DPIIT recognition does not make DPDP lighter for your startup
Need help with dpdp? We can handle it for you.
A founder tells us their startup is DPIIT-recognised, so DPDP applies to them in a lighter form. It's a reasonable guess. Recognition brings tax breaks, easier public procurement, and a self-certification regime under labour and environmental law. Why would data protection be any different? Because the Digital Personal Data Protection Act doesn't work that way, and the gap between the guess and the statute is worth five minutes.
The exemption exists. It has not been switched on.
Section 17(3) of the Act gives the Central Government power to notify particular Data Fiduciaries, startups named specifically among them, as exempt from five obligations: section 5 (the notice requirement), section 8(3) (keeping personal data accurate and complete), section 8(7) (erasure once the purpose is served), section 10, and section 11. That's a real, meaningful carve-out if it's ever used. Read the sentence again, though. It describes a power the government may exercise someday. It does not describe a rule already in force. As of this writing, no notification under section 17(3) has been issued.
The Central Government may, subject to such conditions as may be specified by it by notification, exempt the processing of personal data by any Data Fiduciary or class of Data Fiduciaries, including a startup, from the applicability of the provisions of section 5, sub-section (3) of section 8, sub-section (7) of section 8, and sections 10 and 11, having regard to the volume and nature of personal data processed.
This is a power sitting in the statute, waiting to be used or not used. The correct sentence for a founder is: it could happen, watch for the notification, and don't plan around it as though it already exists.
And there's no small-company exemption either
From the blog
Prefer to skip the paperwork?
BuildWright can take this off your plate — done properly, the first time.
Get new templates and compliance updates by email.