Scope of Section 17 exemptions
Section 17 operates in three tiers:
- Section 17(1): the Central Government is exempt from Section 8(1) (ground for processing) and Section 13 (grievance right) when processing personal data for prevention and detection of offences, or apprehension and prosecution of offenders—no separate notification is needed for this tier
- Section 17(2): by notification, the Central Government may exempt any instrumentality of the state from any provision of the Act on grounds of sovereignty, security of the state, friendly relations with foreign states, maintenance of public order, or prevention/investigation/prosecution of offences. The notification may impose conditions
- Section 17(3): exemption for research, archiving or statistical purposes—personal data must not be used for decisions about individual Data Principals
Constitutional limits: the Puttaswamy test
The Supreme Court’s Puttaswamy judgment (2017) established that any restriction on the right to privacy must satisfy legality, legitimate aim and proportionality. A Section 17(2) notification is “prescribed by law” (legality), and the listed grounds—sovereignty, security—are recognised as legitimate aims. The proportionality question is where challenges will arise.
A notification that exempts an agency from all DPDPA obligations without specifying the scope of data processing, the duration of the exemption or oversight mechanisms may fail the proportionality leg. Courts are likely to require that the exemption be narrowly tailored: limited to the data and purposes necessary for the stated aim, time-bound where possible and subject to review.
Aadhaar and DigiLocker: government platforms under the DPDPA
Aadhaar (UIDAI) and DigiLocker (NeGD) process personal data of hundreds of millions of individuals. The DPDPA applies to these platforms unless they are specifically exempted by a Section 17 notification.
The Aadhaar Act 2016 has its own consent and data-protection provisions. Section 16(2) of the DPDPA preserves stricter obligations in other laws—the Aadhaar Act’s biometric-data restrictions continue to apply. DigiLocker, which stores digitally signed copies of government-issued documents, processes identity data that falls within the DPDPA definition of personal data (Section 2(t)).
RTI vs data privacy: the unresolved tension
The Right to Information Act, 2005 (Section 8(1)(j)) exempts from disclosure personal information that has no relationship to any public activity or interest, or that would cause unwarranted invasion of privacy. The DPDPA does not amend the RTI Act, but the two statutes now operate in parallel.
The practical tension: an RTI applicant requests information that contains personal data of a third party. Under the RTI Act, the public authority must weigh the public interest against the privacy invasion. Under the DPDPA, the same public authority is a Data Fiduciary with obligations to the Data Principal whose data may be disclosed. Neither statute provides a clear priority rule. Courts will need to resolve this on a case-by-case basis—likely using the Puttaswamy proportionality framework.
How AMLEGALS advises on government data compliance
AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder and Managing Partner, with Rohit Lalwani, Associate Partner, working on DPDPA compliance. The firm advises government departments and public-sector undertakings on mapping their data-processing activities to the DPDPA framework, assessing the scope and validity of Section 17 exemptions, and designing compliance programmes that align with both the DPDPA and the Puttaswamy proportionality standard.

