DIGITAL PERSONAL DATA PROTECTION ACT, 2023
[11th August, 2023]
PREAMBLE
An Act to provide for the processing of digital personal data in a manner that recognises both the right of individuals to protect their personal data and the need to process such personal data for lawful purposes and for matters connected therewith or incidental thereto.
Be it enacted by Parliament in the Seventy-fourth Year of the Republic of India as follows:--
The Preliminary section of the Digital Personal Data Protection Act, 2023 (DPDP Act) sets the foundational framework for the legislation, defining key terms, scope, and the overarching purpose of the Act. It establishes the legal context within which subsequent provisions operate, emphasizing the protection of individual privacy and regulation of data processing activities.
The Preliminary section introduces the title, commencement, definitions, and scope of the Act. It clarifies that the Act applies to the processing of digital personal data within India, and lays down the basic principles guiding data processing, including the recognition of individuals' rights and the responsibilities of data fiduciaries.
The section broadly delineates the geographical and functional scope, applying to all digital personal data processed within India, regardless of where the data was collected. It also sets the stage for defining obligations and rights in subsequent chapters.
As a preliminary section, it does not prescribe penalties directly. However, violations related to definitions, scope, or procedural missteps can attract penalties under the later provisions of the Act, which include hefty fines for non-compliance.
This concise legal commentary synthesizes the key aspects of the Preliminary section of the Digital Personal Data Protection Act, 2023, drawing from multiple sources to provide a comprehensive analysis.
(1) This Act may be called the Digital Personal Data Protection Act, 2023.
(2) It shall come into force on such date as the Central Government may, by notification in the Official Gazette, appoint and different dates may be appointed for different provisions of this Act and any reference in any such provision to the commencement of this Act shall be construed as a reference to the coming into force of that provision.
In this Act, unless the context otherwise requires,--
(a) "Appellate Tribunal" means the Telecom Disputes Settlement and Appellate Tribunal established under Section 14 of the Telecom Regulatory Authority of India Act, 1997 (24 of 1997);
(b) "automated" means any digital process capable of operating automatically in response to instructions given or otherwise for the purpose of processing data;
(c) "Board" means the Data Protection Board of India established by the Central Government under Section 18;
(d) "certain legitimate uses" means the uses referred to in Section 7;
(e) "Chairperson" means the Chairperson of the Board;
(f) "child" means an individual who has not completed the age of eighteen years;
(g) "Consent Manager" means a person registered with the Board, who acts as a single point of contact to enable a
Subject to the provisions of this Act, it shall--
(a) apply to the processing of digital personal data within the territory of India where the personal data is collected--
(i) in digital form; or
(ii) in non-digital form and digitised subsequently;
(b) also apply to processing of digital personal data outside the territory of India, if such processing is in connection with any activity related to offering of goods or services to Data Principals within the territory of India;
(c) not apply to--
(i) personal data processed by an individual for any personal or domestic purpose; and
(ii) personal data that is made or caused to be made publicly available by--
(A) the Data Principal to whom such personal data relates; or
(B) any other person who is under an obligation under any
(1) A person may process the personal data of a Data Principal only in accordance with the provisions of this Act and for a lawful purpose,--
(a) for which the Data Principal has given her consent; or
(b) for certain legitimate uses.
(2) For the purposes of this section, the expression "lawful purpose" means any purpose which is not expressly forbidden by law.
(1) Every request made to a Data Principal under Section 6 for consent shall be accompanied or preceded by a notice given by the Data Fiduciary to the Data Principal, informing her,--
(i) the personal data and the purpose for which the same is proposed to be processed;
(ii) the manner in which she may exercise her rights under Sub-Section (4) of Section 6 and Section 13; and
(iii) the manner in which the Data Principal may make a complaint to the Board, in such manner and as may be prescribed.
(2) Where a Data Principal has given her consent for the processing of her personal data before the date of commencement of this Act,--
(a) the Data Fiduciary shall, as soon as it is reasonably practicable, give to the Data Principal a notice informing her,--
(i) the personal data and the purpose for which the same has been processed;
(1) The consent given by the Data Principal shall be free, specific, informed, unconditional and unambiguous with a clear affirmative action, and shall signify an agreement to the processing of her personal data for the specified purpose and be limited to such personal data as is necessary for such specified purpose.
(2) Any part of consent referred in Sub-Section (1) which constitutes an infringement of the provisions of this Act or the rules made thereunder or any other law for the time being in force shall be invalid to the extent of such infringement.
(3) Every request for consent under the provisions of this Act or the rules made thereunder shall be presented to the Data Principal in a clear and plain language, giving her the option to access such request in English or any language specified in the Eighth Schedule to the Constitution and providing the contact details of a Data Protection Officer, where applicable, or o
A Data Fiduciary may process personal data of a Data Principal for any of following uses, namely:--
(a) for the specified purpose for which the Data Principal has voluntarily provided her personal data to the Data Fiduciary, and in respect of which she has not indicated to the Data Fiduciary that she does not consent to the use of her personal data.
(b) for the State and any of its instrumentalities to provide or issue to the Data Principal such subsidy, benefit, service, certificate, licence or permit as may be prescribed, where--
(i) she has previously consented to the processing of her personal data by the State or any of its instrumentalities for any subsidy, benefit, service, certificate, licence or permit; or
(ii) such personal data is available in digital form in, or in non-digital form and digitised subsequently from, any database, register, book or other document which is
(1) A Data Fiduciary shall, irrespective of any agreement to the contrary or failure of a Data Principal to carry out the duties provided under this Act, be responsible for complying with the provisions of this Act and the rules made thereunder in respect of any processing undertaken by it or on its behalf by a Data Processor.
(2) A Data Fiduciary may engage, appoint, use or otherwise involve a Data Processor to process personal data on its behalf for any activity related to offering of goods or services to Data Principals only under a valid contract.
(3) Where personal data processed by a Data Fiduciary is likely to be--
(a) used to make a decision that affects the Data Principal; or
(b) disclosed to another Data Fiduciary,
the Data Fiduciary processing such personal data shall ensure its completeness, accuracy and consistency.
(4) A Da
(1) The Data Fiduciary shall, before processing any personal data of a child or a person with disability who has a lawful guardian obtain verifiable consent of the parent of such child or the lawful guardian, as the case may be, in such manner as may be prescribed.
Explanation.--For the purpose of this sub-section, the expression "consent of the parent" includes the consent of lawful guardian, wherever applicable.
(2) A Data Fiduciary shall not undertake such processing of personal data that is likely to cause any detrimental effect on the well-being of a child.
(3) A Data Fiduciary shall not undertake tracking or behavioural monitoring of children or targeted advertising directed at children.
(4) The provisions of sub-sections (1) and (3) shall not be applicable to processing of personal data of a child by such classes of Data Fiduciaries or for such purposes, and subject to such
(1) The Central Government may notify any Data Fiduciary or class of Data Fiduciaries as Significant Data Fiduciary, on the basis of an assessment of such relevant factors as it may determine, including--
(a) the volume and sensitivity of personal data processed;
(b) risk to the rights of Data Principal;
(c) potential impact on the sovereignty and integrity of India;
(d) risk to electoral democracy;
(e) security of the State; and
(f) public order.
(2) The Significant Data Fiduciary shall--
(a) appoint a Data Protection Officer who shall--
(i) represent the Significant Data Fiduciary under the provisions of this Act;
(ii) be based in India;
(iii) be an individual responsible to the Board of Directors or similar governing body of t
(1) The Data Principal shall have the right to obtain from the Data Fiduciary to whom she has previously given consent, including consent as referred to in clause (a) of Section 7 (hereinafter referred to as the said Data Fiduciary), for processing of personal data, upon making to it a request in such manner as may be prescribed,--
(a) a summary of personal data which is being processed by such Data Fiduciary and the processing activities undertaken by that Data Fiduciary with respect to such personal data;
(b) the identities of all other Data Fiduciaries and Data Processors with whom the personal data has been shared by such Data Fiduciary, along with a description of the personal data so shared; and
(c) any other information related to the personal data of such Data Principal and its processing, as may be prescribed.
(2) Nothing contained in clause (b) or clause (c) of Sub-Secti
(1) A Data Principal shall have the right to correction, completion, updating and erasure of her personal data for the processing of which she has previously given consent, including consent as referred to in clause (a) of Section 7, in accordance with any requirement or procedure under any law for the time being in force.
(2) A Data Fiduciary shall, upon receiving a request for correction, completion or updating from a Data Principal,--
(a) correct the inaccurate or misleading personal data;
(b) complete the incomplete personal data; and
(c) update the personal data.
(3) A Data Principal shall make a request in such manner as may be prescribed to the Data Fiduciary for erasure of her personal data, and upon receipt of such a request, the Data Fiduciary shall erase her personal data unless retention of the same is necessary for the specified purpose or for co
Section 12 of the Digital Personal Data Protection Act, 2023 (DPDP Act) delineates the rights of Data Principals (individuals) regarding their personal data, emphasizing the rights to correction, completion, updating, and erasure. It forms a core component of the data protection framework, balancing individual privacy with lawful data processing.
Section 12 grants Data Principals the right to:- Request correction, completion, and updating of their personal data.- Seek erasure of their personal data when the purpose for which data was processed is no longer valid or with withdrawal of consent.- The Data Fiduciary (entity processing data) must comply unless retention is necessary for legal obligations or other legitimate purposes.
While Section 12 itself primarily confers rights, violations can lead to penalties under Chapter VIII of the DPDP Act:- Penalties for contravention of data erasure or correction obligations can extend up to INR 250 crore.- The Data Protection Board (DPB) has authority to adjudicate and impose penalties for breach of obligations.- Non-compliance may also attract civil liabilities and damages as per applicable laws.
Right to Privacy - Recognized as a fundamental right under Article 21 of the Constitution, Section 12 operationalizes this right by empowering individuals to control their personal data [Karthick Theodore VS Registrar General Madras High Court].
Right to Erasure - Reflects the global trend, akin to GDPR’s Article 17, allowing individuals to request deletion of their data when no longer necessary or with withdrawal of consent, balancing privacy with lawful data processing [Dhritiman Ray VS University of Delhi].
Data Minimization & Purpose Limitation - Section 12 enforces that data must be erased when the purpose is fulfilled, aligning with principles of data minimization and purpose limitation, fundamental to data protection laws [Justice K. S. Puttaswamy (Retd. ) VS Union of India].
Consent & Notice - Mandates that Data Fiduciaries must inform Data Principals of processing and obtain explicit consent, reinforcing the rights to control and transparency [Karthick Theodore VS Registrar General Madras High Court].
Lawful Processing & Exceptions - Data can be retained if necessary for legal obligations, public interest, or national security, indicating a balanced approach respecting rights and state interests [Vysakh K. G. , S/o. Gokuldas VS Union Of India].
Balance with Freedom of Speech - The right to correction and erasure should be balanced against the public interest, especially in judicial records and judgments, where transparency is vital but privacy rights also need protection [T. V. S. Electronics Ltd. VS Collector of Central Excise, Bangalore].
Implication for Judicial Records - Courts have the discretion to redact personal data under Article 21 and Section 12, but cannot completely obliterate judicial records, maintaining transparency while respecting privacy [Karthick Theodore VS Registrar General Madras High Court].
Data Fiduciary Obligations - Entities processing personal data must ensure accuracy, security, and timely response to correction or erasure requests, with penalties for breach .
Inclusion of Data Principals’ Rights - Section 12 embodies the principle that individuals have control over their digital identity, aligning with global standards like GDPR and EU’s “right to be forgotten” [Dhritiman Ray VS University of Delhi].
Limitations & Public Interest - The right to erasure is subject to exceptions where data is necessary for public interest, legal compliance, or freedom of expression, preventing abuse of the right [Vysakh K. G. , S/o. Gokuldas VS Union Of India].
Protection against Data Breach & Misuse - The section emphasizes the importance of data security, with breach notifications and penalties, to prevent misuse and protect individual privacy .
Evolving Data Rights & Digital Age - Section 12 reflects the recognition that data rights are dynamic, adapting to technological advances and societal needs, as seen in global data protection frameworks [University Of Delhi vs Neeraj].
Implementation & Enforcement - The Data Protection Board is empowered to oversee compliance, investigate violations, and impose penalties, ensuring effective enforcement of Section 12 rights [Gopal Vttal, Bharti Airtel Ltd. VS Kamatci Shankar Arumugam].
Interaction with Other Laws - Section 12 rights coexist with other legal provisions, including criminal law, civil law, and constitutional protections, requiring a nuanced, case-specific approach [Dhritiman Ray VS University Of Delhi].
Transparency & Public Confidence - Ensuring that individuals can exercise control over their data fosters trust in digital services and judicial transparency, vital for democratic legitimacy [DPMI Vocational Pvt Ltd vs Union Of India].
Limitations & Safeguards - While empowering data subjects, the law recognizes the need for safeguards to prevent misuse, especially in sensitive sectors like health, finance, and judiciary [Shaurabh Kumar Tripathi VS Vidhi Rawal].
International & Comparative Perspective - The rights conferred under Section 12 mirror international standards such as GDPR, emphasizing global convergence in data privacy rights [Suo Motu VS Travancore Devaswom Board, Nanthancode, Kawdiar Post, Thiruvananthapuram, Represented By Its Secretary].
Section 12 of the Digital Personal Data Protection Act, 2023, enshrines the core rights of Data Principals to correct, update, and erase their personal data, subject to lawful exceptions. It imposes obligations on Data Fiduciaries to ensure data accuracy, security, and responsiveness, with penalties for violations. The section reflects a balanced approach, aligning with global data privacy principles, emphasizing individual autonomy, and fostering trust in digital ecosystems. Its enforcement mechanisms and scope aim to uphold privacy rights while accommodating legitimate state and societal interests.
**- [Karthick Theodore VS Registrar General Madras High Court], [Dhritiman Ray VS University of Delhi], [Vysakh K. G. , S/o. Gokuldas VS Union Of India], [Justice K. S. Puttaswamy (Retd. ) VS Union of India], [T. V. S. Electronics Ltd. VS Collector of Central Excise, Bangalore], [University Of Delhi vs Neeraj], , [Suo Motu VS Travancore Devaswom Board, Nanthancode, Kawdiar Post, Thiruvananthapuram, Represented By Its Secretary], [In Re : In The Matter Of Tackling The Issue Of ‘Digital Arrest Scams’, Cyber Crimes And Saving The Innocent People From Loosing Their Money And Lives], [Akshita Khosla vs University of Delhi], [Commr. of Customs, Bangalore VS M/s ACER India Pvt. Ltd. ], [Commr. of Customs, Bangalore VS M/s ACER India Pvt. Ltd. ], [Regin Vinny VS Union of India, Rep. by the Secretary, New Delhi], [Dhritiman Ray vs University of Delhi], [DPMI Vocational Pvt Ltd vs Union Of India], [Commissioner of Customs, Bangalore VS ACER India Pvt. Ltd. ], [00100061861], [Dharanidhar Karimojji VS Union Of India], [Raghuveer Sharan VS District Sahakari Krishi Gramin Vikas Bank], [Punit S/o. Bhimsingh Rajput VS State of Karnataka, By CPI Mudhol, Represented by State Public Prosecutor], [Vysakh K. G. , S/o. Gokuldas VS Union Of India]
(1) A Data Principal shall have the right to have readily available means of grievance redressal provided by a Data Fiduciary or Consent Manager in respect of any act or omission of such Data Fiduciary or Consent Manager regarding the performance of its obligations in relation to the personal data of such Data Principal or the exercise of her rights under the provisions of this Act and the rules made thereunder.
(2) The Data Fiduciary or Consent Manager shall respond to any grievances referred to in Sub-Section (1) within such period as may be prescribed from the date of its receipt for all or any class of Data Fiduciaries.
(3) The Data Principal shall exhaust the opportunity of redressing her grievance under this Section before approaching the Board.
(1) A Data Principal shall have the right to nominate, in such manner as may be prescribed, any other individual, who shall, in the event of death or incapacity of the Data Principal, exercise the rights of the Data Principal in accordance with the provisions of this Act and the rules made thereunder.
(2) For the purposes of this section, the expression "incapacity" means inability to exercise the rights of the Data Principal under the provisions of this Act or the rules made thereunder due to unsoundness of mind or infirmity of body.
A Data Principal shall perform the following duties, namely:--
(a) comply with the provisions of all applicable laws for the time being in force while exercising rights under the provisions of this Act;
(b) to ensure not to impersonate another person while providing her personal data for a specified purpose;
(c) to ensure not to suppress any material information while providing her personal data for any document, unique identifier, proof of identity or proof of address issued by the State or any of its instrumentalities;
(d) to ensure not to register a false or frivolous grievance or complaint with a Data Fiduciary or the Board; and
(e) to furnish only such information as is verifiably authentic, while exercising the right to correction or erasure under the provisions of this Act or the rules made thereunder.
Section 15 of the Digital Personal Data Protection Act, 2023 (DPDP Act) delineates the specific duties and responsibilities of Data Principals, emphasizing their role in safeguarding their personal data and ensuring responsible data practices. It forms part of the broader framework that balances individual rights with data fiduciaries' obligations, aligning with global privacy standards such as the EU GDPR and principles of informational privacy.
Section 15 prescribes that Data Principals shall perform certain duties in relation to their personal data, including providing informed consent, ensuring data accuracy, and exercising rights such as correction and erasure. It acts as a responsibility clause, complementing the rights granted under Sections 4-14, and emphasizes that these rights must be exercised responsibly to prevent misuse or abuse of data.
Section 15 applies to all Data Principals whose personal data is processed under the DPDP Act, including children and persons with disabilities, and mandates responsible exercise of rights. It covers both online and offline data collection, digitized data, and aligns with the Act’s overarching goal of protecting informational privacy while fostering responsible data use.
While Section 15 itself primarily sets duties, violations—such as exercising rights irresponsibly or maliciously—may attract penalties under Sections 63, 64, or 70 of the Act, including monetary fines up to INR 10,000 for breaches. The Act emphasizes that misuse or abuse of rights can lead to penalties, ensuring accountability of Data Principals' responsible exercise of their duties.
In conclusion, Section 15 of the Digital Personal Data Protection Act, 2023, is a pivotal provision that emphasizes the responsible exercise of data rights by Data Principals. It aims to foster a culture of accountability, prevent misuse, and align India’s data privacy regime with international standards, ensuring that individual rights are exercised responsibly within a well-regulated ecosystem.
(1) The Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary for processing to such country or territory outside India as may be so notified.
(2) Nothing contained in this Section shall restrict the applicability of any law for the time being in force in India that provides for a higher degree of protection for or restriction on transfer of personal data by a Data Fiduciary outside India in relation to any personal data or Data Fiduciary or class thereof.
(1) The provisions of Chapter II, except sub-sections (1) and (5) of Section 8, and those of Chapter III and Section 16 shall not apply where--
(a) the processing of personal data is necessary for enforcing any legal right or claim;
(b) the processing of personal data by any court or tribunal or any other body in India which is entrusted by law with the performance of any judicial or quasi-judicial or regulatory or supervisory function, where such processing is necessary for the performance of such function;
(c) personal data is processed in the interest of prevention, detection, investigation or prosecution of any offence or contravention of any law for the time being in force in India;
(d) personal data of Data Principals not within the territory of India is processed pursuant to any contract entered into with any person outside the territory of India by any person based in Indi
Section 17 of the Digital Personal Data Protection Act, 2023 (DPDPA) delineates specific exemptions and scenarios where certain obligations under the Act may not apply or are modified. It aims to balance individual rights with state interests and lawful processing needs, recognizing the complexities of real-world data processing.
Section 17 provides exemptions for the processing of personal data in particular circumstances, notably for law enforcement, national security, public order, and investigations. It permits processing without consent when necessary for the prevention, detection, investigation, or prosecution of offences or violations of law. The section also grants the Central Government immunity in certain contexts, particularly concerning sovereignty and integrity.
This commentary synthesizes insights from the provided sources, emphasizing the balance between lawful exemptions and protection of individual rights within the framework of the Digital Personal Data Protection Act, 2023.
(1) With effect from such date as the Central Government may, by notification, appoint, there shall be established, for the purposes of this Act, a Board to be called the Data Protection Board of India.
(2) The Board shall be a body corporate by the name aforesaid, having perpetual succession and a common seal, with power, subject to the provisions of this Act, to acquire, hold and dispose of property, both movable and immovable, and to contract and shall, by the said name, sue or be sued.
(3) The headquarters of the Board shall be at such place as the Central Government may notify.
(1) The Board shall consist of a Chairperson and such number of other Members as the Central Government may notify.
(2) The Chairperson and other Members shall be appointed by the Central Government in such manner as may be prescribed.
(3) The Chairperson and other Members shall be a person of ability, integrity and standing who possesses special knowledge or practical experience in the fields of data governance, administration or implementation of laws related to social or consumer protection, dispute resolution, information and communication technology, digital economy, law, regulation or techno-regulation, or in any other field which in the opinion of the Central Government may be useful to the Board, and at least one among them shall be an expert in the field of law.
(1) The salary, allowances and other terms and conditions of service of the Chairperson and other Members shall be such as may be prescribed, and shall not be varied to their disadvantage after their appointment.
(2) The Chairperson and other Members shall hold office for a term of two years and shall be eligible for re-appointment.
(1) A person shall be disqualified for being appointed and continued as the Chairperson or a Member, if she--
(a) has been adjudged as an insolvent;
(b) has been convicted of an offence, which in the opinion of the Central Government, involves moral turpitude;
(c) has become physically or mentally incapable of acting as a Member;
(d) has acquired such financial or other interest, as is likely to affect prejudicially her functions as a Member; or
(e) has so abused her position as to render her continuance in office prejudicial to the public interest.
(2) The Chairperson or Member shall not be removed from her office by the Central Government unless she has been given an opportunity of being heard in the matter.
(1) The Chairperson or any other Member may give notice in writing to the Central Government of resigning from her office, and such resignation shall be effective from the date on which the Central Government permits her to relinquish office, or upon expiry of a period of three months from the date of receipt of such notice, or upon a duly appointed successor entering upon her office, or upon the expiry of the term of her office, whichever is earliest.
(2) A vacancy caused by the resignation or removal or death of the Chairperson or any other Member, or otherwise, shall be filled by fresh appointment in accordance with the provisions of this Act.
(3) The Chairperson and any other Member shall not, for a period of one year from the date on which they cease to hold such office, except with the previous approval of the Central Government, accept any employment, and shall also disclose to the Central Government any subsequent a
(1) The Board shall observe such procedure in regard to the holding of and transaction of business at its meetings, including by digital means, and authenticate its orders, directions and instruments in such manner as may be prescribed.
(2) No act or proceeding of the Board shall be invalid merely by reason of--
(a) any vacancy in or any defect in the constitution of the Board;
(b) any defect in the appointment of a person acting as the Chairperson or other Member of the Board; or
(c) any irregularity in the procedure of the Board, which does not affect the merits of the case.
(3) When the Chairperson is unable to discharge her functions owing to absence, illness or any other cause, the senior-most Member shall discharge the functions of the Chairperson until the date on which the Chairperson resumes her duties.
The Board may, with previous approval of the Central Government, appoint such officers and employees as it may deem necessary for the efficient discharge of its functions under the provisions of this Act, on such terms and conditions of appointment and service as may be prescribed.
The Chairperson, Members, officers and employees of the Board shall be deemed, when acting or purporting to act in pursuance of provisions of this Act, to be public servants within the meaning of Section 21 of the Indian Penal Code (45 of 1860).
The Chairperson shall exercise the following powers, namely:--
(a) general superintendence and giving direction in respect of all administrative matters of the Board;
(b) authorise any officer of the Board to scrutinise any intimation, complaint, reference or correspondence addressed to the Board; and
(c) authorise performance of any of the functions of the Board and conduct any of its proceedings, by an individual Member or groups of Members and to allocate proceedings among them.
(1) The Board shall exercise and perform the following powers and functions, namely:--
(a) on receipt of an intimation of personal data breach under Sub-Section (6) of Section 8, to direct any urgent remedial or mitigation measures in the event of a personal data breach, and to inquire into such personal data breach and impose penalty as provided in this Act;
(b) on a complaint made by a Data Principal in respect of a personal data breach or a breach in observance by a Data Fiduciary of its obligations in relation to her personal data or the exercise of her rights under the provisions of this Act, or on a reference made to it by the Central Government or a State Government, or in compliance of the directions of any court, to inquire into such breach and impose penalty as provided in this Act;
(c) on a complaint made by a Data Principal in respect of a breach in observance by a Consent Manager of its ob
(1) The Board shall function as an independent body and shall, as far as practicable, function as a digital office, with the receipt of complaints and the allocation, hearing and pronouncement of decisions in respect of the same being digital by design, and adopt such techno-legal measures as may be prescribed.
(2) The Board may, on receipt of an intimation or complaint or reference or directions as referred to in Sub-Section (1) of Section 27, take action in accordance with the provisions of this Act and the rules made thereunder.
(3) The Board shall determine whether there are sufficient grounds to proceed with an inquiry.
(4) In case the Board determines that there are insufficient grounds, it may, for reasons to be recorded in writing, close the proceedings.
(5) In case the Board determines that there are sufficient grounds to proceed with inquiry, it may, for reasons to be re
(1) Any person aggrieved by an order or direction made by the Board under this Act may prefer an appeal before the Appellate Tribunal.
(2) Every appeal under Sub-Section (1) shall be filed within a period of sixty days from the date of receipt of the order or direction appealed against and it shall be in such form and manner and shall be accompanied by such fee as may be prescribed.
(3) The Appellate Tribunal may entertain an appeal after the expiry of the period specified in Sub-Section (2), if it is satisfied that there was sufficient cause for not preferring the appeal within that period.
(4) On receipt of an appeal under Sub-Section (1), the Appellate Tribunal may, after giving the parties to the appeal, an opportunity of being heard, pass such orders thereon as it thinks fit, confirming, modifying or setting aside the order appealed against.
(5) The Appellate Tribunal shall s
(1) An order passed by the Appellate Tribunal under this Act shall be executable by it as a decree of civil court, and for this purpose, the Appellate Tribunal shall have all the powers of a civil court.
(2) Notwithstanding anything contained in Sub-Section (1), the Appellate Tribunal may transmit any order made by it to a civil court having local jurisdiction and such civil court shall execute the order as if it were a decree made by that court.
If the Board is of the opinion that any complaint may be resolved by mediation, it may direct the parties concerned to attempt resolution of the dispute through such mediation by such mediator as the parties may mutually agree upon, or as provided for under any law for the time being in force in India.
(1) The Board may accept a voluntary undertaking in respect of any matter related to observance of the provisions of this Act from any person at any stage of a proceeding under Section 28.
(2) The voluntary undertaking referred to in Sub-Section (1) may include an undertaking to take such action within such time as may be determined by the Board, or refrain from taking such action, and or publicising such undertaking.
(3) The Board may, after accepting the voluntary undertaking and with the consent of the person who gave the voluntary undertaking vary the terms included in the voluntary undertaking.
(4) The acceptance of the voluntary undertaking by the Board shall constitute a bar on proceedings under the provisions of this Act as regards the contents of the voluntary undertaking, except in cases covered by Sub-Section (5).
(5) Where a person fails to adhere to any term of the vo
(1) If the Board determines on conclusion of an inquiry that breach of the provisions of this Act or the rules made thereunder by a person is significant, it may, after giving the person an opportunity of being heard, impose such monetary penalty specified in the Schedule.
(2) While determining the amount of monetary penalty to be imposed under Sub-Section (1), the Board shall have regard to the following matters, namely:--
(a) the nature, gravity and duration of the breach;
(b) the type and nature of the personal data affected by the breach;
(c) repetitive nature of the breach;
(d) whether the person, as a result of the breach, has realised a gain or avoided any loss;
(e) whether the person took any action to mitigate the effects and consequences of the breach, and the timeliness and effectiveness of such action;
(
All sums realised by way of penalties imposed by the Board under this Act, shall be credited to the Consolidated Fund of India.
No suit, prosecution or other legal proceedings shall lie against the Central Government, the Board, its Chairperson and any Member, officer or employee thereof for anything which is done or intended to be done in good faith under the provisions of this Act or the rules made thereunder.
The Central Government may, for the purposes of this Act, require the Board and any Data Fiduciary or intermediary to furnish such information as it may call for.
(1) The Central Government or any of its officers specially authorised by it in this behalf may, upon receipt of a reference in writing from the Board that--
(a) intimates the imposition of monetary penalty by the Board on a Data Fiduciary in two or more instances; and
(b) advises, in the interests of the general public, the blocking for access by the public to any information generated, transmitted, received, stored or hosted, in any computer resource that enables such Data Fiduciary to carry on any activity relating to offering of goods or services to Data Principals within the territory of India,
after giving an opportunity of being heard to that Data Fiduciary, on being satisfied that it is necessary or expedient so to do, in the interests of the general public, for reasons to be recorded in writing, by order, direct any agency of the Central Government or any intermediary to block for access by th
(1) The provisions of this Act shall be in addition to and not in derogation of any other law for the time being in force.
(2) In the event of any conflict between a provision of this Act and a provision of any other law for the time being in force, the provision of this Act shall prevail to the extent of such conflict.
No civil court shall have the jurisdiction to entertain any suit or proceeding in respect of any matter for which the Board is empowered under the provisions of this Act and no injunction shall be granted by any court or other authority in respect of any action taken or to be taken in pursuance of any power under the provisions of this Act.
(1) The Central Government may, by notification, and subject to the condition of previous publication, make rules not inconsistent with the provisions of this Act, to carry out the purposes of this Act.
(2) In particular and without prejudice to the generality of the foregoing power, such rules may provide for all or any of the following matters, namely:--
(a) the manner in which the notice given by the Data Fiduciary to a Data Principal shall inform her, under Sub-Section (1) of Section 5;
(b) the manner in which the notice given by the Data Fiduciary to a Data Principal shall inform her, under Sub-Section (2) of Section 5;
(c) the manner of accountability and the obligations of Consent Manager under Sub-Section (8) of Section 6;
(d) the manner of registration of Consent Manager and the conditions relating thereto, under Sub-Section (9) of Section 6;
Every rule made and every notification issued under Section 16 and Section 42 of this Act shall be laid, as soon as may be after it is made, before each House of Parliament, while it is in session, for a total period of thirty days which may be comprised in one session or in two or more successive sessions, and if before the expiry of the session immediately following the session or the successive sessions aforesaid, both Houses agree in making any modification in the rule or notification or both Houses agree that the rule or notification should not be made or issued, the rule or notification shall thereafter have effect only in such modified form or be of no effect, as the case may be; so, however, that any such modification or annulment shall be without prejudice to the validity of anything previously done under that rule or notification.
Section 41 of the Digital Personal Data Protection Act, 2023 (DPDPA) plays a crucial role in ensuring transparency and accountability in the rule-making process related to data protection regulations. It mandates parliamentary oversight over rules and notifications issued under the Act, thereby reinforcing the legislative framework's legitimacy.
Section 41 stipulates that all rules made and notifications issued under Section 16 and Section 42 of the DPDPA must be laid before Parliament for a period of at least 30 days. This provision allows Parliament to scrutinize, modify, or annul such rules and notifications, ensuring they are not arbitrary or beyond the scope of the Act.
Section 41 applies to all rules and notifications issued under Sections 16 and 42 of the DPDPA, which relate to the regulation of data fiduciaries and enforcement agencies. It ensures that the legislative oversight extends to the administrative rules that operationalize the Act’s provisions.
Section 41 itself does not prescribe any specific penalties or punishments. Its primary function is procedural, ensuring transparency and parliamentary oversight over rule-making processes.
Note: The analysis is based on the references provided, focusing on procedural and oversight aspects of Section 41. Specific penalties or enforcement measures are not applicable to this section directly but are related to the overall compliance framework of the Act.
(1) The Central Government may, by notification, amend the Schedule, subject to the restriction that no such notification shall have the effect of increasing any penalty specified therein to more than twice of what was specified in it when this Act was originally enacted.
(2) Any amendment notified under Sub-Section (1) shall have effect as if enacted in this Act and shall come into force on the date of the notification.
(1) If any difficulty arises in giving effect to the provisions of this Act, the Central Government may, by order published in the Official Gazette, make such provisions not inconsistent with the provisions of this Act as may appear to it to be necessary or expedient for removing the difficulty.
(2) No order as referred to in Sub-Section (1) shall be made after the expiry of three years from the date of commencement of this Act.
(3) Every order made under this Section shall be laid, as soon as may be after it is made, before each House of Parliament.
(1) In Section 14 of the Telecom Regulatory Authority of India Act, 1997 (24 of 1997), in clause (c), for sub-clauses (i) and (ii), the following sub-clauses shall be substituted, namely:--
"(i) the Appellate Tribunal under the Information Technology Act, 2000 (21 of 2000);
(ii) the Appellate Tribunal under the Airports Economic Regulatory Authority of India Act, 2008 (27 of 2008); and
(iii) the Appellate Tribunal under the Digital Personal Data Protection Act, 2023.".
(2) The Information Technology Act, 2000 (21 of 2000) shall be amended in the following manner, namely:--
(a) Section 43A shall be omitted;
(b) in Section 81, in the proviso, after the words and figures "the Patents Act, 1970 (39 of 1970)", the words and figures "or the Digital Personal Data Protection Act, 2023" shall be inserted; and
(c) in Section
THE SCHEDULE
[See Section 33 (1)]
| Sl. No. | Breach of provisions of this Act or rules made thereunder | Penalty |
| The Digital Personal Data Protection Act, 2023 (DPDPA) represents a significant legislative step in India towards safeguarding personal data. It establishes a comprehensive framework for the processing of digital personal data, recognizing individuals' rights to privacy and data protection. The Schedule of the DPDPA outlines the penalties for various offenses related to the processing of personal data, including breaches of duty by data fiduciaries and violations concerning children's data. The Schedule applies to all entities processing digital personal data within India, regardless of where the data was originally collected. It includes provisions for both online and offline data that has been digitized. Penalties range from INR 10,000 for minor breaches to INR 250 crore for severe violations, such as unauthorized processing or failure to protect children's data. |
Elevate your legal practice with advanced AI-driven research and drafting solutions. Experience unmatched efficiency, precision, and security, tailored exclusively for legal professionals.