Infosek
INFOSEK

DPDP for Startups: Is There Really an Exemption?

There is a provision. It is not what most founders think it is, it has to be activated by a government notification, and even at its fullest it leaves the two most expensive obligations untouched.

DPDP for Startups: Is There Really an Exemption?

The short answer

Section 17(3) gives the Central Government a power, having regard to the volume and nature of personal data processed, to notify certain Data Fiduciaries including startups as ones to whom section 5, sub-sections (3) and (7) of section 8, and sections 10 and 11 do not apply.

Two things follow, and both matter:

What the definition requires

Section 17(3) defines a startup narrowly. It means a private limited company, a partnership firm or a limited liability partnership incorporated in India, which is eligible to be and is recognised as a startup in accordance with the criteria and process notified by the department to which startup matters are allocated in the Central Government.

So it is not a self-description. It requires formal recognition, and it excludes companies incorporated outside India regardless of how early stage they are.

What it would never cover

This is the part worth reading closely. The provisions capable of being disapplied are section 5, section 8(3), section 8(7), section 10 and section 11. Nothing in that list touches:

The three largest penalty heads in the Schedule sit entirely outside the reach of the startup provision. A startup that assumes it is exempt is assuming away the obligations that are cheapest to build early and most expensive to fail.

Read the provision as relief from paperwork, never as relief from securing data. The drafters left security, breach reporting and children's data in place for everyone, which is a clear signal about what they considered non-negotiable.

Infosek Team

Why building it early is cheaper anyway

Rule 6 requires access control, logging with one year retention, encryption or equivalent, and backups. Rule 8 requires erasure against a retention clock. Rule 14 requires finding one individual's data across your systems on request.

Every one of those is straightforward when you have three services and no legacy, and painful at thirty services with data spread across systems nobody fully remembers. The cost of doing it later is not the compliance work, it is the archaeology.

The enterprise sales reason, which usually lands harder

Long before a regulator asks, a customer will. Any bank, NBFC, insurer or large enterprise buying from you will run a vendor security assessment, and from 2027 those questionnaires will ask about DPDP position directly.

At that point the exemption question is irrelevant, because your customer is not the Data Protection Board and is under no obligation to accept it. A startup that cannot answer how it handles retention, access control or breach notification loses the deal regardless of what section 17(3) says.

What to actually do

Common questions

Are startups exempt from the DPDP Act?

Not automatically. Section 17(3) empowers the Central Government to notify certain Data Fiduciaries, including startups, as ones to whom section 5, section 8(3), section 8(7), section 10 and section 11 do not apply. The exemption depends on a notification being made and covering you. Without that, the full obligations apply.

What counts as a startup under the DPDP Act?

Section 17(3) defines a startup as a private limited company, partnership firm or limited liability partnership incorporated in India that is eligible to be, and is, recognised as a startup in accordance with the criteria and process notified by the government department to which startup matters are allocated.

Building this in early?

Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.

Book Free 30-Min Assessment