DPDP Exemptions6 minutes

DPDP Act Exemption Explained: Regulatory and Judicial Processing

An authoritative guide for enterprise compliance heads on the Section 17(1)(b) exemption for judicial and regulatory bodies, including conditions, surviving obligations, and evidence requirements under the DPDP Act and Rules 2025.

Written byVipul Abhishek· Former Advocate, Supreme Court of India · ComplyDP Co-Founder

Last updated:

The Judicial and Regulatory Carve Out

The Digital Personal Data Protection Act, 2023 provides targeted exemptions for entities performing statutory judicial or regulatory duties. When a court, tribunal, or statutory body in India processes digital personal data, the law disapplies major compliance burdens like consent gathering, itemised notices, and the facilitation of Data Principal rights. This carve out applies exclusively when the processing is necessary for the performance of a judicial, quasi-judicial, regulatory, or supervisory function entrusted by law. For enterprise compliance heads, understanding the boundaries of this exemption is critical when managing data sharing agreements and regulatory data requests. Consent is the primary basis for processing, except where Section 7 legitimate uses apply, but statutory bodies rely directly on Section 17 to bypass consent entirely for their core oversight functions.

Statutory Anchors in Section 17

Section 17(1)(b) of the Act establishes this exemption explicitly for oversight and judicial bodies. It states that the provisions of Chapter II, except sub sections 1 and 5 of Section 8, along with Chapter III and Section 16, shall not apply to processing by any court, tribunal, or other body in India entrusted by law with specific oversight functions. Chapter II normally mandates notices and defines general Data Fiduciary obligations, while Chapter III covers rights such as grievance redressal under Section 13. By invoking Section 17(1)(b), regulatory bodies can process data for investigations or supervisory audits without providing ready means of grievance redressal or facilitating data erasure requests.

Conditions and Strict Limits of the Carve Out

The availability of this exemption is strictly bound by the principle of necessity. The processing of personal data must be directly necessary for performing the statutory function in question. Routine administrative processing by these bodies, such as managing their internal employee payroll, cafeteria operations, or general vendor management, does not automatically qualify for this specific carve out. Those administrative activities must comply with the full Act. Furthermore, this exemption applies directly to the regulatory or judicial body itself. When a large enterprise shares customer data with a regulator under a statutory mandate, the enterprise must still map that outbound transfer in its RoPA. The enterprise typically relies on Section 7 legitimate uses for complying with a legal obligation, while the receiving regulator relies on Section 17 to process that incoming data.

Surviving Obligations for Exempt Entities

Section 17(1) explicitly preserves two critical obligations under the DPDP Act. Section 8(1) ensures that the exempt entity remains responsible for compliance with the surviving provisions, regardless of whether it processes data internally or outsources it to a Data Processor. Section 8(5) mandates that the entity must protect personal data in its possession or under its control by taking reasonable security safeguards to prevent a personal data breach. This means that while regulators do not need to capture consent artefacts or serve notices, they must implement technical access controls. Furthermore, if a breach occurs, the Rules, 2025 require intimation to affected Data Principals without delay and a detailed report to the Data Protection Board within 72 hours. Enterprise platforms selling software solutions to regulatory bodies must build features that support these surviving requirements by logging access and exporting breach logs seamlessly.

Common Misconceptions to Avoid

A significant misconception among enterprise compliance teams is confusing internal audit or governance bodies with statutory regulatory bodies. Corporate grievance committees, internal ethics boards, and industry self-regulatory organisations that lack direct statutory backing cannot claim the Section 17(1)(b) exemption. Their processing must rest on standard legal grounds. Another myth involves international data flows. While Section 16 is disapplied under this specific carve out, cross border transfers are generally permitted unless the Central Government restricts transfer to notified countries or territories. Government and regulatory departments typically follow separate, strict localisation mandates outside the DPDP framework. Lastly, claiming an exemption does not shield an entity from Data Protection Board inquiries if they fail to secure the data under Section 8(5).

Evidentiary Requirements for Auditors

When dealing with data transfers to exempt regulatory bodies, enterprise compliance heads must maintain clear audit trails and board reporting metrics. Auditors will expect a comprehensive evidence pack that logs outbound data sharing tied to regulatory supervision. The following steps ensure regulator ready compliance for your internal control owners.

1. Control Owner Verification. The Data Protection Officer must verify and document that the receiving entity is indeed a statutory body acting within its legal mandate before transferring data sets.

2. Basis Documentation. The compliance team must retain the specific statutory notice, court order, or supervisory mandate that compels the enterprise to share the data, storing it as a secure compliance artifact.

3. Transfer Logging. IT operations must maintain a time stamped audit trail showing exactly which data points were securely transferred to the regulator, ensuring no excess data is shared beyond the mandate.

4. Processor Contracts. If the statutory body uses an enterprise data platform as a Data Processor, the enterprise must ensure the data sharing agreement strictly maps to the surviving Section 8(1) and Section 8(5) responsibilities.

Statutory Cross References

Section 8(1) establishes the continuing responsibility of the entity to ensure compliance with surviving provisions, even when exemptions apply.

Section 8(5) mandates the implementation of reasonable security safeguards to prevent personal data breaches, an obligation that is never exempted.

Section 13 outlines the Data Principal right to readily available means of grievance redressal, which is entirely disapplied for bodies qualifying under Section 17(1)(b).

Final Check Before The Compliance Deadline

With exactly 261 days remaining until the DPDP hard compliance deadline of 13 May 2027, large enterprises must finalise their exemption mapping. Your board needs verifiable assurance that data shared with regulators or courts is properly scoped, tracked, and secured in your RoPA. Visit freescan.complydp.com to run an applicability and exemption-scope gap check across your data workflows today.

Sources

Frequently asked questions

Does the DPDP Act apply to regulators and courts processing personal data?

Yes, but with significant exemptions. Under Section 17(1)(b) of the Act, processing by statutory regulatory and judicial bodies is exempt from obligations like notice, consent gathering, and Data Principal rights. However, they must still implement reasonable security safeguards under Section 8(5) to prevent data breaches.

Are internal corporate grievance committees exempt from DPDP compliance?

No. The Section 17(1)(b) exemption strictly applies to courts, tribunals, and bodies entrusted by law with judicial or regulatory functions. Internal enterprise committees lack this statutory backing and must rely on standard legal grounds like consent or Section 7 legitimate uses.

If an enterprise shares data with a regulator, does the enterprise need to collect consent?

Generally, no. While the regulator relies on Section 17(1) to process the received data, the enterprise transferring the data typically relies on Section 7 legitimate uses for complying with a legal obligation or order. The enterprise must document this transaction in its RoPA to satisfy audit trails.

Do exempt judicial and regulatory bodies have to report data breaches?

Yes. Because Section 8(5) remains fully applicable, these bodies must prevent personal data breaches. If a breach occurs, the Rules, 2025 mandate intimation to affected Data Principals without delay and a detailed report to the Data Protection Board within 72 hours.

How should our DPO document data shared with exempt supervisory bodies?

The Data Protection Officer should ensure the data transfer is explicitly logged in the enterprise RoPA as a regulatory disclosure. The compliance team must retain the statutory notice or order as a verified compliance artifact to demonstrate to auditors exactly why the data was shared.