You are currently viewing THE DIGITAL PERSONAL DATA PROTECTION ACT, 2023(NO. 22 OF 2023)

THE DIGITAL PERSONAL DATA PROTECTION ACT, 2023(NO. 22 OF 2023)

The text you shared is the Preamble and opening of the Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023). Here’s a simple explanation:

What is it?

  • The Digital Personal Data Protection Act, 2023 (DPDP Act) is a law passed by the Parliament of India.
  • It protects the digital personal data of individuals.
  • It also allows organisations to use personal data for lawful purposes.

Objective

The Act aims to balance:

  • People’s right to protect their personal data, and
  • The need to process personal data for legal and legitimate purposes.

Applies to

  • Personal data collected in digital form.
  • Personal data collected offline but later converted into digital form.

Key Terms

  • Data Principal: The individual whose personal data is being collected.
  • Data Fiduciary: The person, company, or organisation that decides how and why personal data is processed.
  • Personal Data: Any information that can identify a person.

Main Features

  • Gives individuals rights over their personal data.
  • Requires organisations to handle data responsibly.
  • Data should be collected only for lawful purposes.
  • Provides penalties for violating the Act.

Interesting Fact

  • The DPDP Act, 2023 is the first Act of the Parliament of India to use “she/her” pronouns instead of the traditional “he/him” pronouns in its drafting.

Remember

DPDP = Digital Personal Data Protection

  • D – Digital
  • P – Personal
  • D – Data
  • P – Protection

Purpose of the Act

The Act establishes a legal framework for how digital personal data should be collected, stored, used, and shared in India. It aims to balance two important objectives:

  1. Protecting individuals’ privacy by giving them rights over their personal data.
  2. Allowing lawful processing of personal data by organizations and the government when necessary for legitimate purposes.

Key ideas in the preamble

  • It applies to digital personal data.
  • It recognizes that people have a right to protect their personal information.
  • It also recognizes that businesses, government bodies, and other organizations may need to process personal data for lawful purposes.
  • It covers not only the main provisions but also related and incidental matters necessary to implement the law.

Digital Personal Data Protection Act, 2023 (DPDP Act) – Background

1. Why was a Data Protection Law Needed?

Before 2023, India did not have a dedicated law to protect personal data. Personal data was mainly regulated under the Information Technology Act, 2000 and its rules, which were considered inadequate due to rapid growth in the digital economy, social media, online banking, e-commerce, and digital government services.

The need for a comprehensive data protection law became stronger after the Supreme Court recognised the Right to Privacy as a Fundamental Right.


2. The Puttaswamy Judgment (2017)

Date

24 August 2017

Case

Justice K.S. Puttaswamy (Retd.) v. Union of India

Importance

A nine-judge Constitution Bench of the Supreme Court unanimously held that:

  • Right to Privacy is a Fundamental Right.
  • It is protected under Article 21 (Right to Life and Personal Liberty).
  • It is also part of the freedoms guaranteed under Part III of the Constitution.

Why was this judgment important?

The Court stated that citizens have the right to control their personal information.

It also observed that:

  • Personal data must be protected.
  • The Government should enact a comprehensive Data Protection Law.

This judgment became the foundation of India’s Data Protection Law.


3. Justice B.N. Srikrishna Committee (2017–18)

After the judgment, the Government constituted a Committee of Experts.

Chairman

Justice B.N. Srikrishna
(Former Judge of the Supreme Court)

Objective

The Committee was asked to:

  • Study international data protection laws.
  • Prepare a legal framework for India.
  • Recommend a comprehensive data protection law.

4. Public Consultation

The Committee released several White Papers and invited:

  • Citizens
  • Industry
  • Technology companies
  • Civil society organisations
  • Legal experts

to submit suggestions.

This helped the Government understand public concerns regarding:

  • Privacy
  • Consent
  • Data processing
  • Government access to data
  • Rights of individuals

5. Personal Data Protection Bill, 2018

Based on consultations, the Committee prepared the Personal Data Protection Bill, 2018.

The Committee also submitted:

  • A detailed report
  • Recommendations on protecting personal data

Although the Bill was not introduced in Parliament, it became the basis for future legislation.


6. Personal Data Protection Bill, 2019

Cabinet Approval

4 December 2019

The Union Cabinet approved a revised version.

Introduced in Parliament

11 December 2019

The Personal Data Protection Bill, 2019 was introduced in the Lok Sabha.


7. Joint Parliamentary Committee (JPC)

After introduction, the Bill was referred to a Joint Parliamentary Committee (JPC).

Purpose

The Committee examined:

  • Every provision of the Bill
  • Suggestions from experts
  • Views of technology companies
  • Public comments
  • Government departments

The Committee held several meetings over nearly two years.


8. JPC Report (2021)

Date

16 December 2021

The Committee submitted its report.

It suggested:

  • Several amendments
  • Stronger protection for citizens
  • Wider regulation of data
  • Changes in the proposed Data Protection Authority
  • Expansion of the Bill’s scope

9. Withdrawal of the 2019 Bill (2022)

Date

3 August 2022

The Government withdrew the Personal Data Protection Bill, 2019.

Reason

The Government stated that:

  • The JPC had suggested many amendments.
  • Instead of making numerous changes, it would prepare an entirely new and simpler Bill.

10. Draft Digital Personal Data Protection Bill (2022)

Date

18 November 2022

The Ministry of Electronics and Information Technology (MeitY) released the draft Digital Personal Data Protection Bill.

The draft was published for public consultation.

Suggestions were invited from:

  • Citizens
  • Industry
  • Technology companies
  • Legal experts

11. Digital Personal Data Protection Bill, 2023

Date Introduced

3 August 2023

Introduced in the Lok Sabha.


Passed by Parliament

Lok Sabha

7 August 2023

Rajya Sabha

9 August 2023


Presidential Assent

11 August 2023

After receiving the President’s assent, it became:


Chapter I – Preliminary

Section 1: Short Title and Commencement

Section 1(1): Name of the Act

The law is called the Digital Personal Data Protection Act, 2023 (DPDP Act, 2023).

Section 1(2): Commencement

  • The Act does not come into force immediately.
  • The Central Government decides the date through a notification in the Official Gazette.
  • Different provisions may come into force on different dates.

Example:
The Government may enforce consent provisions first and penalty provisions later.


Section 2: Definitions

These definitions explain important terms used throughout the Act.

(A). Appellate Tribunal

The Telecom Disputes Settlement and Appellate Tribunal (TDSAT) hears appeals against decisions of the Data Protection Board.

(B) Automated

A digital process that works automatically according to instructions.

Example:

  • Face recognition
  • Spam filters
  • AI recommendation systems

(C) Board

The Data Protection Board of India established under Section 18 to enforce the Act.


(D) Certain Legitimate Uses

Processing allowed under Section 7 even without consent in specified situations.


(E). Chairperson

The head of the Data Protection Board.


(F). Child

A person below 18 years of age.


(G). Consent Manager

A registered person who helps individuals:

  • Give consent
  • Withdraw consent
  • Review consent
  • Manage consent

through one common platform.


(H). Data

Any representation of information such as:

  • Facts
  • Opinions
  • Numbers
  • Images
  • Instructions

that humans or computers can process.


(I). Data Fiduciary

The person or organisation deciding:

  • Why personal data is collected
  • How it is processed

Examples:

  • Banks
  • Hospitals
  • Schools
  • Social media companies
  • E-commerce websites

(J). Data Principal

The individual whose personal data is processed.

Special cases:

  • For children, parents or legal guardians act on their behalf.
  • For persons with disabilities, lawful guardians may act where applicable under the Act.

(K) . Data Processor

Processes personal data for the Data Fiduciary.

Example:
A cloud service provider storing customer information for a bank.


(L) . Data Protection Officer (DPO)

An officer appointed by a Significant Data Fiduciary to ensure compliance with the Act.


M. Digital Office

An office where all proceedings happen online.

Example:

  • Filing complaints
  • Hearings
  • Orders

N. Digital Personal Data

Personal data in electronic form.

Examples:

  • Aadhaar number stored digitally
  • Online medical records
  • Email address
  • Digital photographs

O. Gain

Includes:

  • Property gain
  • Financial benefit
  • Better earning opportunity

P. Loss

Includes:

  • Property loss
  • Loss of services
  • Financial loss
  • Lost earning opportunity

Q. Member

A member of the Data Protection Board, including the Chairperson.


R. Notification

An official announcement published in the Official Gazette.


S. Person

Includes:

  • Individual
  • Hindu Undivided Family (HUF)
  • Company
  • Firm
  • Association
  • Government (State)
  • Artificial legal persons

T. Personal Data

Any information relating to an identifiable individual.

Examples:

  • Name
  • Mobile number
  • Aadhaar number
  • Email
  • Photograph
  • Location data
  • Biometric data

U. Personal Data Breach

Any unauthorized or accidental event involving personal data that compromises its:

  • Confidentiality (kept secret)
  • Integrity (remains accurate and unaltered)
  • Availability (accessible when needed)

Examples:

  • Hacking
  • Data leak
  • Accidental deletion
  • Unauthorized sharing

V. Prescribed

Specified by rules made under the Act.


W. Proceeding

Any action taken by the Data Protection Board.

Examples:

  • Inquiry
  • Hearing
  • Penalty proceedings

X. Processing

Any automated or partly automated operation performed on digital personal data.

Includes:

  • Collection
  • Storage
  • Recording
  • Organization
  • Retrieval
  • Use
  • Sharing
  • Transmission
  • Erasure
  • Destruction

Y. “She”

The word “she” includes every individual regardless of gender.


Z. Significant Data Fiduciary (SDF)

A Data Fiduciary notified by the Central Government based on factors such as the volume and sensitivity of personal data processed, risk to individuals, and impact on the sovereignty and integrity of India.

Examples may include:

  • Large social media platforms
  • Major banks
  • Large e-commerce companies

ZA. Specified Purpose

The purpose stated in the notice given to the Data Principal before collecting personal data.


ZB. State

Has the same meaning as under Article 12 of the Constitution of India, which includes the Government and authorities that fall within that constitutional definition.


Section 3: Application of the Act

The Act explains where it applies and where it does not.

The Act Applies

1. Processing in India

It applies when digital personal data is processed in India if the data was:

  • Collected digitally, or
  • Collected physically and later digitized.

Example:
A hospital collects a paper form and later enters it into a computer.


2. Processing Outside India

The Act also applies outside India if the processing is connected with offering goods or services to people in India.

Example:
A foreign shopping website selling products to Indian customers.


The Act Does Not Apply

1. Personal or Domestic Use

Examples:

  • Saving family photos
  • Maintaining a personal contact list
  • Sending messages to friends

2. Publicly Available Personal Data

The Act does not apply if the personal data is made public by:

  • The Data Principal themselves, or
  • A person legally required to make it public.

Illustration from the Act:
If X voluntarily posts her personal information on social media while blogging, that publicly shared information is outside the scope of the Act.


Chapter II: Obligations of Data Fiduciary


Section 4 – Lawful Processing of Personal Data

Meaning

A Data Fiduciary (company, organisation, government department, etc.) can process personal data only:

  1. With the Data Principal’s (person’s) consent, or
  2. For certain legitimate uses allowed under the Act.

The processing must always be for a lawful purpose.

Lawful Purpose

A purpose that is not prohibited by any law.

Example

  • A bank collects your Aadhaar and PAN for opening an account → Allowed.
  • A company collects your data for an illegal activity → Not allowed.

Section 5 – Notice Before Taking Consent

Before asking for consent, the Data Fiduciary must give a clear notice.

The notice should mention:

1. What personal data will be collected.

Example:

  • Name
  • Mobile number
  • Email
  • Aadhaar

2. Why the data is being collected.

Example:

  • Opening a bank account
  • Delivering products
  • Providing healthcare

3. How the person can exercise their rights.

Example:

  • Withdraw consent
  • Correct data
  • Delete data

4. How to complain to the Data Protection Board.


Illustration

X opens a bank account using Y Bank’s app.

Before collecting documents, Y Bank must tell X:

  • What data will be collected
  • Why it is needed
  • How X can withdraw consent
  • How X can complain

Old Consent (Before the Act)

If consent was taken before this Act started:

The Data Fiduciary must later inform the person:

  • What data is being used
  • Why it is used
  • Their rights
  • Complaint procedure

Processing can continue until consent is withdrawn.


Ilustration

X already uses an online shopping app.

After the Act begins, the company sends an email explaining:

  • Data collected
  • Purpose
  • User rights

Language

The notice must be available in:

  • English
  • Any language listed in the Eighth Schedule of the Constitution.

Section 6 – Consent

Consent must be:

  • Free
  • Specific
  • Informed
  • Unconditional
  • Clear
  • Given by positive action (clicking “I Agree”)

Only necessary data should be collected.


Illustration

A telemedicine app asks for:

✔ Health information

❌ Phone contact list

The contact list is unnecessary.

Only health data can be processed.


Invalid Consent

Any consent against the law is invalid.


Illustration

An insurance company asks the customer to agree that:

“You cannot complain to the Data Protection Board.”

This condition is invalid.

The customer still has the right to complain.


Consent Request Must Be

  • Simple language
  • Easy to understand
  • Available in English or Indian languages
  • Include contact details of the Data Protection Officer (or authorised person)

Right to Withdraw Consent

The Data Principal can withdraw consent anytime.

It should be as easy as giving consent.


Example

If consent was given by clicking one button,

Withdrawal should also be possible with similar ease.


Effect of Withdrawal

Withdrawal does not make previous processing illegal.

Only future processing must stop.


Illustration

X orders a laptop online.

After payment, X withdraws consent.

The company:

✔ Can deliver the laptop already ordered.

❌ Cannot continue using data for future orders.


Duty After Withdrawal

The Data Fiduciary must:

  • Stop processing personal data.
  • Ensure Data Processors also stop processing.

Unless another law allows processing.


Illustration

A telecom company emails bills through another company.

Customer changes preference to receive bills only in the app.

Both companies must stop emailing bills.


Consent Manager

A person may:

  • Give consent
  • Review consent
  • Withdraw consent

through a Consent Manager.

Consent Managers:

  • Act on behalf of the Data Principal.
  • Must be registered with the Data Protection Board.

Burden of Proof

If there is a dispute,

The Data Fiduciary must prove:

  • Proper notice was given.
  • Valid consent was obtained.

Section 7 – Legitimate Uses (No Consent Required)

Personal data may be processed without consent in certain situations.


(a) Voluntarily Provided Data

If a person voluntarily provides data for a purpose.

Illustration 1

A customer gives a phone number to receive a payment receipt.

The pharmacy can send the receipt.


Illustration 2

A person contacts a real estate broker to find a rented house.

The broker may use the data until the person says services are no longer needed.


(b) Government Benefits

Government may process data for:

  • Subsidies
  • Certificates
  • Licences
  • Permits
  • Welfare schemes

Illustration

A pregnant woman applies for maternity benefits.

Government may use the data to check eligibility for other welfare schemes.


(c) Government Functions

Data may be processed for:

  • Government duties
  • National security
  • Sovereignty
  • Integrity of India

(d) Legal Obligation

Processing is allowed if required by law.

Example:

Banks reporting information to government authorities.


(e) Court Orders

Data may be processed to comply with:

  • Court orders
  • Judgments
  • Decrees

(f) Medical Emergency

Processing is allowed to save someone’s life or health.

Example:

Hospital treating an unconscious patient.


(g) Epidemic or Public Health

Example:

COVID-19 testing and vaccination.


(h) Disaster Management

Example:

Flood relief

Earthquake rescue

Cyclone evacuation


(i) Employment Purposes

Employers may process employee data for:

  • Salary
  • Attendance
  • Benefits
  • Protecting trade secrets
  • Preventing fraud

Section 8 – General Duties of Data Fiduciary

1. Responsibility

The Data Fiduciary remains responsible even if a Data Processor handles the data.


2. Data Processor

A Data Processor can process data only under a valid contract.


3. Accurate Data

If data affects decisions or is shared with another Data Fiduciary,

It must be:

  • Complete
  • Accurate
  • Consistent

4. Security Measures

Appropriate:

  • Technical measures
  • Organisational measures

must protect personal data.


5. Prevent Data Breaches

Reasonable security safeguards must be maintained.


6. Data Breach

If a breach happens,

The Data Fiduciary must inform:

  • Data Protection Board
  • Affected Data Principals

7. Erasure of Data

Data must be deleted:

  • After consent is withdrawn, or
  • When the purpose is completed,

unless another law requires retention.


Illustration 1

A user sells a car through an online marketplace.

After the sale,

The company should delete the user’s personal data.


Illustration 2

A customer closes a bank account.

Banks must legally keep records for 10 years.

So the bank cannot immediately delete the data.


8. Purpose Ends When

If a person:

  • Stops using the service, and
  • Does not contact the company for the prescribed period,

the purpose is treated as finished.


9. Contact Information

The Data Fiduciary must publish:

  • Data Protection Officer’s details
  • Or authorised contact person

10. Grievance Redressal

Every Data Fiduciary must provide an effective complaint mechanism.


Section 9 – Personal Data of Children

Before processing children’s data,

The Data Fiduciary must obtain:

✔ Verifiable consent from the parent or lawful guardian.


Children Must Not Be Harmed

Processing should not negatively affect a child’s well-being.


No Tracking or Targeted Ads

Companies cannot:

  • Track children’s behaviour
  • Monitor children
  • Show targeted advertisements

Exceptions

Government may exempt certain Data Fiduciaries or processing activities.


Relaxation

If a company proves it processes children’s data safely,

Government may relax some obligations for older children.


Section 10 – Significant Data Fiduciary (SDF)

Government may declare certain organisations as Significant Data Fiduciaries (SDFs).


Factors Considered

  • Volume of personal data
  • Sensitive data
  • Risk to individuals
  • National security
  • Electoral democracy
  • Public order

Duties of Significant Data Fiduciary

1. Appoint a Data Protection Officer (DPO)

The DPO must:

  • Be based in India
  • Report to the Board of Directors
  • Represent the organisation
  • Handle grievances

2. Independent Data Auditor

Must conduct regular compliance audits.


3. Data Protection Impact Assessment (DPIA)

Regular assessment of:

  • Purpose of processing
  • Risks to individuals
  • Protection measures

4. Periodic Audits

Regular checks to ensure compliance.


5. Other Measures

Must comply with any additional requirements prescribed by the Government.


CHAPTER III – RIGHTS AND DUTIES OF DATA PRINCIPAL

Who is a Data Principal?

A Data Principal is the person to whom the personal data belongs.

Example:

  • Your Aadhaar details
  • Mobile number
  • Email ID
  • PAN
  • Bank details
  • Health records

All belong to you, so you are the Data Principal.


SECTION 11 – Right to Access Information

Objective

This section gives individuals the Right to Know how their personal data is being used.


Section 11(1)

If a person has already given consent to a Data Fiduciary for processing personal data, he/she can request information from that Data Fiduciary.

The request must be made in the prescribed manner.


Clause (a)

Right to obtain summary of personal data

The Data Principal can ask for:

  • What personal data is being processed.
  • Why it is being processed.
  • What activities are being carried out on the data.

Example

Suppose you created an account on Flipkart.

You can ask:

  • Which of my details are stored?
  • Is my phone number stored?
  • Is my address stored?
  • Is my purchase history stored?
  • Why are you using my information?

The company must provide a summary.


Clause (b)

Right to know with whom data has been shared

The Data Principal can ask:

  • Which Data Fiduciaries received my data?
  • Which Data Processors received my data?
  • What type of data was shared?

Example

You use a food delivery app.

The app shares:

  • Address with restaurant
  • Phone number with delivery partner
  • Payment details with payment gateway

You can ask for details of all such sharing.


Clause (c)

Right to receive any other prescribed information

Government may prescribe additional information that companies must provide.

Examples may include:

  • Date of collection
  • Duration of storage
  • Categories of data
  • Security measures
  • Processing purpose

Section 11(2)

Exception

Clause (b) and Clause (c) do not apply when data is shared with authorities authorised by law.

Applies where:

The information is shared for:

  • Prevention of offences
  • Detection of offences
  • Investigation of offences
  • Cyber incident investigation
  • Prosecution
  • Punishment

The request must be:

  • In writing
  • Made by an authority authorised by law.

Example

Police request your data from a telecom company during a criminal investigation.

The telecom company need not tell you that your data was shared.

Reason:

Investigation should not be compromised.


Important Points of Section 11

✔ Right to know how data is processed

✔ Right to know data sharing

✔ Right to receive prescribed information

✔ Exception for law enforcement agencies


SECTION 12 – Right to Correction, Completion, Updating and Erasure

Objective

This section ensures that personal data remains:

  • Accurate
  • Complete
  • Updated
  • Deleted when no longer required

Section 12(1)

A Data Principal has the right to request:

  • Correction
  • Completion
  • Updating
  • Erasure

This applies only where consent has been given.

It must also comply with other applicable laws.


Right to Correction

Correction means removing wrong information.

Example

Wrong Name:
“Ramesh Kumar”

Correct Name:
“Ramesh Sharma”

Company must correct it.


Right to Completion

Incomplete information should be completed.

Example

Address stored:

“Delhi”

Correct address:

House No. 21,
Lajpat Nagar,
New Delhi,
110024

Company must complete the record.


Right to Updating

Old information must be updated.

Example

Old mobile number

9876543210

New mobile number

9876000000

Company should update it.


Right to Erasure

Erasure means deleting personal data.

The Data Principal can request deletion.


Section 12(2)

After receiving a request:

The Data Fiduciary shall:


Clause (a)

Correct inaccurate or misleading data.


Clause (b)

Complete incomplete data.


Clause (c)

Update outdated data.


Section 12(3)

The Data Principal may request erasure.

After receiving the request:

The Data Fiduciary must erase the data.


Exception

The Data Fiduciary can retain data if:

(1) It is necessary for the specified purpose.

Example

Bank records needed to maintain customer account.


(2) Retention is required under law.

Example

Income Tax laws require financial records to be preserved.

Company cannot delete them immediately.


Important Points of Section 12

✔ Correct wrong data

✔ Complete incomplete data

✔ Update old data

✔ Delete unnecessary data

✔ Exception where law requires retention


SECTION 13 – Right to Grievance Redressal

Objective

If the Data Principal faces any issue regarding personal data, there must be a proper complaint mechanism.


Section 13(1)

Every Data Principal has the right to an easy grievance redressal mechanism.

Complaint may be against:

  • Data Fiduciary
  • Consent Manager

Complaint may relate to:

  • Data misuse
  • Delay in correction
  • Failure to delete data
  • Privacy violation
  • Failure to fulfil obligations

Example

You request deletion.

Company ignores it.

You can file a grievance.


Section 13(2)

The Data Fiduciary or Consent Manager must respond within the prescribed period.

Time limit will be notified by Rules.


Section 13(3)

Before approaching the Data Protection Board,

The Data Principal must first:

  • File complaint with Data Fiduciary or Consent Manager.

Only after exhausting this internal mechanism can the person approach the Board.


Purpose

To reduce unnecessary litigation.


Important Points of Section 13

✔ Right to complain

✔ Easy grievance mechanism

✔ Company must respond

✔ Internal remedy first

✔ Then approach Data Protection Board


SECTION 14 – Right to Nominate

Objective

Allows another person to exercise the rights of the Data Principal after death or incapacity.


Section 14(1)

A Data Principal may nominate another individual.

The nominee can exercise rights if the Data Principal:

  • Dies, or
  • Becomes incapable.

Example

Rahul nominates his wife.

After Rahul’s death,

His wife may request:

  • Access to data
  • Correction
  • Deletion
  • Grievance redressal

As allowed by the Act.


Section 14(2)

Meaning of Incapacity

“Incapacity” means inability to exercise rights because of:

Unsoundness of mind

Examples

  • Severe mental illness
  • Coma affecting decision-making

Infirmity of body

Examples

  • Serious physical disability
  • Medical condition preventing communication

Important Points of Section 14

✔ Right to nominate

✔ Rights continue after death

✔ Rights continue during incapacity

✔ Protects continuity of personal data rights


SECTION 15 – Duties of Data Principal

Rights come with responsibilities.

Every Data Principal must perform certain duties.


Clause (a)

Comply with all applicable laws while exercising rights.

Example

Do not misuse the Act to harass companies.


Clause (b)

Do not impersonate another person.

Meaning:

Never pretend to be someone else while providing personal data.


Example

Using another person’s Aadhaar to open an account.

This violates the Act.


Clause (c)

Do not suppress material information.

Meaning:

Do not hide important facts while giving information for:

  • Identity proof
  • Address proof
  • Government documents
  • Unique identifiers

Example

Hiding previous name while obtaining government documents.


Clause (d)

Do not file false or frivolous complaints.

Example

Submitting fake complaints repeatedly just to trouble a company.

This is prohibited.


Clause (e)

Provide only authentic information while requesting:

  • Correction
  • Erasure

Information must be verifiable.


Example

Changing date of birth using fake documents is prohibited.


Important Points of Section 15

✔ Follow the law

✔ No impersonation

✔ No hiding material facts

✔ No false complaints

✔ Give authentic information only


Quick Revision Table

SectionTopicMain Right/Duty
Section 11Right to InformationKnow what data is processed, why, and with whom it is shared (subject to law enforcement exceptions).
Section 12Right to Correction, Completion, Updating & ErasureCorrect inaccurate data, complete incomplete data, update outdated data, and request deletion unless retention is legally required.
Section 13Right to Grievance RedressalComplain to the Data Fiduciary/Consent Manager first, then approach the Data Protection Board if unresolved.
Section 14Right to NominateNominate another person to exercise data rights after death or incapacity.
Section 15Duties of Data PrincipalFollow the law, avoid impersonation, provide truthful information, avoid false complaints, and submit authentic information for corrections or erasure.

CHAPTER IV – SPECIAL PROVISIONS

Purpose of Chapter IV

This chapter provides exceptions and special rules under the DPDP Act. It explains:

  • When personal data can be transferred outside India.
  • Situations where the Act or some of its provisions do not apply.
  • Powers of the Central Government to exempt certain Data Fiduciaries or State authorities.

SECTION 16 – Transfer of Personal Data Outside India

Objective

Section 16 regulates the cross-border transfer of personal data.

Unlike some earlier proposals, the DPDP Act does not impose a general ban on transferring personal data outside India. Instead, it follows a negative list approach.


Section 16(1)

Provision

The Central Government may, through a notification, restrict the transfer of personal data by a Data Fiduciary to specified countries or territories outside India.

Meaning

  • Personal data can generally be transferred abroad.
  • However, if the Government identifies a country as unsafe or unsuitable, it may prohibit or restrict data transfers to that country.

Example

A company wants to transfer customer data to Country X.

If the Central Government has notified Country X as a restricted country, the transfer cannot take place.


Why this power is given?

To protect:

  • National security
  • Privacy of Indian citizens
  • Strategic interests
  • Data security

Section 16(2)

Higher Protection under Other Laws

This section clarifies that Section 16 does not override other Indian laws that provide stricter protection for personal data.

Meaning

If another law imposes stronger restrictions on cross-border transfer, that law will continue to apply.

Example

Suppose a future banking law states:

“Customer financial data cannot leave India.”

Even though DPDP generally allows international transfers, the banking law will prevail because it provides higher protection.


Important Points – Section 16

✔ Cross-border transfer is generally allowed.

✔ Government may prohibit transfer to notified countries.

✔ Other laws with stricter safeguards continue to apply.


SECTION 17 – Exemptions from the DPDP Act

Objective

Section 17 lists situations where:

  • Certain provisions of the Act do not apply, or
  • The entire Act does not apply, or
  • Certain Data Fiduciaries receive exemptions.

Section 17(1)

Certain provisions of:

  • Chapter II (except Section 8(1) and Section 8(5)),
  • Chapter III, and
  • Section 16

do not apply in the following situations.


Clause (a) – Legal Proceedings

Provision

Processing personal data is allowed if necessary for enforcing any legal right or legal claim.

Meaning

Personal data may be processed to:

  • File a case
  • Defend a case
  • Recover money
  • Enforce contractual rights

Example

A landlord sues a tenant for unpaid rent.

The landlord may process the tenant’s address, identity documents, and payment history.


Clause (b) – Courts, Tribunals and Regulatory Authorities

Provision

Courts, tribunals, regulators, or supervisory authorities may process personal data where necessary for performing their legal functions.

Includes

  • Courts
  • Tribunals
  • Regulatory bodies
  • Quasi-judicial authorities

Example

The Supreme Court processes personal records while deciding a case.

The Election Commission verifies a voter information.

SEBI investigates insider trading.


Clause (c) – Criminal Investigation

Provision

Personal data may be processed for:

  • Prevention of offences
  • Detection of offences
  • Investigation
  • Prosecution
  • Enforcement of laws

Example

Police collect:

  • CCTV footage
  • Mobile location
  • Bank records

to investigate fraud.


Clause (d) – Foreign Data Processing

Provision

Processing personal data of persons outside India under contracts with foreign clients is exempt.

Meaning

Indian companies providing outsourcing services can process foreign citizens’ data.

Example

An Indian IT company processes payroll data of employees in Canada under a contract.

The exemption applies.


Clause (e) – Corporate Restructuring

Provision

Processing personal data is allowed during:

  • Merger
  • Amalgamation
  • Demerger
  • Reconstruction
  • Transfer of business
  • Scheme of compromise or arrangement

provided the transaction is approved by a competent court or authority.

Example

Company A merges with Company B.

Employee and customer records may be transferred as part of the merger.


Clause (f) – Loan Defaults

Provision

Banks and financial institutions may process personal data to determine:

  • Financial information
  • Assets
  • Liabilities

of a person who has defaulted on a loan.

Such processing must comply with other applicable laws.

Example

A borrower fails to repay a loan.

The bank may examine:

  • Income
  • Property
  • Investments
  • Outstanding liabilities

to recover the loan.


Explanation

The terms “default” and “financial institution” have the same meanings as under the Insolvency and Bankruptcy Code, 2016 (IBC).


Illustration (Given in the Act)

  • X borrows a loan from Bank Y.
  • X fails to pay the monthly instalment.
  • Bank Y may process X’s personal data to assess financial information, assets, and liabilities.

Important Points – Section 17(1)

These exemptions apply for:

✔ Legal claims

✔ Courts and tribunals

✔ Criminal investigations

✔ Outsourcing foreign data

✔ Company mergers

✔ Loan recovery


Section 17(2)

Certain processing activities are completely exempt from the DPDP Act.


Clause (a) – State Exemption

Provision

The Central Government may exempt certain State instrumentalities when processing personal data is necessary for:

  • Sovereignty and integrity of India
  • Security of the State
  • Friendly relations with foreign States
  • Public order
  • Preventing incitement to cognizable offences

The exemption also covers processing by the Central Government of data received from such instrumentalities.

Example

An intelligence agency processes personal data to prevent terrorism.

The Act may not apply if the Government has issued the required notification.


Clause (b) – Research, Archiving and Statistics

Provision

Processing personal data for:

  • Research
  • Archiving
  • Statistical purposes

is exempt if:

  1. The data is not used to make decisions about a specific individual, and
  2. The prescribed standards are followed.

Example

The Government conducts a population health study using anonymised data.

Since no decision is made about any individual, the exemption applies.


Important Points – Section 17(2)

✔ National security exemptions.

✔ Research and statistical processing exemptions.

✔ No individual decision should be based on such research data.


Section 17(3)

Exemption for Certain Data Fiduciaries

The Central Government may exempt certain Data Fiduciaries, including recognised startups, from complying with:

  • Section 5 (Notice)
  • Section 8(3)
  • Section 8(7)
  • Section 10 (Children’s Data)
  • Section 11 (Right to Information)

The decision depends on:

  • Volume of personal data processed.
  • Nature of personal data processed.

Why?

To reduce the compliance burden on small organisations and startups.


Meaning of Startup

A startup means a:

  • Private Limited Company,
  • Partnership Firm, or
  • Limited Liability Partnership (LLP),

that is recognised under the Government’s Startup framework.


Example

A small educational startup processing limited customer data may receive exemptions from some compliance obligations.


Section 17(4)

Special Rule for the State

When personal data is processed by:

  • The State, or
  • A State instrumentality,

the following provisions do not apply:

  • Section 8(7)
  • Section 12(3) (Right to Erasure)

Additionally, if the processing does not involve making a decision affecting the Data Principal, Section 12(2) (Correction, Completion, Updating) also does not apply.

Example

The Government stores census records only for statistical purposes.

Since no decision affecting an individual is taken, correction obligations may not apply.


Section 17(5)

Temporary Exemptions

Within five years from the commencement of the DPDP Act, the Central Government may, by notification:

  • Exempt any Data Fiduciary or class of Data Fiduciaries from any provision of the Act,
  • For a specified period.

Purpose

To allow organisations time to adapt to the new compliance framework.

Example

The Government may temporarily exempt a category of healthcare institutions while they implement data protection systems.


Quick Revision Table

SectionTopicKey Provision
Section 16(1)Cross-border Data TransferGovernment may restrict transfer of personal data to notified countries or territories outside India.
Section 16(2)Other LawsLaws providing stricter protection for data transfers continue to prevail over the DPDP Act.
Section 17(1)(a)Legal ClaimsProcessing allowed to enforce legal rights or claims.
Section 17(1)(b)Courts & RegulatorsCourts, tribunals, and regulatory authorities may process data for their official functions.
Section 17(1)(c)Criminal JusticeProcessing allowed for prevention, detection, investigation, prosecution, or punishment of offences.
Section 17(1)(d)Foreign ContractsIndian entities processing foreign individuals’ data under overseas contracts are exempt.
Section 17(1)(e)Corporate RestructuringData processing allowed during mergers, amalgamations, demergers, and restructuring approved by competent authorities.
Section 17(1)(f)Loan RecoveryFinancial institutions may process data of loan defaulters to assess assets and liabilities.
Section 17(2)(a)National SecurityGovernment-notified State instrumentalities are exempt for sovereignty, security, public order, etc.
Section 17(2)(b)Research & StatisticsExemption for research, archiving, and statistical purposes if no decision is taken about an individual.
Section 17(3)Startup & Small Data Fiduciary ExemptionsGovernment may exempt notified Data Fiduciaries, including recognised startups, from selected compliance obligations.
Section 17(4)State ProcessingCertain correction and erasure rights do not apply to specified State processing.
Section 17(5)Temporary Government ExemptionsGovernment may exempt specified Data Fiduciaries from provisions of the Act for a limited period within five years of the Act’s commencement.

CHAPTER V – DATA PROTECTION BOARD OF INDIA

Purpose of Chapter V

Chapter V establishes the Data Protection Board of India (DPBI), the main authority responsible for implementing and enforcing the DPDP Act.

Main Functions of the Board

  • Receive complaints from Data Principals.
  • Inquire into personal data breaches.
  • Direct Data Fiduciaries to comply with the Act.
  • Impose monetary penalties.
  • Resolve disputes under the DPDP Act.

Remember: The Board is a digital-first adjudicatory body, not a traditional court.


SECTION 18 – Establishment of the Data Protection Board of India

Objective

This section creates the Data Protection Board of India (DPBI).


Section 18(1)

Provision

The Central Government shall establish the Data Protection Board of India by issuing a notification.

Meaning

  • The Board comes into existence only after the Government officially notifies its establishment.
  • The Board is created specifically to implement the DPDP Act.

Section 18(2)

Body Corporate

The Board is a body corporate.

Meaning of Body Corporate

It has a separate legal identity from the Government.

The Board can:

  • Own movable property (computers, furniture, vehicles).
  • Own immovable property (land, buildings).
  • Enter into contracts.
  • Sue others.
  • Be sued in its own name.

Important Features

  • Perpetual succession – the Board continues even if members change.
  • Common seal – official seal used for legal authentication.

Section 18(3)

Headquarters

The headquarters of the Board will be located at the place notified by the Central Government.

The Act does not specify a fixed city.


SECTION 19 – Composition of the Board

Objective

Explains who will be members of the Board and how they are appointed.


Section 19(1)

Composition

The Board consists of:

  • One Chairperson.
  • Such number of Members as notified by the Central Government.

The Act does not fix the number of Members.


Section 19(2)

Appointment

The Chairperson and Members are appointed by the Central Government.

The appointment procedure will be prescribed by Rules.


Section 19(3)

Qualifications

Members should possess:

  • Ability
  • Integrity
  • Good reputation (standing)

They should also have special knowledge or practical experience in one or more of the following fields:

  • Data governance
  • Administration
  • Consumer protection
  • Social protection laws
  • Dispute resolution
  • Information Technology (IT)
  • Communication technology
  • Digital economy
  • Law
  • Regulation
  • Techno-regulation
  • Any other useful field identified by the Government

Important Requirement

At least one Member must be an expert in law.


SECTION 20 – Salary, Service Conditions and Tenure

Section 20(1)

Salary and Service Conditions

Salary, allowances and other service conditions will be prescribed by Rules.

Protection

Once appointed, these service conditions cannot be changed to the disadvantage of the Chairperson or Members.

This protects their independence.


Section 20(2)

Tenure

The Chairperson and Members hold office for:

  • 2 years.

They are eligible for reappointment.


SECTION 21 – Disqualification and Removal

Objective

Specifies who cannot become or continue as Chairperson or Member.


Section 21(1)

Clause (a) – Insolvency

A person is disqualified if declared an insolvent (unable to pay debts).


Clause (b) – Conviction

Disqualified if convicted of an offence involving moral turpitude, in the opinion of the Central Government.

Examples:

  • Fraud
  • Bribery
  • Corruption
  • Forgery

Clause (c) – Physical or Mental Incapacity

Disqualified if physically or mentally incapable of performing official duties.


Clause (d) – Conflict of Interest

Disqualified if the person acquires a financial or other interest that may affect impartiality.

Example:

A Board Member owns a company being investigated by the Board.


Clause (e) – Abuse of Position

Disqualified if the Member misuses official powers against the public interest.


Section 21(2)

Removal Procedure

Before removing the Chairperson or a Member,

The Central Government must provide an opportunity of being heard.

This follows the principle of Natural Justice (Audi Alteram Partem).


SECTION 22 – Resignation, Vacancy and Post-Service Restrictions


Section 22(1)

Resignation

The Chairperson or Member may resign by giving written notice to the Central Government.

The resignation becomes effective on the earliest of:

  1. Government accepts the resignation.
  2. Three months after notice.
  3. Successor joins office.
  4. Expiry of tenure.

Section 22(2)

Filling Vacancies

Vacancies due to:

  • Resignation
  • Removal
  • Death
  • Any other reason

shall be filled through a fresh appointment.


Section 22(3)

Post-Retirement Restriction (Cooling-off Period)

For one year after leaving office,

the Chairperson or Member cannot accept employment without prior approval of the Central Government.

If they later join a Data Fiduciary against whom proceedings had been initiated during their tenure, they must disclose this to the Government.

Purpose

To prevent conflict of interest and ensure impartiality.


SECTION 23 – Meetings and Procedure


Section 23(1)

Procedure

The Board may decide its own procedure for:

  • Conducting meetings.
  • Holding digital meetings.
  • Authenticating orders and directions.

The detailed procedure will be prescribed by Rules.


Section 23(2)

Validity of Proceedings

Board proceedings remain valid even if:

Clause (a)

There is a vacancy.

Clause (b)

There is a defect in appointment.

Clause (c)

There is a procedural irregularity,

provided it does not affect the merits of the case.

Purpose

To ensure technical defects do not invalidate proceedings.


Section 23(3)

Acting Chairperson

If the Chairperson cannot perform duties due to:

  • Illness
  • Absence
  • Any other reason

the senior-most Member acts as Chairperson until the Chairperson resumes duties.


SECTION 24 – Officers and Employees

Provision

The Board may appoint officers and employees with prior approval of the Central Government.

Appointments are made to ensure efficient functioning of the Board.

Their:

  • Service conditions
  • Appointment terms

will be prescribed by Rules.


Example

The Board may appoint:

  • Legal Officers
  • Technical Experts
  • Investigation Officers
  • Administrative Staff
  • IT Specialists

SECTION 25 – Public Servant Status

Provision

The following persons are deemed to be Public Servants:

  • Chairperson
  • Members
  • Officers
  • Employees

when acting under the DPDP Act.

Meaning

They enjoy legal protection while performing official duties and are subject to responsibilities applicable to public servants under criminal law.


SECTION 26 – Powers of the Chairperson

Objective

Defines the administrative powers of the Chairperson.


Clause (a)

General Superintendence

The Chairperson supervises:

  • Administration
  • Management
  • Overall functioning of the Board.

Clause (b)

Scrutiny of Complaints

The Chairperson may authorise any officer to examine:

  • Complaints
  • Intimations
  • References
  • Correspondence

received by the Board.


Clause (c)

Allocation of Work

The Chairperson may:

  • Authorise individual Members.
  • Create groups of Members.
  • Allocate cases among them.
  • Delegate functions.

Example

One Member may hear complaints relating to children’s data, while another handles personal data breach cases.


Quick Revision Table

SectionTopicKey Provision
18EstablishmentCreates the Data Protection Board of India as a body corporate with perpetual succession and legal personality.
19CompositionChairperson and Members appointed by the Central Government; at least one Member must be a legal expert.
20Salary & TenureSalary and service conditions prescribed by Rules; tenure of 2 years with eligibility for reappointment.
21Disqualification & RemovalGrounds include insolvency, conviction, incapacity, conflict of interest, and abuse of office; removal only after an opportunity to be heard.
22Resignation & VacanciesWritten resignation, fresh appointments to fill vacancies, and a one-year cooling-off period after leaving office.
23Meetings & ProcedureBoard regulates its own procedure, including digital meetings; proceedings remain valid despite minor defects; senior-most Member acts as Chairperson when necessary.
24StaffBoard may appoint officers and employees with prior Central Government approval.
25Public ServantsChairperson, Members, officers, and employees are deemed public servants while acting under the Act.
26Powers of ChairpersonSupervises administration, authorises scrutiny of complaints, and allocates functions and proceedings among Members.

CHAPTER VI – POWERS, FUNCTIONS AND PROCEDURE OF THE BOARD

Purpose of Chapter VI

This chapter explains:

  • What powers the Data Protection Board of India (DPBI) has.
  • What functions it performs.
  • How it conducts inquiries.
  • The procedure it follows while deciding cases.

Remember: The Board is the main authority for enforcing the DPDP Act.


SECTION 27 – Powers and Functions of the Board

Objective

Section 27 explains when the Board can act and what actions it can take.


Section 27(1)

The Board performs the following functions.


Clause (a) – Personal Data Breach

Provision

When a Data Fiduciary informs the Board about a Personal Data Breach under Section 8(6), the Board may:

  1. Direct urgent remedial or mitigation measures.
  2. Conduct an inquiry.
  3. Impose a penalty if there is a violation.

Meaning

The Board acts quickly to reduce the harm caused by a data breach.

Example

A bank’s customer database is hacked.

The bank informs the Board.

The Board may direct the bank to:

  • Stop further data leakage.
  • Inform affected customers.
  • Strengthen cybersecurity.
  • Conduct an investigation.
  • Pay penalties if negligence is found.

Clause (b) – Complaints Against Data Fiduciaries

Provision

The Board can inquire into complaints made by:

  • A Data Principal, or
  • The Central Government, or
  • A State Government, or
  • On the directions of a Court.

The complaint may relate to:

  • Personal Data Breach.
  • Failure of a Data Fiduciary to perform its legal obligations.
  • Violation of the rights of a Data Principal.

Example

A company refuses to delete a user’s personal data even after receiving a valid request.

The user files a complaint.

The Board investigates the matter.


Clause (c) – Complaints Against Consent Managers

Provision

If a Consent Manager violates its legal obligations regarding personal data, the Data Principal may file a complaint.

The Board can:

  • Conduct an inquiry.
  • Impose a penalty.

Example

A Consent Manager shares user consent records without permission.

The Board may investigate and penalise the Consent Manager.


Clause (d) – Breach of Registration Conditions

Provision

If a Consent Manager violates the conditions of its registration, the Board may:

  • Conduct an inquiry.
  • Impose penalties.

Example

A registered Consent Manager fails to follow Government-prescribed technical standards.

The Board investigates.


Clause (e) – Intermediaries

Provision

If the Central Government refers a case regarding violation of Section 37(2) by an intermediary, the Board may:

  • Conduct an inquiry.
  • Impose penalties.

(Section 37 deals with blocking access to information in certain situations.)

Example

A social media platform fails to comply with Government directions under the Act.

The Board may investigate.


Section 27(2)

Power to Issue Directions

The Board may issue necessary directions to any person for proper implementation of the Act.

Conditions

Before issuing directions:

  • The person must be given an opportunity to be heard.
  • Reasons must be recorded in writing.

Example

The Board may direct a company to:

  • Stop unlawful processing.
  • Delete illegally collected data.
  • Improve cybersecurity.

The company must comply.


Section 27(3)

Modification or Cancellation of Directions

A person affected by the Board’s direction may submit a representation.

The Central Government may also make a reference.

After considering the matter, the Board may:

  • Modify the direction.
  • Suspend it.
  • Withdraw it.
  • Cancel it.

The Board may also impose conditions.

Example

A company proves that it has already corrected the violation.

The Board may modify its earlier order.


SECTION 28 – Procedure to be Followed by the Board

Objective

Section 28 explains how the Board functions and how inquiries are conducted.


Section 28(1)

Digital Office

The Board should function as an independent body.

As far as possible, it should operate as a Digital Office.

Digital by Design

The following should preferably happen online:

  • Filing complaints.
  • Allocation of cases.
  • Hearings.
  • Passing decisions.

The Government may prescribe technological and legal standards.

Purpose

  • Faster disposal.
  • Less paperwork.
  • Better accessibility.
  • Transparency.

Section 28(2)

Taking Action

After receiving:

  • Complaint.
  • Data breach report.
  • Government reference.
  • Court direction.

The Board may proceed according to the DPDP Act.


Section 28(3)

Preliminary Examination

The Board first decides whether there are sufficient grounds for inquiry.

Meaning

Not every complaint automatically leads to investigation.

The Board first checks whether the complaint appears genuine.


Section 28(4)

No Sufficient Grounds

If the Board finds no sufficient grounds:

  • It may close the proceedings.
  • Reasons must be recorded in writing.

Example

A complaint contains no evidence.

The Board dismisses it after recording reasons.


Section 28(5)

Sufficient Grounds

If sufficient grounds exist:

The Board may investigate whether the person has complied with the DPDP Act.

Example

The Board examines whether a company:

  • Collected valid consent.
  • Protected personal data.
  • Deleted data when required.

Section 28(6)

Principles of Natural Justice

The Board must follow the Principles of Natural Justice.

This means:

  • Give every party an opportunity to present its case.
  • No one should be condemned without hearing.
  • Decisions should be fair and unbiased.
  • Reasons should be recorded.

Example

Before imposing a penalty,

the company gets a chance to explain its conduct.


Section 28(7)

Civil Court Powers

For inquiries, the Board has powers similar to a Civil Court under the Code of Civil Procedure, 1908.

Clause (a)

Summon persons.

Enforce attendance.

Examine witnesses under oath.


Clause (b)

Receive affidavits.

Require production of documents.


Clause (c)

Inspect:

  • Data
  • Documents
  • Registers
  • Books of account
  • Other records

Clause (d)

Exercise additional powers prescribed by Rules.


Example

The Board may summon:

  • Company officials.
  • IT managers.
  • Cybersecurity experts.

It may inspect:

  • Server logs.
  • Security reports.
  • Customer records.

Section 28(8)

Limitation on the Board

The Board or its officers cannot:

  • Seal premises.
  • Prevent access to offices.
  • Seize computers or equipment if it would seriously affect day-to-day business operations.

Purpose

To avoid unnecessary disruption of business activities.


Section 28(9)

Assistance from Government

The Board may seek assistance from:

  • Police officers.
  • Central Government officers.
  • State Government officers.

Such officers are legally required to assist the Board.


Section 28(10)

Interim Orders

During the inquiry,

if necessary,

the Board may issue Interim Orders.

Conditions

  • Reasons must be recorded.
  • Opportunity of hearing must be given.

Example

The Board orders a company to temporarily stop processing certain personal data until the inquiry is completed.


Section 28(11)

Final Decision

After completing the inquiry and hearing all parties,

the Board may:

Option 1

Close the proceedings.

OR

Option 2

Proceed under Section 33 (imposition of monetary penalty).

Reasons must be recorded in writing.


Section 28(12)

False or Frivolous Complaints

If the Board finds that a complaint is:

  • False, or
  • Frivolous (without genuine purpose),

it may:

  • Issue a warning, or
  • Impose costs on the complainant.

Example

A person repeatedly files fake complaints merely to harass a company.

The Board may impose costs.

.


Quick Revision Table

SectionTopicKey Provision
27(1)(a)Personal Data BreachBoard directs urgent remedial measures, conducts inquiry, and may impose penalties.
27(1)(b)Complaints Against Data FiduciariesInquires into complaints by Data Principals, Government references, or Court directions regarding breaches and violations.
27(1)(c)Consent Manager ComplaintsInquires into breaches by Consent Managers and may impose penalties.
27(1)(d)Registration ConditionsInvestigates breaches of Consent Manager registration conditions.
27(1)(e)IntermediariesInquires into violations referred by the Central Government under Section 37(2).
27(2)DirectionsBoard may issue binding directions after giving an opportunity of hearing and recording reasons.
27(3)Review of DirectionsBoard may modify, suspend, withdraw, or cancel its directions upon representation or Government reference.
28(1)Digital OfficeBoard functions independently and, as far as practicable, digitally by design.
28(2)Action on ComplaintsBoard acts on complaints, breach intimations, references, and court directions.
28(3)Preliminary ScrutinyDetermines whether sufficient grounds exist for inquiry.
28(4)ClosureMay close proceedings if no sufficient grounds exist, with written reasons.
28(5)InquiryInvestigates compliance with the Act where sufficient grounds exist.
28(6)Natural JusticeMust provide a fair hearing and record reasons for its actions.
28(7)Civil Court PowersCan summon witnesses, receive affidavits, and inspect records.
28(8)Business ProtectionCannot unnecessarily seize equipment or stop normal business operations.
28(9)Government AssistanceMay require assistance from police or Government officers.
28(10)Interim OrdersMay issue temporary orders after hearing the concerned person.
28(11)Final OrderMay close the case or proceed to impose penalties under Section 33.
28(12)False ComplaintsMay warn or impose costs on complainants filing false or frivolous complaints.

CHAPTER VII – APPEAL AND ALTERNATE DISPUTE RESOLUTION

Purpose of Chapter VII

This chapter provides the remedies available after a decision of the Data Protection Board of India (DPBI). It explains:

  • How a person can appeal against the Board’s order.
  • The role of the Appellate Tribunal.
  • Mediation as an alternative method of dispute resolution.
  • Voluntary Undertakings to settle proceedings without a final penalty.

Remember: This chapter focuses on review, appeal, mediation, and settlement of disputes under the DPDP Act.


SECTION 29 – Appeal to the Appellate Tribunal

Objective

Section 29 gives a person the right to appeal against any order or direction passed by the Data Protection Board.


Section 29(1)

Right to Appeal

Provision

Any person who is aggrieved (affected) by an order or direction of the Board may file an appeal before the Appellate Tribunal.

Meaning

If a person believes that the Board’s decision is incorrect or unfair, they can challenge it before the Appellate Tribunal.

Example

The Board imposes a penalty of ₹50 lakh on a company.

The company believes the decision is wrong.

It can file an appeal before the Appellate Tribunal.


Section 29(2)

Time Limit for Appeal

Provision

The appeal must be filed:

  • Within 60 days from the date the order or direction is received.

The appeal should:

  • Be in the prescribed form.
  • Follow the prescribed procedure.
  • Be accompanied by the prescribed fee.

Example

Board’s order received on 1 January.

The appeal should normally be filed by 2 March (within 60 days).


Section 29(3)

Delay in Filing Appeal

Provision

The Appellate Tribunal may accept an appeal filed after 60 days if:

  • There was sufficient cause for the delay.

Example

A natural disaster, serious illness, or unavoidable circumstances prevented timely filing.

The Tribunal may condone the delay.


Section 29(4)

Powers of the Appellate Tribunal

Provision

After hearing both parties, the Tribunal may:

  • Confirm the Board’s order.
  • Modify the Board’s order.
  • Set aside (cancel) the Board’s order.

Example

The Board imposed a penalty of ₹10 crore.

The Tribunal finds the penalty excessive.

It reduces the penalty to ₹5 crore.


Section 29(5)

Copy of Order

The Appellate Tribunal must send a copy of its order to:

  • The Data Protection Board.
  • All parties to the appeal.

Purpose

Ensures transparency and official communication.


Section 29(6)

Time for Disposal

The Tribunal should decide appeals:

  • As quickly as possible.
  • It should try to dispose of the appeal within 6 months.

Meaning

The six-month period is a goal (directory), not a strict mandatory deadline.


Section 29(7)

Delay Beyond Six Months

If the appeal is not decided within six months,

the Tribunal must:

  • Record the reasons in writing.

Purpose

To ensure accountability and transparency.


Section 29(8)

Procedure of the Tribunal

The Appellate Tribunal shall hear appeals according to:

  • The DPDP Act.
  • The prescribed Rules.
  • Relevant provisions of the Telecom Regulatory Authority of India (TRAI) Act, 1997, particularly Sections 14A and 16.

Meaning

The Tribunal follows an established legal procedure for hearing appeals.


Section 29(9)

Further Appeal

If a person wants to challenge the Appellate Tribunal’s order,

the provisions of Section 18 of the TRAI Act, 1997 apply.

Meaning

Under the TRAI Act, an appeal from the Tribunal’s decision lies to the Supreme Court of India on specified grounds.


Section 29(10)

Digital Office

The Appellate Tribunal should function, as far as practicable, as a digital office.

This means:

  • Filing appeals online.
  • Online hearings.
  • Online decisions.

Purpose

To improve speed, accessibility, and efficiency.


Important Points – Section 29

✔ Appeal against Board’s order.

✔ Time limit = 60 days.

✔ Delay may be condoned for sufficient cause.

✔ Tribunal may confirm, modify, or cancel the order.

✔ Aim to dispose of appeals within 6 months.

✔ Digital appeal system.


SECTION 30 – Execution of Orders

Objective

Section 30 explains how the Appellate Tribunal’s orders are enforced.


Section 30(1)

Tribunal’s Power

An order passed by the Appellate Tribunal is executable like a Civil Court Decree.

Meaning

The Tribunal has the same powers as a Civil Court to enforce its orders.

Example

If the Tribunal directs a company to pay compensation or comply with an order and it refuses, the Tribunal can enforce its decision as a court decree.


Section 30(2)

Transfer to Civil Court

Instead of enforcing the order itself,

the Tribunal may send the order to a Civil Court having local jurisdiction.

The Civil Court will execute the order as if it had passed the decree itself.

Example

A company’s office is located in Delhi.

The Tribunal may transfer the order to the appropriate Civil Court in Delhi for execution.


Important Points – Section 30

✔ Tribunal’s orders are legally enforceable.

✔ Orders are treated like Civil Court decrees.

✔ Tribunal may transfer execution to a Civil Court.


SECTION 31 – Mediation (Alternative Dispute Resolution)

Objective

Section 31 encourages settlement through mediation instead of prolonged litigation.


Provision

If the Board believes that a complaint can be resolved through mediation,

it may direct the parties to attempt mediation.

The mediator may be:

  • A person mutually agreed by both parties, or
  • A mediator appointed under any applicable law in India.

What is Mediation?

Mediation is a process where:

  • A neutral third person (Mediator) helps both parties reach a voluntary settlement.
  • The mediator does not impose a decision.

Example

A Data Principal complains that a company delayed correcting personal data.

The Board believes the issue can be settled.

It directs both parties to mediation.

If they agree on corrective action, the dispute may end without a formal inquiry.


Advantages of Mediation

  • Faster resolution.
  • Less expensive.
  • Friendly settlement.
  • Reduces litigation.
  • Saves time for the Board.

Important Points – Section 31

✔ Board may refer disputes to mediation.

✔ Mediator may be chosen by mutual agreement.

✔ Promotes amicable settlement.

✔ Alternative to formal proceedings.


SECTION 32 – Voluntary Undertaking

Objective

Section 32 allows a person to voluntarily promise compliance with the Act instead of continuing legal proceedings.


What is a Voluntary Undertaking?

It is a written promise given by a person to the Board stating that they will:

  • Correct the violation.
  • Stop the unlawful activity.
  • Take specific corrective measures within a specified time.

Section 32(1)

Acceptance of Voluntary Undertaking

The Board may accept a voluntary undertaking:

  • From any person.
  • At any stage of proceedings under Section 28.

Example

During an inquiry, a company admits its mistake and voluntarily agrees to:

  • Improve security systems.
  • Delete unlawfully collected data.
  • Train employees on data protection.

The Board may accept this undertaking.


Section 32(2)

Contents of the Undertaking

The undertaking may include a promise to:

  • Take specified action.
  • Complete the action within a specified time.
  • Stop a particular activity.
  • Publicise the undertaking if required.

Example

The company promises:

  • To delete unnecessary personal data within 30 days.
  • To stop sharing customer information without consent.
  • To publish a notice on its website informing users about corrective measures.

Section 32(3)

Modification

The Board may change the terms of the undertaking,

but only:

  • With the consent of the person who gave the undertaking.

Example

The Board extends the compliance period from 30 days to 45 days with the company’s consent.


Section 32(4)

Effect of Acceptance

Once the Board accepts the voluntary undertaking,

no further proceedings will continue regarding the matters covered by that undertaking.

Meaning

The dispute is treated as settled, unless the undertaking is later violated.


Section 32(5)

Breach of Undertaking

If the person fails to follow the undertaking,

the breach is treated as a breach of the DPDP Act itself.

The Board may:

  • Give the person an opportunity of being heard.
  • Proceed under Section 33 (imposition of monetary penalties).

Example

A company promised to delete customer data within 30 days but failed to do so.

The Board may reopen the matter and impose penalties.


Important Points – Section 32

✔ Voluntary compliance encouraged.

✔ Can be offered at any stage of inquiry.

✔ May require corrective action or stopping certain activities.

✔ Board may modify terms with consent.

✔ Accepted undertaking bars further proceedings on that issue.

✔ Breach of the undertaking leads to fresh proceedings and possible penalties.


Quick Revision Table

SectionTopicKey Provision
29(1)Right to AppealAny aggrieved person may appeal against an order or direction of the Data Protection Board before the Appellate Tribunal.
29(2)LimitationAppeal must be filed within 60 days in the prescribed form and with the prescribed fee.
29(3)Condonation of DelayTribunal may accept a delayed appeal if sufficient cause is shown.
29(4)Tribunal’s PowersTribunal may confirm, modify, or set aside the Board’s order after hearing the parties.
29(5)Communication of OrderCopy of the Tribunal’s order must be sent to the Board and all parties.
29(6)Disposal of AppealTribunal should endeavour to decide appeals within 6 months.
29(7)DelayReasons must be recorded if the appeal is not decided within six months.
29(8)ProcedureTribunal follows the prescribed procedure and relevant provisions of the TRAI Act, 1997.
29(9)Further AppealAppeals against Tribunal orders are governed by Section 18 of the TRAI Act, enabling appeal to the Supreme Court.
29(10)Digital OfficeAppeals should, as far as practicable, be filed, heard, and decided digitally.
30Execution of OrdersTribunal’s orders are executable as Civil Court decrees or may be transferred to a Civil Court for execution.
31MediationBoard may refer disputes to mediation for amicable settlement.
32(1)Voluntary UndertakingBoard may accept a voluntary undertaking from any person at any stage of proceedings.
32(2)TermsUndertaking may include promises to take or refrain from specified actions within a specified time.
32(3)VariationTerms may be modified with the person’s consent.
32(4)EffectAcceptance generally bars further proceedings on the matters covered by the undertaking.
32(5)BreachFailure to comply with the undertaking is treated as a breach of the Act and may result in proceedings under Section 33.

CHAPTER VIII – PENALTIES AND ADJUDICATION

Purpose of Chapter VIII

This chapter explains:

  • When penalties can be imposed under the DPDP Act.
  • How the Data Protection Board decides the amount of penalty.
  • Where the penalty money goes after collection.

Remember: The DPDP Act mainly provides for monetary (financial) penalties, not imprisonment.


SECTION 33 – Monetary Penalties

Objective

Section 33 gives the Data Protection Board of India (DPBI) the power to impose monetary penalties on persons who violate the provisions of the DPDP Act or the Rules.


Section 33(1)

Power to Impose Monetary Penalty

Provision

After completing an inquiry under Section 28, if the Board finds that:

  • A person has breached the provisions of the DPDP Act or the Rules, and
  • The breach is significant,

then the Board may impose a monetary penalty as specified in the Schedule to the Act.

Important Conditions

Before imposing a penalty:

  1. The inquiry must be completed.
  2. The Board must determine that the breach is significant.
  3. The person must be given an opportunity of being heard (Principles of Natural Justice).
  4. The penalty must be within the limits prescribed in the Schedule.

Meaning of “Significant Breach”

The Act does not define the word “significant.”

Therefore, the Board decides whether a breach is significant by considering the seriousness of the facts and the factors listed in Section 33(2).


Example

A social media company:

  • Stores personal data without valid consent.
  • Experiences a major data breach.
  • Fails to inform affected users.

After inquiry, the Board concludes that the breach is significant and imposes a monetary penalty.


Important Features of Section 33(1)

✔ Inquiry must be completed first.

✔ Penalty only for significant violations.

✔ Opportunity of hearing is mandatory.

✔ Penalty amount comes from the Schedule to the Act.


Section 33(2)

Factors for Determining the Amount of Penalty

The Board does not automatically impose the maximum penalty.

It must consider several important factors before deciding the amount.


Clause (a)

Nature, Gravity and Duration of the Breach

The Board examines:

  • How serious the violation is.
  • How long it continued.
  • How harmful it was.

Example

A company accidentally exposed data for one day.

This may attract a lower penalty.

If it knowingly ignored security for two years,

the penalty is likely to be much higher.


Clause (b)

Type and Nature of Personal Data Affected

The Board considers what type of personal data was affected.

Some personal data is more sensitive than others.

Example

Lower impact:

  • Email address.

Higher impact:

  • Aadhaar number.
  • Financial information.
  • Medical records.
  • Biometric information.

The more sensitive the data, the higher the possible penalty.


Clause (c)

Repetitive Nature of the Breach

The Board checks whether the person has committed similar violations before.

Example

A company violates the Act once.

Penalty may be moderate.

If the same company repeatedly violates the Act,

the Board may impose a much higher penalty.


Clause (d)

Gain or Avoidance of Loss

The Board considers whether the person:

  • Earned extra profit because of the breach, or
  • Avoided financial loss by violating the law.

Example

A company secretly sells customer data to advertisers.

It earns huge profits.

The Board may impose a higher penalty.


Clause (e)

Steps Taken to Reduce Harm (Mitigation)

The Board considers whether the person tried to reduce the damage.

It also checks:

  • How quickly action was taken.
  • Whether the action was effective.

Example

Immediately after discovering a cyberattack,

the company:

  • Informs users.
  • Stops further leakage.
  • Fixes the security issue.

These actions may reduce the penalty.


Clause (f)

Proportionate and Effective Penalty

The Board must ensure that the penalty is:

Proportionate

Not too harsh.

Not too lenient.

Effective

Strong enough to ensure compliance.

Deterrent

Discourages future violations.

Example

A small startup should not automatically receive the same penalty as a multinational company if the circumstances are substantially different.


Clause (g)

Impact of Penalty on the Person

The Board considers how the penalty will affect the person or organisation.

Example

A very small organisation making an honest mistake may receive a lower penalty than a large corporation committing a deliberate and serious violation.


Summary of Factors under Section 33(2)

The Board considers:

✔ Seriousness of breach.

✔ Duration.

✔ Type of personal data.

✔ Repeat offences.

✔ Financial gain.

✔ Mitigation efforts.

✔ Proportionality.

✔ Impact of penalty.


Illustration

Suppose Company ABC:

  • Leaks Aadhaar and PAN details of 5 lakh customers.
  • Ignores security warnings for one year.
  • Earns money by sharing customer data.
  • Does not inform affected users.
  • Takes no corrective action.

The Board may consider:

  • Serious nature of breach.
  • Sensitive personal data.
  • Long duration.
  • Financial gain.
  • No mitigation.

Result:

A very high monetary penalty may be imposed.


Important Points – Section 33

✔ Board imposes monetary penalties.

✔ Penalty only after inquiry.

✔ Opportunity of hearing required.

✔ Factors listed in Section 33(2) must be considered.

✔ Penalty limits are prescribed in the Schedule to the Act.


SECTION 34 – Credit of Penalties

Objective

Explains where the collected penalty money goes.


Provision

All penalties collected under the DPDP Act shall be credited to the:

Consolidated Fund of India (CFI).


What is the Consolidated Fund of India?

The Consolidated Fund of India is the main government account established under Article 266(1) of the Constitution of India.

It contains:

  • Tax revenue.
  • Government receipts.
  • Borrowed money.
  • Other income received by the Central Government.

Money can be withdrawn from this Fund only with the approval of Parliament.


Example

The Board imposes a penalty of ₹50 crore on a company.

The company deposits the amount.

The ₹50 crore is credited to the Consolidated Fund of India, not to the Board.


Why is the Money Credited to the CFI?

Because:

  • The Board is a statutory authority, not a profit-making body.
  • Penalties are Government revenue.
  • This ensures transparency and public accountability.

Important Points – Section 34

✔ All penalties go to the Consolidated Fund of India.

✔ The Board does not retain penalty money.

✔ Ensures transparency and constitutional control over public funds.


Quick Revision Table

SectionTopicKey Provision
33(1)Monetary PenaltyAfter completing an inquiry, the Board may impose a monetary penalty for a significant breach of the Act or Rules, after giving the person an opportunity of being heard.
33(2)(a)Nature, Gravity & DurationConsiders how serious the breach is and how long it continued.
33(2)(b)Type of Personal DataConsiders the sensitivity and nature of the personal data affected.
33(2)(c)Repeated ViolationsHigher penalties may apply for repeated breaches.
33(2)(d)Financial GainConsiders whether the person profited from the breach or avoided a loss.
33(2)(e)MitigationConsiders whether timely and effective steps were taken to reduce harm.
33(2)(f)ProportionalityPenalty must be fair, effective, and sufficient to ensure compliance and deter future violations.
33(2)(g)ImpactConsiders the likely impact of the penalty on the person or organisation.
34Credit of PenaltiesAll penalties collected are credited to the Consolidated Fund of India.

Schedule to the DPDP Act

The exact maximum penalties are provided in the Schedule to the Act. Some important limits include:

ViolationMaximum Monetary Penalty
Failure to take reasonable security safeguards leading to a personal data breach₹250 crore
Failure to notify the Board and affected Data Principals of a personal data breach₹200 crore
Breach of obligations relating to children’s personal data₹200 crore
Breach of additional obligations of Significant Data Fiduciaries₹150 crore
Breach of duties by a Data Principal (where applicable)₹10,000
Other breaches where no specific penalty is prescribedUp to ₹50 crore

Note: These are maximum limits. The Board is not required to impose the maximum penalty in every case. It must determine the appropriate amount by considering the factors listed in Section 3


CHAPTER IX – MISCELLANEOUS

Purpose of Chapter IX

Chapter IX contains general, administrative, and miscellaneous provisions of the DPDP Act. It explains:

  • Protection for Government and Board officials acting in good faith.
  • Power of the Central Government to seek information.
  • Blocking powers against repeat offenders.
  • Relationship with other laws.
  • Rule-making powers.
  • Parliamentary oversight.
  • Power to amend the Schedule.
  • Removal of difficulties.
  • Amendments to other Acts.

SECTION 35 – Protection of Action Taken in Good Faith

Objective

This section protects Government and Board officials from legal proceedings when they act honestly while implementing the Act.


Provision

No:

  • Suit
  • Prosecution
  • Other legal proceeding

shall lie against:

  • Central Government
  • Data Protection Board
  • Chairperson
  • Members
  • Officers
  • Employees

for anything done or intended to be done in good faith under the DPDP Act or Rules.


Meaning of “Good Faith”

Good faith means:

  • Honest intention.
  • Acting without fraud.
  • Acting without malicious motive.
  • Acting reasonably while performing official duties.

It does not protect dishonest, corrupt, or malicious actions.


Example

The Board issues a notice believing there has been a data breach.

Later, it turns out no breach occurred.

If the notice was issued honestly and with reasonable care, Board officials are protected.


Important Points – Section 35

✔ Protects honest official actions.

✔ Applies only to actions done in good faith.

✔ Does not protect bad faith or misuse of power.


SECTION 36 – Power of Central Government to Call for Information

Objective

Allows the Central Government to obtain information needed for implementing the Act.


Provision

The Central Government may require:

  • The Board,
  • Any Data Fiduciary, or
  • Any Intermediary,

to furnish any information required for the purposes of the Act.


Example

The Government asks a social media company to provide information about:

  • Number of reported data breaches.
  • Compliance measures adopted.

The company must provide the information.


Important Points – Section 36

✔ Government can seek information.

✔ Applies to the Board, Data Fiduciaries, and Intermediaries.

✔ Used for implementation and monitoring of the Act.


SECTION 37 – Blocking of Information

Objective

Provides a strong enforcement mechanism against repeat violators.


Section 37(1)

When can blocking be ordered?

The Central Government may block public access to information only after receiving a written reference from the Board.

The Board’s reference must contain both:

Clause (a)

The Board has imposed a monetary penalty on the Data Fiduciary on two or more occasions.

Clause (b)

The Board advises that blocking access is necessary in the interests of the general public.


Additional Conditions

Before blocking:

  • The Data Fiduciary must be given an opportunity to be heard.
  • The Government must record reasons in writing.
  • The Government must be satisfied that blocking is necessary or expedient in the public interest.

What may be blocked?

Information generated, transmitted, received, stored, or hosted on any computer resource that enables the Data Fiduciary to offer goods or services to Data Principals in India.


Example

A platform repeatedly violates the DPDP Act and has already been penalised twice.

The Board recommends blocking.

After hearing the platform, the Government may direct Internet Service Providers (ISPs) to block access to that platform in India.


Section 37(2)

Duty of Intermediaries

Every intermediary receiving a blocking direction must comply.

Example

Internet Service Providers (ISPs) or social media platforms must implement the blocking order.


Section 37(3)

Definitions

The expressions:

  • Computer Resource
  • Information
  • Intermediary

have the same meanings as under the Information Technology Act, 2000.


Important Points – Section 37

✔ Applies only after two or more penalties.

✔ Requires Board recommendation.

✔ Opportunity of hearing is mandatory.

✔ Reasons must be recorded.

✔ Intermediaries must comply.


SECTION 38 – Relationship with Other Laws


Section 38(1)

Additional Law

The DPDP Act is in addition to other laws.

Meaning

The Act does not automatically replace other laws.

Other applicable laws continue to operate.


Section 38(2)

Conflict Rule

If there is a conflict between:

  • DPDP Act
  • Another law

the DPDP Act will prevail to the extent of the conflict.


Example

Another law allows disclosure of personal data without safeguards.

If this conflicts with the DPDP Act, the DPDP Act prevails for that conflict.


Important Points – Section 38

✔ DPDP works alongside other laws.

✔ DPDP prevails where there is inconsistency.


SECTION 39 – Bar of Civil Court Jurisdiction

Objective

Prevents Civil Courts from interfering in matters assigned to the Board.


Provision

Civil Courts cannot:

  • Hear matters assigned to the Board.
  • Grant injunctions against actions taken under the Act.

Example

A company cannot bypass the Board by filing a Civil Suit challenging an ongoing inquiry.

The proper remedy is an appeal under Section 29.


Important Points – Section 39

✔ Civil Courts have no jurisdiction over matters assigned to the Board.

✔ No injunction against Board proceedings.


SECTION 40 – Power to Make Rules

Objective

Empowers the Central Government to make detailed Rules for implementing the Act.


Section 40(1)

The Central Government may:

  • Make Rules by notification.
  • Publish draft Rules before finalising them (previous publication).
  • Ensure Rules are consistent with the Act.

Section 40(2)

Matters for Which Rules May Be Made

The Rules may prescribe details regarding:

(a) Notice to Data Principal (Section 5(1))

How notice should be given.


(b) Additional Notice Requirements (Section 5(2))

How existing Data Principals should be informed.


(c) Consent Manager Accountability (Section 6(8))

Responsibilities and accountability.


(d) Registration of Consent Managers (Section 6(9))

Registration procedure and conditions.


(e) Government Benefits (Section 7)

Processing of personal data for subsidies, licences, permits, etc.


(f) Data Breach Intimation (Section 8(6))

How breaches should be reported.


(g) Storage Period (Section 8(8))

Time after which the specified purpose is treated as completed.


(h) Data Protection Officer Details (Section 8(9))

Publication of DPO contact information.


(i) Verifiable Parental Consent (Section 9)

Procedure for obtaining parental consent.


(j) Children’s Data Processing (Section 9(4))

Permitted purposes and conditions.


(k) Data Protection Impact Assessment (Section 10)

Procedure and requirements.


(l) Additional Measures for Significant Data Fiduciaries

Extra compliance obligations.


(m) Right to Information Requests (Section 11)

How Data Principals request information.


(n) Erasure Requests (Section 12)

Procedure for deletion requests.


(o) Grievance Response Time (Section 13)

Time within which grievances must be answered.


(p) Nomination Procedure (Section 14)

How nominations are made.


(q) Research Standards (Section 17)

Standards for research exemptions.


(r) Appointment of Board Members (Section 19)

Appointment procedure.


(s) Salary and Service Conditions (Section 20)

Pay and allowances.


(t) Authentication of Orders (Section 23)

How Board orders are authenticated.


(u) Appointment of Officers (Section 24)

Service conditions.


(v) Digital Procedures (Section 28)

Techno-legal measures.


(w) Additional Civil Court Powers (Section 28)

Other prescribed powers.


(x) Appeal Procedure (Section 29)

Form, fee, and filing procedure.


(y) Tribunal Procedure (Section 29)

Procedure for hearing appeals.


(z) Any Other Matter

Any additional matter requiring Rules.


Important Points – Section 40

✔ Government frames detailed Rules.

✔ Rules cannot contradict the Act.

✔ Rules provide operational details.


SECTION 41 – Laying Before Parliament

Objective

Ensures Parliamentary oversight over Rules and certain Notifications.


Provision

Every:

  • Rule
  • Notification under Sections 16 and 42

must be laid before both Houses of Parliament for 30 days.

Parliament may:

  • Approve.
  • Modify.
  • Reject.

Actions already taken under the Rule remain valid even if later modified or annulled.


Important Points – Section 41

✔ Parliamentary control.

✔ 30-day review period.

✔ Previous actions remain valid.


SECTION 42 – Power to Amend the Schedule


Section 42(1)

The Central Government may amend the Schedule by notification.

Restriction

Penalty amounts cannot exceed twice the amount specified when the Act was originally enacted.


Section 42(2)

The amendment:

  • Becomes part of the Act.
  • Takes effect from the date of notification.

Example

If the original maximum penalty is ₹250 crore,

it cannot be increased beyond ₹500 crore through a notification.


Important Points – Section 42

✔ Government can amend penalty Schedule.

✔ Maximum increase limited to double the original amount.


SECTION 43 – Power to Remove Difficulties


Section 43(1)

If any practical difficulty arises in implementing the Act,

the Central Government may issue orders to remove the difficulty.

Such orders must be:

  • Consistent with the Act.
  • Published in the Official Gazette.

Section 43(2)

This power exists only for 3 years from the commencement of the Act.


Section 43(3)

Every such order must be laid before Parliament.


Important Points – Section 43

✔ Temporary power.

✔ Valid only for three years.

✔ Parliamentary oversight.


SECTION 44 – Amendments to Other Acts

Objective

Makes consequential amendments to align other laws with the DPDP Act.


Section 44(1)

Amendment to the TRAI Act, 1997

The Telecom Disputes Settlement and Appellate Tribunal (TDSAT) is designated as the Appellate Tribunal for:

  • Information Technology Act.
  • Airports Economic Regulatory Authority Act.
  • DPDP Act.

Section 44(2)

Amendments to the Information Technology Act, 2000

Clause (a)

Section 43A is omitted.

Reason: Data protection is now governed by the DPDP Act.


Clause (b)

Section 81 is amended to clarify that the DPDP Act also prevails where applicable.


Clause (c)

Rule-making provision relating to Section 43A is omitted.


Section 44(3)

Amendment to the Right to Information (RTI) Act, 2005

Section 8(1)(j) is substituted.

The exemption now simply covers:

“information which relates to personal information.”

This aligns the RTI Act with the DPDP Act’s protection of personal data.


Important Points – Section 44

✔ TDSAT acts as the Appellate Tribunal under the DPDP Act.

✔ IT Act provisions on compensation for failure to protect data (Section 43A) are removed.

✔ RTI Act is amended to harmonise personal information protections with the DPDP framework.


Quick Revision Table

SectionTopicKey Provision
35Good Faith ProtectionProtects the Central Government, the Board, and its officials from legal proceedings for acts done honestly under the Act.
36Information PowerCentral Government may require information from the Board, Data Fiduciaries, and Intermediaries.
37Blocking PowerGovernment may block access to repeat violators after two or more penalties, a Board recommendation, hearing, and recorded reasons.
38Relationship with Other LawsDPDP Act is in addition to other laws; it prevails where there is a conflict.
39Civil Court BarCivil Courts cannot hear matters assigned to the Board or grant injunctions against Board actions.
40Rule-MakingCentral Government may make Rules to implement the Act on numerous procedural and operational matters.
41Parliamentary OversightRules and specified Notifications must be laid before Parliament for review.
42Amendment of ScheduleGovernment may amend the Schedule, but penalty amounts cannot exceed twice the original maximum.
43Removal of DifficultiesGovernment may issue orders to remove implementation difficulties within 3 years of the Act’s commencement.
44Amendments to Other ActsAmends the TRAI Act, Information Technology Act, and RTI Act to align them with the DPDP Act.