The State Exemption Under DPDPA Section 17(2)(a): What Vendors Must Know
The State Exemption Under DPDPA Section 17(2)(a): What Vendors Must Know
Read the notification. Then read your contract. Then read them again.
The scene
The vendor's compliance note said ‘Government client, DPDPA not applicable’. It had been copied from a deck. Nobody had read the notification, because none had been issued for that department.
Where the thinking breaks
The unclear thought What it breaks The clearer thought
All government work is exempt.
Section 17(2)(a) applies only to instrumentalities the Government notifies, for stated interests.
Check whether a notification exists and what it covers.
If the department is exempt, so are we.
Your own processing and your own staff data remain in scope.
Separate the department's position from yours.
Contracts are catching up
Government contracts increasingly include data protection terms regardless of exemptions. The vendor that already meets them is the vendor that renews.
Monday morning
01 List every government contract involving personal data.
02 Check for any exemption notification.
03 Brief delivery teams on what applies regardless.
Questions, answered plainly
Does DPDPA apply to government departments? +
DPDPA applies to the State, but Section 17(2)(a) lets the Central Government exempt notified instrumentalities in specified interests such as sovereignty, security and public order.
Are private vendors covered by government exemptions? +
Not automatically. The scope depends on the notification. Vendors should assume DPDPA applies to their own processing and contract accordingly.
Sector · Government vendors The State's exemption is not your exemption. Read →
Government vendors · Deep dive The contract ended. The citizens' data did not. Read →
Government vendors · Deep dive Real citizens in test data. Read →
Tell us where your data sits. We'll show you where the exposure is.
A partner replies within one working day, with a first view on your penalty exposure.
Speak to a partner →
Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).