8 minutes

DPDP Act State Exemptions Explained: Section 17 and Section 7 Legal Liabilities

An analysis of Section 17(2)(a) exemptions, Section 17(4) erasure carve-outs, and Section 7(b) legitimate uses for State instrumentalities under the DPDP Act.

Written byVipul Abhishek· Former Advocate, Supreme Court of India

Last updated:

The Digital Personal Data Protection Act, 2023 sets specific legal boundaries for government bodies processing personal data. Section 17(2)(a) empowers the Central Government to exempt notified State instrumentalities entirely. This applies strictly when the processing targets national security, sovereignty, or public order. Section 17(4) removes specific data erasure duties for these public entities. Section 7(b) establishes a distinct lawful basis for the State to process data for subsidies, benefits, and licenses. This basis operates entirely outside of consent. The State functions as a fully regulated Data Fiduciary under Section 7(b). Private enterprises negotiating vendor agreements with public departments require distinct contract terms based on these statutory differences. A misclassification exposes the private vendor to uncalculated breach liabilities. Government contracts demand precise mapping to the relevant section before data collection begins.

Section 17 Exemption Mechanics

Section 17(1) extracts specific activities from standard Chapter II and III obligations. Processing data to enforce a legal right or claim falls outside general compliance requirements. Courts and tribunals process personal data without seeking permission from the Data Principal. The law also exempts processing executed for the prevention, detection, investigation, or prosecution of any offence. Law enforcement agencies collect evidence and suspect information under this direct statutory protection. The DPDP Act prevents suspects from using privacy rights to obstruct ongoing criminal investigations.

Section 17(2)(a) demands a formal published gazette notification from the Central Government. It designates exact agencies handling the sovereignty and integrity of India. Standard public sector undertakings or municipal boards do not automatically receive this protected status. Private processors handling information for an exempt agency rely completely on that formal notification. Without the published gazette document, the enterprise processor assumes standard regulatory duties. The vendor requires the gazette reference during the procurement phase.

The Section 17(4) Erasure Carve-Out

Section 17(4) directly alters the data lifecycle for public records. Section 8(7) normally mandates the deletion of personal data when the specified purpose concludes. Section 12(3) grants Data Principals the legal right to demand correction and erasure of their records. Neither provision applies to the State or its specific instrumentalities. Maintaining historical public records forms a core function of the administrative state. An agency managing land registries or tax filings relies on Section 17(4) to preserve the integrity of national databases.

Government departments retain administrative records indefinitely for legal continuity. A private cloud provider hosting government data modifies its automated deletion protocols. The commercial contract instructs the vendor to bypass standard retention schedules. The enterprise strictly follows the State fiduciary commands to prevent unlawful data destruction. The vendor retains these instructions to prove the extended retention period originates from the government principal.

Section 7(b) Lawful Basis And Operational Standards

A common error treats Section 7(b) as an exemption from the law. Section 7(b) covers processing for the provision of any subsidy, benefit, service, certificate, license, or permit. A government hospital or municipal licensing board uses this lawful basis. Section 4(1)(b) establishes legitimate uses as a valid lawful purpose alongside consent. Operating under Section 7(b) leaves the government entity fully regulated as a Data Fiduciary. The Second Schedule details specific operational standards for this processing. The State entity maps the data collection directly to a notified statutory function.

The government body implements reasonable security safeguards under Section 8(5). It provides timely responses to access requests submitted under Section 11. The State entity reports personal data breaches to the Data Protection Board of India within 72 hours, as directed by the DPDP Rules, 2025. Failure to meet these operational standards exposes the State fiduciary to full regulatory penalties.

Processor Liability In Public Sector Contracts

A private enterprise supplying software or storage to a government department operates purely as a Data Processor. Section 8(2) mandates a valid contract between the State fiduciary and the private vendor. The enterprise faces severe financial risk if the contract lacks precise liability allocation. The State instrumentality faces penalties reaching 250 crore rupees for failing to secure personal data. The government department often attempts to transfer this risk to the vendor through standard indemnification clauses.

The processor limits its exposure by documenting the exact lawful basis of the government principal. If the State entity relies on Section 7(b), the processor ensures the contract specifies the exact statutory function involved. The private vendor builds technical logs proving compliance with the State principal security instructions. These logs form the primary defense during a regulatory inquiry. Vendor reliance on verbal assurances from public officials offers no legal protection.

Evidence And Contract Documentation

1. Legal counsel indexes every public sector contract against published Section 17(2)(a) gazette notifications.

2. Contract managers draft limitation of liability clauses restricting indemnification exposure for vendor data breaches.

3. Compliance officers document the specific Section 7(b) subsidy or license justifying the collection of personal data.

4. Cloud architects configure storage systems to bypass automated deletion rules when instructed by a State entity under Section 17(4).

5. Security teams maintain immutable audit logs proving Section 8(5) safeguards protect State data hosted on private infrastructure.

6. Procurement officers require the government department to state its legal processing basis in the primary service agreement.

Cross Referenced Provisions

Section 4 requires a lawful purpose for all processing, identifying consent or specific legitimate uses as valid bases.

Section 8(2) dictates the contractual agreement required to engage a private data processor.

Section 8(5) commands the implementation of security safeguards regardless of a Section 7 lawful basis.

Section 12 outlines correction and erasure rights, which Section 17(4) restricts against government bodies.

Section 11 grants Data Principals the right to access a summary of their processed personal data.

Section 17 completely removes the application of Chapter II and Chapter III duties for designated national security processing. The Data Protection Board of India reviews the application of these exemptions during breach investigations.

With 222 days remaining until the 13 May 2027 compliance deadline, outside counsel spend on public sector contract remediation is accelerating. Map your State instrumentality contracts and exemption exposure using our compliance gap check at https://www.complydp.com/audit-preview.

Sources

Frequently asked questions

Does a contract with a government department exempt our enterprise from DPDP Act liabilities?

No. Unless the Central Government explicitly notifies the State instrumentality under Section 17(2)(a), the standard rules apply. Your enterprise operates as a Data Processor. The commercial contract dictates your indemnification exposure for data breaches.

What separates Section 17(2)(a) from Section 7(b) for State entities?

Section 17(2)(a) creates a complete exemption via a published notification for national security or public order. Section 7(b) provides a lawful basis for processing subsidies or licenses. The State entity remains a Data Fiduciary bound by security and breach reporting duties under Section 7(b).

Do State entities report personal data breaches to the regulatory board?

State entities operating under Section 7(b) report personal data breaches to the Data Protection Board of India within 72 hours. The DPDP Rules, 2025 require this action. Only entities designated by gazette notification under Section 17(2)(a) escape this specific duty.

How does the Section 17(4) data erasure carve-out affect software vendors?

Section 17(4) eliminates the obligation for the State to erase data once the specified purpose concludes. Software vendors adjust their data retention schedules to reflect the State fiduciary instructions. The vendor requires precise contract clauses to authorize indefinite retention on private servers.

What financial exposure do State instrumentalities face under the DPDP Act?

State instrumentalities face standard penalty ceilings unless exempted by a Section 17(2)(a) notification. Failure to implement reasonable security safeguards carries a maximum penalty of up to 250 crore rupees. A government entity holds the primary liability for breaches caused by its vendors.