Section 17 (
Exemptions): Two layers of exemptions apply. (i) Under Section 17(2)(a), the Central Government may notify specific instrumentalities to be exempt from the entire Act in the interest of sovereignty and integrity of India, security of the State, friendly relations with foreign States, maintenance of public order, or prevention of offences. (ii) Section 17(1) also provides "automatic" exemptions for all Data Fiduciaries (including private entities) for specific purposes such as enforcement of legal claims, judicial functions, and prevention, detection, investigation or prosecution of offences - without requiring a separate notification.
Section 7 (
Legitimate Uses): Government processing falls under specific, enumerated legitimate use categories - performance of State functions (permits, licenses, subsidies, benefits) and compliance with legal obligations. The DPDPA does not include a broad "public interest" ground equivalent to the GDPR; processing must map to a specific Section 7 sub-clause or rely on consent.
Section 8 (Residual Obligations): Section 8(5) (Security Safeguards) is non-derogable - even notified exempt agencies (such as IB or CBI) must maintain reasonable security safeguards. By contrast, under Section 17(4), the State is specifically exempted from the accuracy requirement (Section 8(3)) and the erasure requirement (Section 8(7)) where the processing is not used to make a decision that affects the Data Principal.
Section 18-26 (
Data Protection Board): The Board adjudicates complaints against Government bodies (unless exempted). Government entities must establish grievance redressal mechanisms and respond to Data Principal requests.