Chapter 3 — Scope, Roles, Exemptions and Processing Grounds
1. The first question, asked per activity, not per enterprise
Before authorising a processing activity, an enterprise must answer the question its controls presuppose; immediate incident containment and governance need not wait: is this processing in scope, and who am I in it?
The question sounds elementary, but two contrasting errors show its importance. In the first hypothetical, an enterprise assumes processing is out of scope and builds nothing. If the actual digital, territorial and exclusion facts make the activity covered once the relevant provisions commence, applicable unfulfilled duties may be breached. No retroactive violation is inferred merely from the later discovery of scope. The second enterprise assumes itself uniformly in scope, over-builds where the exemptions would have saved it, burns the goodwill and budget that Chapter 24 taught it to husband, and teaches the organisation that privacy work is disproportionate busywork.
The errors are expensive because applicability in DPDP is not an enterprise-level answer. It is a per-processing-activity answer, run against definitions that have surprising reach (digitised paper is expressly covered), exclusions that have surprising narrowness (“publicly available” is not what it sounds like), exemptions with different effects, including conditioned Act-level relief, and a role architecture in which the same organisation can be fiduciary for one dataset and processor for another on the same day — and owe different obligations to each.
Scope is a test, not an assumption: a decision tree run per processing activity — is it personal data, was it collected or digitised, where is it processed, does an exclusion apply, does an exemption bite — followed by the role determination (fiduciary, processor, both, consent manager, principal-side) and the ground (consent or a named Section 7 clause). Five fields, one row per activity, and the enterprise’s entire compliance posture inherits from those rows. The trees and the role matrix are this chapter’s deliverable — the instruments that make “applicability” a recorded decision instead of a folk belief.
2. The tension: the reach of the Act versus the wish to be out
The tension deserves honest naming, because it operates on well-meaning people. An enterprise wants the honest answer to be “out of scope” — for this dataset, this vendor, this offshore flow — because out-of-scope work is free. And the Act’s definitions are wide enough that every tempting exit looks plausible until read closely. The chapter names the four most tempting exits, because each fails in a characteristic way:
“It’s not digital.” Section 3(a) covers personal data “collected in digital form” or “in non-digital form and digitised subsequently” The scanned KYC bundle, the OCR’d paper application, the digitised archive from the pre-digital era — all squarely in scope where the territorial facts are met. This is a statutory inclusion, not an empirical claim about every programme. The exit fails at the scanner (ACT:135–157[3]).
“It’s offshore.” Section 3(b) extends the Act to processing outside India “in connection with any activity related to offering of goods or services to Data Principals within the territory of India;” The overseas analytics vendor, the foreign support desk with production access, the offshore group entity — if the specified goods/services nexus concerns principals within India, the Act’s hand does not stop at the border. The exit fails at the coordinates.
“It’s publicly available.” Section 3(c)(ii) excludes data made or caused to be publicly available by the principal, or made public by another person under a legal obligation in India to do so (paraphrase, ACT:149–157[3]). That is two narrow gates, not one broad one: the principal’s own publication, or a legally-mandated publication. Data scraped from third-party sites, aggregated from broker lists, or someone else’s “open” dataset does not establish either condition merely because it is accessible. Verify whether the principal made or caused the publication or the publisher was legally obliged. A third-party host can carry principal-published data; a stolen or broker-published list is not automatically excluded. The exit depends on provenance, not the website label (ACT:149–157[3]).
“An exemption covers us.” Section 17’s exemptions are real and valuable (§4 below) — and their actors, conditions and effects differ. Some require necessity, some a qualifying territorial/contractual relationship, and some a Government notification. Recording a named owner is this book’s recommended control, not a statutory form. The full table below prevents one exemption from being used as a substitute for another.
The failure modes at the two poles:
- Assume-out. The dataset, vendor, or flow declared out of scope on instinct — the folk-belief error, and the parent of the un-built control.
- Over-claim-out. The eager reading — “publicly-available” stretched past its text, “necessary for” assumed rather than tested — which converts a compliance posture into a catalogue of misrepresentations, each with a confident border drawn on it.
The reconciliation is the tree, run honestly, per activity, with every exclusion and exemption treated as a gate rather than an exit — each “out” answer a recorded decision citing its provision, reviewable by counsel, revisitable on change (Chapter 36’s rhythm). An enterprise with a documented out-of-scope register has a defensible perimeter; an enterprise with an assumed one has a liability with a confident border drawn on it. And the discipline pays twice: the same recorded rows that defend an inquiry also tell Chapter 24’s budget where not to spend.
3. The applicability decision tree
Five steps, in order, each with its statutory anchor and its characteristic trap:
Step one — is it personal data? Section 2(t): “any data about an individual who is identifiable by or in relation to such data” The test is identifiability, and it follows the data through transforms — the pseudonymised profile that remains re-identifiable is still personal data (Chapter 21’s derived-data rules inherit here, and the “we anonymised it” claim is only as good as its evidence). No → out, recorded.
Step two — is it digital personal data? Section 2(n) defines it; Section 3(a) brings in the collected-in-digital-form data and the digitised-later data. The paper archive enters here. No → out, recorded.
Step three — the territorial test. Section 3(a): processing within India. Section 3(b): even outside India, if connected to offering goods or services to Data Principals within the territory of India, irrespective of citizenship. The offshore flow that believed coordinates exempted it answers here.
Step four — the exclusions. Section 3(c)(i): personal or domestic processing by an individual. The Act’s blogger illustration concerns her own publicly made available data under the public-data exclusion; it does not make an enterprise HR blog personal/domestic processing. Section 3(c)(ii): principal-published, or legally-mandated publication — read narrowly, decided per source, and recorded with the source named.
Step five — test every potentially applicable Section 17 branch independently. Record exactly which provisions it disapplies and what remains. Section 17(1) preserves Section 8(1) responsibility and Section 8(5) safeguards; Section 17(2) can exempt qualifying processing from the Act. Notification-dependent branches require the actual instrument. Where evidence is missing, keep the proposed processing stopped or restricted; do not manufacture an exclusion (ACT:523–583[3]).
Identifiable personal data? No -> record evidenced non-personal classification.
Digital, including later digitisation? No -> record why this Act's digital scope is not met.
India processing OR offshore goods/services nexus to principals within India?
No -> record territorial facts; other laws may still apply.
Individual personal/domestic or qualifying public-data exclusion? Yes -> record source/facts.
Otherwise -> test s.17(1)(a)-(f), (2)(a)-(b), (3), (4), (5) separately.
Proven exemption -> record precise disapplication AND surviving duties.
Unproven exemption -> no exemption assumed.
For remaining duties -> per-activity role, lawful purpose and authority decision.
This is a recommended decision workflow, not a substitute for reading the Act. Scope comes before the affected duty, but a team can build its inventory and incident capability while legal review resolves an uncertain perimeter.
4. The complete exemption decision table
The following is an author paraphrase of ACT:523–583[3], not a quotation. Every row is scheduled for 13 May 2027 under the retained commencement notice. “Remaining Act” means provisions not disapplied by that row, subject to their own scope and commencement. The Section 17(1) common effect is to disapply Chapter II except Section 8(1),(5), Chapter III and Section 16; responsibility and safeguards survive. No row grants permission under a different law.
| Branch | Actor and factual trigger | Effect / what remains | Notification or evidence gate; counterexample |
|---|---|---|---|
| Section 17(1)(a) | Person processing data necessary for enforcing any legal right or claim | Common Section 17(1) effect | Identify the right/claim and necessity. An unrelated marketing audience is not claim enforcement. |
| Section 17(1)(b) | Court, tribunal or other body in India entrusted by law with judicial, quasi-judicial, regulatory or supervisory functions; necessary processing for that function | Common effect | Identify entrusting law and function. An employer’s disciplinary committee is not automatically such a body. |
| Section 17(1)(c) | Processing in the interest of preventing, detecting, investigating or prosecuting an offence OR contravention of Indian law | Common effect | Identify actual legal contravention and activity; the text is not confined to criminal-process actors or a universal necessity formulation. A vague “fraud” product label proves neither fit nor exclusion. |
| Section 17(1)(d) | Person based in India processes data of principals not within India pursuant to a contract with a person outside India | Common effect | All three location/contract facts are needed. Citizenship and customer nationality are not the test. No new Government exemption notification is stated for this branch. |
| Section 17(1)(e) | Processing necessary for a listed compromise/arrangement, merger/amalgamation, reconstruction/demerger, undertaking transfer or division scheme approved by a competent court/tribunal/authority under law | Common effect | Retain scheme, competent approval and processing necessity. Pre-deal commercial prospecting is not automatically covered; this is not a Section 7 ground. |
| Section 17(1)(f) | Ascertain financial information, assets and liabilities of a person defaulting on a loan/advance from a financial institution | Common effect | Apply IBC Section 3(12)/(14) definitions and other-law disclosure requirements. No blanket authority to market to a borrower or their contacts. |
| Section 17(2)(a) | Notified State instrumentality processing for the listed sovereignty/integrity/security, friendly-relations, public-order or related incitement interests; also Central Government processing its furnished data | Act-level exemption for qualifying processing | Actual notification and interest are needed. A private supplier cannot assume its own unrelated reuse shares the exemption. |
| Section 17(2)(b) | Necessary research, archiving or statistics processing, not used for a principal-specific decision, with prescribed standards | Act-level exemption conditional on all requirements | Rule 16 and Second Schedule; no principal-specific decision. A model that scores this borrower is not exempt simply because its team calls it research. |
| Section 17(3) | Government-notified fiduciary/class, including eligible startups, having regard to volume/nature | Only Section 5, Section 8(3),(7), Sections 10,11 disapplied; remaining Act applies | Retain notification and class match. Startup recognition alone does not confer relief. |
| Section 17(4) | Processing by State/instrumentality | Section 8(7), Section 12(3) disapplied; Section 12(2) also disapplied where purpose excludes a principal-affecting decision; remaining Act applies | Establish actor and decision/non-decision purpose. This is not a private employer exemption. |
| Section 17(5) | Government notification before expiry of five years from applicable commencement | Specified provisions disapplied for specified fiduciary/classes and period only | Actual notification, scope and duration required; not a universal five-year grace period. |
For the Section 17(2)(b) research branch, the Second Schedule is substantive: appropriate technical and organisational measures support lawfulness, specified-use limitation, necessary-data limitation, reasonable completeness/accuracy/consistency efforts, retention only as required for purpose/law, safeguards and accountability. Its additional intimation/contact/rights provisions apply to the Section 7(b) State-use branch as specified, not indiscriminately to every exempt researcher (RULES:1324–1326,1553–1595[4]).
The useful distinction is not “exempt enterprise” versus “regulated enterprise”. A claim file can have a scoped Section 17(1)(a) decision while the same person’s marketing data remains subject to consent and cessation. A processor handling qualifying export data can remain a fiduciary for its own billing records. The decision register must therefore preserve dataset, activity, actor and territorial facts; a company-wide exemption flag would erase these differences.
A worked negative decision uses CASE-001 / PUR-003: the Company proposes training and using a model to decide SUB-001’s loan. No separate training authority is recorded. The research label does not establish Section 17(2)(b), especially when principal-specific decisions are intended. DEC-001 remains stop; the author recommendation is to redesign or establish an applicable authority before ingestion, not anonymise after unauthorised collection and declare the past lawful.
5. The role matrix: who is accountable for what
With scope settled, the role decides which obligations attach — and the matrix’s discipline is that the role is determined per data scope, not per organisation. The definitions first, read for their operative words:
| Role | The definition’s operative words | The obligations that attach |
|---|---|---|
| Data Fiduciary (Section 2(i)) | “determines the purpose and means of processing” — purpose-setting is the fiduciary’s defining act | applicable fiduciary duties: grounds (Section 4), notice/consent where relevant (Sections 5 to 6), Section 8, scoped rights (Sections 11 to 14), breach (Section 8(6)), retention (Section 8(7)); Section 15 addresses principal duties — and Section 8(1): responsible for processor acts, irrespective of any agreement to the contrary |
| Data Processor (Section 2(k)) | “processes personal data on behalf of” the fiduciary — on whose instruction, for whose purpose | Section 8(2)/(7)(b) direct the fiduciary to contract and cause erasure; the processor executes applicable contractual/law obligations; see Chapter 17 |
| Data Principal (Section 2(j)) | the individual; for a child, the parents/lawful guardian are included; for disability, the lawful guardian acting on her behalf (paraphrase, ACT:73–77[3]) | the rights (Sections 11 to 14) and the duties (Section 15) |
| Significant Data Fiduciary (Section 2(z), Section 10(1)) | notified by the Central Government — designation is the Government’s act | the Chapter 19 envelope: DPO, independent auditor, DPIA/audit cycles |
| Consent Manager (Section 2(g)) | registered with the Board; the principal’s single point for give/manage/review/withdraw | Rule 4 registration + First Schedule obligations (Ch.11) |
The two errors the matrix exists to kill, each worth its full paragraph:
The processor shrug. “We’re just the processor; compliance is the client’s problem.” Section 8(1) provides that the fiduciary is responsible for processing undertaken on its behalf by the processor, “irrespective of any agreement to the contrary” — no clause shifts it, and no vendor’s own certification dissolves it. But the shrug misreads the processor’s own position too: Section 8(2) directs the fiduciary to engage the covered processor only under a valid contract; Section 8(7)(b) directs it to cause processor erasure. Processor execution is implemented through applicable contract/law rather than relabelling those clauses as direct processor duties. An enterprise can be a processor in one relationship and a fiduciary in another simultaneously. The white-label operator, SaaS provider or analytics vendor may determine purposes/means for its own customer or HR activity while acting on behalf of clients for a different activity. The facts, not the supplier label, decide. The obligations are the union of the hats, and the matrix is drawn per data scope because that is the only grain at which the union resolves.
The single-hat assumption. The mirror error: the enterprise that determines its role once (“we’re a fiduciary”) and applies fiduciary duties to every dataset — including the client data it holds as a processor, where the correct posture is the contractual flow-down; or the reverse, where client-side processing is assumed “covered” by the client’s compliance. Both mis-grainings produce the same artifact: obligations applied where they do not attach, and unapplied where they do.
6. The grounds: two doors, no third
Section 4 permits processing only in accordance with the Act and for a lawful purpose, either with the principal’s consent or for certain legitimate uses. A lawful purpose is one not expressly forbidden by law (ACT:160–166[3]). This is a paraphrase; the exact primary text is linked in ACT-4. Lawful purpose and processing authority are different checks.
Door one: consent (Section 6). Free, specific, informed, unconditional, unambiguous, by clear affirmative action, purpose-scoped, necessary-data-limited — the general- purpose ground and the one with the most machinery (Chapters 9–10 build it). The Act’s own illustrations police its quality: the telemedicine app’s request for phone contacts is void for the unnecessary part; the insurance consent’s waiver of the Board-complaint right is void as an infringement.
Door two: the conditioned Section 7 uses. The exact clause text below is generated from the retained primary source, with original extraction spacing normalised only for display. It is followed by author application guidance. None of the nine clauses supplies general permission for corporate “reasonable purposes” or an unrestricted contract ground.
Section 7(a) — exact retained passage
(a) for the specified purpose for which the Data Principal has voluntarily provided her personal data to the Data Fiduciary, and in respect of which she has not indicated to the Data Fiduciary that she does not consent to the use of her personal data. Illustrations. (I) X, an individual, makes a purchase at Y, a pharmacy. She voluntarily provides Y her personal data and requests Y to acknowledge receipt of the payment made for the purchase by sending a message to her mobile phone. Y may process the personal data of X for the purpose of sending the receipt. (II) X, an individual, electronically messages Y, a real estate broker, requesting Y to help identify a suitable rented accommodation for her and shares her personal data for this purpose. Y may process her personal data to identify and intimate to her the details of accommodation available on rent. Subsequently, X informs Y that X no longer needs help from Y. Y shall cease to process the personal data of X;
Source: ACT-7(a) — research/legal/evidence/01_dpdp_act_2023_gazette.txt:271–284. Extraction includes any original page/header text; it is not author wording.
Section 7(b) — exact retained passage
(b) for the State and any of its instrumentalities to provide or issue to the Data Principal such subsidy, benefit, service, certificate, licence or permit as may be prescribed, where–– (i) she has previously consented to the processing of her personal data by the State or any of its instrumentalities for any subsidy, benefit, service, certificate, licence or permit; or (ii) such personal data is available in digital form in, or in non-digital form and digitised subsequently from, any database, register, book or other document which is maintained by the State or any of its instrumentalities and is notified by the Central Government, subject to standards followed for processing being in accordance with the policy issued by the Central Government or any law for the time being in force for governance of personal data. Illustration. X. a pregnant woman, enrols herself on an app or website to avail of government’s maternity benefits programme, while consenting to provide her personal data for the purpose of availing of such benefits. Government may process the personal data of X processing to determine her eligibility to receive any other prescribed benefit from the government;
Source: ACT-7(b) — research/legal/evidence/01_dpdp_act_2023_gazette.txt:285–302. Extraction includes any original page/header text; it is not author wording.
Section 7(c) — exact retained passage
(c) for the performance by the State or any of its instrumentalities of any function under any law for the time being in force in India or in the interest of sovereignty and integrity of India or security of the State;
Source: ACT-7(c) — research/legal/evidence/01_dpdp_act_2023_gazette.txt:306–308. Extraction includes any original page/header text; it is not author wording.
Section 7(d) — exact retained passage
(d) for fulfilling any obligation under any law for the time being in force in India on any person to disclose any information to the State or any of its instrumentalities, subject to such processing being in accordance with the provisions regarding disclosure of such information in any other law for the time being in force;
Source: ACT-7(d) — research/legal/evidence/01_dpdp_act_2023_gazette.txt:309–312. Extraction includes any original page/header text; it is not author wording.
Section 7(e) — exact retained passage
(e) for compliance with any judgment or decree or order issued under any law for the time being in force in India, or any judgment or order relating to claims of a contractual or civil nature under any law for the time being in force outside India;
Source: ACT-7(e) — research/legal/evidence/01_dpdp_act_2023_gazette.txt:313–315. Extraction includes any original page/header text; it is not author wording.
Section 7(f) — exact retained passage
(f) for responding to a medical emergency involving a threat to the life or immediate threat to the health of the Data Principal or any other individual;
Source: ACT-7(f) — research/legal/evidence/01_dpdp_act_2023_gazette.txt:316–317. Extraction includes any original page/header text; it is not author wording.
Section 7(g) — exact retained passage
(g) for taking measures to provide medical treatment or health services to any individual during an epidemic, outbreak of disease, or any other threat to public health;
Source: ACT-7(g) — research/legal/evidence/01_dpdp_act_2023_gazette.txt:318–320. Extraction includes any original page/header text; it is not author wording.
Section 7(h) — exact retained passage
(h) for taking measures to ensure safety of, or provide assistance or services to, any individual during any disaster, or any breakdown of public order. Explanation.—For the purposes of this clause, the expression “disaster” shall have the same meaning as assigned to it in clause (d) of section 2 of the Disaster53 of 2005. Management Act, 2005; or
Source: ACT-7(h) — research/legal/evidence/01_dpdp_act_2023_gazette.txt:321–325. Extraction includes any original page/header text; it is not author wording.
Section 7(i) — exact retained passage
(i) for the purposes of employment or those related to safeguarding the employer from loss or liability, such as prevention of corporate espionage, maintenance of confidentiality of trade secrets, intellectual property, classified information or provision of any service or benefit sought by a Data Principal who is an employee.
Source: ACT-7(i) — research/legal/evidence/01_dpdp_act_2023_gazette.txt:326–329. Extraction includes any original page/header text; it is not author wording.
| Clause | Eligible actor / facts and permitted purpose | Rejected branch | Recommended downstream control |
|---|---|---|---|
| (a) | Fiduciary receives the principal’s own voluntarily supplied data for specified purpose, with no indication of non-consent; requested receipt is the Act’s example | Notice alone, someone else’s contact, or later marketing without qualifying facts | Record voluntary action, subject, requested use and non-consent signals; stop when facts cease to hold |
| (b) | State/instrumentality prescribed benefit/service/certificate/licence/permit; qualifying prior consent OR qualifying notified State-maintained document; policy/law standards and Rule 5/Second Schedule | Private lender’s promotional offer | Validate State actor, alternative condition, notified document where relied on, purpose and standards |
| (c) | State/instrumentality performs function under Indian law or listed sovereignty/integrity/security interest | Private enterprise merely regulated by the State | Attach law/function or specified interest and actor facts |
| (d) | Indian law obliges a person to disclose information to State/instrumentality, consistently with the relevant disclosure law | Private contract or unspecified “legal compliance” | Attach exact instrument, required recipient, fields and disclosure conditions |
| (e) | Indian-law judgment/decree/order, or foreign judgment/order relating to contractual/civil claims | Informal commercial demand without qualifying order | Check authenticity, issuing authority, subject matter and permitted data scope |
| (f) | Medical emergency threatens life or immediately threatens health of principal or another individual | Ordinary marketing follow-up after emergency | Record emergency facts, recipient/data/time scope; do not invent incapacity as a prerequisite |
| (g) | Medical treatment/health services during epidemic, outbreak or other public-health threat | Unrelated profiling while an outbreak exists | Record threat and treatment nexus; no invented formal-declaration prerequisite |
| (h) | Safety, assistance or services during disaster as statutorily defined or public-order breakdown | Routine employee administration | Record event and safety/service purpose; terminate exceptional path when facts end |
| (i) | Employment or safeguarding employer from loss/liability, with the listed examples and employee-sought service/benefit | Group-company marketing; automatic unsuccessful-applicant retention | Record employment purpose and actual facts; applicant/monitoring boundaries require scoped review (QL-007) |
There is no GDPR-style legitimate-interest balancing ground in Section 4/Section 7. A useful impact assessment cannot invent one. Equally, a rejected clause does not prove that no other lawful route could ever exist: the decision must identify the actual remaining options, obtain evidence before approval, and preserve the refusal of the proposal as submitted.
7. A populated activity determination
CASE-001 / ENT-001 requests ENT-003 to host DS-002 in SYS-002. The fictional Company determines loan-application purpose and means; the host acts on documented instructions. India-based digital processing meets Section 3(a). The Company is fiduciary for PUR-001; the host is processor for hosting, not automatically for its own billing or product analytics. CONSENT-001 is the proposed recorded Section 6 authority for the Company’s application processing; no blanket contract ground is inferred. Hosting terms must support the Company’s Section 8(1)/(2)/(5)/(7) responsibilities (ACT:71–79,135–143,330–359[3]).
The recommended record is more than five labels: case_id=CASE-001, flow_id=FLOW-001, datasets=DS-001,DS-002, purpose_id=PUR-001, fiduciary=ENT-001, processor=ENT-003, territory=India, authority=CONSENT-001, exemption=none established, source_ids=ACT-2,ACT-3,ACT-4,ACT-6,ACT-8, decision=conditional, owner=legal and application owner, review=author synthetic; independent deployment review required. Conditions include adequate notice, necessary data, valid affirmative grant and no unsupported vendor reuse. Recording a consent identifier alone is not proof these conditions hold.
Compare ENT-005’s proposed independent use of DS-006 to develop its own product. The stipulated purpose/means facts make that a separate fiduciary activity, not an extension of its instructed analytics role. No authority is recorded; DEC-005 is stop. The contract cannot manufacture a processor role inconsistent with those facts. This distinction is what the role matrix contributes to procurement: the same supplier can require two decisions, and approval of one is not approval of the other.
8. Three counterexamples that test the boundary
Requested receipt versus marketing. In CASE-001, SUB-001 voluntarily supplies her own contact and asks the Company to acknowledge a payment. PUR-007 records that requested receipt and no indication of non-consent; the author application of Section 7(a) conditionally permits only that use. A growth team then proposes sending promotions to the same contact. The receipt facts do not establish authority for PUR-002. Separate consent CONSENT-002 is required by this scenario’s chosen route, and WITHDRAW-001 later ends that marketing authority. Merely adding marketing to a notice is not voluntary provision for that purpose. The recommended gate checks current purpose-specific authority, not whether the customer is somewhere in the database (ACT:271–284[3]).
Scraped directory. A separate hypothetical directory operator obtains profiles published by a broker without the principals making or causing publication and without a legal publication obligation. On those stipulated facts Section 3(c)(ii) does not apply. Section 7(a) also fails: the principals did not voluntarily supply their data to this operator for the directory. The submitted ingestion proposal is stopped. If later evidence establishes principal-caused publication for some records, rerun the exclusion per source; do not pretend every third-party website is automatically outside or inside the exclusion. Consent acquisition or genuinely non-personal design can be future alternatives, but processing to produce an anonymous output still needs its own lawful analysis while personal data is involved.
Export services without nationality shorthand. CASE-104 / ENT-104 is a separate fictional Indian SaaS exporter, not the Company’s lending estate. Assume it processes hosted foreign-customer contact records in India under a contract with a person outside India, and the data principals are not within India. Those facts support the Section 17(1)(d) branch; Chapter II except Section 8(1),(5), Chapter III and Section 16 are disapplied for that activity. Change the facts so that the affected principals are within India, or the supplier reuses the records for its own unrelated product, and the same exemption decision cannot simply be copied. Citizenship never resolves this row. The provider’s own billing/security activities need separate scope, role and ground decisions (ACT:534–536[3]).
These are author-applied hypothetical decisions, not counsel-approved facts or observed successful controls. A useful review challenges the conditions rather than admiring a green row. The output of a failed condition is a named stop/review action, not an undocumented exception approved by the commercial sponsor.
9. Remaining application questions
All Section 7 clauses and Section 17 branches have been read; there is no outstanding basic-source task. Real-entity decisions still require proof of territorial facts, public-data provenance, legal claim/contravention, approved restructuring or default-information conditions, and any relied-on notification. QL-007 preserves applicant, monitoring and third-person-contact boundaries; QL-004 preserves the bounded later-instrument search. Unknown facts do not authorise processing.
The decision owner must also check compatible sector obligations and the specific transfer saving without rewriting DPDP scope from a vague regulator label. Chapter 5 supplies that separation. Entity legal advice and independent book review remain distinct from this author’s source-based repair.
Bridge to the next chapter
Scope, role and ground now have source-backed decision records with express conditions; defensibility depends on the actual evidence and legal review. But the statute’s most important person has not yet appeared in the operating chapters: the Data Principal herself, whose rights turn the fiduciary’s obligations into services that must actually be run. Chapter 4 takes up Data Principal Rights and Organisational Accountability — the rights-to-service matrix and the named owners who make rights real.
References (sources retained)
- DPDP Act 2023 — research/legal/evidence/01_dpdp_act_2023_gazette.txt (Sections 2, 3, 4, 7, 17 — quoted from the retained gazette text).
- DPDP Rules 2025 (GSR 846(E)) — research/legal/evidence/05_gsr_846e_dpdp_rules_2025.txt (Rule 5 and its Second Schedule conditions).
- Commencement GSR 843(E) — research/legal/evidence/02_gsr_843e_commencement.txt.
- Chapters 2 (the register these decisions feed), 7 (the inventory the rows join on), 8 (the matrix this chapter’s grounds column feeds), 17 (the processor hat’s schedule), 21 (identifiability through transforms), 34 (the two-hat enterprise walked here first).
Source key and provenance legend
Physical references use newline-based line numbers in the following retained source paths; each numbered reference resolves to its original source URL. Review date: 15 September 2026. Full calculated hashes and source versions: out/remediation/Q02/source-manifest.json. The Q01 baseline and its bounded official-update limitations remain controlling; no later-law absence or entity certification is asserted.
- ACT:
research/legal/evidence/01_dpdp_act_2023_gazette.txt— Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023).[3] - RULES:
research/legal/evidence/05_gsr_846e_dpdp_rules_2025.txt— Digital Personal Data Protection Rules, 2025, G.S.R. 846(E).[4] - COMM:
research/legal/evidence/02_gsr_843e_commencement.txt— G.S.R. 843(E), DPDP Act commencement notification.[5] - EST:
research/legal/evidence/03_gsr_844e_board_establishment.txt— G.S.R. 844(E), establishment of Data Protection Board of India.[6] - MEMBERS:
research/legal/evidence/04_gsr_845e_board_members.txt— G.S.R. 845(E), number of members of Data Protection Board of India.[7] - CORR:
research/legal/evidence/06_gsr_892e_corrigendum.txt— Corrigenda to G.S.R. 846(E), G.S.R. 892(E).[8] - RECRUIT:
research/legal/evidence/07_board_recruitment_notice_2026.txt— Filling up the post of Chairman & Members in the Data Protection Board of India.[9]
Sources
[3] https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf [4] https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf [5] https://www.meity.gov.in/static/uploads/2025/11/c56ceae6c383460ca69577428d36828b.pdf [6] https://www.meity.gov.in/static/uploads/2025/11/cc217843dc3bcb37b2b05bcc3b4e031f.pdf [7] https://www.meity.gov.in/static/uploads/2025/11/f6c0837972422cf79d890bfe84cc04d6.pdf [8] https://www.meity.gov.in/static/uploads/2025/12/3c7ebbae0e5456f493f486e6845df86b.pdf [9] https://www.meity.gov.in/static/uploads/2026/05/53b1bcf01cab9a0adde463e73fbc3417.pdf
Contents · Reader guide and citation conventions · Artifact index