The Scope of State Exemptions under Section 17 of the DPDP Act, 2023: National Security Overrides, Surveillance Safeguards, and Article 21 Compatibility in India

ABSTRACT :

We always give our data to government for some specific reasons as it is an requirement but at this time of digital governance when we hand over our information online in their official portal trusting it will serve a single, specific purpose. Have you ever thought what happens after you upload those data’s to the government portals. But once in the system, that single file splits into dozens of unseen streams—stored, cross-referenced, and retained indefinitely under the silent umbrella of ‘state security. The moment that file hits the server, however, state exemption clauses rewrite the rules, the requirement for consent vanishes, storage limits expire, and notice is no longer required. What begins as a simple administrative exchange quietly evolves into an unmonitored archive of personal identity. This article critically examines the scope of state exemptions under Section 17, evaluating whether broad national security overrides undermine fundamental privacy guarantees under Article 21 of the Constitution of India.

INTRODUCTION :

In this article we will be examining “the scope of state exemptions under section 17 of the DPDP Act,2023: National security overrides and article 21 compatibility” in India. Every time we sign up for a government service whether it is applying for an Aadhaar card, registering a vehicle, or filling out a welfare form, we share intimate personal details. Most of us assume that this information will only be used for that specific purpose and then kept safe. However, once our data enters government servers, the rules of privacy change dramatically. In 2023, India took a huge step forward by passing the Digital Personal Data Protection (DPDP) Act. On paper, this law was created to shield citizens from corporate data abuse. If a private company misuses your data, you have rights, and they face heavy penalties. But there is a major catch built into the law Section 17 which gives the Central Government the power to exempt its own agencies from almost all privacy rules. In the name of “national security” or “public order,” state bodies can collect, share, and keep your data indefinitely—without needing your consent, without giving you notice, and without allowing you to ask for your data to be deleted. This created a serious legal conflict, which we will be discussing further to simplified it and try to make this controversial issue easy to understand.

BACKGROUND :

In 2023, India passed a major privacy law called the DPDP Act (Digital Personal Data Protection Act).Companies (like Google, banks, or apps) cannot take or use your personal data without your permission. The government gave itself a massive free pass. Under Section 17, if the government says it needs your data for “national security” or “public order,” it can collect and look at your data without asking for your consent or giving you any notice. Is it fair for the government to give itself this huge power? Does this violate our Article 21 right to privacy under the Indian Constitution?

LEGAL FRAMEWORK :

Under Section 17(2)(a) of the DPDP Act, the Central Government may exempt any processing of personal data by a notified state instrumentality from the provisions of the Act in the interest of: Sovereignty and integrity of India, Security of the State, Friendly relations with foreign States, Maintenance of public order or prevention of incitement to any cognizable offence.

Scope of Exemption- When an exemption under Section 17 applies, the state entity is essentially relieved from:

  • Notice and Consent Requirements (Sections 5 & 6): Data can be collected and processed without informing the data principal or securing consent.
  • Data Minimization & Storage Limitation (Section 8): Retaining personal data beyond necessary durations without strict statutory caps.
  • Data Principal Rights (Sections 11–14): Rights to access, correction, erasure, and grievance redressal are suspended against exempted state bodies.

Under Article 21 of the Indian Constitution, every citizen is guaranteed the fundamental right to life and personal liberty. In the landmark Justice K.S. Puttaswamy (2017) judgment, the Supreme Court ruled that privacy is an essential part of Article 21. While privacy is not absolute, any government action that limits a citizen’s data privacy must meet three mandatory conditions:

Scope of Protection— To legally restrict privacy under Article 21, the government must follow three core principles:

  • Legality (Law Requirement): Any state interference with personal data must be backed by a clear, written law, not just an executive order.
  • Legitimate Aim: The state must have a real, valid public purpose—such as protecting national security or public order—for processing data without consent.
  • Proportionality and Safeguards: The state must use the least intrusive method possible to achieve its goal. It must also provide clear safeguards, such as independent judicial oversight and strict limits on how long data is kept.

Hence, Section 17 of the DPDP Act struggles to align with Article 21 because it grants broad, blanket exemptions to government bodies without providing independent checks or clear limits to prevent misuse.

ANALYSIS  AND CASE STUDY :

When executive agencies operate without strict legal bounds, broad exemptions under Section 17 create significant constitutional risks for ordinary citizens:

  •  Instead of granting exceptions only during real, temporary national emergencies, Section 17 allows the government to completely shield entire agencies. This means exempted bodies do not have to follow privacy rules even during normal, daily activities.
  •  The framework does not require an independent judge, court, or committee to approve or monitor state data requests. Without outside supervision, executive agencies are free to collect citizen data without any public accountability.
  •  Because exempted agencies are not required to delete data after using it, they can store citizen records indefinitely. Over time, this allows the state to build massive digital profiles on individuals without their knowledge or consent.

K.S. Puttaswamy V. Union Of India (2017) Case – Justice K.S. Puttaswamy, a 91-year-old retired High Court judge, filed a petition challenging the government’s mandatory Aadhaar scheme. He argued that collecting biometric and personal data without sufficient safeguards violated citizens’ personal liberty. The central question before the Supreme Court was whether privacy is a Fundamental Right protected by the Indian Constitution. A historic 9-judge bench unanimously held that privacy is a Fundamental Right under Article 21 (Right to Life and Personal Liberty). The Court ruled that privacy covers personal choices, body integrity, and digital informational privacy.

This case is highly relevant because it established the proportionality test which the Court declared that the government cannot take away data privacy just by issuing an order. Any state intrusion must pass three tests and it must be backed by a clear Law, have a Legitimate Goal like national security, and be Proportionate such as using minimal force with strong safeguards. There is also an direct Impact on Section 17 by the Puttaswamy judgment as it sets the precise standard used to evaluate the DPDP Act. Section 17 fails this standard because it gives the state wide powers without building in the strong safeguards and judicial checks required by the Supreme Court.

CONCLUSION:

National security is crucial, but it shouldn’t come at the cost of individual privacy rights under Article 21. While intelligence agencies need flexibility, Section 17 of the DPDP Act currently gives the government overly broad exemption powers without necessary safeguards. To fix this and match the standards set by the Puttaswamy judgment, India needs to reform this section. Instead of broad, permanent exemptions granted solely by the executive branch, exemptions should be narrow, temporary, and limited to active threats. Furthermore, an independent judge or committee should oversee government data requests, state agencies should be legally required to delete personal data once an investigation ends, and periodic audits should be conducted to ensure state power isn’t abused.

FAQs

1.What is Section 17 of the DPDP Act, 2023, and why is it controversial?

Section 17 allows the government to exempt certain state agencies from following data protection rules. It is controversial because it gives the government wide powers to collect and hold citizen data without requiring user consent or providing clear safeguards against abuse.

2.How does Section 17 conflict with Article 21 of the Indian Constitution?

Article 21 protects the Right to Life and Personal Liberty, which includes the fundamental right to privacy. Section 17 conflicts with Article 21 because its broad exemptions allow the state to bypass privacy protections without proper judicial oversight or checks and balances.

3.What did the Supreme Court decide in the K.S. Puttaswamy (2017) case?

The Supreme Court unanimously ruled that privacy is a Fundamental Right under Article 21. It established that any government action invading privacy must pass a “proportionality test”—meaning it must be backed by law, have a legitimate public goal, and use minimal, necessary intrusion.

4.Why do the broad exemptions under Section 17 raise concerns about mass surveillance?

Because exempted agencies are not required to limit data collection or delete records after an investigation ends, they can store citizen information indefinitely. This creates a risk of continuous state monitoring without individual awareness.

5.What key reforms are needed to make Section 17 constitutionally valid?

A: To align Section 17 with constitutional standards, the law should require independent judicial oversight for exemptions, limit exceptions to specific temporary threats, enforce rules to delete data after use, and mandate periodic independent audits.

 

SANIA REHAN
Author: SANIA REHAN