Section 17 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Clauses (d), (e) and (f) of section 17(1) cover three commercial situations: an India-based business processing data of people outside India under a contract with a person outside India, processing needed for a court-approved merger, demerger or similar scheme, and a financial institution ascertaining the finances of a defaulter. In each, Chapters II and III and section 16 are disapplied, except section 8(1) and 8(5). Our legal due diligence team regularly deals with the data side of such transactions.
Clause (d): personal data of Data Principals not within India, processed under a contract with a person outside India by a person based in India. Clause (e): processing necessary for a scheme of compromise, arrangement, merger, amalgamation, demerger, transfer of undertaking or division of companies approved by a competent court, tribunal or authority. Clause (f): ascertaining the financial information, assets and liabilities of a person who has defaulted on a loan or advance from a financial institution, subject to other laws on disclosure. Section 8(1) and 8(5) still apply in all three.
Reminder: what the exemption removes
Under section 17(1) the provisions of Chapter II (sections 4 to 10), Chapter III (sections 11 to 15) and section 16 do not apply, except sub-sections (1) and (5) of section 8. The Board and penalties stay. Clauses (a) to (c) are in the earlier article.
At a glance
| Clause | Situation | Key conditions |
|---|---|---|
| (d) | Overseas customers' data processed in India | Data Principals not within India; contract with a person outside India; processor is based in India |
| (e) | Corporate restructuring | Processing necessary for the scheme; scheme approved by a court, tribunal or competent authority |
| (f) | Loan defaulters | Purpose is ascertaining financial information, assets and liabilities; person has defaulted on a loan or advance from a financial institution; other disclosure laws respected |
Clause (d): the outsourcing exemption
The text applies where "personal data of Data Principals not within the territory of India is processed pursuant to any contract entered into with any person outside the territory of India by any person based in India". Three conditions must all be met.
- The Data Principals are not within India.
- There is a contract with a person outside India.
- The processing is by a person based in India under that contract.
This is the situation of an Indian service provider handling data for a foreign client. The clause is aimed at that arrangement and relieves the Indian provider from Chapters II and III and section 16 for that data. The Act's reach over processing outside India in section 3(b) depends on offering goods or services to Data Principals within India; clause (d) speaks to the reverse flow. See section 3.
What it does not say: it does not exempt the foreign client, it does not cover data of people who are in India, and it does not say what happens if a Data Principal is in India at the time of processing. Questions like a foreign customer travelling in India are not answered by the text; take advice on such mixed datasets and keep them separate where you can. Section 8(1) and 8(5) apply, so the Indian provider remains responsible for security and for its own processors.
Clause (e): court-approved schemes
Clause (e) covers processing "necessary for a scheme of compromise or arrangement or merger or amalgamation of two or more companies or a reconstruction by way of demerger or otherwise of a company, or transfer of undertaking of one or more company to another company, or involving division of one or more companies". The scheme must be "approved by a court or tribunal or other authority competent to do so by any law for the time being in force".
Two practical points.
- Approval is a condition. The text speaks of a scheme "approved by" the competent body. It does not say whether processing before approval is covered, so a cautious approach is to limit pre-approval sharing to what the scheme needs and treat a data room as a place for minimal personal data.
- Necessity again. Employee lists, customer contracts and vendor records may need to move. Data that the scheme does not need does not fall within the clause.
This matters in transactions where the buyer's team reviews employee and customer data. Section 17(1)(e) does not exempt a due diligence exercise for a private share purchase with no court-approved scheme. See the related discussion in section 7 for legitimate uses tied to legal and court functions.
Clause (f): loan defaulters
Clause (f) applies where processing is "for the purpose of ascertaining the financial information and assets and liabilities of any person who has defaulted in payment due on account of a loan or advance taken from a financial institution, subject to such processing being in accordance with the provisions regarding disclosure of information or data in any other law for the time being in force."
The Explanation gives "default" and "financial institution" the meanings in sub-sections (12) and (14) of section 3 of the Insolvency and Bankruptcy Code, 2016. So the clause uses that Code's definitions and the lender must fit them.
The Act's own Illustration. X takes a loan from Y, a bank. X defaults on her monthly instalment on the due date. Y may process X's personal data for ascertaining her financial information, assets and liabilities.
Three limits are worth stating.
- The purpose is tracing financial information and assets and liabilities, not any use of the borrower's data.
- The processing must follow other laws on disclosure of information or data, so the clause does not override confidentiality or disclosure rules in other laws.
- The text does not say how long after default the clause applies or that a single missed instalment is enough; the Illustration uses a missed instalment on the due date.
What the three clauses have in common
- Section 8(1) and 8(5) continue, so security safeguards and responsibility for Data Processors stay.
- No consent or notice is required for the covered processing.
- The Data Principal's rights in sections 11 to 14 do not apply.
- The Board's inquiry power and penalties continue.
Common mistakes
- Using clause (d) for data of people in India or for marketing to foreign customers.
- Treating a due diligence data room as a clause (e) scheme when no approved scheme exists.
- Using clause (f) for debt collection activities beyond ascertaining finances, such as contacting relatives.
- Dropping security controls on the footing that the data is exempt.
Need help with data in transactions and recoveries?
If you are preparing a restructuring, a cross-border service contract or a lender's recovery process, the data questions should be settled before documents move. Our legal due diligence team can help you work out what may be shared, with whom and on what record.
Key takeaways
- Clause (d) protects India-based processing of non-India Data Principals' data under a contract with a person outside India.
- Clause (e) needs a scheme approved by a competent court, tribunal or authority.
- Clause (f) uses the IBC 2016 meanings of "default" and "financial institution" and respects other disclosure laws.
- Section 8(1) and 8(5) apply in all three.
- Necessity and purpose limit each clause.
Read next
- Section 17: legal claims, courts and offences
- Section 17(3): startups and notified Data Fiduciaries
- Section 3 of the DPDP Act, 2023: application inside and outside India
- Data processing agreement template for DPDP compliance
Disclaimer: Based on the Digital Personal Data Protection Act, 2023 (official text as enacted, No. 22 of 2023) as on 30 September 2026. The DPDP Rules, 2025 were notified in November 2025 and different provisions commence on different dates; this article does not state rule-level detail. Verify the current position in the Rules and the commencement notifications before acting.
