The text you shared is the Preamble and opening of the Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023). Here’s a simple explanation:
What is it?
- The Digital Personal Data Protection Act, 2023 (DPDP Act) is a law passed by the Parliament of India.
- It protects the digital personal data of individuals.
- It also allows organisations to use personal data for lawful purposes.
Objective
The Act aims to balance:
- People’s right to protect their personal data, and
- The need to process personal data for legal and legitimate purposes.
Applies to
- Personal data collected in digital form.
- Personal data collected offline but later converted into digital form.
Key Terms
- Data Principal: The individual whose personal data is being collected.
- Data Fiduciary: The person, company, or organisation that decides how and why personal data is processed.
- Personal Data: Any information that can identify a person.
Main Features
- Gives individuals rights over their personal data.
- Requires organisations to handle data responsibly.
- Data should be collected only for lawful purposes.
- Provides penalties for violating the Act.
Interesting Fact
- The DPDP Act, 2023 is the first Act of the Parliament of India to use “she/her” pronouns instead of the traditional “he/him” pronouns in its drafting.
Remember
DPDP = Digital Personal Data Protection
- D – Digital
- P – Personal
- D – Data
- P – Protection
Purpose of the Act
The Act establishes a legal framework for how digital personal data should be collected, stored, used, and shared in India. It aims to balance two important objectives:
- Protecting individuals’ privacy by giving them rights over their personal data.
- Allowing lawful processing of personal data by organizations and the government when necessary for legitimate purposes.
Key ideas in the preamble
- It applies to digital personal data.
- It recognizes that people have a right to protect their personal information.
- It also recognizes that businesses, government bodies, and other organizations may need to process personal data for lawful purposes.
- It covers not only the main provisions but also related and incidental matters necessary to implement the law.
Digital Personal Data Protection Act, 2023 (DPDP Act) – Background
1. Why was a Data Protection Law Needed?
Before 2023, India did not have a dedicated law to protect personal data. Personal data was mainly regulated under the Information Technology Act, 2000 and its rules, which were considered inadequate due to rapid growth in the digital economy, social media, online banking, e-commerce, and digital government services.
The need for a comprehensive data protection law became stronger after the Supreme Court recognised the Right to Privacy as a Fundamental Right.
2. The Puttaswamy Judgment (2017)
Date
24 August 2017
Case
Justice K.S. Puttaswamy (Retd.) v. Union of India
Importance
A nine-judge Constitution Bench of the Supreme Court unanimously held that:
- Right to Privacy is a Fundamental Right.
- It is protected under Article 21 (Right to Life and Personal Liberty).
- It is also part of the freedoms guaranteed under Part III of the Constitution.
Why was this judgment important?
The Court stated that citizens have the right to control their personal information.
It also observed that:
- Personal data must be protected.
- The Government should enact a comprehensive Data Protection Law.
This judgment became the foundation of India’s Data Protection Law.
3. Justice B.N. Srikrishna Committee (2017–18)
After the judgment, the Government constituted a Committee of Experts.
Chairman
Justice B.N. Srikrishna
(Former Judge of the Supreme Court)
Objective
The Committee was asked to:
- Study international data protection laws.
- Prepare a legal framework for India.
- Recommend a comprehensive data protection law.
4. Public Consultation
The Committee released several White Papers and invited:
- Citizens
- Industry
- Technology companies
- Civil society organisations
- Legal experts
to submit suggestions.
This helped the Government understand public concerns regarding:
- Privacy
- Consent
- Data processing
- Government access to data
- Rights of individuals
5. Personal Data Protection Bill, 2018
Based on consultations, the Committee prepared the Personal Data Protection Bill, 2018.
The Committee also submitted:
- A detailed report
- Recommendations on protecting personal data
Although the Bill was not introduced in Parliament, it became the basis for future legislation.
6. Personal Data Protection Bill, 2019
Cabinet Approval
4 December 2019
The Union Cabinet approved a revised version.
Introduced in Parliament
11 December 2019
The Personal Data Protection Bill, 2019 was introduced in the Lok Sabha.
7. Joint Parliamentary Committee (JPC)
After introduction, the Bill was referred to a Joint Parliamentary Committee (JPC).
Purpose
The Committee examined:
- Every provision of the Bill
- Suggestions from experts
- Views of technology companies
- Public comments
- Government departments
The Committee held several meetings over nearly two years.
8. JPC Report (2021)
Date
16 December 2021
The Committee submitted its report.
It suggested:
- Several amendments
- Stronger protection for citizens
- Wider regulation of data
- Changes in the proposed Data Protection Authority
- Expansion of the Bill’s scope
9. Withdrawal of the 2019 Bill (2022)
Date
3 August 2022
The Government withdrew the Personal Data Protection Bill, 2019.
Reason
The Government stated that:
- The JPC had suggested many amendments.
- Instead of making numerous changes, it would prepare an entirely new and simpler Bill.
10. Draft Digital Personal Data Protection Bill (2022)
Date
18 November 2022
The Ministry of Electronics and Information Technology (MeitY) released the draft Digital Personal Data Protection Bill.
The draft was published for public consultation.
Suggestions were invited from:
- Citizens
- Industry
- Technology companies
- Legal experts
11. Digital Personal Data Protection Bill, 2023
Date Introduced
3 August 2023
Introduced in the Lok Sabha.
Passed by Parliament
Lok Sabha
7 August 2023
Rajya Sabha
9 August 2023
Presidential Assent
11 August 2023
After receiving the President’s assent, it became:
Chapter I – Preliminary
Section 1: Short Title and Commencement
Section 1(1): Name of the Act
The law is called the Digital Personal Data Protection Act, 2023 (DPDP Act, 2023).
Section 1(2): Commencement
- The Act does not come into force immediately.
- The Central Government decides the date through a notification in the Official Gazette.
- Different provisions may come into force on different dates.
Example:
The Government may enforce consent provisions first and penalty provisions later.
Section 2: Definitions
These definitions explain important terms used throughout the Act.
(A). Appellate Tribunal
The Telecom Disputes Settlement and Appellate Tribunal (TDSAT) hears appeals against decisions of the Data Protection Board.
(B) Automated
A digital process that works automatically according to instructions.
Example:
- Face recognition
- Spam filters
- AI recommendation systems
(C) Board
The Data Protection Board of India established under Section 18 to enforce the Act.
(D) Certain Legitimate Uses
Processing allowed under Section 7 even without consent in specified situations.
(E). Chairperson
The head of the Data Protection Board.
(F). Child
A person below 18 years of age.
(G). Consent Manager
A registered person who helps individuals:
- Give consent
- Withdraw consent
- Review consent
- Manage consent
through one common platform.
(H). Data
Any representation of information such as:
- Facts
- Opinions
- Numbers
- Images
- Instructions
that humans or computers can process.
(I). Data Fiduciary
The person or organisation deciding:
- Why personal data is collected
- How it is processed
Examples:
- Banks
- Hospitals
- Schools
- Social media companies
- E-commerce websites
(J). Data Principal
The individual whose personal data is processed.
Special cases:
- For children, parents or legal guardians act on their behalf.
- For persons with disabilities, lawful guardians may act where applicable under the Act.
(K) . Data Processor
Processes personal data for the Data Fiduciary.
Example:
A cloud service provider storing customer information for a bank.
(L) . Data Protection Officer (DPO)
An officer appointed by a Significant Data Fiduciary to ensure compliance with the Act.
M. Digital Office
An office where all proceedings happen online.
Example:
- Filing complaints
- Hearings
- Orders
N. Digital Personal Data
Personal data in electronic form.
Examples:
- Aadhaar number stored digitally
- Online medical records
- Email address
- Digital photographs
O. Gain
Includes:
- Property gain
- Financial benefit
- Better earning opportunity
P. Loss
Includes:
- Property loss
- Loss of services
- Financial loss
- Lost earning opportunity
Q. Member
A member of the Data Protection Board, including the Chairperson.
R. Notification
An official announcement published in the Official Gazette.
S. Person
Includes:
- Individual
- Hindu Undivided Family (HUF)
- Company
- Firm
- Association
- Government (State)
- Artificial legal persons
T. Personal Data
Any information relating to an identifiable individual.
Examples:
- Name
- Mobile number
- Aadhaar number
- Photograph
- Location data
- Biometric data
U. Personal Data Breach
Any unauthorized or accidental event involving personal data that compromises its:
- Confidentiality (kept secret)
- Integrity (remains accurate and unaltered)
- Availability (accessible when needed)
Examples:
- Hacking
- Data leak
- Accidental deletion
- Unauthorized sharing
V. Prescribed
Specified by rules made under the Act.
W. Proceeding
Any action taken by the Data Protection Board.
Examples:
- Inquiry
- Hearing
- Penalty proceedings
X. Processing
Any automated or partly automated operation performed on digital personal data.
Includes:
- Collection
- Storage
- Recording
- Organization
- Retrieval
- Use
- Sharing
- Transmission
- Erasure
- Destruction
Y. “She”
The word “she” includes every individual regardless of gender.
Z. Significant Data Fiduciary (SDF)
A Data Fiduciary notified by the Central Government based on factors such as the volume and sensitivity of personal data processed, risk to individuals, and impact on the sovereignty and integrity of India.
Examples may include:
- Large social media platforms
- Major banks
- Large e-commerce companies
ZA. Specified Purpose
The purpose stated in the notice given to the Data Principal before collecting personal data.
ZB. State
Has the same meaning as under Article 12 of the Constitution of India, which includes the Government and authorities that fall within that constitutional definition.
Section 3: Application of the Act
The Act explains where it applies and where it does not.
The Act Applies
1. Processing in India
It applies when digital personal data is processed in India if the data was:
- Collected digitally, or
- Collected physically and later digitized.
Example:
A hospital collects a paper form and later enters it into a computer.
2. Processing Outside India
The Act also applies outside India if the processing is connected with offering goods or services to people in India.
Example:
A foreign shopping website selling products to Indian customers.
The Act Does Not Apply
1. Personal or Domestic Use
Examples:
- Saving family photos
- Maintaining a personal contact list
- Sending messages to friends
2. Publicly Available Personal Data
The Act does not apply if the personal data is made public by:
- The Data Principal themselves, or
- A person legally required to make it public.
Illustration from the Act:
If X voluntarily posts her personal information on social media while blogging, that publicly shared information is outside the scope of the Act.
Chapter II: Obligations of Data Fiduciary
Section 4 – Lawful Processing of Personal Data
Meaning
A Data Fiduciary (company, organisation, government department, etc.) can process personal data only:
- With the Data Principal’s (person’s) consent, or
- For certain legitimate uses allowed under the Act.
The processing must always be for a lawful purpose.
Lawful Purpose
A purpose that is not prohibited by any law.
Example
- A bank collects your Aadhaar and PAN for opening an account → Allowed.
- A company collects your data for an illegal activity → Not allowed.
Section 5 – Notice Before Taking Consent
Before asking for consent, the Data Fiduciary must give a clear notice.
The notice should mention:
1. What personal data will be collected.
Example:
- Name
- Mobile number
- Aadhaar
2. Why the data is being collected.
Example:
- Opening a bank account
- Delivering products
- Providing healthcare
3. How the person can exercise their rights.
Example:
- Withdraw consent
- Correct data
- Delete data
4. How to complain to the Data Protection Board.
Illustration
X opens a bank account using Y Bank’s app.
Before collecting documents, Y Bank must tell X:
- What data will be collected
- Why it is needed
- How X can withdraw consent
- How X can complain
Old Consent (Before the Act)
If consent was taken before this Act started:
The Data Fiduciary must later inform the person:
- What data is being used
- Why it is used
- Their rights
- Complaint procedure
Processing can continue until consent is withdrawn.
Ilustration
X already uses an online shopping app.
After the Act begins, the company sends an email explaining:
- Data collected
- Purpose
- User rights
Language
The notice must be available in:
- English
- Any language listed in the Eighth Schedule of the Constitution.
Section 6 – Consent
Consent must be:
- Free
- Specific
- Informed
- Unconditional
- Clear
- Given by positive action (clicking “I Agree”)
Only necessary data should be collected.
Illustration
A telemedicine app asks for:
✔ Health information
❌ Phone contact list
The contact list is unnecessary.
Only health data can be processed.
Invalid Consent
Any consent against the law is invalid.
Illustration
An insurance company asks the customer to agree that:
“You cannot complain to the Data Protection Board.”
This condition is invalid.
The customer still has the right to complain.
Consent Request Must Be
- Simple language
- Easy to understand
- Available in English or Indian languages
- Include contact details of the Data Protection Officer (or authorised person)
Right to Withdraw Consent
The Data Principal can withdraw consent anytime.
It should be as easy as giving consent.
Example
If consent was given by clicking one button,
Withdrawal should also be possible with similar ease.
Effect of Withdrawal
Withdrawal does not make previous processing illegal.
Only future processing must stop.
Illustration
X orders a laptop online.
After payment, X withdraws consent.
The company:
✔ Can deliver the laptop already ordered.
❌ Cannot continue using data for future orders.
Duty After Withdrawal
The Data Fiduciary must:
- Stop processing personal data.
- Ensure Data Processors also stop processing.
Unless another law allows processing.
Illustration
A telecom company emails bills through another company.
Customer changes preference to receive bills only in the app.
Both companies must stop emailing bills.
Consent Manager
A person may:
- Give consent
- Review consent
- Withdraw consent
through a Consent Manager.
Consent Managers:
- Act on behalf of the Data Principal.
- Must be registered with the Data Protection Board.
Burden of Proof
If there is a dispute,
The Data Fiduciary must prove:
- Proper notice was given.
- Valid consent was obtained.
Section 7 – Legitimate Uses (No Consent Required)
Personal data may be processed without consent in certain situations.
(a) Voluntarily Provided Data
If a person voluntarily provides data for a purpose.
Illustration 1
A customer gives a phone number to receive a payment receipt.
The pharmacy can send the receipt.
Illustration 2
A person contacts a real estate broker to find a rented house.
The broker may use the data until the person says services are no longer needed.
(b) Government Benefits
Government may process data for:
- Subsidies
- Certificates
- Licences
- Permits
- Welfare schemes
Illustration
A pregnant woman applies for maternity benefits.
Government may use the data to check eligibility for other welfare schemes.
(c) Government Functions
Data may be processed for:
- Government duties
- National security
- Sovereignty
- Integrity of India
(d) Legal Obligation
Processing is allowed if required by law.
Example:
Banks reporting information to government authorities.
(e) Court Orders
Data may be processed to comply with:
- Court orders
- Judgments
- Decrees
(f) Medical Emergency
Processing is allowed to save someone’s life or health.
Example:
Hospital treating an unconscious patient.
(g) Epidemic or Public Health
Example:
COVID-19 testing and vaccination.
(h) Disaster Management
Example:
Flood relief
Earthquake rescue
Cyclone evacuation
(i) Employment Purposes
Employers may process employee data for:
- Salary
- Attendance
- Benefits
- Protecting trade secrets
- Preventing fraud
Section 8 – General Duties of Data Fiduciary
1. Responsibility
The Data Fiduciary remains responsible even if a Data Processor handles the data.
2. Data Processor
A Data Processor can process data only under a valid contract.
3. Accurate Data
If data affects decisions or is shared with another Data Fiduciary,
It must be:
- Complete
- Accurate
- Consistent
4. Security Measures
Appropriate:
- Technical measures
- Organisational measures
must protect personal data.
5. Prevent Data Breaches
Reasonable security safeguards must be maintained.
6. Data Breach
If a breach happens,
The Data Fiduciary must inform:
- Data Protection Board
- Affected Data Principals
7. Erasure of Data
Data must be deleted:
- After consent is withdrawn, or
- When the purpose is completed,
unless another law requires retention.
Illustration 1
A user sells a car through an online marketplace.
After the sale,
The company should delete the user’s personal data.
Illustration 2
A customer closes a bank account.
Banks must legally keep records for 10 years.
So the bank cannot immediately delete the data.
8. Purpose Ends When
If a person:
- Stops using the service, and
- Does not contact the company for the prescribed period,
the purpose is treated as finished.
9. Contact Information
The Data Fiduciary must publish:
- Data Protection Officer’s details
- Or authorised contact person
10. Grievance Redressal
Every Data Fiduciary must provide an effective complaint mechanism.
Section 9 – Personal Data of Children
Before processing children’s data,
The Data Fiduciary must obtain:
✔ Verifiable consent from the parent or lawful guardian.
Children Must Not Be Harmed
Processing should not negatively affect a child’s well-being.
No Tracking or Targeted Ads
Companies cannot:
- Track children’s behaviour
- Monitor children
- Show targeted advertisements
Exceptions
Government may exempt certain Data Fiduciaries or processing activities.
Relaxation
If a company proves it processes children’s data safely,
Government may relax some obligations for older children.
Section 10 – Significant Data Fiduciary (SDF)
Government may declare certain organisations as Significant Data Fiduciaries (SDFs).
Factors Considered
- Volume of personal data
- Sensitive data
- Risk to individuals
- National security
- Electoral democracy
- Public order
Duties of Significant Data Fiduciary
1. Appoint a Data Protection Officer (DPO)
The DPO must:
- Be based in India
- Report to the Board of Directors
- Represent the organisation
- Handle grievances
2. Independent Data Auditor
Must conduct regular compliance audits.
3. Data Protection Impact Assessment (DPIA)
Regular assessment of:
- Purpose of processing
- Risks to individuals
- Protection measures
4. Periodic Audits
Regular checks to ensure compliance.
5. Other Measures
Must comply with any additional requirements prescribed by the Government.
CHAPTER III – RIGHTS AND DUTIES OF DATA PRINCIPAL
Who is a Data Principal?
A Data Principal is the person to whom the personal data belongs.
Example:
- Your Aadhaar details
- Mobile number
- Email ID
- PAN
- Bank details
- Health records
All belong to you, so you are the Data Principal.
SECTION 11 – Right to Access Information
Objective
This section gives individuals the Right to Know how their personal data is being used.
Section 11(1)
If a person has already given consent to a Data Fiduciary for processing personal data, he/she can request information from that Data Fiduciary.
The request must be made in the prescribed manner.
Clause (a)
Right to obtain summary of personal data
The Data Principal can ask for:
- What personal data is being processed.
- Why it is being processed.
- What activities are being carried out on the data.
Example
Suppose you created an account on Flipkart.
You can ask:
- Which of my details are stored?
- Is my phone number stored?
- Is my address stored?
- Is my purchase history stored?
- Why are you using my information?
The company must provide a summary.
Clause (b)
Right to know with whom data has been shared
The Data Principal can ask:
- Which Data Fiduciaries received my data?
- Which Data Processors received my data?
- What type of data was shared?
Example
You use a food delivery app.
The app shares:
- Address with restaurant
- Phone number with delivery partner
- Payment details with payment gateway
You can ask for details of all such sharing.
Clause (c)
Right to receive any other prescribed information
Government may prescribe additional information that companies must provide.
Examples may include:
- Date of collection
- Duration of storage
- Categories of data
- Security measures
- Processing purpose
Section 11(2)
Exception
Clause (b) and Clause (c) do not apply when data is shared with authorities authorised by law.
Applies where:
The information is shared for:
- Prevention of offences
- Detection of offences
- Investigation of offences
- Cyber incident investigation
- Prosecution
- Punishment
The request must be:
- In writing
- Made by an authority authorised by law.
Example
Police request your data from a telecom company during a criminal investigation.
The telecom company need not tell you that your data was shared.
Reason:
Investigation should not be compromised.
Important Points of Section 11
✔ Right to know how data is processed
✔ Right to know data sharing
✔ Right to receive prescribed information
✔ Exception for law enforcement agencies
SECTION 12 – Right to Correction, Completion, Updating and Erasure
Objective
This section ensures that personal data remains:
- Accurate
- Complete
- Updated
- Deleted when no longer required
Section 12(1)
A Data Principal has the right to request:
- Correction
- Completion
- Updating
- Erasure
This applies only where consent has been given.
It must also comply with other applicable laws.
Right to Correction
Correction means removing wrong information.
Example
Wrong Name:
“Ramesh Kumar”
Correct Name:
“Ramesh Sharma”
Company must correct it.
Right to Completion
Incomplete information should be completed.
Example
Address stored:
“Delhi”
Correct address:
House No. 21,
Lajpat Nagar,
New Delhi,
110024
Company must complete the record.
Right to Updating
Old information must be updated.
Example
Old mobile number
9876543210
New mobile number
9876000000
Company should update it.
Right to Erasure
Erasure means deleting personal data.
The Data Principal can request deletion.
Section 12(2)
After receiving a request:
The Data Fiduciary shall:
Clause (a)
Correct inaccurate or misleading data.
Clause (b)
Complete incomplete data.
Clause (c)
Update outdated data.
Section 12(3)
The Data Principal may request erasure.
After receiving the request:
The Data Fiduciary must erase the data.
Exception
The Data Fiduciary can retain data if:
(1) It is necessary for the specified purpose.
Example
Bank records needed to maintain customer account.
(2) Retention is required under law.
Example
Income Tax laws require financial records to be preserved.
Company cannot delete them immediately.
Important Points of Section 12
✔ Correct wrong data
✔ Complete incomplete data
✔ Update old data
✔ Delete unnecessary data
✔ Exception where law requires retention
SECTION 13 – Right to Grievance Redressal
Objective
If the Data Principal faces any issue regarding personal data, there must be a proper complaint mechanism.
Section 13(1)
Every Data Principal has the right to an easy grievance redressal mechanism.
Complaint may be against:
- Data Fiduciary
- Consent Manager
Complaint may relate to:
- Data misuse
- Delay in correction
- Failure to delete data
- Privacy violation
- Failure to fulfil obligations
Example
You request deletion.
Company ignores it.
You can file a grievance.
Section 13(2)
The Data Fiduciary or Consent Manager must respond within the prescribed period.
Time limit will be notified by Rules.
Section 13(3)
Before approaching the Data Protection Board,
The Data Principal must first:
- File complaint with Data Fiduciary or Consent Manager.
Only after exhausting this internal mechanism can the person approach the Board.
Purpose
To reduce unnecessary litigation.
Important Points of Section 13
✔ Right to complain
✔ Easy grievance mechanism
✔ Company must respond
✔ Internal remedy first
✔ Then approach Data Protection Board
SECTION 14 – Right to Nominate
Objective
Allows another person to exercise the rights of the Data Principal after death or incapacity.
Section 14(1)
A Data Principal may nominate another individual.
The nominee can exercise rights if the Data Principal:
- Dies, or
- Becomes incapable.
Example
Rahul nominates his wife.
After Rahul’s death,
His wife may request:
- Access to data
- Correction
- Deletion
- Grievance redressal
As allowed by the Act.
Section 14(2)
Meaning of Incapacity
“Incapacity” means inability to exercise rights because of:
Unsoundness of mind
Examples
- Severe mental illness
- Coma affecting decision-making
Infirmity of body
Examples
- Serious physical disability
- Medical condition preventing communication
Important Points of Section 14
✔ Right to nominate
✔ Rights continue after death
✔ Rights continue during incapacity
✔ Protects continuity of personal data rights
SECTION 15 – Duties of Data Principal
Rights come with responsibilities.
Every Data Principal must perform certain duties.
Clause (a)
Comply with all applicable laws while exercising rights.
Example
Do not misuse the Act to harass companies.
Clause (b)
Do not impersonate another person.
Meaning:
Never pretend to be someone else while providing personal data.
Example
Using another person’s Aadhaar to open an account.
This violates the Act.
Clause (c)
Do not suppress material information.
Meaning:
Do not hide important facts while giving information for:
- Identity proof
- Address proof
- Government documents
- Unique identifiers
Example
Hiding previous name while obtaining government documents.
Clause (d)
Do not file false or frivolous complaints.
Example
Submitting fake complaints repeatedly just to trouble a company.
This is prohibited.
Clause (e)
Provide only authentic information while requesting:
- Correction
- Erasure
Information must be verifiable.
Example
Changing date of birth using fake documents is prohibited.
Important Points of Section 15
✔ Follow the law
✔ No impersonation
✔ No hiding material facts
✔ No false complaints
✔ Give authentic information only
Quick Revision Table
| Section | Topic | Main Right/Duty |
|---|---|---|
| Section 11 | Right to Information | Know what data is processed, why, and with whom it is shared (subject to law enforcement exceptions). |
| Section 12 | Right to Correction, Completion, Updating & Erasure | Correct inaccurate data, complete incomplete data, update outdated data, and request deletion unless retention is legally required. |
| Section 13 | Right to Grievance Redressal | Complain to the Data Fiduciary/Consent Manager first, then approach the Data Protection Board if unresolved. |
| Section 14 | Right to Nominate | Nominate another person to exercise data rights after death or incapacity. |
| Section 15 | Duties of Data Principal | Follow the law, avoid impersonation, provide truthful information, avoid false complaints, and submit authentic information for corrections or erasure. |
CHAPTER IV – SPECIAL PROVISIONS
Purpose of Chapter IV
This chapter provides exceptions and special rules under the DPDP Act. It explains:
- When personal data can be transferred outside India.
- Situations where the Act or some of its provisions do not apply.
- Powers of the Central Government to exempt certain Data Fiduciaries or State authorities.
SECTION 16 – Transfer of Personal Data Outside India
Objective
Section 16 regulates the cross-border transfer of personal data.
Unlike some earlier proposals, the DPDP Act does not impose a general ban on transferring personal data outside India. Instead, it follows a negative list approach.
Section 16(1)
Provision
The Central Government may, through a notification, restrict the transfer of personal data by a Data Fiduciary to specified countries or territories outside India.
Meaning
- Personal data can generally be transferred abroad.
- However, if the Government identifies a country as unsafe or unsuitable, it may prohibit or restrict data transfers to that country.
Example
A company wants to transfer customer data to Country X.
If the Central Government has notified Country X as a restricted country, the transfer cannot take place.
Why this power is given?
To protect:
- National security
- Privacy of Indian citizens
- Strategic interests
- Data security
Section 16(2)
Higher Protection under Other Laws
This section clarifies that Section 16 does not override other Indian laws that provide stricter protection for personal data.
Meaning
If another law imposes stronger restrictions on cross-border transfer, that law will continue to apply.
Example
Suppose a future banking law states:
“Customer financial data cannot leave India.”
Even though DPDP generally allows international transfers, the banking law will prevail because it provides higher protection.
Important Points – Section 16
✔ Cross-border transfer is generally allowed.
✔ Government may prohibit transfer to notified countries.
✔ Other laws with stricter safeguards continue to apply.
SECTION 17 – Exemptions from the DPDP Act
Objective
Section 17 lists situations where:
- Certain provisions of the Act do not apply, or
- The entire Act does not apply, or
- Certain Data Fiduciaries receive exemptions.
Section 17(1)
Certain provisions of:
- Chapter II (except Section 8(1) and Section 8(5)),
- Chapter III, and
- Section 16
do not apply in the following situations.
Clause (a) – Legal Proceedings
Provision
Processing personal data is allowed if necessary for enforcing any legal right or legal claim.
Meaning
Personal data may be processed to:
- File a case
- Defend a case
- Recover money
- Enforce contractual rights
Example
A landlord sues a tenant for unpaid rent.
The landlord may process the tenant’s address, identity documents, and payment history.
Clause (b) – Courts, Tribunals and Regulatory Authorities
Provision
Courts, tribunals, regulators, or supervisory authorities may process personal data where necessary for performing their legal functions.
Includes
- Courts
- Tribunals
- Regulatory bodies
- Quasi-judicial authorities
Example
The Supreme Court processes personal records while deciding a case.
The Election Commission verifies a voter information.
SEBI investigates insider trading.
Clause (c) – Criminal Investigation
Provision
Personal data may be processed for:
- Prevention of offences
- Detection of offences
- Investigation
- Prosecution
- Enforcement of laws
Example
Police collect:
- CCTV footage
- Mobile location
- Bank records
to investigate fraud.
Clause (d) – Foreign Data Processing
Provision
Processing personal data of persons outside India under contracts with foreign clients is exempt.
Meaning
Indian companies providing outsourcing services can process foreign citizens’ data.
Example
An Indian IT company processes payroll data of employees in Canada under a contract.
The exemption applies.
Clause (e) – Corporate Restructuring
Provision
Processing personal data is allowed during:
- Merger
- Amalgamation
- Demerger
- Reconstruction
- Transfer of business
- Scheme of compromise or arrangement
provided the transaction is approved by a competent court or authority.
Example
Company A merges with Company B.
Employee and customer records may be transferred as part of the merger.
Clause (f) – Loan Defaults
Provision
Banks and financial institutions may process personal data to determine:
- Financial information
- Assets
- Liabilities
of a person who has defaulted on a loan.
Such processing must comply with other applicable laws.
Example
A borrower fails to repay a loan.
The bank may examine:
- Income
- Property
- Investments
- Outstanding liabilities
to recover the loan.
Explanation
The terms “default” and “financial institution” have the same meanings as under the Insolvency and Bankruptcy Code, 2016 (IBC).
Illustration (Given in the Act)
- X borrows a loan from Bank Y.
- X fails to pay the monthly instalment.
- Bank Y may process X’s personal data to assess financial information, assets, and liabilities.
Important Points – Section 17(1)
These exemptions apply for:
✔ Legal claims
✔ Courts and tribunals
✔ Criminal investigations
✔ Outsourcing foreign data
✔ Company mergers
✔ Loan recovery
Section 17(2)
Certain processing activities are completely exempt from the DPDP Act.
Clause (a) – State Exemption
Provision
The Central Government may exempt certain State instrumentalities when processing personal data is necessary for:
- Sovereignty and integrity of India
- Security of the State
- Friendly relations with foreign States
- Public order
- Preventing incitement to cognizable offences
The exemption also covers processing by the Central Government of data received from such instrumentalities.
Example
An intelligence agency processes personal data to prevent terrorism.
The Act may not apply if the Government has issued the required notification.
Clause (b) – Research, Archiving and Statistics
Provision
Processing personal data for:
- Research
- Archiving
- Statistical purposes
is exempt if:
- The data is not used to make decisions about a specific individual, and
- The prescribed standards are followed.
Example
The Government conducts a population health study using anonymised data.
Since no decision is made about any individual, the exemption applies.
Important Points – Section 17(2)
✔ National security exemptions.
✔ Research and statistical processing exemptions.
✔ No individual decision should be based on such research data.
Section 17(3)
Exemption for Certain Data Fiduciaries
The Central Government may exempt certain Data Fiduciaries, including recognised startups, from complying with:
- Section 5 (Notice)
- Section 8(3)
- Section 8(7)
- Section 10 (Children’s Data)
- Section 11 (Right to Information)
The decision depends on:
- Volume of personal data processed.
- Nature of personal data processed.
Why?
To reduce the compliance burden on small organisations and startups.
Meaning of Startup
A startup means a:
- Private Limited Company,
- Partnership Firm, or
- Limited Liability Partnership (LLP),
that is recognised under the Government’s Startup framework.
Example
A small educational startup processing limited customer data may receive exemptions from some compliance obligations.
Section 17(4)
Special Rule for the State
When personal data is processed by:
- The State, or
- A State instrumentality,
the following provisions do not apply:
- Section 8(7)
- Section 12(3) (Right to Erasure)
Additionally, if the processing does not involve making a decision affecting the Data Principal, Section 12(2) (Correction, Completion, Updating) also does not apply.
Example
The Government stores census records only for statistical purposes.
Since no decision affecting an individual is taken, correction obligations may not apply.
Section 17(5)
Temporary Exemptions
Within five years from the commencement of the DPDP Act, the Central Government may, by notification:
- Exempt any Data Fiduciary or class of Data Fiduciaries from any provision of the Act,
- For a specified period.
Purpose
To allow organisations time to adapt to the new compliance framework.
Example
The Government may temporarily exempt a category of healthcare institutions while they implement data protection systems.
Quick Revision Table
| Section | Topic | Key Provision |
|---|---|---|
| Section 16(1) | Cross-border Data Transfer | Government may restrict transfer of personal data to notified countries or territories outside India. |
| Section 16(2) | Other Laws | Laws providing stricter protection for data transfers continue to prevail over the DPDP Act. |
| Section 17(1)(a) | Legal Claims | Processing allowed to enforce legal rights or claims. |
| Section 17(1)(b) | Courts & Regulators | Courts, tribunals, and regulatory authorities may process data for their official functions. |
| Section 17(1)(c) | Criminal Justice | Processing allowed for prevention, detection, investigation, prosecution, or punishment of offences. |
| Section 17(1)(d) | Foreign Contracts | Indian entities processing foreign individuals’ data under overseas contracts are exempt. |
| Section 17(1)(e) | Corporate Restructuring | Data processing allowed during mergers, amalgamations, demergers, and restructuring approved by competent authorities. |
| Section 17(1)(f) | Loan Recovery | Financial institutions may process data of loan defaulters to assess assets and liabilities. |
| Section 17(2)(a) | National Security | Government-notified State instrumentalities are exempt for sovereignty, security, public order, etc. |
| Section 17(2)(b) | Research & Statistics | Exemption for research, archiving, and statistical purposes if no decision is taken about an individual. |
| Section 17(3) | Startup & Small Data Fiduciary Exemptions | Government may exempt notified Data Fiduciaries, including recognised startups, from selected compliance obligations. |
| Section 17(4) | State Processing | Certain correction and erasure rights do not apply to specified State processing. |
| Section 17(5) | Temporary Government Exemptions | Government may exempt specified Data Fiduciaries from provisions of the Act for a limited period within five years of the Act’s commencement. |
CHAPTER V – DATA PROTECTION BOARD OF INDIA
Purpose of Chapter V
Chapter V establishes the Data Protection Board of India (DPBI), the main authority responsible for implementing and enforcing the DPDP Act.
Main Functions of the Board
- Receive complaints from Data Principals.
- Inquire into personal data breaches.
- Direct Data Fiduciaries to comply with the Act.
- Impose monetary penalties.
- Resolve disputes under the DPDP Act.
Remember: The Board is a digital-first adjudicatory body, not a traditional court.
SECTION 18 – Establishment of the Data Protection Board of India
Objective
This section creates the Data Protection Board of India (DPBI).
Section 18(1)
Provision
The Central Government shall establish the Data Protection Board of India by issuing a notification.
Meaning
- The Board comes into existence only after the Government officially notifies its establishment.
- The Board is created specifically to implement the DPDP Act.
Section 18(2)
Body Corporate
The Board is a body corporate.
Meaning of Body Corporate
It has a separate legal identity from the Government.
The Board can:
- Own movable property (computers, furniture, vehicles).
- Own immovable property (land, buildings).
- Enter into contracts.
- Sue others.
- Be sued in its own name.
Important Features
- Perpetual succession – the Board continues even if members change.
- Common seal – official seal used for legal authentication.
Section 18(3)
Headquarters
The headquarters of the Board will be located at the place notified by the Central Government.
The Act does not specify a fixed city.
SECTION 19 – Composition of the Board
Objective
Explains who will be members of the Board and how they are appointed.
Section 19(1)
Composition
The Board consists of:
- One Chairperson.
- Such number of Members as notified by the Central Government.
The Act does not fix the number of Members.
Section 19(2)
Appointment
The Chairperson and Members are appointed by the Central Government.
The appointment procedure will be prescribed by Rules.
Section 19(3)
Qualifications
Members should possess:
- Ability
- Integrity
- Good reputation (standing)
They should also have special knowledge or practical experience in one or more of the following fields:
- Data governance
- Administration
- Consumer protection
- Social protection laws
- Dispute resolution
- Information Technology (IT)
- Communication technology
- Digital economy
- Law
- Regulation
- Techno-regulation
- Any other useful field identified by the Government
Important Requirement
At least one Member must be an expert in law.
SECTION 20 – Salary, Service Conditions and Tenure
Section 20(1)
Salary and Service Conditions
Salary, allowances and other service conditions will be prescribed by Rules.
Protection
Once appointed, these service conditions cannot be changed to the disadvantage of the Chairperson or Members.
This protects their independence.
Section 20(2)
Tenure
The Chairperson and Members hold office for:
- 2 years.
They are eligible for reappointment.
SECTION 21 – Disqualification and Removal
Objective
Specifies who cannot become or continue as Chairperson or Member.
Section 21(1)
Clause (a) – Insolvency
A person is disqualified if declared an insolvent (unable to pay debts).
Clause (b) – Conviction
Disqualified if convicted of an offence involving moral turpitude, in the opinion of the Central Government.
Examples:
- Fraud
- Bribery
- Corruption
- Forgery
Clause (c) – Physical or Mental Incapacity
Disqualified if physically or mentally incapable of performing official duties.
Clause (d) – Conflict of Interest
Disqualified if the person acquires a financial or other interest that may affect impartiality.
Example:
A Board Member owns a company being investigated by the Board.
Clause (e) – Abuse of Position
Disqualified if the Member misuses official powers against the public interest.
Section 21(2)
Removal Procedure
Before removing the Chairperson or a Member,
The Central Government must provide an opportunity of being heard.
This follows the principle of Natural Justice (Audi Alteram Partem).
SECTION 22 – Resignation, Vacancy and Post-Service Restrictions
Section 22(1)
Resignation
The Chairperson or Member may resign by giving written notice to the Central Government.
The resignation becomes effective on the earliest of:
- Government accepts the resignation.
- Three months after notice.
- Successor joins office.
- Expiry of tenure.
Section 22(2)
Filling Vacancies
Vacancies due to:
- Resignation
- Removal
- Death
- Any other reason
shall be filled through a fresh appointment.
Section 22(3)
Post-Retirement Restriction (Cooling-off Period)
For one year after leaving office,
the Chairperson or Member cannot accept employment without prior approval of the Central Government.
If they later join a Data Fiduciary against whom proceedings had been initiated during their tenure, they must disclose this to the Government.
Purpose
To prevent conflict of interest and ensure impartiality.
SECTION 23 – Meetings and Procedure
Section 23(1)
Procedure
The Board may decide its own procedure for:
- Conducting meetings.
- Holding digital meetings.
- Authenticating orders and directions.
The detailed procedure will be prescribed by Rules.
Section 23(2)
Validity of Proceedings
Board proceedings remain valid even if:
Clause (a)
There is a vacancy.
Clause (b)
There is a defect in appointment.
Clause (c)
There is a procedural irregularity,
provided it does not affect the merits of the case.
Purpose
To ensure technical defects do not invalidate proceedings.
Section 23(3)
Acting Chairperson
If the Chairperson cannot perform duties due to:
- Illness
- Absence
- Any other reason
the senior-most Member acts as Chairperson until the Chairperson resumes duties.
SECTION 24 – Officers and Employees
Provision
The Board may appoint officers and employees with prior approval of the Central Government.
Appointments are made to ensure efficient functioning of the Board.
Their:
- Service conditions
- Appointment terms
will be prescribed by Rules.
Example
The Board may appoint:
- Legal Officers
- Technical Experts
- Investigation Officers
- Administrative Staff
- IT Specialists
SECTION 25 – Public Servant Status
Provision
The following persons are deemed to be Public Servants:
- Chairperson
- Members
- Officers
- Employees
when acting under the DPDP Act.
Meaning
They enjoy legal protection while performing official duties and are subject to responsibilities applicable to public servants under criminal law.
SECTION 26 – Powers of the Chairperson
Objective
Defines the administrative powers of the Chairperson.
Clause (a)
General Superintendence
The Chairperson supervises:
- Administration
- Management
- Overall functioning of the Board.
Clause (b)
Scrutiny of Complaints
The Chairperson may authorise any officer to examine:
- Complaints
- Intimations
- References
- Correspondence
received by the Board.
Clause (c)
Allocation of Work
The Chairperson may:
- Authorise individual Members.
- Create groups of Members.
- Allocate cases among them.
- Delegate functions.
Example
One Member may hear complaints relating to children’s data, while another handles personal data breach cases.
Quick Revision Table
| Section | Topic | Key Provision |
|---|---|---|
| 18 | Establishment | Creates the Data Protection Board of India as a body corporate with perpetual succession and legal personality. |
| 19 | Composition | Chairperson and Members appointed by the Central Government; at least one Member must be a legal expert. |
| 20 | Salary & Tenure | Salary and service conditions prescribed by Rules; tenure of 2 years with eligibility for reappointment. |
| 21 | Disqualification & Removal | Grounds include insolvency, conviction, incapacity, conflict of interest, and abuse of office; removal only after an opportunity to be heard. |
| 22 | Resignation & Vacancies | Written resignation, fresh appointments to fill vacancies, and a one-year cooling-off period after leaving office. |
| 23 | Meetings & Procedure | Board regulates its own procedure, including digital meetings; proceedings remain valid despite minor defects; senior-most Member acts as Chairperson when necessary. |
| 24 | Staff | Board may appoint officers and employees with prior Central Government approval. |
| 25 | Public Servants | Chairperson, Members, officers, and employees are deemed public servants while acting under the Act. |
| 26 | Powers of Chairperson | Supervises administration, authorises scrutiny of complaints, and allocates functions and proceedings among Members. |
CHAPTER VI – POWERS, FUNCTIONS AND PROCEDURE OF THE BOARD
Purpose of Chapter VI
This chapter explains:
- What powers the Data Protection Board of India (DPBI) has.
- What functions it performs.
- How it conducts inquiries.
- The procedure it follows while deciding cases.
Remember: The Board is the main authority for enforcing the DPDP Act.
SECTION 27 – Powers and Functions of the Board
Objective
Section 27 explains when the Board can act and what actions it can take.
Section 27(1)
The Board performs the following functions.
Clause (a) – Personal Data Breach
Provision
When a Data Fiduciary informs the Board about a Personal Data Breach under Section 8(6), the Board may:
- Direct urgent remedial or mitigation measures.
- Conduct an inquiry.
- Impose a penalty if there is a violation.
Meaning
The Board acts quickly to reduce the harm caused by a data breach.
Example
A bank’s customer database is hacked.
The bank informs the Board.
The Board may direct the bank to:
- Stop further data leakage.
- Inform affected customers.
- Strengthen cybersecurity.
- Conduct an investigation.
- Pay penalties if negligence is found.
Clause (b) – Complaints Against Data Fiduciaries
Provision
The Board can inquire into complaints made by:
- A Data Principal, or
- The Central Government, or
- A State Government, or
- On the directions of a Court.
The complaint may relate to:
- Personal Data Breach.
- Failure of a Data Fiduciary to perform its legal obligations.
- Violation of the rights of a Data Principal.
Example
A company refuses to delete a user’s personal data even after receiving a valid request.
The user files a complaint.
The Board investigates the matter.
Clause (c) – Complaints Against Consent Managers
Provision
If a Consent Manager violates its legal obligations regarding personal data, the Data Principal may file a complaint.
The Board can:
- Conduct an inquiry.
- Impose a penalty.
Example
A Consent Manager shares user consent records without permission.
The Board may investigate and penalise the Consent Manager.
Clause (d) – Breach of Registration Conditions
Provision
If a Consent Manager violates the conditions of its registration, the Board may:
- Conduct an inquiry.
- Impose penalties.
Example
A registered Consent Manager fails to follow Government-prescribed technical standards.
The Board investigates.
Clause (e) – Intermediaries
Provision
If the Central Government refers a case regarding violation of Section 37(2) by an intermediary, the Board may:
- Conduct an inquiry.
- Impose penalties.
(Section 37 deals with blocking access to information in certain situations.)
Example
A social media platform fails to comply with Government directions under the Act.
The Board may investigate.
Section 27(2)
Power to Issue Directions
The Board may issue necessary directions to any person for proper implementation of the Act.
Conditions
Before issuing directions:
- The person must be given an opportunity to be heard.
- Reasons must be recorded in writing.
Example
The Board may direct a company to:
- Stop unlawful processing.
- Delete illegally collected data.
- Improve cybersecurity.
The company must comply.
Section 27(3)
Modification or Cancellation of Directions
A person affected by the Board’s direction may submit a representation.
The Central Government may also make a reference.
After considering the matter, the Board may:
- Modify the direction.
- Suspend it.
- Withdraw it.
- Cancel it.
The Board may also impose conditions.
Example
A company proves that it has already corrected the violation.
The Board may modify its earlier order.
SECTION 28 – Procedure to be Followed by the Board
Objective
Section 28 explains how the Board functions and how inquiries are conducted.
Section 28(1)
Digital Office
The Board should function as an independent body.
As far as possible, it should operate as a Digital Office.
Digital by Design
The following should preferably happen online:
- Filing complaints.
- Allocation of cases.
- Hearings.
- Passing decisions.
The Government may prescribe technological and legal standards.
Purpose
- Faster disposal.
- Less paperwork.
- Better accessibility.
- Transparency.
Section 28(2)
Taking Action
After receiving:
- Complaint.
- Data breach report.
- Government reference.
- Court direction.
The Board may proceed according to the DPDP Act.
Section 28(3)
Preliminary Examination
The Board first decides whether there are sufficient grounds for inquiry.
Meaning
Not every complaint automatically leads to investigation.
The Board first checks whether the complaint appears genuine.
Section 28(4)
No Sufficient Grounds
If the Board finds no sufficient grounds:
- It may close the proceedings.
- Reasons must be recorded in writing.
Example
A complaint contains no evidence.
The Board dismisses it after recording reasons.
Section 28(5)
Sufficient Grounds
If sufficient grounds exist:
The Board may investigate whether the person has complied with the DPDP Act.
Example
The Board examines whether a company:
- Collected valid consent.
- Protected personal data.
- Deleted data when required.
Section 28(6)
Principles of Natural Justice
The Board must follow the Principles of Natural Justice.
This means:
- Give every party an opportunity to present its case.
- No one should be condemned without hearing.
- Decisions should be fair and unbiased.
- Reasons should be recorded.
Example
Before imposing a penalty,
the company gets a chance to explain its conduct.
Section 28(7)
Civil Court Powers
For inquiries, the Board has powers similar to a Civil Court under the Code of Civil Procedure, 1908.
Clause (a)
Summon persons.
Enforce attendance.
Examine witnesses under oath.
Clause (b)
Receive affidavits.
Require production of documents.
Clause (c)
Inspect:
- Data
- Documents
- Registers
- Books of account
- Other records
Clause (d)
Exercise additional powers prescribed by Rules.
Example
The Board may summon:
- Company officials.
- IT managers.
- Cybersecurity experts.
It may inspect:
- Server logs.
- Security reports.
- Customer records.
Section 28(8)
Limitation on the Board
The Board or its officers cannot:
- Seal premises.
- Prevent access to offices.
- Seize computers or equipment if it would seriously affect day-to-day business operations.
Purpose
To avoid unnecessary disruption of business activities.
Section 28(9)
Assistance from Government
The Board may seek assistance from:
- Police officers.
- Central Government officers.
- State Government officers.
Such officers are legally required to assist the Board.
Section 28(10)
Interim Orders
During the inquiry,
if necessary,
the Board may issue Interim Orders.
Conditions
- Reasons must be recorded.
- Opportunity of hearing must be given.
Example
The Board orders a company to temporarily stop processing certain personal data until the inquiry is completed.
Section 28(11)
Final Decision
After completing the inquiry and hearing all parties,
the Board may:
Option 1
Close the proceedings.
OR
Option 2
Proceed under Section 33 (imposition of monetary penalty).
Reasons must be recorded in writing.
Section 28(12)
False or Frivolous Complaints
If the Board finds that a complaint is:
- False, or
- Frivolous (without genuine purpose),
it may:
- Issue a warning, or
- Impose costs on the complainant.
Example
A person repeatedly files fake complaints merely to harass a company.
The Board may impose costs.
.
Quick Revision Table
| Section | Topic | Key Provision |
|---|---|---|
| 27(1)(a) | Personal Data Breach | Board directs urgent remedial measures, conducts inquiry, and may impose penalties. |
| 27(1)(b) | Complaints Against Data Fiduciaries | Inquires into complaints by Data Principals, Government references, or Court directions regarding breaches and violations. |
| 27(1)(c) | Consent Manager Complaints | Inquires into breaches by Consent Managers and may impose penalties. |
| 27(1)(d) | Registration Conditions | Investigates breaches of Consent Manager registration conditions. |
| 27(1)(e) | Intermediaries | Inquires into violations referred by the Central Government under Section 37(2). |
| 27(2) | Directions | Board may issue binding directions after giving an opportunity of hearing and recording reasons. |
| 27(3) | Review of Directions | Board may modify, suspend, withdraw, or cancel its directions upon representation or Government reference. |
| 28(1) | Digital Office | Board functions independently and, as far as practicable, digitally by design. |
| 28(2) | Action on Complaints | Board acts on complaints, breach intimations, references, and court directions. |
| 28(3) | Preliminary Scrutiny | Determines whether sufficient grounds exist for inquiry. |
| 28(4) | Closure | May close proceedings if no sufficient grounds exist, with written reasons. |
| 28(5) | Inquiry | Investigates compliance with the Act where sufficient grounds exist. |
| 28(6) | Natural Justice | Must provide a fair hearing and record reasons for its actions. |
| 28(7) | Civil Court Powers | Can summon witnesses, receive affidavits, and inspect records. |
| 28(8) | Business Protection | Cannot unnecessarily seize equipment or stop normal business operations. |
| 28(9) | Government Assistance | May require assistance from police or Government officers. |
| 28(10) | Interim Orders | May issue temporary orders after hearing the concerned person. |
| 28(11) | Final Order | May close the case or proceed to impose penalties under Section 33. |
| 28(12) | False Complaints | May warn or impose costs on complainants filing false or frivolous complaints. |
CHAPTER VII – APPEAL AND ALTERNATE DISPUTE RESOLUTION
Purpose of Chapter VII
This chapter provides the remedies available after a decision of the Data Protection Board of India (DPBI). It explains:
- How a person can appeal against the Board’s order.
- The role of the Appellate Tribunal.
- Mediation as an alternative method of dispute resolution.
- Voluntary Undertakings to settle proceedings without a final penalty.
Remember: This chapter focuses on review, appeal, mediation, and settlement of disputes under the DPDP Act.
SECTION 29 – Appeal to the Appellate Tribunal
Objective
Section 29 gives a person the right to appeal against any order or direction passed by the Data Protection Board.
Section 29(1)
Right to Appeal
Provision
Any person who is aggrieved (affected) by an order or direction of the Board may file an appeal before the Appellate Tribunal.
Meaning
If a person believes that the Board’s decision is incorrect or unfair, they can challenge it before the Appellate Tribunal.
Example
The Board imposes a penalty of ₹50 lakh on a company.
The company believes the decision is wrong.
It can file an appeal before the Appellate Tribunal.
Section 29(2)
Time Limit for Appeal
Provision
The appeal must be filed:
- Within 60 days from the date the order or direction is received.
The appeal should:
- Be in the prescribed form.
- Follow the prescribed procedure.
- Be accompanied by the prescribed fee.
Example
Board’s order received on 1 January.
The appeal should normally be filed by 2 March (within 60 days).
Section 29(3)
Delay in Filing Appeal
Provision
The Appellate Tribunal may accept an appeal filed after 60 days if:
- There was sufficient cause for the delay.
Example
A natural disaster, serious illness, or unavoidable circumstances prevented timely filing.
The Tribunal may condone the delay.
Section 29(4)
Powers of the Appellate Tribunal
Provision
After hearing both parties, the Tribunal may:
- Confirm the Board’s order.
- Modify the Board’s order.
- Set aside (cancel) the Board’s order.
Example
The Board imposed a penalty of ₹10 crore.
The Tribunal finds the penalty excessive.
It reduces the penalty to ₹5 crore.
Section 29(5)
Copy of Order
The Appellate Tribunal must send a copy of its order to:
- The Data Protection Board.
- All parties to the appeal.
Purpose
Ensures transparency and official communication.
Section 29(6)
Time for Disposal
The Tribunal should decide appeals:
- As quickly as possible.
- It should try to dispose of the appeal within 6 months.
Meaning
The six-month period is a goal (directory), not a strict mandatory deadline.
Section 29(7)
Delay Beyond Six Months
If the appeal is not decided within six months,
the Tribunal must:
- Record the reasons in writing.
Purpose
To ensure accountability and transparency.
Section 29(8)
Procedure of the Tribunal
The Appellate Tribunal shall hear appeals according to:
- The DPDP Act.
- The prescribed Rules.
- Relevant provisions of the Telecom Regulatory Authority of India (TRAI) Act, 1997, particularly Sections 14A and 16.
Meaning
The Tribunal follows an established legal procedure for hearing appeals.
Section 29(9)
Further Appeal
If a person wants to challenge the Appellate Tribunal’s order,
the provisions of Section 18 of the TRAI Act, 1997 apply.
Meaning
Under the TRAI Act, an appeal from the Tribunal’s decision lies to the Supreme Court of India on specified grounds.
Section 29(10)
Digital Office
The Appellate Tribunal should function, as far as practicable, as a digital office.
This means:
- Filing appeals online.
- Online hearings.
- Online decisions.
Purpose
To improve speed, accessibility, and efficiency.
Important Points – Section 29
✔ Appeal against Board’s order.
✔ Time limit = 60 days.
✔ Delay may be condoned for sufficient cause.
✔ Tribunal may confirm, modify, or cancel the order.
✔ Aim to dispose of appeals within 6 months.
✔ Digital appeal system.
SECTION 30 – Execution of Orders
Objective
Section 30 explains how the Appellate Tribunal’s orders are enforced.
Section 30(1)
Tribunal’s Power
An order passed by the Appellate Tribunal is executable like a Civil Court Decree.
Meaning
The Tribunal has the same powers as a Civil Court to enforce its orders.
Example
If the Tribunal directs a company to pay compensation or comply with an order and it refuses, the Tribunal can enforce its decision as a court decree.
Section 30(2)
Transfer to Civil Court
Instead of enforcing the order itself,
the Tribunal may send the order to a Civil Court having local jurisdiction.
The Civil Court will execute the order as if it had passed the decree itself.
Example
A company’s office is located in Delhi.
The Tribunal may transfer the order to the appropriate Civil Court in Delhi for execution.
Important Points – Section 30
✔ Tribunal’s orders are legally enforceable.
✔ Orders are treated like Civil Court decrees.
✔ Tribunal may transfer execution to a Civil Court.
SECTION 31 – Mediation (Alternative Dispute Resolution)
Objective
Section 31 encourages settlement through mediation instead of prolonged litigation.
Provision
If the Board believes that a complaint can be resolved through mediation,
it may direct the parties to attempt mediation.
The mediator may be:
- A person mutually agreed by both parties, or
- A mediator appointed under any applicable law in India.
What is Mediation?
Mediation is a process where:
- A neutral third person (Mediator) helps both parties reach a voluntary settlement.
- The mediator does not impose a decision.
Example
A Data Principal complains that a company delayed correcting personal data.
The Board believes the issue can be settled.
It directs both parties to mediation.
If they agree on corrective action, the dispute may end without a formal inquiry.
Advantages of Mediation
- Faster resolution.
- Less expensive.
- Friendly settlement.
- Reduces litigation.
- Saves time for the Board.
Important Points – Section 31
✔ Board may refer disputes to mediation.
✔ Mediator may be chosen by mutual agreement.
✔ Promotes amicable settlement.
✔ Alternative to formal proceedings.
SECTION 32 – Voluntary Undertaking
Objective
Section 32 allows a person to voluntarily promise compliance with the Act instead of continuing legal proceedings.
What is a Voluntary Undertaking?
It is a written promise given by a person to the Board stating that they will:
- Correct the violation.
- Stop the unlawful activity.
- Take specific corrective measures within a specified time.
Section 32(1)
Acceptance of Voluntary Undertaking
The Board may accept a voluntary undertaking:
- From any person.
- At any stage of proceedings under Section 28.
Example
During an inquiry, a company admits its mistake and voluntarily agrees to:
- Improve security systems.
- Delete unlawfully collected data.
- Train employees on data protection.
The Board may accept this undertaking.
Section 32(2)
Contents of the Undertaking
The undertaking may include a promise to:
- Take specified action.
- Complete the action within a specified time.
- Stop a particular activity.
- Publicise the undertaking if required.
Example
The company promises:
- To delete unnecessary personal data within 30 days.
- To stop sharing customer information without consent.
- To publish a notice on its website informing users about corrective measures.
Section 32(3)
Modification
The Board may change the terms of the undertaking,
but only:
- With the consent of the person who gave the undertaking.
Example
The Board extends the compliance period from 30 days to 45 days with the company’s consent.
Section 32(4)
Effect of Acceptance
Once the Board accepts the voluntary undertaking,
no further proceedings will continue regarding the matters covered by that undertaking.
Meaning
The dispute is treated as settled, unless the undertaking is later violated.
Section 32(5)
Breach of Undertaking
If the person fails to follow the undertaking,
the breach is treated as a breach of the DPDP Act itself.
The Board may:
- Give the person an opportunity of being heard.
- Proceed under Section 33 (imposition of monetary penalties).
Example
A company promised to delete customer data within 30 days but failed to do so.
The Board may reopen the matter and impose penalties.
Important Points – Section 32
✔ Voluntary compliance encouraged.
✔ Can be offered at any stage of inquiry.
✔ May require corrective action or stopping certain activities.
✔ Board may modify terms with consent.
✔ Accepted undertaking bars further proceedings on that issue.
✔ Breach of the undertaking leads to fresh proceedings and possible penalties.
Quick Revision Table
| Section | Topic | Key Provision |
|---|---|---|
| 29(1) | Right to Appeal | Any aggrieved person may appeal against an order or direction of the Data Protection Board before the Appellate Tribunal. |
| 29(2) | Limitation | Appeal must be filed within 60 days in the prescribed form and with the prescribed fee. |
| 29(3) | Condonation of Delay | Tribunal may accept a delayed appeal if sufficient cause is shown. |
| 29(4) | Tribunal’s Powers | Tribunal may confirm, modify, or set aside the Board’s order after hearing the parties. |
| 29(5) | Communication of Order | Copy of the Tribunal’s order must be sent to the Board and all parties. |
| 29(6) | Disposal of Appeal | Tribunal should endeavour to decide appeals within 6 months. |
| 29(7) | Delay | Reasons must be recorded if the appeal is not decided within six months. |
| 29(8) | Procedure | Tribunal follows the prescribed procedure and relevant provisions of the TRAI Act, 1997. |
| 29(9) | Further Appeal | Appeals against Tribunal orders are governed by Section 18 of the TRAI Act, enabling appeal to the Supreme Court. |
| 29(10) | Digital Office | Appeals should, as far as practicable, be filed, heard, and decided digitally. |
| 30 | Execution of Orders | Tribunal’s orders are executable as Civil Court decrees or may be transferred to a Civil Court for execution. |
| 31 | Mediation | Board may refer disputes to mediation for amicable settlement. |
| 32(1) | Voluntary Undertaking | Board may accept a voluntary undertaking from any person at any stage of proceedings. |
| 32(2) | Terms | Undertaking may include promises to take or refrain from specified actions within a specified time. |
| 32(3) | Variation | Terms may be modified with the person’s consent. |
| 32(4) | Effect | Acceptance generally bars further proceedings on the matters covered by the undertaking. |
| 32(5) | Breach | Failure to comply with the undertaking is treated as a breach of the Act and may result in proceedings under Section 33. |
CHAPTER VIII – PENALTIES AND ADJUDICATION
Purpose of Chapter VIII
This chapter explains:
- When penalties can be imposed under the DPDP Act.
- How the Data Protection Board decides the amount of penalty.
- Where the penalty money goes after collection.
Remember: The DPDP Act mainly provides for monetary (financial) penalties, not imprisonment.
SECTION 33 – Monetary Penalties
Objective
Section 33 gives the Data Protection Board of India (DPBI) the power to impose monetary penalties on persons who violate the provisions of the DPDP Act or the Rules.
Section 33(1)
Power to Impose Monetary Penalty
Provision
After completing an inquiry under Section 28, if the Board finds that:
- A person has breached the provisions of the DPDP Act or the Rules, and
- The breach is significant,
then the Board may impose a monetary penalty as specified in the Schedule to the Act.
Important Conditions
Before imposing a penalty:
- The inquiry must be completed.
- The Board must determine that the breach is significant.
- The person must be given an opportunity of being heard (Principles of Natural Justice).
- The penalty must be within the limits prescribed in the Schedule.
Meaning of “Significant Breach”
The Act does not define the word “significant.”
Therefore, the Board decides whether a breach is significant by considering the seriousness of the facts and the factors listed in Section 33(2).
Example
A social media company:
- Stores personal data without valid consent.
- Experiences a major data breach.
- Fails to inform affected users.
After inquiry, the Board concludes that the breach is significant and imposes a monetary penalty.
Important Features of Section 33(1)
✔ Inquiry must be completed first.
✔ Penalty only for significant violations.
✔ Opportunity of hearing is mandatory.
✔ Penalty amount comes from the Schedule to the Act.
Section 33(2)
Factors for Determining the Amount of Penalty
The Board does not automatically impose the maximum penalty.
It must consider several important factors before deciding the amount.
Clause (a)
Nature, Gravity and Duration of the Breach
The Board examines:
- How serious the violation is.
- How long it continued.
- How harmful it was.
Example
A company accidentally exposed data for one day.
This may attract a lower penalty.
If it knowingly ignored security for two years,
the penalty is likely to be much higher.
Clause (b)
Type and Nature of Personal Data Affected
The Board considers what type of personal data was affected.
Some personal data is more sensitive than others.
Example
Lower impact:
- Email address.
Higher impact:
- Aadhaar number.
- Financial information.
- Medical records.
- Biometric information.
The more sensitive the data, the higher the possible penalty.
Clause (c)
Repetitive Nature of the Breach
The Board checks whether the person has committed similar violations before.
Example
A company violates the Act once.
Penalty may be moderate.
If the same company repeatedly violates the Act,
the Board may impose a much higher penalty.
Clause (d)
Gain or Avoidance of Loss
The Board considers whether the person:
- Earned extra profit because of the breach, or
- Avoided financial loss by violating the law.
Example
A company secretly sells customer data to advertisers.
It earns huge profits.
The Board may impose a higher penalty.
Clause (e)
Steps Taken to Reduce Harm (Mitigation)
The Board considers whether the person tried to reduce the damage.
It also checks:
- How quickly action was taken.
- Whether the action was effective.
Example
Immediately after discovering a cyberattack,
the company:
- Informs users.
- Stops further leakage.
- Fixes the security issue.
These actions may reduce the penalty.
Clause (f)
Proportionate and Effective Penalty
The Board must ensure that the penalty is:
Proportionate
Not too harsh.
Not too lenient.
Effective
Strong enough to ensure compliance.
Deterrent
Discourages future violations.
Example
A small startup should not automatically receive the same penalty as a multinational company if the circumstances are substantially different.
Clause (g)
Impact of Penalty on the Person
The Board considers how the penalty will affect the person or organisation.
Example
A very small organisation making an honest mistake may receive a lower penalty than a large corporation committing a deliberate and serious violation.
Summary of Factors under Section 33(2)
The Board considers:
✔ Seriousness of breach.
✔ Duration.
✔ Type of personal data.
✔ Repeat offences.
✔ Financial gain.
✔ Mitigation efforts.
✔ Proportionality.
✔ Impact of penalty.
Illustration
Suppose Company ABC:
- Leaks Aadhaar and PAN details of 5 lakh customers.
- Ignores security warnings for one year.
- Earns money by sharing customer data.
- Does not inform affected users.
- Takes no corrective action.
The Board may consider:
- Serious nature of breach.
- Sensitive personal data.
- Long duration.
- Financial gain.
- No mitigation.
Result:
A very high monetary penalty may be imposed.
Important Points – Section 33
✔ Board imposes monetary penalties.
✔ Penalty only after inquiry.
✔ Opportunity of hearing required.
✔ Factors listed in Section 33(2) must be considered.
✔ Penalty limits are prescribed in the Schedule to the Act.
SECTION 34 – Credit of Penalties
Objective
Explains where the collected penalty money goes.
Provision
All penalties collected under the DPDP Act shall be credited to the:
Consolidated Fund of India (CFI).
What is the Consolidated Fund of India?
The Consolidated Fund of India is the main government account established under Article 266(1) of the Constitution of India.
It contains:
- Tax revenue.
- Government receipts.
- Borrowed money.
- Other income received by the Central Government.
Money can be withdrawn from this Fund only with the approval of Parliament.
Example
The Board imposes a penalty of ₹50 crore on a company.
The company deposits the amount.
The ₹50 crore is credited to the Consolidated Fund of India, not to the Board.
Why is the Money Credited to the CFI?
Because:
- The Board is a statutory authority, not a profit-making body.
- Penalties are Government revenue.
- This ensures transparency and public accountability.
Important Points – Section 34
✔ All penalties go to the Consolidated Fund of India.
✔ The Board does not retain penalty money.
✔ Ensures transparency and constitutional control over public funds.
Quick Revision Table
| Section | Topic | Key Provision |
|---|---|---|
| 33(1) | Monetary Penalty | After completing an inquiry, the Board may impose a monetary penalty for a significant breach of the Act or Rules, after giving the person an opportunity of being heard. |
| 33(2)(a) | Nature, Gravity & Duration | Considers how serious the breach is and how long it continued. |
| 33(2)(b) | Type of Personal Data | Considers the sensitivity and nature of the personal data affected. |
| 33(2)(c) | Repeated Violations | Higher penalties may apply for repeated breaches. |
| 33(2)(d) | Financial Gain | Considers whether the person profited from the breach or avoided a loss. |
| 33(2)(e) | Mitigation | Considers whether timely and effective steps were taken to reduce harm. |
| 33(2)(f) | Proportionality | Penalty must be fair, effective, and sufficient to ensure compliance and deter future violations. |
| 33(2)(g) | Impact | Considers the likely impact of the penalty on the person or organisation. |
| 34 | Credit of Penalties | All penalties collected are credited to the Consolidated Fund of India. |
Schedule to the DPDP Act
The exact maximum penalties are provided in the Schedule to the Act. Some important limits include:
| Violation | Maximum Monetary Penalty |
|---|---|
| Failure to take reasonable security safeguards leading to a personal data breach | ₹250 crore |
| Failure to notify the Board and affected Data Principals of a personal data breach | ₹200 crore |
| Breach of obligations relating to children’s personal data | ₹200 crore |
| Breach of additional obligations of Significant Data Fiduciaries | ₹150 crore |
| Breach of duties by a Data Principal (where applicable) | ₹10,000 |
| Other breaches where no specific penalty is prescribed | Up to ₹50 crore |
Note: These are maximum limits. The Board is not required to impose the maximum penalty in every case. It must determine the appropriate amount by considering the factors listed in Section 3
CHAPTER IX – MISCELLANEOUS
Purpose of Chapter IX
Chapter IX contains general, administrative, and miscellaneous provisions of the DPDP Act. It explains:
- Protection for Government and Board officials acting in good faith.
- Power of the Central Government to seek information.
- Blocking powers against repeat offenders.
- Relationship with other laws.
- Rule-making powers.
- Parliamentary oversight.
- Power to amend the Schedule.
- Removal of difficulties.
- Amendments to other Acts.
SECTION 35 – Protection of Action Taken in Good Faith
Objective
This section protects Government and Board officials from legal proceedings when they act honestly while implementing the Act.
Provision
No:
- Suit
- Prosecution
- Other legal proceeding
shall lie against:
- Central Government
- Data Protection Board
- Chairperson
- Members
- Officers
- Employees
for anything done or intended to be done in good faith under the DPDP Act or Rules.
Meaning of “Good Faith”
Good faith means:
- Honest intention.
- Acting without fraud.
- Acting without malicious motive.
- Acting reasonably while performing official duties.
It does not protect dishonest, corrupt, or malicious actions.
Example
The Board issues a notice believing there has been a data breach.
Later, it turns out no breach occurred.
If the notice was issued honestly and with reasonable care, Board officials are protected.
Important Points – Section 35
✔ Protects honest official actions.
✔ Applies only to actions done in good faith.
✔ Does not protect bad faith or misuse of power.
SECTION 36 – Power of Central Government to Call for Information
Objective
Allows the Central Government to obtain information needed for implementing the Act.
Provision
The Central Government may require:
- The Board,
- Any Data Fiduciary, or
- Any Intermediary,
to furnish any information required for the purposes of the Act.
Example
The Government asks a social media company to provide information about:
- Number of reported data breaches.
- Compliance measures adopted.
The company must provide the information.
Important Points – Section 36
✔ Government can seek information.
✔ Applies to the Board, Data Fiduciaries, and Intermediaries.
✔ Used for implementation and monitoring of the Act.
SECTION 37 – Blocking of Information
Objective
Provides a strong enforcement mechanism against repeat violators.
Section 37(1)
When can blocking be ordered?
The Central Government may block public access to information only after receiving a written reference from the Board.
The Board’s reference must contain both:
Clause (a)
The Board has imposed a monetary penalty on the Data Fiduciary on two or more occasions.
Clause (b)
The Board advises that blocking access is necessary in the interests of the general public.
Additional Conditions
Before blocking:
- The Data Fiduciary must be given an opportunity to be heard.
- The Government must record reasons in writing.
- The Government must be satisfied that blocking is necessary or expedient in the public interest.
What may be blocked?
Information generated, transmitted, received, stored, or hosted on any computer resource that enables the Data Fiduciary to offer goods or services to Data Principals in India.
Example
A platform repeatedly violates the DPDP Act and has already been penalised twice.
The Board recommends blocking.
After hearing the platform, the Government may direct Internet Service Providers (ISPs) to block access to that platform in India.
Section 37(2)
Duty of Intermediaries
Every intermediary receiving a blocking direction must comply.
Example
Internet Service Providers (ISPs) or social media platforms must implement the blocking order.
Section 37(3)
Definitions
The expressions:
- Computer Resource
- Information
- Intermediary
have the same meanings as under the Information Technology Act, 2000.
Important Points – Section 37
✔ Applies only after two or more penalties.
✔ Requires Board recommendation.
✔ Opportunity of hearing is mandatory.
✔ Reasons must be recorded.
✔ Intermediaries must comply.
SECTION 38 – Relationship with Other Laws
Section 38(1)
Additional Law
The DPDP Act is in addition to other laws.
Meaning
The Act does not automatically replace other laws.
Other applicable laws continue to operate.
Section 38(2)
Conflict Rule
If there is a conflict between:
- DPDP Act
- Another law
the DPDP Act will prevail to the extent of the conflict.
Example
Another law allows disclosure of personal data without safeguards.
If this conflicts with the DPDP Act, the DPDP Act prevails for that conflict.
Important Points – Section 38
✔ DPDP works alongside other laws.
✔ DPDP prevails where there is inconsistency.
SECTION 39 – Bar of Civil Court Jurisdiction
Objective
Prevents Civil Courts from interfering in matters assigned to the Board.
Provision
Civil Courts cannot:
- Hear matters assigned to the Board.
- Grant injunctions against actions taken under the Act.
Example
A company cannot bypass the Board by filing a Civil Suit challenging an ongoing inquiry.
The proper remedy is an appeal under Section 29.
Important Points – Section 39
✔ Civil Courts have no jurisdiction over matters assigned to the Board.
✔ No injunction against Board proceedings.
SECTION 40 – Power to Make Rules
Objective
Empowers the Central Government to make detailed Rules for implementing the Act.
Section 40(1)
The Central Government may:
- Make Rules by notification.
- Publish draft Rules before finalising them (previous publication).
- Ensure Rules are consistent with the Act.
Section 40(2)
Matters for Which Rules May Be Made
The Rules may prescribe details regarding:
(a) Notice to Data Principal (Section 5(1))
How notice should be given.
(b) Additional Notice Requirements (Section 5(2))
How existing Data Principals should be informed.
(c) Consent Manager Accountability (Section 6(8))
Responsibilities and accountability.
(d) Registration of Consent Managers (Section 6(9))
Registration procedure and conditions.
(e) Government Benefits (Section 7)
Processing of personal data for subsidies, licences, permits, etc.
(f) Data Breach Intimation (Section 8(6))
How breaches should be reported.
(g) Storage Period (Section 8(8))
Time after which the specified purpose is treated as completed.
(h) Data Protection Officer Details (Section 8(9))
Publication of DPO contact information.
(i) Verifiable Parental Consent (Section 9)
Procedure for obtaining parental consent.
(j) Children’s Data Processing (Section 9(4))
Permitted purposes and conditions.
(k) Data Protection Impact Assessment (Section 10)
Procedure and requirements.
(l) Additional Measures for Significant Data Fiduciaries
Extra compliance obligations.
(m) Right to Information Requests (Section 11)
How Data Principals request information.
(n) Erasure Requests (Section 12)
Procedure for deletion requests.
(o) Grievance Response Time (Section 13)
Time within which grievances must be answered.
(p) Nomination Procedure (Section 14)
How nominations are made.
(q) Research Standards (Section 17)
Standards for research exemptions.
(r) Appointment of Board Members (Section 19)
Appointment procedure.
(s) Salary and Service Conditions (Section 20)
Pay and allowances.
(t) Authentication of Orders (Section 23)
How Board orders are authenticated.
(u) Appointment of Officers (Section 24)
Service conditions.
(v) Digital Procedures (Section 28)
Techno-legal measures.
(w) Additional Civil Court Powers (Section 28)
Other prescribed powers.
(x) Appeal Procedure (Section 29)
Form, fee, and filing procedure.
(y) Tribunal Procedure (Section 29)
Procedure for hearing appeals.
(z) Any Other Matter
Any additional matter requiring Rules.
Important Points – Section 40
✔ Government frames detailed Rules.
✔ Rules cannot contradict the Act.
✔ Rules provide operational details.
SECTION 41 – Laying Before Parliament
Objective
Ensures Parliamentary oversight over Rules and certain Notifications.
Provision
Every:
- Rule
- Notification under Sections 16 and 42
must be laid before both Houses of Parliament for 30 days.
Parliament may:
- Approve.
- Modify.
- Reject.
Actions already taken under the Rule remain valid even if later modified or annulled.
Important Points – Section 41
✔ Parliamentary control.
✔ 30-day review period.
✔ Previous actions remain valid.
SECTION 42 – Power to Amend the Schedule
Section 42(1)
The Central Government may amend the Schedule by notification.
Restriction
Penalty amounts cannot exceed twice the amount specified when the Act was originally enacted.
Section 42(2)
The amendment:
- Becomes part of the Act.
- Takes effect from the date of notification.
Example
If the original maximum penalty is ₹250 crore,
it cannot be increased beyond ₹500 crore through a notification.
Important Points – Section 42
✔ Government can amend penalty Schedule.
✔ Maximum increase limited to double the original amount.
SECTION 43 – Power to Remove Difficulties
Section 43(1)
If any practical difficulty arises in implementing the Act,
the Central Government may issue orders to remove the difficulty.
Such orders must be:
- Consistent with the Act.
- Published in the Official Gazette.
Section 43(2)
This power exists only for 3 years from the commencement of the Act.
Section 43(3)
Every such order must be laid before Parliament.
Important Points – Section 43
✔ Temporary power.
✔ Valid only for three years.
✔ Parliamentary oversight.
SECTION 44 – Amendments to Other Acts
Objective
Makes consequential amendments to align other laws with the DPDP Act.
Section 44(1)
Amendment to the TRAI Act, 1997
The Telecom Disputes Settlement and Appellate Tribunal (TDSAT) is designated as the Appellate Tribunal for:
- Information Technology Act.
- Airports Economic Regulatory Authority Act.
- DPDP Act.
Section 44(2)
Amendments to the Information Technology Act, 2000
Clause (a)
Section 43A is omitted.
Reason: Data protection is now governed by the DPDP Act.
Clause (b)
Section 81 is amended to clarify that the DPDP Act also prevails where applicable.
Clause (c)
Rule-making provision relating to Section 43A is omitted.
Section 44(3)
Amendment to the Right to Information (RTI) Act, 2005
Section 8(1)(j) is substituted.
The exemption now simply covers:
“information which relates to personal information.”
This aligns the RTI Act with the DPDP Act’s protection of personal data.
Important Points – Section 44
✔ TDSAT acts as the Appellate Tribunal under the DPDP Act.
✔ IT Act provisions on compensation for failure to protect data (Section 43A) are removed.
✔ RTI Act is amended to harmonise personal information protections with the DPDP framework.
Quick Revision Table
| Section | Topic | Key Provision |
|---|---|---|
| 35 | Good Faith Protection | Protects the Central Government, the Board, and its officials from legal proceedings for acts done honestly under the Act. |
| 36 | Information Power | Central Government may require information from the Board, Data Fiduciaries, and Intermediaries. |
| 37 | Blocking Power | Government may block access to repeat violators after two or more penalties, a Board recommendation, hearing, and recorded reasons. |
| 38 | Relationship with Other Laws | DPDP Act is in addition to other laws; it prevails where there is a conflict. |
| 39 | Civil Court Bar | Civil Courts cannot hear matters assigned to the Board or grant injunctions against Board actions. |
| 40 | Rule-Making | Central Government may make Rules to implement the Act on numerous procedural and operational matters. |
| 41 | Parliamentary Oversight | Rules and specified Notifications must be laid before Parliament for review. |
| 42 | Amendment of Schedule | Government may amend the Schedule, but penalty amounts cannot exceed twice the original maximum. |
| 43 | Removal of Difficulties | Government may issue orders to remove implementation difficulties within 3 years of the Act’s commencement. |
| 44 | Amendments to Other Acts | Amends the TRAI Act, Information Technology Act, and RTI Act to align them with the DPDP Act. |
