AMLEGALS — Strategic Lawyering
Government & Public Sector

Government data processing under the DPDPA: exemptions, limits and accountability

The DPDPA grants the Central Government broad exemption powers under Section 17. By notification, it can exempt any instrumentality of the state from any or all provisions of the Act on grounds of sovereignty, security of the state, public order or friendly relations with foreign states. These exemptions are the most constitutionally sensitive provisions in the entire Act—and the most likely to face judicial challenge under the Puttaswamy three-part test.

Updated · Checked against the DPDP Act, 2023 and the DPDP Rules, 2025 · 4 min read

Abstract institutional dome geometry with radiating structured lines on navy and gold background
Short answer

Section 17(2) of the DPDPA allows the Central Government to exempt any instrumentality of the state from the Act’s obligations by notification, on specified grounds (sovereignty, security of the state, public order, friendly relations). Section 17(3) permits exemption for research, archiving or statistical purposes. These exemptions are not self-executing—they require a formal notification and must satisfy the Puttaswamy proportionality test to survive constitutional challenge.

  • Government Data
  • Section 17
  • DPDPA Exemptions
  • Aadhaar
  • RTI
  • Public Sector
Key provision
Section 17(2) and 17(3)
Grounds
Sovereignty, security, public order
Constitutional limit
Puttaswamy proportionality test
RTI interaction
Section 8(1)(j) RTI Act 2005

Scope of Section 17 exemptions

Section 17 operates in three tiers:

  • Section 17(1): the Central Government is exempt from Section 8(1) (ground for processing) and Section 13 (grievance right) when processing personal data for prevention and detection of offences, or apprehension and prosecution of offenders—no separate notification is needed for this tier
  • Section 17(2): by notification, the Central Government may exempt any instrumentality of the state from any provision of the Act on grounds of sovereignty, security of the state, friendly relations with foreign states, maintenance of public order, or prevention/investigation/prosecution of offences. The notification may impose conditions
  • Section 17(3): exemption for research, archiving or statistical purposes—personal data must not be used for decisions about individual Data Principals

Constitutional limits: the Puttaswamy test

The Supreme Court’s Puttaswamy judgment (2017) established that any restriction on the right to privacy must satisfy legality, legitimate aim and proportionality. A Section 17(2) notification is “prescribed by law” (legality), and the listed grounds—sovereignty, security—are recognised as legitimate aims. The proportionality question is where challenges will arise.

A notification that exempts an agency from all DPDPA obligations without specifying the scope of data processing, the duration of the exemption or oversight mechanisms may fail the proportionality leg. Courts are likely to require that the exemption be narrowly tailored: limited to the data and purposes necessary for the stated aim, time-bound where possible and subject to review.

Aadhaar and DigiLocker: government platforms under the DPDPA

Aadhaar (UIDAI) and DigiLocker (NeGD) process personal data of hundreds of millions of individuals. The DPDPA applies to these platforms unless they are specifically exempted by a Section 17 notification.

The Aadhaar Act 2016 has its own consent and data-protection provisions. Section 16(2) of the DPDPA preserves stricter obligations in other laws—the Aadhaar Act’s biometric-data restrictions continue to apply. DigiLocker, which stores digitally signed copies of government-issued documents, processes identity data that falls within the DPDPA definition of personal data (Section 2(t)).

RTI vs data privacy: the unresolved tension

The Right to Information Act, 2005 (Section 8(1)(j)) exempts from disclosure personal information that has no relationship to any public activity or interest, or that would cause unwarranted invasion of privacy. The DPDPA does not amend the RTI Act, but the two statutes now operate in parallel.

The practical tension: an RTI applicant requests information that contains personal data of a third party. Under the RTI Act, the public authority must weigh the public interest against the privacy invasion. Under the DPDPA, the same public authority is a Data Fiduciary with obligations to the Data Principal whose data may be disclosed. Neither statute provides a clear priority rule. Courts will need to resolve this on a case-by-case basis—likely using the Puttaswamy proportionality framework.

How AMLEGALS advises on government data compliance

AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder and Managing Partner, with Rohit Lalwani, Associate Partner, working on DPDPA compliance. The firm advises government departments and public-sector undertakings on mapping their data-processing activities to the DPDPA framework, assessing the scope and validity of Section 17 exemptions, and designing compliance programmes that align with both the DPDPA and the Puttaswamy proportionality standard.

Bottom line

Section 17 exemptions are not blanket—they require formal notification, must state grounds and will face proportionality review under Puttaswamy. No government agency is automatically outside the DPDPA.

Key terms
Instrumentality of the state
A body that performs government functions or is under substantial government control—the entity that Section 17(2) exemptions can apply to.
Section 8(1)(j) RTI Act
The RTI exemption for personal information unrelated to public activity or interest, or disclosure of which would cause unwarranted privacy invasion.
Questions and answers

Government Data Processing: common questions

Are government agencies exempt from the DPDPA?

Not by default. Section 17(1) provides a narrow automatic exemption for crime prevention/prosecution. All other exemptions under Section 17(2) require a formal Central Government notification with stated grounds.

Can a Section 17 exemption be challenged in court?

Yes. Any exemption that fails the Puttaswamy proportionality test—lacking narrow tailoring, time limits or oversight—is vulnerable to constitutional challenge.

Does the DPDPA override the RTI Act?

No. The two statutes operate in parallel. The DPDPA does not amend the RTI Act. Where they conflict—a disclosure request for third-party personal data—courts will resolve the tension using the proportionality framework.

Is Aadhaar data exempt from the DPDPA?

Not automatically. The Aadhaar Act’s own data-protection provisions continue to apply under Section 16(2) of the DPDPA. A specific Section 17 notification would be needed to exempt UIDAI from DPDPA obligations.

Contact

Questions on government data compliance?

Submit a question about Section 17 exemptions or public-sector DPDPA obligations.

Or write to [email protected]

Your details

Name and email are enough to start. The reply comes from [email protected].

Your information is handled in accordance with our privacy obligations. No spam, ever.

Government Data Processing: questions and answers

What is the legal framework for data protection in India?

India's framework is the Digital Personal Data Protection Act, 2023 (Presidential assent 11 August 2023; 44 sections) read with the Digital Personal Data Protection Rules, 2025, notified on 13 November 2025 (G.S.R. 846(E)) with 23 Rules and 7 Schedules.

When do DPDPA obligations apply to businesses?

The Act and Rules follow phased commencement. Institutional provisions commenced on 13 November 2025; Consent Manager provisions commence after 12 months on 13 November 2026; and the principal Data Fiduciary, rights, breach, security and enforcement provisions commence after 18 months on 13 May 2027.

What is the maximum penalty under DPDPA?

Highest listed maximum for a specified contravention: ₹250 crore under the Schedule to the Act. Penalties are imposed by the Data Protection Board of India after an inquiry, and Section 33(2) requires the Board to consider factors such as the nature, gravity and duration of the breach, the type of personal data affected, repetition, mitigation steps and proportionality.

Which provisions of the DPDPA and the DPDP Rules, 2025 are relevant to Government Data Processing?

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).

Who advises businesses on Government Data Processing under India's DPDPA?

AMLEGALS, an Indian law firm, advises Data Fiduciaries, Data Processors and foreign companies on Government Data Processing under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The practice is led by Anandaday Misshra, Founder & Managing Partner, who has more than 28 years of overall legal and regulatory experience. Enquiries: https://amlegalsdpdpa.com/contact or [email protected] or [email protected].

What should I send AMLEGALS to get a scoped proposal on Government Data Processing?

Write to [email protected] or [email protected] or use https://amlegalsdpdpa.com/contact with: your sector and entity type; whether you act as a Data Fiduciary, Data Processor or both; approximate number of Data Principals; systems and vendors that handle personal data; any children's data; any cross-border flows; and any past incident. With these facts a partner can propose a scope for Government Data Processing rather than a generic checklist.

How do I get a first view of my DPDPA exposure on Government Data Processing?

Use the DPDPA Exposure Assessment at https://amlegalsdpdpa.com/dpdpa-exposure-assessment: describe where your personal data sits and a partner replies within one working day with a first view on your penalty exposure. Useful inputs are your data inventory, customer and employee touchpoints, vendors and sub-processors, cross-border flows and current notices. The principal obligations commence on 13 May 2027. Content is general legal information and not legal advice.

Contact AMLEGALS about Government Data Processing · DPDPA Exposure Assessment