6 mins

DPDP Act Exemption Explained: Court-Approved Mergers and Amalgamations

A definitive guide for CFOs on how Section 17(1) of the DPDP Act treats personal data processing during corporate restructuring, detailing the specific conditions for the exemption and the security liabilities that remain.

Written byVipul Abhishek· Former Advocate, Supreme Court of India

Last updated:

Corporate restructuring requires moving massive volumes of employee and customer records. The Digital Personal Data Protection Act, 2023 provides a specific exemption for this activity. When a company processes personal data to execute a scheme of compromise, merger, amalgamation, or demerger approved by a court or tribunal, standard consent requirements are suspended. The competent authority sanctions the transaction. This statutory mechanism stops individual Data Principals from blocking a legally approved corporate transaction by withholding or withdrawing consent. For a Chief Financial Officer, this carve-out prevents unexpected compliance costs from derailing deal timelines. Acquiring entities inherit data assets without executing millions of new consent requests on the closing date. The law recognizes the practical impossibility of obtaining fresh consent during a court-mandated transition.

Section 17(1) of the Act establishes the boundaries of this carve-out. The text states that the provisions of Chapter II, Chapter III, and Section 16 shall not apply to processing necessary for a court-approved scheme of compromise, merger, amalgamation, or demerger. Chapter II covers general obligations like obtaining consent through itemised notices and retaining data only as long as necessary. Suspending this chapter means the merging entities do not need to pause operations to collect fresh signatures from millions of customers. Chapter III covers specific Data Principal rights. These include the right to access data, the right to correction, the right to grievance redressal, and the right to erasure. Section 16 governs cross-border transfers. Disapplying these sections allows the data integration to proceed without individual approvals or government transfer restrictions. A company executing an order from the National Company Law Tribunal does not need to publish a new privacy notice before copying databases to the surviving entity. The legal order substitutes the standard statutory mechanisms. Data subjects cannot demand deletion of their records from the merging systems to halt the transition.

The exemption is strictly conditional. The statutory text specifies the processing must be necessary for an approved scheme. A recognized statutory authority must sanction the transaction. Routine asset sales do not qualify for this specific carve-out. Internal reorganizations lacking formal court approval fall outside the scope. Cross-border mergers introduce another layer of complexity. If a foreign entity acquires an Indian firm, the transfer of Indian databases abroad typically faces scrutiny under Section 16. The Section 17(1) exemption disapplies Section 16 during the execution of the approved scheme. The data moves across borders without triggering the standard Central Government notification limits. Early-stage exploratory due diligence requires a different lawful basis. Prior to the court order, organizations rely on consent or Section 7 legitimate uses to review target data. CFOs must direct their legal teams to map exactly when court approval triggers the Section 17(1) exemption. Moving data under the assumption of an exemption before the tribunal signs the order creates immediate penalty exposure. The timeline defines the liability. Diligence requires strict access controls until the ink dries on the legal order.

Section 17(1) explicitly preserves two core statutory obligations. The text retains Data Fiduciary responsibility for compliance under Section 8(1). It also mandates reasonable security safeguards to prevent personal data breaches under Section 8(5). A data breach during post-merger integration exposes the merged entity to severe financial penalties. The Data Protection Board can levy fines up to 250 crore INR for failing to secure systems. Migrating massive databases creates temporary vulnerabilities. Cyber insurance policies require exact adherence to statutory security standards during this transition phase. Insurers investigate compliance controls during claim adjustments. A security failure during a merger directly impacts EBITDA. It alters target company valuation immediately. Audit fees for post-breach forensics quickly erode any financial synergies gained from vendor consolidation. The surviving entity must lock down API endpoints and secure cloud storage buckets during the entire integration process.

A widespread misconception assumes all merger and acquisition activity falls under this exemption. Early diligence requires a separate lawful basis before a tribunal order exists. Another error is assuming that inheriting non-compliant data carries no penalty. The surviving entity assumes the data sets and the actual compliance posture of the target firm. If the acquired firm failed to issue itemised notices under the DPDP Rules, 2025, the acquirer absorbs that compliance debt. The exemption covers the mechanical transfer process itself. It does not cure the underlying illegality of the acquired data. The acquirer must provision funds to remediate inherited compliance gaps post-close. Legal teams must audit the target company consent logs during the diligence phase. Discovering undocumented data pools after the transaction closes forces the surviving entity into an immediate remediation project.

Financial leaders must mandate a documented paper trail to prove the exemption applies and that security holds firm. The compliance team should maintain a specific transaction file.

1. Certified copies of the court or tribunal order approving the scheme.

2. Data migration logs showing exactly which databases were transferred under the scheme.

3. Security audit reports on the virtual data rooms used during the transaction.

4. Integration governance records proving Section 8(5) safeguards remained active during system consolidation.

5. Due diligence reports identifying the total cost of ownership to bring the target company data up to DPDP standards.

6. Network architecture diagrams showing encrypted data transit paths between the two corporate environments.

Section 8(5) defines the continuing obligation to protect data against breaches. Section 7 details legitimate uses which cover employment-related data processing before court approval. The DPDP Rules, 2025 outline the 72-hour timeline for reporting any breach to the Data Protection Board. Section 33 lists the penalty ceilings for failing to maintain security standards. Organizations have 253 days remaining until the DPDP Act compliance deadline of 13 May 2027. Avoid unforeseen compliance costs and audit failures during your next corporate transaction. Use our gap analysis tool at freescan.complydp.com to evaluate your data handling procedures.

Sources

Frequently asked questions

Does the DPDP Act apply to M&A due diligence?

The Act applies fully to early-stage corporate due diligence. The Section 17(1) exemption activates only after a court or tribunal approves a formal scheme of compromise, merger, or amalgamation. You rely on consent or legitimate uses before securing the legal order.

What happens if a data breach occurs during a court-approved merger?

The merged entity faces severe financial liability. The exemption explicitly preserves Section 8(5) security duties. Failure to secure the data triggers a penalty of up to 250 crore INR. You must notify the Data Protection Board within 72 hours as specified by the DPDP Rules, 2025.

Will cyber insurance cover DPDP penalties during post-merger integration?

Cyber insurance covers breach response costs but often excludes regulatory fines if you ignore statutory security standards. Insurers assess your Section 8(5) compliance controls before paying claims. Weak integration security during the data migration process can void coverage entirely.

Do we need consent to transfer employee data during an approved amalgamation?

Consent is the primary basis for processing, except where Section 7 legitimate uses apply or specific exemptions trigger. Under a court-approved amalgamation scheme, Section 17(1) suspends the consent requirement for processing necessary to execute that scheme.

How does this exemption impact cross-border data transfers during an acquisition?

Section 17(1) disapplies Section 16 for court-approved schemes. Data transfers required by the approved scheme are exempt from government notification restrictions during the execution of that transaction. Post-integration operations must resume standard cross-border compliance once the restructuring completes.