Section 17 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
The first three clauses of section 17(1) remove most of the Act's obligations where personal data is processed to enforce a legal right or claim, by a court, tribunal or regulatory body for its function, or for the prevention, detection, investigation or prosecution of offences. Two duties survive: section 8(1) and section 8(5). If you handle disputes or recoveries and need to know how far this goes, our legal dispute resolution team can help.
Under section 17(1), Chapter II (sections 4 to 10), Chapter III (sections 11 to 15) and section 16 do not apply in the listed cases, except section 8(1) and section 8(5). Clauses (a) to (c) cover processing necessary for enforcing a legal right or claim, processing by a court, tribunal or body entrusted with a judicial, quasi-judicial, regulatory or supervisory function, and processing in the interest of prevention, detection, investigation or prosecution of an offence or contravention of law. The Board, penalties and the rest of the Act still apply.
The opening words: what is switched off
Section 17(1) begins: "The provisions of Chapter II, except sub-sections (1) and (5) of section 8, and those of Chapter III and section 16 shall not apply where" one of the six clauses is met. This article covers clauses (a), (b) and (c). Clauses (d), (e) and (f) are in the next article.
| Part of the Act | Sections | In a section 17(1) case |
|---|---|---|
| Chapter II | 4 to 10 | Does not apply, except 8(1) and 8(5) |
| Chapter III | 11 to 15 | Does not apply |
| Section 16 (cross-border) | 16 | Does not apply |
| Board, inquiry, appeal, penalties, miscellaneous | 18 onwards | Continue to apply |
So in these cases the fiduciary need not rely on consent or a legitimate use (section 4 to 7), need not give notice (section 5), and need not observe the section 8 duties other than 8(1) and 8(5). That means no section 8(6) breach intimation, no section 8(7) erasure, no accuracy duty under 8(3) and no Data Protection Officer contact publication under 8(9). Children's and Significant Data Fiduciary duties (sections 9 and 10) also fall away, as do the Data Principal's rights in sections 11 to 14 and the duties in section 15.
What still applies: section 8(1) and section 8(5)
- Section 8(1): the Data Fiduciary is responsible for complying with the Act in respect of processing under its control, including by a Data Processor, irrespective of any agreement or failure of a Data Principal.
- Section 8(5): the duty to protect personal data in its possession or control by taking reasonable security safeguards to prevent a personal data breach.
A breach of the safeguards duty is penalised under item 1 of the Schedule, up to two hundred and fifty crore rupees. The exemption therefore never reaches the security duty. A litigation team holding a dataset for a claim must still secure it. See section 8(5).
Clause (a): necessary for enforcing any legal right or claim
The test is necessity for enforcing "any legal right or claim". The clause does not say whose right or what forum. It can cover a business preparing or pursuing a recovery, a contract claim or a defence. The word "necessary" limits it: data that the claim does not need is outside the clause. The Act does not define "enforcing", and it does not say whether it reaches threatened claims that have not been filed; read the clause on its words and keep the file factual.
Example: a company is sued by a former distributor and gathers invoices and emails that name individuals. Processing needed to assert or defend the claim falls within clause (a); circulating the same data to staff who have no role in the case would not be "necessary".
Clause (b): courts, tribunals and regulatory bodies
Clause (b) applies to processing "by any court or tribunal or any other body in India which is entrusted by law with the performance of any judicial or quasi-judicial or regulatory or supervisory function", where the processing is necessary for that function. Three features matter.
- The body must be entrusted by law. A private organisation cannot claim it because it supervises its own members by policy.
- The body must be in India.
- The processing must be necessary for the function. A regulator's ordinary staff records, payroll for example, are not covered by the function test.
Whether the clause helps the parties who supply data to such a body is a separate question. A company that files documents with a tribunal is processing for enforcing a claim or defence, which is clause (a), not clause (b).
Clause (c): prevention, detection, investigation or prosecution of offences
Clause (c) covers personal data processed "in the interest of prevention, detection, investigation or prosecution of any offence or contravention of any law for the time being in force in India". Note the width: "contravention of any law", not only crimes. The clause does not limit the processor to the State. A bank or an employer running an internal fraud investigation may rely on it if the processing is truly in the interest of detecting or investigating an offence or contravention.
Section 11(2) is a related but narrower rule. It excludes from the access right the sharing of data with another Data Fiduciary authorised by law that has made a written request for prevention, detection or investigation of offences or cyber incidents, or for prosecution or punishment. See section 11.
What section 17(1) does not do
- It does not exempt the fiduciary from the Board's jurisdiction. The Board can inquire under section 28 and penalise under section 33.
- It does not remove section 8(1) or 8(5).
- It does not say the exempt data may be kept indefinitely. Section 8(7) erasure does not apply, but the Act sets no retention period for exempt processing; other laws and court directions govern.
- It does not create a new ground for using data for unrelated purposes. The exemption is tied to the stated necessity.
Common mistakes
- Treating the exemption as a blanket licence for a department because one matter is in court.
- Forgetting the security duty on exempt data.
- Relying on clause (b) when the body is not entrusted by law with the function.
- Stretching clause (c) to routine staff monitoring with no offence or contravention in view.
Need help with exemptions and disputes?
Deciding whether a dispute file, a regulator response or an internal investigation fits section 17(1) is a question of facts and records. Our legal dispute resolution team can help you document the necessity and set up access controls for exempt data.
Key takeaways
- Section 17(1) disapplies Chapters II and III and section 16 in six listed cases; this article covers three.
- Section 8(1) and 8(5) continue to apply.
- Clause (a): necessary to enforce a legal right or claim. Clause (b): courts, tribunals and bodies with judicial, quasi-judicial, regulatory or supervisory functions. Clause (c): offences and contraventions of law.
- The Board and penalties still apply.
- Necessity is the limit in all three clauses.
Read next
- Section 17: foreign contracts, mergers and defaulters
- Section 17(2): State security, research and statistics
- Section 8 of the DPDP Act, 2023: reasonable security safeguards
- Section 7 of the DPDP Act, 2023: legal obligations, courts and State functions
Disclaimer: Based on the Digital Personal Data Protection Act, 2023 (official text as enacted, No. 22 of 2023) as on 30 September 2026. The DPDP Rules, 2025 were notified in November 2025 and different provisions commence on different dates; this article does not state rule-level detail. Verify the current position in the Rules and the commencement notifications before acting.
