shortcut without careful legal scrutiny introduces risk that a narrow reading of the provision would avoid.
For most of India's private businesses, the practical starting point is building a compliance program around the assumption that the DPDPA applies in full. Where a narrow exemption genuinely applies to a specific activity, that can be treated as a bonus consideration layered onto an existing compliance foundation, rather than the basis for the program itself.
Section 17 works best when read as a short list of specific, limited carve-outs rather than a general way out of DPDPA obligations. For a closer look at what building that compliance foundation involves in practice, OneConsent's guide to implementing a consent management system under the DPDP Act walks through the operational side of the same question.
Building a practical DPDPA compliance framework involves confirming which exemptions apply and putting the right systems in place. OneConsent is a DPDPA consent management platform that brings consent, preferences, and data principal rights management into one place. Request a demo to see how OneConsent's DPDPA compliance software works and explore how it can support your organization's DPDPA compliance journey.
Frequently Asked Questions
Have more questions?
Search our full DPDP knowledge base for more answers.