Section 17 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Section 17(3) does not exempt startups automatically. It lets the Central Government, having regard to the volume and nature of personal data processed, notify certain Data Fiduciaries or classes of them, "including startups", to whom section 5, sub-sections (3) and (7) of section 8, and sections 10 and 11 shall not apply. Until a notification covers your business, the full Act applies. A legal consultation can help you check where you stand.
The power is exercised by notification, having regard to volume and nature of personal data. A notified fiduciary is relieved of only five things: the notice in section 5, the accuracy duty in section 8(3), the erasure and retention duty in section 8(7), the Significant Data Fiduciary provisions in section 10, and the right of access in section 11. Consent, security safeguards, breach intimation, children's protections and most rights still apply. "Startup" has a defined meaning in the Explanation.
What is relieved and what is not
| Provision | Subject | For a notified Data Fiduciary |
|---|---|---|
| Section 5 | Notice to Data Principal | Does not apply |
| Section 8(3) | Completeness, accuracy and consistency where data is used for a decision affecting the Data Principal or disclosed to another Data Fiduciary | Does not apply |
| Section 8(7) | Erasure on withdrawal of consent or when the specified purpose is no longer served; Data Processor to erase | Does not apply |
| Section 10 | Significant Data Fiduciary duties | Does not apply |
| Section 11 | Right to access information about personal data | Does not apply |
| Sections 4, 6, 7 | Grounds, consent, legitimate uses | Apply |
| Section 8(1), (2), (4), (5), (6), (9), (10), (11) | Responsibility, processors, measures, security, breach, contact, grievance | Apply |
| Section 9 | Children | Applies |
| Sections 12 to 15 | Correction, erasure request, grievance, nomination, duties | Apply |
Two items deserve attention. Section 8(7) is about erasure by the fiduciary, but the Data Principal's right to ask for erasure in section 12(3) is not listed in section 17(3), so it is not disapplied for startups by this sub-section. And section 8(5) is untouched: a notified startup faces the same security duty and the same Schedule item 1 penalty, up to two hundred and fifty crore rupees, as anyone else.
"Startup" in the Act
The Explanation says a startup means "a private limited company or a partnership firm or a limited liability partnership incorporated in India, which is eligible to be and is recognised as such in accordance with the criteria and process notified by the department to which matters relating to startups are allocated in the Central Government."
Break that into parts.
- Form: a private limited company, a partnership firm or an LLP. A proprietorship or a public company is not in the text.
- Incorporated in India.
- Recognition: eligible to be, and recognised as, a startup under the criteria and process notified by the relevant department. The Act does not state the criteria.
Being a recognised startup is therefore a necessary start but not enough. The clause says the Government "may" notify, and the power is exercised having regard to "the volume and nature of personal data processed". A startup that processes a very large volume of sensitive data is not assured of relief, and a business that is not a startup may still be notified as part of a class.
Not limited to startups
The phrase is "certain Data Fiduciaries or class of Data Fiduciaries, including startups". So a notification could cover, for example, small processors of a specified kind of data, whether or not they are startups. The Act does not give a size test, a turnover figure or a list of classes. Read the notification and the DPDP Rules, 2025 (notified November 2025) for what has actually been notified; the Act does not say.
Interaction with other sections
- Section 10. A fiduciary to whom section 10 does not apply cannot be treated as a Significant Data Fiduciary under it. That also removes the section 10(2) duties and the Schedule item 4 penalty for them. See section 10.
- Section 17(5). A separate five-year power allows the Government to declare that any provision of the Act shall not apply to specified fiduciaries for a specified period. See sections 17(4) and (5).
- Section 5(2). Section 5 is relieved, which includes the notice for consent given before commencement. The Act does not say more.
Practical consequences for a startup
- Do not assume. Keep a simple record of whether any notification covers your entity, and of the date and text.
- Build the basics anyway. Consent records, security safeguards, breach response and grievance handling apply regardless, and they are where the larger penalties sit.
- Design for removal of relief. Notified relief can change. If you build notice and erasure routines now, a change costs you little.
- Investors and buyers. In diligence, a buyer will ask whether you rely on an exemption. Be ready to show the notification, not a guess.
Example
A recognised LLP runs a small app with a modest volume of data. Suppose a notification covers it under section 17(3). It need not send a section 5 notice or respond to a section 11 access request under the Act. But if a user asks it to correct her data under section 12(2), it must act. And if its database is breached, sections 8(5) and 8(6) apply: safeguards, and intimation of the breach to the Board and affected Data Principals in the manner the Rules prescribe.
Mistakes to avoid
- Saying "we are a startup, so the DPDP Act does not apply to us".
- Dropping consent capture because notice is relieved. Section 6 requires consent to be given for a specified purpose and to be free, specific, informed, unconditional and unambiguous; dropping notice weakens that basis.
- Ignoring the requirement to be recognised as a startup under the notified criteria.
- Forgetting that the penalty for other provisions is up to fifty crore rupees (Schedule, item 7).
Need help deciding what applies to your business?
Whether you rely on a notification or plan to build the full programme, the first step is an honest map of your data and duties. Our legal consultation team can help you test your position and prepare the records a buyer or investor will want to see.
Key takeaways
- Section 17(3) is a notification power, not an automatic exemption.
- Relief covers only section 5, sections 8(3) and 8(7), section 10 and section 11.
- Consent, security, breach intimation, children and most rights continue.
- "Startup" means a recognised private limited company, partnership firm or LLP incorporated in India.
- The Government looks at volume and nature of data processed.
Read next
- Impact of the DPDP Act on startups
- Section 17(4) and (5): State processing and the five-year power
- Section 10 of the DPDP Act, 2023: notifying a Significant Data Fiduciary
- Section 11 of the DPDP Act, 2023: right to access information
Disclaimer: Based on the Digital Personal Data Protection Act, 2023 (official text as enacted, No. 22 of 2023) as on 30 September 2026. The DPDP Rules, 2025 were notified in November 2025 and different provisions commence on different dates; this article does not state rule-level detail. Verify the current position in the Rules and the commencement notifications before acting.
