DPDP Exemptions6 mins

DPDP Act Section 17(1)(a): The Legal Right and Claim Exemption Explained

A definitive guide for General Counsel on the DPDP Act Section 17(1)(a) exemption. Learn how to secure litigation data, manage outside counsel risk, and maintain regulatory defensibility during legal disputes.

Written byVipul Abhishek· Former Advocate, Supreme Court of India · ComplyDP Co-Founder

Last updated:

The Carve-Out In Plain Language

When an enterprise faces litigation, initiates a contract dispute, or conducts a formal internal investigation, the legal department must process massive volumes of personal data. This creates an immediate compliance conflict if an opposing party or a disgruntled employee attempts to weaponize data erasure requests to destroy evidence. Section 17(1)(a) of the Digital Personal Data Protection Act, 2023 provides a critical carve-out for this exact scenario. It exempts the processing of personal data from standard notice, consent, and data principal rights requirements, provided that the processing is necessary for enforcing any legal right or claim. For a General Counsel, this exemption acts as a vital safe harbour, ensuring that active legal defense and enforcement operations are not paralyzed by privacy mandates.

Statutory Anchors And Scope

Section 17(1)(a) explicitly states that the provisions of Chapter II, Chapter III, and Section 16 shall not apply where the processing of personal data is necessary for enforcing any legal right or claim. Chapter II contains the primary obligations regarding notice, consent, and data retention limits. Consent is the primary basis for processing, except where Section 7 legitimate uses apply, but this specific carve-out bypasses both mechanisms for litigation purposes. Chapter III outlines the rights of the Data Principal, including the right to correction and erasure. By disapplying these chapters, the DPDP Act ensures that an enterprise can collect, retain, and process data for litigation without seeking permission from the very individuals they might be investigating or suing.

Conditions And Limitations Of The Exemption

The safe harbour provided by Section 17(1)(a) is conditional and strictly tied to the word necessary. General Counsel cannot use this clause as a blanket excuse to bypass compliance for all legal department operations. The processing must directly tie to a specific, identifiable legal right, contract enforcement, or active claim. If outside counsel collects a massive repository of enterprise data during e-discovery, only the data strictly necessary for the claim falls under the exemption. Expanding the scope to include unrelated employee files or historical customer records exposes the enterprise to severe regulatory scrutiny. Regulator engagement on this issue will likely focus on how the legal team documents the necessity of the data held under this exemption.

What Still Binds The Enterprise

While many operational hurdles are removed, the exemption explicitly states that Section 8(1) and Section 8(5) still apply. Section 8(1) ensures the Data Fiduciary retains ultimate accountability for compliance. More importantly, Section 8(5) mandates that the enterprise must implement reasonable security safeguards to prevent a personal data breach. This has profound implications for outside counsel spend and vendor management. If your external law firm or e-discovery platform suffers a breach involving litigation data, the enterprise faces penalty ceilings up to 250 crore rupees. Furthermore, the DPDP Rules, 2025 dictate that the Data Fiduciary must intimate affected Data Principals without delay and submit a detailed report to the Data Protection Board within 72 hours. The exemption protects your right to hold the data, but it does not forgive a failure to secure it.

Misconceptions And Indemnity Risks

A dangerous misconception among enterprise legal teams is that litigation data is entirely outside the scope of the DPDP Act. Because Section 8(5) survives the exemption, enterprises must carefully review the limitation of liability and indemnity clauses in their contracts with external law firms. Another common myth is that this exemption allows for indefinite data retention. While Chapter II retention limits are technically disapplied during the active claim, standard civil procedure and data minimization principles suggest that once the claim is permanently settled or time-barred, retaining the data indefinitely creates unshielded risk. The data must eventually be deleted or brought into standard compliance.

Evidence To Keep For Regulatory Defensibility

To survive an audit or an inquiry from the Data Protection Board, the legal department must maintain a clear paper trail demonstrating that the exemption was applied correctly. 1. Legal Hold Notice - Owned by the General Counsel, this document must clearly define the specific legal right or claim triggering the exemption and outline the boundaries of the data freeze. 2. Data Scope Memorandum - Prepared by internal legal operations or outside counsel, detailing exactly which datasets are necessary for the claim and justifying their inclusion. 3. Vendor Security Addendum - Managed by the legal team, ensuring that any external legal service provider handling the exempt data contractually commits to Section 8(5) security safeguards and rapid breach notification. 4. Expiry Trigger Record - A tracking mechanism to flag when the legal claim is resolved, prompting the legal team to transition the data out of the exemption status and into standard erasure workflows.

Key Statutory Cross-References

Section 8(1) defines the overarching responsibility of the Data Fiduciary to ensure processing complies with the Act, even when utilizing external processors. Section 8(5) establishes the non-negotiable mandate to implement reasonable security safeguards to protect personal data from breaches. Section 17(1)(c) offers a parallel exemption for processing in the interest of prevention, detection, investigation, or prosecution of any offence, which is highly relevant for internal corporate fraud investigations.

Next Steps For Your Organization

With exactly 261 days remaining until the DPDP compliance deadline of 13 May 2027, enterprise legal teams must finalize their legal hold procedures and outside counsel security audits. A failure to map the boundaries of your litigation data could lead to disastrous regulatory penalties if a breach occurs at an external law firm. Evaluate your current vendor contracts and data flows today. Visit freescan.complydp.com to run an applicability and exemption-scope gap check for your organization.

Sources

Frequently asked questions

Can a former employee use a data erasure request to destroy evidence during a dispute?

No. If the enterprise is actively enforcing or defending a legal right or claim, Section 17(1)(a) disapplies the Data Principal rights found in Chapter III. You are not obligated to honor erasure requests for personal data that is necessary for the dispute.

Do we need to issue a privacy notice before processing data for an active legal claim?

Notice obligations under Chapter II are disapplied for this specific carve-out. If processing is strictly necessary to enforce a legal right, you do not need to issue an itemised notice to the opposing party or the affected Data Principals involved in the claim.

Are our outside law firms exempt from data breach reporting under this rule?

No. The exemption explicitly retains Section 8(5) security obligations. If a breach occurs at your outside counsel, the Data Fiduciary must still intimate affected Data Principals without delay and submit a detailed report to the Data Protection Board within 72 hours per the DPDP Rules, 2025.

Does this exemption apply to routine legal operations like contract drafting?

Section 17(1)(a) is designed for the enforcement of a legal right or claim, which typically implies an active dispute, litigation, or formal demand. Routine legal operations require standard compliance measures where consent is the primary basis for processing, except where Section 7 legitimate uses apply.

What happens to the data after the legal claim is permanently settled?

Once the claim is resolved and the data is no longer necessary for enforcement, the Section 17(1)(a) exemption ceases to apply to that specific processing purpose. The enterprise must then either delete the data or establish a new, valid legal basis for retention under the DPDP Act.