DPDP for Startups: Is There Really an Exemption?
There is a provision. It is not what most founders think it is, it has to be activated by a government notification, and even at its fullest it leaves the two most expensive obligations untouched.
The short answer
Section 17(3) gives the Central Government a power, having regard to the volume and nature of personal data processed, to notify certain Data Fiduciaries including startups as ones to whom section 5, sub-sections (3) and (7) of section 8, and sections 10 and 11 do not apply.
Two things follow, and both matter:
- It is a power to notify. Unless a notification has been made and it covers you, nothing is disapplied.
- Even when it applies, it disapplies a specific and fairly short list. It is not a general exemption from the Act.
What the definition requires
Section 17(3) defines a startup narrowly. It means a private limited company, a partnership firm or a limited liability partnership incorporated in India, which is eligible to be and is recognised as a startup in accordance with the criteria and process notified by the department to which startup matters are allocated in the Central Government.
So it is not a self-description. It requires formal recognition, and it excludes companies incorporated outside India regardless of how early stage they are.
What it would never cover
This is the part worth reading closely. The provisions capable of being disapplied are section 5, section 8(3), section 8(7), section 10 and section 11. Nothing in that list touches:
- Section 8(5), reasonable security safeguards. The head carrying up to ₹250 crore.
- Section 8(6), notice of a personal data breach to the Board and affected Data Principals. Up to ₹200 crore.
- Section 9, the additional obligations in relation to children. Up to ₹200 crore.
The three largest penalty heads in the Schedule sit entirely outside the reach of the startup provision. A startup that assumes it is exempt is assuming away the obligations that are cheapest to build early and most expensive to fail.
Read the provision as relief from paperwork, never as relief from securing data. The drafters left security, breach reporting and children's data in place for everyone, which is a clear signal about what they considered non-negotiable.
Infosek Team
Why building it early is cheaper anyway
Rule 6 requires access control, logging with one year retention, encryption or equivalent, and backups. Rule 8 requires erasure against a retention clock. Rule 14 requires finding one individual's data across your systems on request.
Every one of those is straightforward when you have three services and no legacy, and painful at thirty services with data spread across systems nobody fully remembers. The cost of doing it later is not the compliance work, it is the archaeology.
The enterprise sales reason, which usually lands harder
Long before a regulator asks, a customer will. Any bank, NBFC, insurer or large enterprise buying from you will run a vendor security assessment, and from 2027 those questionnaires will ask about DPDP position directly.
At that point the exemption question is irrelevant, because your customer is not the Data Protection Board and is under no obligation to accept it. A startup that cannot answer how it handles retention, access control or breach notification loses the deal regardless of what section 17(3) says.
What to actually do
- Assume full applicability unless you can point to a notification that covers you.
- Build the Rule 6 controls now. They are never exempted and they are the largest penalty head.
- Write down a retention period per data set and enforce it in code before the data volume makes it hard.
- If under-18s can access your product, treat section 9 and Rule 10 as a priority. No startup provision reaches them.
- Keep a short record of what you hold and why. It becomes your inventory, your notice content and your questionnaire answers at once.
Common questions
Are startups exempt from the DPDP Act?
Not automatically. Section 17(3) empowers the Central Government to notify certain Data Fiduciaries, including startups, as ones to whom section 5, section 8(3), section 8(7), section 10 and section 11 do not apply. The exemption depends on a notification being made and covering you. Without that, the full obligations apply.
What counts as a startup under the DPDP Act?
Section 17(3) defines a startup as a private limited company, partnership firm or limited liability partnership incorporated in India that is eligible to be, and is, recognised as a startup in accordance with the criteria and process notified by the government department to which startup matters are allocated.
Building this in early?
Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.
Book Free 30-Min Assessment