Hands of a young startup founder resting on a closed laptop beside a steel tumbler of chai in a small Indian software office

DPDP Act startups India: the exemption exists, and it is narrow

A thirty-four person software startup in Indore had been told it was exempt. The clause they were relying on is real. It is also three lines long, and it has not been switched on.

Hands of a young startup founder resting on a closed laptop beside a steel tumbler of chai in a small Indian software office
Most founders meet DPDP through a customer’s security questionnaire, not through a regulator.
The short version

Do startups in India need to comply with the DPDP Act? Yes, today they do. There is a genuine startup exemption written into the law, and it has not been switched on. Section 17(3) of the Digital Personal Data Protection Act, 2023 lets the Central Government exempt notified classes of data fiduciaries, startups named among them, from Section 5, Sections 8(3) and 8(7), Section 10 and Section 11.

Two things stop that from being an answer. It reaches only a startup recognised by DPIIT, and it works only once the government publishes a notification naming that class. No such notification has been published.

Even at full stretch it leaves consent, security safeguards, breach intimation, correction and erasure on request, and grievance redressal exactly where they are. Substantive obligations commence on 13 May 2027, under the phased notification of 13 November 2025.

10:05 AM on a Tuesday, and Sanjana had sent me a screenshot instead of a question.

It was a WhatsApp message from someone on her cap table. Four words and a full stop. Startups are exempt, relax. She runs a B2B software company in Indore, thirty-four people, four years old, DPIIT recognised, and she had just been handed a vendor security questionnaire by her first real enterprise customer. An NBFC. Twenty-two pages. Page nine asked how she handled data principal rights requests.

So she wanted to know whether she could write not applicable in that box and move on with her week.

No, I said. But you were not wrong to ask, because there is a clause, and almost nobody who quotes it has read past the first line.

10:40 AM, and the clause was three lines long

Section 17(3) is the only place in the Act where the word startup appears. It says the Central Government may notify certain data fiduciaries, or classes of them, including startups, to whom five things will not apply. Section 5, which is the notice you give people. Sub-section (3) of Section 8, which is keeping data accurate when you use it to make a decision about someone. Sub-section (7) of Section 8, which is deleting data once the purpose is done. Section 10, which is the extra apparatus a Significant Data Fiduciary carries. Section 11, which is a person’s right to ask what you hold about them.

That is the whole exemption. Five items, and the Act is careful to define what it means by startup: a private limited company, a partnership firm or an LLP incorporated in India and recognised as a startup by the department that handles startups in the Central Government. That department is DPIIT.

Sanjana read it twice on the call and then said the thing every founder says at this point. So we are covered.

Not yet. The sub-section is permissive. It gives the government a power to notify, and until a notification names a class, nothing lifts. I have watched people build a compliance plan on a sentence that begins with the words may notify.

Three gates the startup exemption has to pass

Here is the part founders get wrong. They read Section 17(3) as a status they already hold. It is a door with three locks on it, and at least one of them is not yours to open.

The first is recognition. You need a live DPIIT startup certificate, not a self-description. The recognition framework was revised this year: the ten-year window from incorporation stays, and the turnover ceiling moved up to ₹200 crore for a regular startup, per the DPIIT notifications page. Plenty of companies that call themselves startups in a pitch deck have never applied. A four-year-old trading firm with eleven employees is a small business, and small businesses get nothing from this clause.

The second is the notification itself. It has to exist, it has to name your class, and it can carve the list narrower than the Act allows. Nothing has been issued. Until one is, Section 17(3) is a possibility in a statute, not a defence in a questionnaire.

The third is scope. Even the widest reading of the clause touches five obligations out of the set your customers actually ask about. The ones that hurt on a Tuesday afternoon are not on the list.

The line to remember
Sub-section (7) of Section 8 can be lifted. Section 12 cannot. That means an exempt startup would lose the duty to delete data on its own initiative, and keep the duty to delete it when a person asks. Your housekeeping goes away. Their right does not.

What Section 17(3) would remove, and what stays

We went through it line by line on a shared screen, because the table is the argument. This is the version I sent her afterwards.

ObligationWhat it asks of youWould 17(3) lift it
Section 5, noticeTell people what you collect, why, and how to complain, in plain languageYes, once notified
Section 8(3), accuracyKeep data correct where you use it to decide about someone or share it onwardYes, once notified
Section 8(7), erasure on your own initiativeDelete when consent is withdrawn or the purpose endsYes, once notified
Section 10, Significant Data Fiduciary dutiesNamed DPO in India, independent audit, impact assessmentYes, and you were unlikely to be notified as one anyway
Section 11, right to informationGive a person a summary of their data and the parties you shared it withYes, once notified
Section 6, consentFree, specific, informed and unconditional, with a plain withdrawal routeNo
Section 8(5), security safeguardsEncryption, access control, logs, backups, and the same on your processorsNo
Section 8(6), breach intimationTell the Board and every affected personNo
Section 12, correction and erasure on requestFix it or delete it when the person asks you toNo
Section 13, grievance redressalA published contact, an owner, and a stated response periodNo

Section numbering follows the Digital Personal Data Protection Act, 2023. The operating detail for safeguards, breach reporting and grievance handling sits in the Digital Personal Data Protection Rules, 2025.

Look at the bottom half of that table and then look at page nine of a vendor questionnaire. They are the same list. Procurement teams do not ask whether you are exempt from notice. They ask who owns a rights request, how fast you answer it, and what happens the day something leaks.

The Rules cap your grievance response at 90 days (Rule 14), and that ceiling applies to you whether or not a notification ever names startups. We wrote up what that clock does to a firm that ignores it in the enforcement piece on how the first complaint actually reaches you.

The bit I got wrong for most of a year

I want to be honest about a mistake, because the mistake is the lesson.

Through most of last year I repeated the startup exemption line myself. I had picked it up from a conference slide, one of those summary decks where 17(3) sits in a green box labelled relief for small business, and I passed it on in three or four scoping calls without opening the bare Act. A founder in Kochi asked me directly whether he needed a deletion process. I said probably not, given your stage. Achha, that was a bad answer, and it was bad in a specific way. Section 8(7) was the sub-section in my head. Section 12 was the one his customer’s contract was about to reference.

He did not get hurt by it. His enterprise deal simply stalled for a quarter while we built what I had told him he could skip. Bas, I read the bare text now, every time, and I have stopped quoting green boxes.

What DPDP compliance actually costs a company this size

Then Sanjana asked the real question, which was about money and her engineering roadmap.

Her worry was reasonable. She had priced a compliance consultant at a number that would have taken a full sprint out of her quarter, and the proposal came with a data protection officer, a records-of-processing platform and a quarterly audit. For thirty-four people. That is the vendor we claim to hate, so I will say it plainly: she needed almost none of it.

DPDP does not have a headcount exemption, so data governance applies to you the same as it applies to the 2,500-device shop, just cheaper to set up now than to retrofit after an incident. Small is the right time to do this, not the reason to skip it. What that looked like for her was four weeks of ordinary work.

Name an owner. One person, by role, who receives rights requests and grievances. In a company this size that is usually the founder or the head of engineering, and writing the name down is most of the job.

Publish a contact and a period. An address that a human monitors and a stated window. Do not publish a general enquiries form. A published route nobody owns is worse than none, because it proves you knew the duty existed.

Write the retention rule before you buy anything. How long a trial signup survives, what happens to support attachments, when a churned customer’s records go. Most of what a rights request costs you is data that should already have been deleted. That deletion discipline is the same one we walk through in the DPDP guide written for Indian MSMEs.

Then find where personal data sits. For her that was the product database, a support desk, two spreadsheets and a shared drive of onboarding call recordings nobody had thought about. The recordings were the surprise. They usually are.

Last, close the exits. Knowing that a customer list left for a personal drive is a monitoring job, and that sits in Secure Data Guard. The other exit is hardware. A developer laptop that leaves the company unwiped carries a copy of production data more often than anyone admits, which is device lifecycle management rather than security software. If you are buying fifty or more machines this year, ask us about DaaS in the same conversation, because a certified wipe on return is cheaper as a line item than as a project.

Where our pitch loses, and I would rather write it here than defend it in a proposal. If you already have a named owner, a retention rule and a way to search your own systems, you do not need Sirius Star for the compliance part. Ask us for the endpoint and data-movement layer, or do not ask us at all. A founder who can answer a customer in a week has already bought most of what this article is about.

What sits at the far end
The Schedule to the Act prices a failure to take reasonable security safeguards at up to ₹250 crore, per the Act text. Quoting that ceiling at a thirty-four person company is fear-selling and we try not to do it. The realistic cost to Sanjana was a stalled enterprise deal and one awkward call with a customer’s risk team.

What to take away

  1. The clause is real and it is asleep. Section 17(3) names startups. It needs a government notification that has not been issued, so today it protects nobody.
  2. DPIIT recognition is the entry ticket. Ten years from incorporation, turnover under the revised ceiling, and an actual certificate. Calling yourself a startup does not count.
  3. Five obligations lift, five stay. Consent, security safeguards, breach intimation, correction and erasure on request, and grievance redressal are untouched by the exemption.
  4. Deleting on request survives. Section 8(7) is on the exempt list, Section 12 is not, so a person can still make you erase their data even if your own housekeeping duty is lifted.
  5. Your customer arrives before the regulator. Enterprise and BFSI procurement teams are asking these questions in vendor packs now, well ahead of 13 May 2027.

Four terms in this piece, in plain English

DPDP Act 2023
India’s national data protection law. If your company holds information about people in India, names, phone numbers, payment details, support tickets, the Act sets out what you may do with it and what you owe those people. The Rules under it, notified in November 2025, add the operating detail.
Data fiduciary
Your company, when it decides why and how personal data gets used. If you choose what to collect and what to do with it, you are the fiduciary and these duties are yours. There is a longer plain-English version in who counts as a data fiduciary under DPDP.
DPIIT recognition
A certificate from the Department for Promotion of Industry and Internal Trade confirming your company qualifies as a startup. It is an application with eligibility conditions on age, entity type and turnover. Section 17(3) borrows this definition, so without the certificate the exemption cannot reach you even after it is notified.
DaaS, or Device-as-a-Service
Renting your laptops instead of buying them. One monthly cost per device covers supply, support, replacement and a certified wipe when the machine comes back. It matters here because a developer’s returned laptop is one of the quietest ways customer data leaves a small company.

Questions Sanjana asked on that call

Does the DPDP Act exempt startups in India?

Not today. Section 17(3) of the Act allows the Central Government to notify classes of data fiduciaries, including startups, that are excused from Section 5, Sections 8(3) and 8(7), Section 10 and Section 11. That exemption takes effect only when a notification is published naming the class, and no such notification has been issued. Even after one arrives, it would reach only companies holding a live DPIIT startup recognition, and it would leave consent, security safeguards, breach intimation, correction and erasure on request, and grievance redressal fully in place.

We are a five-person company with no funding. Does DPDP apply to us?

Yes, if you hold information that identifies a living person in India. There is no headcount or revenue threshold in the Act. Customer email addresses, employee records, payment references and support tickets all count. What changes with size is proportionality rather than applicability. A five-person company needs a named owner for requests, a published contact, a retention rule and a way to search its own systems. It does not need the apparatus a bank builds, and a vendor telling you otherwise is selling licences.

If we get the exemption later, can we stop deleting customer data?

No. Sub-section (7) of Section 8, the duty to erase once consent is withdrawn or the purpose is served, sits on the exempt list. Section 12, the data principal’s right to demand correction and erasure, does not. So a notified startup would lose the obligation to clean up on its own schedule and keep the obligation to delete when a person asks. In practice you still need to know where the data is and be able to remove it, which is the expensive part either way.

Our customers keep sending security questionnaires. What do they actually check?

The bottom half of the obligation list rather than the top. Across the vendor packs we have reviewed for clients this year the recurring items are a named contact for data protection queries, a stated response time, evidence of encryption and access control, a breach notification process with a defined trigger, and a retention schedule. None of those is affected by Section 17(3). A startup that can answer those five questions in writing clears most enterprise onboarding, whatever its exemption status.

P.S. Priya here.
Sanjana closed the NBFC deal in September. The security questionnaire came back with one comment on it, from a risk analyst who had clearly read every answer. He had written a single word next to page nine. Finally. She screenshotted that one too and sent it to the investor who had told her to relax. Theek hai, she is allowed that.
Free readiness check
Get a free DPDP readiness check for your startup

We take the data protection section of a real enterprise vendor questionnaire, run it against your estate, and hand back the answers you can paste into the next one, plus the gaps that would fail it.

Get my free DPDP readiness check

Free. A short form, then we reply inside 24 working hours. 200+ Indian businesses work with us, from Vashi, Navi Mumbai.

Section numbering, exemption scope and commencement dates above follow the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 as they stood at the time of writing. The status of any notification under Section 17(3), and the current DPIIT recognition conditions, can change. Confirm both before relying on them. The Indore engagement is one anonymised client matter. This is a practitioner note on operating practice, not legal advice.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *