# Adv. K J Muhammed Aslam: articles and procedure guides (full text) > Articles and guides by Adv. K J Muhammed Aslam, advocate, 3rd Floor, Lalan Towers (KGL Builders), Vanchi Square, High Court Junction, Ernakulam, Kerala 682031. General information on Indian and Kerala law, not legal advice for any particular matter. Practice areas: Cyber crime & IT Act matters; Data protection & DPDP compliance; Business, banking & IPR; Legal drafting & documents; Criminal law: bail, quash & appeals; High Court writs & procedure; Civil, property & consumer matters; Family & succession; Service & labour matters. Index of the site: https://advaslam.com/llms.txt # Articles ## Cyber Fraud Defence in Kerala: Freeze to Recovery Hub URL: https://advaslam.com/writing/cyber-fraud-defence-kerala/ Author: Adv. K J Muhammed Aslam, Advocate (Bar Council of Kerala, K/001823/2026) Published 5 October 2026 Practice area: Cyber crime & IT Act matters Answer cyber fraud in Kerala step by step: freeze unfreezing, UPI and task-scam recovery, P2P taint, notices, escalation, evidence, ED and CIBIL sequels. Cyber fraud in Kerala follows repeatable tracks — freeze, UPI and task-scam recovery, P2P taint, notices, escalation, evidence — with ED and CIBIL sequels where cases graduate. This hub orders the fraud-defence series into first-hour, investigation, and recovery sequences. It is general information, not legal advice. ## First hours — freeze, report, preserve? Freeze response by type: [police-freeze complete guide](https://advaslam.com/writing/bank-account-frozen-cyber-cell-kerala/) versus [bank suo-motu SOP](https://advaslam.com/writing/bank-freeze-without-police-rbi-kerala-hc-sop/). Reporting through [UPI fraud recovery sequencing](https://advaslam.com/writing/upi-fraud-complaint-recovery/), [Telegram task-scam recovery](https://advaslam.com/writing/telegram-job-task-scam-recovery/), and [crypto P2P taint with FIU and PMLA overlays](https://advaslam.com/writing/crypto-p2p-account-frozen-fiu-pmla/). Preservation under the [Section 63 evidence methodology](https://advaslam.com/writing/electronic-evidence-bsa-section-63-certificate-guide/) from hour one. ## Investigation — notices, escalation, arrest risk? [Section 35 vs 94 notice response](https://advaslam.com/writing/cyber-cell-notice-section-35-vs-94-bnss/) with bail architecture behind it — [regular bail](https://advaslam.com/writing/regular-bail-kerala-480-bnss/), [anticipatory bail](https://advaslam.com/writing/anticipatory-bail-kerala-high-court-process-fees/) — and [no-action escalation](https://advaslam.com/writing/cyber-complaint-filed-no-action-escalation/) where the machinery stalls. Threat and harassment overlays run through [loan-app harassment](https://advaslam.com/writing/loan-app-harassment-rbi-digital-lending/), [digital arrest](https://advaslam.com/writing/digital-arrest-scam-india-what-to-do/), and [sextortion](https://advaslam.com/writing/sextortion-blackmail-kerala-legal-remedies/). ## Recovery sequels — ED, lien, CIBIL? | Sequel | Guide | |---|---| | Laundering predicates and attachment | ED summons and PMLA response | | Lien-vs-freeze confusion with score damage | Bank lien vs freeze plus CIBIL fix | | Offence and procedure map | [IT Act offences explained](https://advaslam.com/writing/it-act-offences-explained/) | ## What evidence wins — preservation from hour one? Original-device preservation with hash-noted exports, indexed handover with chain-of-custody covers, and Section 63(4) dual-signature certification at tender — the methodology that converts screenshots into admissible proof and sustains complaints through trial. ## When do fraud cases reach the High Court? Stale or disproportionate freezes challengeable by writ, quash petitions where criminal proceedings abuse process, bail where arrest follows notices, and appeals from convictions — the High Court tracks mapped in the litigation hub with forum strategy for each escalation. ## Primary sources - [Information Technology Act, 2000](https://indiacode.gov.in/handle/123456789/496511) (India Code) - [Bharatiya Nagarik Suraksha Sanhita, 2023 — Sections 35, 94, 106, 173, 175](https://indiacode.gov.in/handle/123456789/496550) (India Code) - [National Cyber Crime Reporting Portal](https://cybercrime.gov.in/) (confirm live procedure) *General information — not legal advice. Office at High Court Junction, Ernakulam; practice before the High Court of Kerala.* ### Frequently asked questions **My account is frozen — where do I start?** Get the bank's written freeze note with requisition reference, preserve transaction proof, then follow the police-freeze or bank suo-motu workflow in the linked guides — representation to the cell, Magistrate release, or writ — matched to the freeze type, not a generic complaint. **I lost money to UPI or task-scam fraud — what is the order?** 1930 and NCRP within the golden hours, bank lien-marking, FIR under Section 173 BNSS, evidence preservation for Section 63 BSA, and Magistrate release plus forum escalation where the trail stalls — sequenced in the recovery guides below. **What if my cyber complaint gets no action?** Escalate SP to CPGRAMS to Section 175(3) Magistrate directions on the documented trail — the escalation ladder with paperbook discipline in its dedicated guide. **How do I keep digital evidence court-ready?** Original-device preservation with hash-noted exports, indexed handover, and Section 63(4) dual-signature certification at tender — the evidence methodology every fraud track on this hub consumes. **When does fraud become an ED or CIBIL matter?** Where laundering predicates or attachment follow, the PMLA track answers; where scores collapse after fraud, the CIBIL-correction ladder answers — sequels linked below, each at its own forum. **I received a cyber-cell notice — reply or ignore?** Classify Section 35 (appearance) versus Section 94 (production) and answer on its track with counsel — the notice guide maps both with arrest-risk sequencing. --- ## Regular Bail in Kerala: Section 480 BNSS Process Explained URL: https://advaslam.com/writing/regular-bail-kerala-480-bnss/ Author: Adv. K J Muhammed Aslam, Advocate (Bar Council of Kerala, K/001823/2026) Published 30 September 2026 Practice area: Criminal law: bail, quash & appeals Regular bail under Sections 478 and 480 BNSS in Kerala: forums, paperbook, default-bail clocks, undertrial release, conditions and sureties explained. A person in custody after arrest seeks release through regular bail — the post-arrest remedy under Sections 478 and 480 of the Bharatiya Nagarik Suraksha Sanhita, 2023, in force from 1 July 2024. Whether release is a right or a discretion turns on one classification: bailable or non-bailable. This guide explains that classification, the forum ladder in Kerala, the paperbook, the two clocks that release undertrials as of right, and the conditions and sureties that follow a grant. It is general information, not legal advice. ## Is the offence bailable or non-bailable — and why does it decide everything? The First Schedule to the BNSS classifies each offence, and the statute creating an offence may itself declare the classification. **Bailable offences (Section 478 BNSS):** the person has an effective right to release where prepared to give bail at any time while in custody; a person unable to furnish surety within a week of arrest is presumed indigent and may be released on personal bond. **Non-bailable offences (Section 480 BNSS):** release is discretionary. For non-bailable offences the court weighs the considerations in the table below. Section 480(1) BNSS additionally bars bail outright where there are reasonable grounds to believe the accused is guilty of an offence punishable with death or life imprisonment, or where specified prior-conviction patterns exist — subject to the proviso permitting release for children, women, the sick or infirm, and other special reasons the court finds just and proper. | Factor (Section 480 BNSS) | What the court examines | |---|---| | Nature and gravity | Punishment bracket, including death and life-imprisonment cases | | Prosecution evidence | Strength of the material collected, not a mini-trial | | Flight risk | Roots, residence, occupation, cross-border mobility | | Tampering risk | Access to witnesses and evidence; prior threats or influence | | Antecedents | Previous convictions and compliance with earlier bail | | Health, age, gender | Child, woman, sick or infirm person — special consideration | | Trial delay | Non-conclusion of a Magistrate-triable trial within 60 days of first evidence date favours release, where the accused has been in custody throughout (Section 480(6)) | ## Where do I file — Magistrate, Sessions, or High Court? | Forum | Jurisdiction | |---|---| | Police officer | Bailable offences only (Section 478) | | Judicial Magistrate | Non-bailable offences except those exclusively triable by Sessions | | Court of Session | Any offence including exclusively Sessions-triable matters (Section 483) | | High Court of Kerala | Any offence; concurrent jurisdiction (Section 483) | The ordinary course ascends this ladder: refusal below is addressed above with the reasons for refusal answered by fresh material or changed circumstances. For offences punishable with death, life imprisonment, or seven years and above, notice to the Public Prosecutor is mandatory and must be heard before grant. Cyber-offence bail additionally draws on the offence map in [IT Act offences explained](https://advaslam.com/writing/it-act-offences-explained/); where the arrest follows a Section 35 or 94 BNSS notice, the notice-response record forms part of the bail papers: [what a Section 35 or 94 notice means](https://advaslam.com/writing/cyber-cell-notice-section-35-vs-94-bnss/). ## What paperbook does a regular bail application need? 1. **Case identifiers** — crime number, police station, sections invoked, custody details with remand orders. 2. **Grounds mapped to the table above** — why custody is unnecessary: cooperation record, roots, medical or family grounds, delay, parity with co-accused already released. 3. **Custody memo and case diary references** — what investigation remains that genuinely requires detention, answered specifically. 4. **Undertaking and sureties** — readiness to abide by Section 480(3) conditions; surety particulars with identity, address, and solvency material where known. 5. **Annexures** — FIR, remand orders, prior bail orders in the crime, medical records where relied upon, proof of residence and occupation. 6. **Affidavit and verification** — with disclosure of antecedents and of any earlier bail proceedings and their outcomes. ## Which clocks release an undertrial as of right? Two provisions operate independently of merits discretion. **Default bail (Section 187(3) BNSS):** where the investigation report is not filed within 60 days — or 90 days where the offence carries death, life imprisonment, or a minimum term of ten years or more — the accused in custody gains an indefeasible right to release on bail if the application is made before the report reaches the court. Following Rakesh Kumar Paul v. State of Assam, (2017) 15 SCC 67, the 90-day track applies only where the offence carries a minimum of ten years — an offence punishable "up to ten years" falls in the 60-day track — and a special statute's own investigation period governs where prescribed. The right, once accrued and claimed in time, survives the subsequent filing of the report. **Undertrial release (Section 479 BNSS):** an undertrial who has undergone half the maximum imprisonment prescribed for the offence — one-third for a first-time offender, released on bond — must be released, except in death and life-imprisonment cases and subject to the Section 479(2) bar on multiple pending cases; the jail Superintendent must move the court under Section 479(3). **Magistrate-track trial delay (Section 480(6)):** release follows where a Magistrate-triable trial is not concluded within 60 days of the first evidence date, the accused having been in custody throughout, unless the Magistrate records reasons otherwise. Families tracking a long remand should compute both clocks, not merely wait for the charge sheet. ## What conditions and sureties follow a grant? Section 480(3) BNSS permits conditions including appearance before the court as per the bond, no commission of a similar offence while on bail, no threat or inducement to witnesses, and such other conditions as the court considers necessary. Execution runs under Section 485 BNSS through a personal bond with or without sureties, and release follows under Section 487 BNSS. Breach — absconding, tampering, re-offending, or violating a travel restriction — invites cancellation with re-arrest and surety forfeiture, and poisons every later remedy including appeal-stage bail under Section 430 BNSS. ## What if bail is refused, and how does this connect to quash and appeal? Refusal at one forum is addressed at the next, answering the stated reasons. Where the prosecution itself is misconceived — no prima facie offence, civil dispute dressed as criminal, or genuine settlement — the parallel remedy is a quash petition under Section 528 BNSS: [how to quash an FIR in the Kerala High Court](https://advaslam.com/writing/quash-fir-kerala-high-court-crlmc-528-bnss/). After conviction, suspension of sentence with release pending appeal runs under Section 430 BNSS. The full forum map across writs, bail, quash, and appeals sits in the [Kerala High Court litigation guide](https://advaslam.com/writing/kerala-high-court-litigation-guide/). ## Primary sources - [Bharatiya Nagarik Suraksha Sanhita, 2023 — Sections 478, 480, 483, 485, 487 (bail); Section 187(3) (default release), Section 479 (undertrial release); Section 430 (pending appeal)](https://indiacode.gov.in/handle/123456789/496550) (India Code) - [Rakesh Kumar Paul v. State of Assam, (2017) 15 SCC 67](https://indiankanoon.org/doc/194334432/) — the 90-day default-bail track requires a minimum sentence of ten years - [Bharatiya Nyaya Sanhita, 2023 — punishment brackets relevant to classification](https://indiacode.gov.in/handle/123456789/496548) (India Code) - [Kerala High Court — official website](https://highcourt.kerala.gov.in/) - [Kerala courts e-filing and case services](https://ecourt.keralacourts.in/) *General information — not legal advice. Office at High Court Junction, Ernakulam; practice before the High Court of Kerala.* ### Frequently asked questions **What is the difference between bailable and non-bailable offences for bail?** For bailable offences under Section 478 BNSS, release on bail is effectively a right where the person is prepared to give bail, including release on personal bond for an indigent person. For non-bailable offences under Section 480 BNSS, bail is discretionary and the court weighs gravity, evidence, flight risk, tampering risk, and antecedents. **Where do I file a regular bail application in Kerala?** Bailable offences: before the police officer or the Magistrate. Non-bailable offences: before the jurisdictional Magistrate, the Sessions Court, or the High Court, which hold concurrent power under Sections 480 and 483 BNSS. Exclusively Sessions-triable offences ordinarily go to Sessions Court or High Court. **What is default bail and when does it arise?** If the investigation report is not filed within the statutory period — 60 days for most offences, 90 days only where the offence carries death, life imprisonment, or a minimum term of ten years or more — the accused in custody gains an indefeasible right to release on bail under Section 187(3) BNSS, provided the application is made before the report is filed. Following Rakesh Kumar Paul v. State of Assam, (2017) 15 SCC 67, an offence merely punishable 'up to ten years' stays in the 60-day track, and a special statute's own investigation period governs where prescribed. **Can an undertrial get bail merely because the trial is delayed?** Yes, in defined circumstances. Section 479 BNSS mandates release where an undertrial has undergone half the maximum imprisonment for the offence — one-third for a first-time offender, who is released on bond rather than bail — except in death and life-imprisonment cases, and subject to the Section 479(2) bar where investigation, inquiry, or trial in multiple cases or offences is pending against the person; Section 479(3) obliges the jail Superintendent to move the court once the period is completed. Section 480(6) separately requires release in a Magistrate-triable case where the trial is not concluded within 60 days of the first date fixed for evidence, provided the accused has been in custody throughout, and unless the Magistrate directs otherwise for reasons recorded in writing. **What conditions and sureties follow a bail grant?** The court may impose appearance, non-repetition, and non-interference conditions under Section 480(3) BNSS, executed through a personal bond with or without sureties under Section 485 BNSS. Breach invites cancellation and re-arrest. **What if regular bail is refused?** Move the higher forum — Magistrate to Sessions to High Court — addressing the reasons for refusal with fresh material or changed circumstances, or challenge the underlying proceedings by quash petition under Section 528 BNSS where recognised grounds exist. --- ## Anticipatory Bail in Kerala High Court: Process, Fees and Time URL: https://advaslam.com/writing/anticipatory-bail-kerala-high-court-process-fees/ Author: Adv. K J Muhammed Aslam, Advocate (Bar Council of Kerala, K/001823/2026) Published 28 September 2026 Practice area: Criminal law: bail, quash & appeals Anticipatory bail under Sec 482 BNSS in Kerala: Sessions vs High Court route, paperbook, conditions, SC/ST bar, timelines and what follows rejection. A person who has reason to believe they may be arrested for a non-bailable offence need not wait for the police at the door. Section 482 of the Bharatiya Nagarik Suraksha Sanhita, 2023 — successor to Section 438 CrPC for proceedings under the new law in force from 1 July 2024 — empowers the High Court and the Court of Session to direct that, in the event of arrest, the person shall be released on bail. This guide explains the forum choice in Kerala, the paperbook, the conditions courts impose, the categories where anticipatory bail is barred, and the path after rejection. It is general information, not legal advice. ## Who can seek anticipatory bail, and when? Any person who apprehends arrest for a non-bailable offence may apply before arrest. The apprehension must be reasonable and connected to an identifiable accusation — ordinarily a registered crime, a complaint likely to become one, or a credible threat of implication. Applications founded on vague or hypothetical fear, without any crime or complaint in view, are liable to be rejected at threshold. Two statutory exclusions matter at the outset. Under Section 482(4) BNSS, anticipatory bail does not apply to offences under Section 65 (punishment for rape in certain cases) and Section 70(2) (gang rape) of the Bharatiya Nyaya Sanhita. Separately, Section 18 of the SC/ST (Prevention of Atrocities) Act, 1989 bars anticipatory bail where the complaint prima facie discloses an offence under that Act. Cases in these categories proceed by quash petition, surrender with regular bail, or trial defences — not by pre-arrest protection. ## Sessions Court or High Court — where should I file? | Forum | When it fits | Practical notes | |---|---|---| | Court of Session (District) | Ordinary first forum; local FIRs, early-stage crimes, cost and listing speed | Usually faster listing; Public Prosecutor of the district responds | | High Court of Kerala (Ernakulam) | Grave or sensitive offences, inter-district implications, urgency requiring Division-level attention, or after Sessions rejection | E-filing through the High Court system; State represented through the Public Prosecutor at Ernakulam | Both forums hold concurrent jurisdiction. Filing simultaneously in both is impermissible, and repeating an identical rejected application without changed circumstances invites dismissal with costs. A Sessions rejection followed by a High Court application should disclose the earlier order and explain what is new — fresh material, a charge-sheet development, or a legal ground not earlier urged. ## What paperbook does the application need? 1. **Cause title and provision** — application under Section 482 BNSS (with Section 438 CrPC reference only for transitional cases), naming the State through the Station House Officer and Public Prosecutor. 2. **Reason to believe** — the specific basis of arrest apprehension: crime number and sections, or the complaint and its trajectory. 3. **Factual answer to the FIR** — relationship background, timeline, and why the allegations, even as stated, do not warrant custodial interrogation; denial of ingredients, not a mini-trial on evidence. 4. **Roots and cooperation** — fixed residence, occupation, family ties, and an express undertaking to appear for interrogation and abide by conditions. 5. **Annexures** — FIR, related civil or commercial documents showing the dispute's true nature where relevant, prior court orders, identity and address proof. 6. **Affidavit and verification** — sworn support, with disclosure of any earlier bail or quash proceedings and their outcomes; suppression of a prior rejection is itself ground for refusal. 7. **Interim prayer** — interim protection from arrest pending disposal, with reasons for urgency. Cyber-offence apprehensions additionally engage the offence and investigation provisions summarised in [IT Act offences explained](https://advaslam.com/writing/it-act-offences-explained/). Where a Section 35 or 94 BNSS notice has already arrived, answer it on its own track first: [what a Section 35 or 94 notice means](https://advaslam.com/writing/cyber-cell-notice-section-35-vs-94-bnss/). ## What happens at the hearing — including interim protection? The court hears the applicant and the Public Prosecutor. The notice practice at these hearings draws on the Section 483 provisos, which by their terms govern bail before the High Court and Court of Session: for offences triable exclusively by the Sessions or punishable with life imprisonment, notice to the Public Prosecutor precedes grant (unless the court records that notice is impracticable); and in Section 65 and Section 70(2) BNS matters — outside Section 482(4) — notice within fifteen days and the informant's presence under Section 483(2) bind the bail hearing on surrender. In urgent cases showing a prima facie case for protection, the court frequently grants interim protection from arrest at the first hearing, returnable on the Prosecutor's response. At final hearing the court either grants anticipatory bail with conditions, rejects the application, or disposes with directions — for instance, directing surrender before a specified court within a fixed time with a direction to consider regular bail on the same day. On arrest following grant, Section 482(3) BNSS provides that the person shall be released on bail. ## What conditions will bind me? Under Section 482(2) BNSS the court may impose conditions including availability for police interrogation when required, no inducement or threat to witnesses, no leaving India without court permission, and any Section 480(3) conditions — appearance as per bond, no similar offence while on bail, no witness interference, and such other conditions as the court considers necessary. Breach invites cancellation and re-arrest, addressed alongside the regular-bail regime in the [High Court litigation guide](https://advaslam.com/writing/kerala-high-court-litigation-guide/). ## How long does it take, and what does it cost in court process? Interim protection, where granted, typically comes at the first hearing. Final disposal ranges from weeks to a few months with roster and contest. The current court-fee amount, e-filing defect-cure periods and listing practice follow the Kerala High Court Rules and the District Court practice directions; confirm them at the time of filing. Advocate fees are a matter of private engagement and are not stated on this site. ## What if anticipatory bail is rejected? Three lawful paths remain, chosen on facts. **Surrender with regular bail** under Section 480 BNSS before the jurisdictional court, supported by the cooperation record built during the anticipatory proceedings. **Higher-forum application** on fresh or materially strengthened grounds, disclosing the rejection order. Or **quash petition** under Section 528 BNSS where recognised grounds exist — no prima facie offence, civil dispute dressed as criminal, or genuine settlement: [how to quash an FIR in the Kerala High Court](https://advaslam.com/writing/quash-fir-kerala-high-court-crlmc-528-bnss/). What must not follow rejection is absconding: evasion converts a defensible bail case into a coercive-process case with warrants and proclamation. ## Primary sources - [Bharatiya Nagarik Suraksha Sanhita, 2023 — Section 482 (anticipatory bail); Sections 478, 480, 483 (bail architecture)](https://indiacode.gov.in/handle/123456789/496550) (India Code) - [Scheduled Castes and Scheduled Tribes (Prevention of Atrocities) Act, 1989 — Section 18](https://indiacode.gov.in/handle/123456789/496156) (India Code) - [Bharatiya Nyaya Sanhita, 2023 — Sections 65, 70(2)](https://indiacode.gov.in/handle/123456789/496548) (India Code) - [Kerala High Court — official website](https://highcourt.kerala.gov.in/) - [Kerala courts e-filing and case services](https://ecourt.keralacourts.in/) *General information — not legal advice. Office at High Court Junction, Ernakulam; practice before the High Court of Kerala.* ### Frequently asked questions **Which court should I approach for anticipatory bail in Kerala — Sessions Court or High Court?** Both have concurrent power under Section 482 BNSS. Sessions Court is the ordinary first forum and usually faster to list; the High Court at Ernakulam is approached directly in serious, sensitive, or urgent matters, or after a Sessions rejection. Sequential applications to both forums on identical grounds without changed circumstances are discouraged. **What must an anticipatory bail application contain?** The crime number, police station, and sections; the reason to believe arrest is apprehended; a factual background answering the FIR; roots in the community and readiness to cooperate; an undertaking to abide by conditions; and annexures including the FIR, prior orders, and identity and address proof. The application is supported by affidavit. **Can anticipatory bail be granted in SC/ST Act cases?** Section 18 of the Scheduled Castes and Scheduled Tribes (Prevention of Atrocities) Act, 1989 bars anticipatory bail where the complaint prima facie discloses an offence under the Act. The remedy is to seek quashing under Section 528 BNSS or to surrender and seek regular bail, depending on the allegations. **What conditions does the court usually impose?** Availability for interrogation when required; no inducement or threat to witnesses; no leaving India without permission; and any Section 480(3) conditions such as appearance before the court, no similar offence while on bail, and no witness interference. Conditions bind from the date of the order. **How long does anticipatory bail take in Kerala?** Interim protection from arrest is frequently considered at the first hearing where urgency and a prima facie case for protection are shown. Final disposal typically follows within weeks to a few months depending on roster and whether the prosecution seeks custodial interrogation. Timelines here are practice ranges, not promises. **What if anticipatory bail is rejected?** Options include surrendering and seeking regular bail under Section 480 BNSS, approaching the higher forum on fresh or strengthened grounds, or challenging the underlying proceedings by quash petition under Section 528 BNSS where recognised grounds exist. Evading process after rejection worsens every subsequent remedy. --- ## DPDP Compliance Guide for Kerala Businesses to May 2027 URL: https://advaslam.com/writing/dpdp-compliance-guide-kerala-businesses/ Author: Adv. K J Muhammed Aslam, Advocate (Bar Council of Kerala, K/001823/2026) Published 25 September 2026 Practice area: Data protection & DPDP compliance DPDP readiness for Kerala SMEs: phased timeline to May 2027, notices, safeguards, breach response, rights, children, SDF, transfer, contracts, penalties. Every Kerala business processing customer data faces the same May 2027 horizon: notices, consent, safeguards, breach response, rights handling, retention, vendor contracts, and possibly children-data and SDF duties — with penalties to 250 crore rupees per instance. This hub orders the fifteen-guide DPDP series into a build sequence with the phased timeline. It is general information, not legal advice. ## What is the phased timeline — what bites when? | Phase | Date | Content | |---|---|---| | Board constitution | 14 November 2025 | Rules 1–2 and 17–21 in force from Gazette notification; inquiry machinery stands up | | Consent Managers | ≈13 November 2026 (displayed as 14 November 2026 on this site) | Rule 4 registration; architecture must interoperate | | Substantive duties + penalties | ≈13 May 2027 (displayed as 14 May 2027 on this site) | Rules 3, 5–16, 22–23; obligations and Schedule penalties enforceable | *Timing note: G.S.R. 846(E) is dated 13 November 2025 and was notified on 14 November 2025 (PIB); 12- and 18-month periods computed from the 13 November 2025 date give ≈13 November 2026 and ≈13 May 2027 — displayed on this site as 14 November 2026 and 14 May 2027.* ## What is the build sequence — which guide when? Foundations: the [countdown and 9-month plan](https://advaslam.com/writing/dpdp-act-deadline-businesses/) with consent-notice drafting and safeguards plus retention. Operations: breach playbook with the [CERT-In clock comparison](https://advaslam.com/writing/cert-in-6-hour-vs-dpdp-72-hour-breach-reporting/), principal rights workflow, processor contracts and DPIA, and employee and CCTV discipline. Special tracks: [children's data](https://advaslam.com/writing/dpdp-children-data-parental-consent-guide/), [Significant Data Fiduciaries](https://advaslam.com/writing/dpdp-significant-data-fiduciary-sdf-obligations/), [cross-border transfers](https://advaslam.com/writing/dpdp-cross-border-data-transfer-section-16/), Consent Managers. Enforcement: penalties, Board inquiry, and TDSAT appeal with the [victim-rights mirror](https://advaslam.com/writing/data-breach-victim-rights-dpdp-compensation/). ## How do penalties and enforcement work — and what mitigates? Schedule ceilings to 250 crore rupees per instance with Section 33 seven-factor grading, Board digital inquiry with voluntary-undertakings tracks, and TDSAT appeal beyond — the enforcement companion maps limitation, stay, and the mitigation file to build now rather than during inquiry. ## What comes after May 2027 — continuous compliance? Compliance does not end at enforcement: periodic audits, DPIA refresh on new processing, retention-schedule execution with 48-hour notices, vendor re-assessments, rights-request metrics, and breach-drill cycles convert the May 2027 programme into steady-state governance with Board-ready evidence every quarter. ## Primary sources - [Digital Personal Data Protection Act, 2023 — India Code](https://indiacode.gov.in/handle/123456789/496508) - [DPDP Rules, 2025 (G.S.R. 846(E), 13 November 2025) — MeitY](https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf) - [PIB press release on notification of the DPDP Rules, 14 November 2025 (PRID 2190014)](https://www.pib.gov.in/PressReleasePage.aspx?PRID=2190014) and [PIB backgrounder, 17 November 2025 (PRID 2190655)](https://www.pib.gov.in/PressReleasePage.aspx?PRID=2190655) - Gazette notifications — [G.S.R. 843(E)](https://egazette.gov.in/WriteReadData/2025/267647.pdf) and [G.S.R. 846(E)](https://egazette.gov.in/WriteReadData/2025/267650.pdf) — e-Gazette *General information — not legal advice. Office at High Court Junction, Ernakulam; practice before the High Court of Kerala.* ### Frequently asked questions **When do DPDP obligations actually bite?** Board Rules from November 2025, Consent Manager registration around November 2026, and substantive duties with penalties around May 2027 under GSR 843(E)/846(E) phasing. Build across 2026; enforcement-grade operation by early 2027. **Does DPDP apply to my small business?** Yes where it processes digital personal data — no small-business carve-out from notice, consent, safeguards, breach, rights, and retention duties. Scale calibrates depth, not applicability. **What is the compliance sequence?** Map data, fix notices and consent, build safeguards and retention, rehearse breach response, stand up rights handling, amend vendor contracts, assess children and SDF exposure, and file the inquiry-ready evidence set — each mapped to a guide below. **What penalties apply?** Schedule ceilings to 250 crore rupees per instance for safeguard failures, 200 for breach-notification and children's violations, with Section 33 factors grading actual quantum. Mitigation files built now discount later penalties. **Do we need a Consent Manager?** Most businesses interoperate rather than register — see the Consent Manager decision guide. Consent architecture must be Manager-compatible before the November 2026 window regardless. **Where do we start this quarter?** Data mapping with the safeguards checklist and consent-notice drafting in parallel — the two foundations every later workstream consumes. --- ## How to Quash FIR in Kerala High Court: Crl.MC Sec 528 Guide URL: https://advaslam.com/writing/quash-fir-kerala-high-court-crlmc-528-bnss/ Author: Adv. K J Muhammed Aslam, Advocate (Bar Council of Kerala, K/001823/2026) Published 21 September 2026 Practice area: Criminal law: bail, quash & appeals Quash FIR or criminal case in Kerala High Court under Sec 528 BNSS: recognised grounds, paperbook, interim stay, settlement route, fees and timelines. A First Information Report that should never have become a criminal case can still be ended without trial — through a Criminal Miscellaneous Case (Crl.MC) before the High Court of Kerala invoking inherent power under Section 528 of the Bharatiya Nagarik Suraksha Sanhita, 2023. The power is exercised sparingly, on affidavits, and only on recognised grounds. This guide explains those grounds, the paperbook that carries them, the interim protection to seek at admission, the settlement route, and what follows if quashing is refused. It is general information, not legal advice. ## What does Section 528 BNSS empower the High Court to do? Section 528 BNSS preserves the High Court's inherent power to make orders necessary to give effect to orders under the Sanhita, to prevent abuse of the process of any court, or otherwise to secure the ends of justice. It succeeds Section 482 of the Code of Criminal Procedure, 1973 for proceedings governed by the new law in force from 1 July 2024. Petitions are conventionally laid under Section 528 BNSS read with Article 227 of the Constitution. Three limits follow. The power is exceptional, not an alternative trial: the court does not weigh competing evidence or hear witnesses. It is exercised with caution, guided by the tests in State of Haryana v. Bhajan Lal (1992 Supp (1) SCC 335). And it does not condone suppression — concealment of a material fact, such as a pending parallel proceeding on the same dispute, is itself ground for dismissal with costs. The petition map in [Kerala High Court litigation guide](https://advaslam.com/writing/kerala-high-court-litigation-guide/) places quashing among the five HC tracks. ## Which grounds actually succeed — the Bhajan Lal tests in plain words? | Ground | What it means in practice | |---|---| | No offence on the FIR's face | Even accepting every allegation as true, the ingredients of the cited sections are absent | | Absurd or inherently improbable allegations | The story, read whole, no prudent person could accept as capable of proof | | Civil dispute dressed as criminal | Property, commercial, money, or family dispute recast as cheating, breach of trust, or intimidation to coerce | | Mala fide or abuse of process | Proceedings launched to harass, after suppression of material facts, or in violation of procedure | | Genuine settlement of a private dispute | Parties have resolved the underlying dispute; continuation serves no public purpose (subject to offence gravity) | The most common Kerala filings combine the first and third rows: a commercial or family disagreement registered as a criminal complaint. The petition must show, paragraph by paragraph, why the cited sections fail on the complainant's own version — not merely assert innocence, which is a trial defence. ## Quash vs discharge vs compounding — which exit fits my stage? | Route | Forum | Stage | Effect | |---|---|---|---| | Quash (Section 528 BNSS) | High Court (Crl.MC) | Any stage, usually FIR or charge-sheet stage | Proceedings end; no trial | | Discharge (Sections 250 / 262–263 / 268 BNSS; summons cases via the s.274 proviso) | Trial court at charge-framing | After charge sheet, before charge is framed | Accused discharged without trial; distinct provisions for Sessions, warrant, complaint, and summons tracks (framing under s.269; s.273 is the separate compensation-for-groundless-accusation provision) | | Compounding (Section 359 BNSS) | Trial court (or High Court in settlement-quash form) | Where the offence is compoundable, with or without court permission as scheduled | Composition has the effect of acquittal | [External verification required: confirm the applicable discharge provision for the trial type and the Section 359 compounding table entry for the specific offence against the enacted text before filing. Schedules changed in the CrPC-to-BNSS transition.] Where the offence is compoundable and relations permit, compounding before the trial court is usually faster and cheaper than a High Court quash. Where it is non-compoundable but essentially private — matrimonial, commercial, or neighbourhood disputes now settled — the settlement-quash before the High Court is the recognised route, following Gian Singh v. State of Punjab (2012) 10 SCC 303, Narinder Singh v. State of Punjab (2014), and Parbatbhai Aahir v. State of Gujarat (2017). Heinous offences stand outside this route. ## What paperbook does a Crl.MC need? 1. **Memo of parties** — petitioner-accused against the State (through the Station House Officer and Public Prosecutor) and the de facto complainant as contesting respondent. 2. **Chronological facts** — relationship background, the complaint's summary, Crime number, sections invoked, investigation status, and whether a final report has been filed and as which calendar or committal case. 3. **Grounds** — mapped to the table above, each tied to annexures, not bare assertions. 4. **Annexures** — FIR, subsequent reports, charge sheet or final report where filed, the underlying civil or commercial documents showing the true nature of the dispute, and, in settlement cases, the settlement agreement plus the complainant's sworn affidavit of no objection. 5. **Verification and affidavit** — petition verified paragraph-wise; supporting affidavit sworn before an authorised attestor; disclosure that no other petition for the same relief is pending. 6. **Prayers** — quash the proceedings in the specified crime or calendar case with number, police station, court, and sections; interim prayer for stay of investigation or trial pending disposal; any bail-pending-disposal prayer where custody or arrest risk exists. E-filing runs through the Kerala High Court's e-filing system; interlocutory applications within the Crl.MC take the Crl.MA number series. [External verification required: current e-filing portal fields, court-fee amount, and defect-cure periods under the Kerala High Court Rules.] ## Should I ask for interim stay — and bail alongside? Yes, routinely, but as a prayer, never an assumption. At admission the court may dismiss at threshold, order notice, grant interim stay of investigation or further proceedings, or dispose with directions. Where the petitioner is in custody or apprehends arrest, the Crl.MC includes or is accompanied by a bail prayer pending disposal. Bail itself follows the tracks in the litigation guide — regular bail under Sections 478 or 480 BNSS and anticipatory protection under Section 482 BNSS — and a Section 35 or 94 BNSS notice from a cyber cell is answered on its own track first: [what a Section 35 or 94 notice means](https://advaslam.com/writing/cyber-cell-notice-section-35-vs-94-bnss/). Offence and investigation provisions for IT-act cases are summarised in [IT Act offences explained](https://advaslam.com/writing/it-act-offences-explained/). ## What does settlement-based quashing require in practice? Settlement alone does not compel quashing; the court examines genuineness, voluntariness, the nature of the offence, and public interest. Practice points from the Kerala template notes: - File the complainant's sworn affidavit confirming settlement and no objection; produce the complainant for identification where the court directs. - Annex the written settlement terms, not an oral understanding. - A costs condition payable to the Kerala State Legal Services Authority is often imposed in settlement cases at the Bench's discretion; the figure is fixed by the court. - Matrimonial settlements follow the Gian Singh–Narinder Singh–Parbatbhai line; commercial settlements additionally show the underlying transaction documents. ## What if quashing is refused? The refusal decides only that the case is not fit for exceptional interference — not guilt. The matter returns to the trial court, where discharge at framing, compounding where available, or a contested trial on evidence follows. A second quash on the same grounds without fresh material is not a strategy. Related High Court tracks — when a writ rather than a quash is the vehicle, and when an appeal rather than either — are mapped in [when Article 226 is the right remedy](https://advaslam.com/writing/writ-petition-high-court-kerala/) and the [litigation guide](https://advaslam.com/writing/kerala-high-court-litigation-guide/). A legal notice already received in the underlying civil dispute is answered separately: [how to respond to a legal notice](https://advaslam.com/writing/how-to-respond-legal-notice/). ## Primary sources - [Bharatiya Nagarik Suraksha Sanhita, 2023 — Section 528 (inherent power); Sections 250, 262–263, 268 (discharge), 269 (framing), 274 (summons-case release); Section 273 (compensation for groundless accusation); Section 359 (compounding); Sections 478–482 (bail)](https://indiacode.gov.in/handle/123456789/496550) (India Code; confirm proviso and schedule numbering against the Gazette) - [State of Haryana v. Bhajan Lal, 1992 Supp (1) SCC 335](https://indiankanoon.org/doc/1033637/) — quashing tests - [Gian Singh v. State of Punjab, (2012) 10 SCC 303](https://indiankanoon.org/doc/69949024/); [Narinder Singh v. State of Punjab, (2014) 6 SCC 466](https://indiankanoon.org/doc/160278245/); [Parbatbhai Aahir v. State of Gujarat, (2017) 9 SCC 641](https://indiankanoon.org/doc/7293093/) — settlement quashing scope and limits - [Constitution of India — Article 227](https://legislative.gov.in/constitution-of-india/) (Legislative Department) - [Kerala High Court — official website](https://highcourt.kerala.gov.in/) - [Kerala courts e-filing and case services](https://ecourt.keralacourts.in/) *General information — not legal advice. Office at High Court Junction, Ernakulam; practice before the High Court of Kerala.* ### Frequently asked questions **Which provision is used to quash an FIR in Kerala now — 482 CrPC or 528 BNSS?** For cases governed by the new procedure, Section 528 of the Bharatiya Nagarik Suraksha Sanhita, 2023 (in force from 1 July 2024) carries the inherent power formerly in Section 482 CrPC. Petitions filed after that date invoke Section 528 BNSS, often read with Article 227 of the Constitution. Pending cases under the old procedure retain CrPC references. **What are the strongest grounds for quashing in the Kerala High Court?** The FIR, taken at face value, discloses no offence; its allegations are absurd or inherently improbable; the dispute is purely civil dressed as criminal; the proceeding is mala fide or an abuse of process; or the parties have genuinely settled a private dispute. These track the Bhajan Lal tests the courts apply. **Is there a time limit for filing a quash petition?** No statute fixes limitation for Section 528 BNSS, but delay weakens the petition and can invite dismissal on laches. Filing promptly after the FIR or charge sheet, rather than mid-trial, is the safer course. **Can a criminal case be quashed after the parties settle, even for non-compoundable offences?** In appropriate private disputes the High Court can quash on settlement even where the offence is non-compoundable, following Gian Singh v. State of Punjab (2012). Heinous offences such as murder or rape cannot be quashed on settlement alone. A sworn affidavit of the de facto complainant confirming settlement is ordinarily required. **What happens if the quash petition fails?** The case returns to the trial court. Depending on stage, the accused may seek discharge at charge-framing (Sections 250, 262–263, or 268 BNSS), compounding under Section 359 BNSS where the offence qualifies, or contest the trial. An adverse quash order does not decide guilt. **Will I have to pay costs if the case is quashed on settlement?** The Kerala High Court often imposes costs payable to the Kerala State Legal Services Authority as a condition of settlement-based quashing, at the Bench's discretion. Prepare for this possibility; the amount is fixed by the court in each case. --- ## Kerala High Court Litigation Guide: Writs, Bail, Quash, Appeals URL: https://advaslam.com/writing/kerala-high-court-litigation-guide/ Author: Adv. K J Muhammed Aslam, Advocate (Bar Council of Kerala, K/001823/2026) Published 19 September 2026 Practice area: High Court writs & procedure Which Kerala High Court remedy fits your case — writ, bail, quash, appeal or revision — with sections, forums, and limitation periods explained. A legal problem that belongs in the High Court of Kerala usually presents as one of five questions: has a public authority acted illegally or refused to act, is someone in custody or fearing arrest, should a criminal case be ended without trial, or has a judgment already been passed that needs challenge. Each question maps to a different remedy — writ petition, bail application, quash petition, appeal, or revision — with its own provision, forum, paperbook, and limitation period. This guide maps the whole terrain so the reader reaches the correct detailed guide. It is general information, not legal advice. ## Which High Court remedy fits my problem? | Your situation | Likely remedy | Core provision | |---|---|---| | Government body or statutory authority acted illegally, refused to act, or denied a hearing | Writ petition | Article 226 of the Constitution | | Order of a subordinate court or tribunal suffers jurisdictional error or perversity | Supervisory petition | Article 227 of the Constitution | | Person arrested and in custody | Regular bail | Sections 478 (bailable) or 480 (non-bailable) BNSS | | Person apprehending arrest | Anticipatory bail | Section 482 BNSS | | FIR or criminal proceedings should end without trial | Quash petition (Crl.MC) | Section 528 BNSS | | Judgment or order already passed and adverse | Appeal, writ appeal, or revision | Section 5, Kerala High Court Act (writ appeals); Sections 413–435 BNSS (appeals), 438–442 (revision); Order XLI–XLIV CPC (civil) | | Authority disobeys a court order | Contempt petition | Contempt of Courts Act, 1971 | Choosing wrongly costs months. A writ filed where a statutory appeal exists will usually be returned to that appeal, subject to the recognised exceptions. A criminal revision filed where an appeal lies faces the same fate. The sections below summarise each route; linked guides carry the full procedure. ## When is a writ petition under Article 226 the right remedy? Article 226 empowers every High Court to issue directions, orders, or writs — habeas corpus, mandamus, prohibition, quo warranto, certiorari — for the enforcement of fundamental rights and "for any other purpose," meaning ordinary legal rights as well. The jurisdiction is discretionary: the court weighs alternative remedies, delay, and conduct. The five writs and their Kerala uses are explained in [when Article 226 is the right remedy](https://advaslam.com/writing/writ-petition-high-court-kerala/), with writ-specific guides for [mandamus](https://advaslam.com/writing/writ-mandamus-kerala-high-court/), [certiorari](https://advaslam.com/writing/writ-certiorari-kerala-high-court/), [habeas corpus](https://advaslam.com/writing/writ-habeas-corpus-kerala-high-court/), [prohibition](https://advaslam.com/writing/writ-prohibition-kerala-high-court/), and [quo warranto](https://advaslam.com/writing/writ-quo-warranto-kerala-high-court/). A bank account frozen at a cyber cell's instance, challenged where the freeze operates in Kerala, is a recurring example even against an out-of-state freezing authority, under Article 226(2) — see [what to do when a cyber cell freezes your bank account](https://advaslam.com/writing/bank-account-frozen-cyber-cell-kerala/). A writ is usually the wrong remedy where a statutory appeal exists (subject to the exceptions for natural-justice violations, total lack of jurisdiction, challenge to vires, or fundamental-right infringement), where facts are seriously disputed (writs run on affidavits, with no cross-examination), or where the dispute is purely private. The SARFAESI context illustrates the appeal-first rule and its exceptions: [can you go to the High Court or must you go to DRT](https://advaslam.com/writing/sarfesi-notice-article226-vs-drt-remedy/). ## When should I use Article 227 instead of Article 226? Article 227 is the High Court's power of superintendence over subordinate courts and tribunals. It is a supervisory jurisdiction, not a writ. Following Radhey Shyam v. Chhabi Nath (2015) 5 SCC 423, orders of civil courts are challenged under Article 227 rather than as writs of certiorari under Article 226. In practice, Article 227 is considered where a family court, MACT, rent control court, or consumer forum is said to have acted perversely, exceeded jurisdiction, or committed patent illegality — and where no equally efficacious statutory appeal or revision is available. Petitions that merely re-argue facts fail; the error must go to jurisdiction or legality. ## What are the bail routes: regular, anticipatory, default, and pending appeal? Bail practice before Kerala courts runs under Chapter XXXV of the Bharatiya Nagarik Suraksha Sanhita, 2023 (Sections 478–496), in force from 1 July 2024, read with Article 21. - **Bailable offences (Section 478 BNSS):** release is effectively a right where the person is prepared to give bail; an indigent person unable to furnish surety within a week of arrest may be released on personal bond. - **Non-bailable offences (Section 480 BNSS):** discretionary, weighing the nature of the offence, the evidence, the risk of absconding or tampering, and the need for custody. - **Anticipatory bail (Section 482 BNSS):** protection from arrest, sought from Sessions Court or High Court before arrest, with conditions; certain grave offences carry statutory exclusions and informant-notice requirements. - **Default bail (Section 187(3) BNSS):** an indefeasible right to release where the investigation report under Section 193 BNSS (charge-sheet) is not filed within 60 or 90 days, depending on offence gravity. - **Undertrial release (Section 479 BNSS):** mandatory release thresholds at half (or for first-time offenders, one-third) of the maximum imprisonment, excluding death and life-imprisonment cases. - **Bail pending appeal (Section 430 BNSS):** suspension of sentence with release during appeal. Cyber-offence bail additionally engages the Information Technology Act's offence and investigation provisions summarised in [IT Act offences explained](https://advaslam.com/writing/it-act-offences-explained/), and a Section 35 or 94 BNSS notice from a cyber cell should be answered on its own track first: [what a Section 35 or 94 notice means](https://advaslam.com/writing/cyber-cell-notice-section-35-vs-94-bnss/). ## How does quashing an FIR or criminal case work (Crl.MC, Section 528 BNSS)? A Criminal Miscellaneous Case under Section 528 BNSS (successor to Section 482 CrPC) asks the High Court to exercise inherent power to prevent abuse of process or secure the ends of justice — typically to quash an FIR, a charge sheet, or the proceedings in a complaint case. Grounds the court recognises include the absence of a prima facie case on the FIR's own allegations, a civil or commercial dispute dressed as a criminal complaint, a genuine settlement in compoundable or appropriately settleable matters, and proceedings that are otherwise an abuse of process. The paperbook ordinarily contains the FIR, subsequent reports, the charge sheet where issued, and any settlement or joint memo. Interim stay of investigation or trial is sought at admission but never assumed. Quashing is distinct from discharge at charge-framing (Sections 250, 262–263, or 268 BNSS depending on trial type; framing under Section 269) and from compounding under Section 359 BNSS. Where the parties have settled, the choice between compounding before the trial court and quashing before the High Court turns on whether the offence is compoundable and at what stage the case stands. ## I lost — what are the appeal and revision routes and their time limits? | From | To | Basis and limit | |---|---|---| | Single Judge writ judgment | Division Bench (writ appeal) | Section 5, Kerala High Court Act, 1958; 30 days (Article 117, Limitation Act) | | Division Bench or other HC judgment | Supreme Court | Special Leave Petition, Article 136; 90 days (60 days where the High Court refused leave to appeal or a death sentence is involved — Article 133, Limitation Act) | | Magistrate conviction | Sessions Court | Criminal appeal; 30 days in the ordinary course | | Sessions conviction | High Court | Criminal appeal; 60 days in the ordinary course | | Acquittal (State or victim challenge) | Higher court | Article 114, Limitation Act: 90 days (State) / 30 days from grant of special leave (complainant); Section 419(5) BNSS leave-application windows: 6 months (public servant) / 60 days (other) | | Civil decree | First appeal | Section 96 CPC with Order XLI; 30 days (District) or 90 days (High Court) | | Interlocutory or no-appeal orders | Revision | Sections 438–442 BNSS (criminal) or Section 115 CPC (civil), subject to bars | Delay condonation requires sufficient cause specifically pleaded and proved; limitation tables and the acknowledgment-reset rules are reference material for the filing advocate, not DIY computation. Consumer, MACT, and tribunal appeals each carry their own forum-specific limits and deposit conditions, addressed in their subject guides. ## What if the other side may get an ex-parte order, or disobeys one? Two protective procedures flank the main remedies. A **caveat** under Section 148A CPC secures a right of pre-decision hearing: a person apprehending an ex-parte interim order lodges a caveat, valid for 90 days, so the court hears them before granting interim relief. It grants no stay itself. **Contempt** under the Contempt of Courts Act, 1971 addresses wilful disobedience of a court order or undertaking — civil contempt for disobedience, criminal contempt for scandalising or obstructing justice — subject to a one-year limitation and the court's assessment of apology, purge, and undertaking. ## How is a High Court case actually filed and heard at Ernakulam? The High Court of Kerala sits at Ernakulam. Filings move through the Registry substantially through the e-filing system, with pleadings as signed PDFs, exhibits marked (P1, P2 in writs; Annexures A1, A2 in criminal miscellaneous cases), and supporting affidavits sworn before an authorised attestor. The Registry scrutinises and either numbers the matter or returns defects — pagination, attestation, court-fee shortfall — for cure within the allowed time. Listing follows the roster: admission hearing (dismiss, admit with notice, or dispose with directions), interim-orders stage (with the Article 226(3) two-week vacate safeguard for ex-parte interim orders), counter and reply affidavits, then final hearing on the papers. Effective relief frequently arrives at the interim stage — a stay, a direction to decide a representation within weeks, protection from arrest — long before final judgment. [External verification required: court-fee amounts, e-filing defect-cure periods, and roster practice change by notification. Confirm current Kerala High Court Rules and fee schedule before filing.] ## Where do related subject guides fit? - Bank-freeze and seizure challenges: [Complete Kerala Guide](https://advaslam.com/writing/bank-account-frozen-cyber-cell-kerala/) and [bank suo-motu SOP](https://advaslam.com/writing/bank-freeze-without-police-rbi-kerala-hc-sop/). - UPI and online-fraud recovery: [From Complaint to Recovery](https://advaslam.com/writing/upi-fraud-complaint-recovery/) and [no action after complaint — escalation](https://advaslam.com/writing/cyber-complaint-filed-no-action-escalation/). - Digital-evidence proof: [Section 63 BSA certificate](https://advaslam.com/writing/electronic-evidence-bsa-section-63-certificate-guide/). - Notices and replies: [Received a legal notice](https://advaslam.com/writing/how-to-respond-legal-notice/). ## Primary sources - [Constitution of India — Articles 226, 227, 136](https://legislative.gov.in/constitution-of-india/) (Legislative Department) - [Bharatiya Nagarik Suraksha Sanhita, 2023 — Chapters on bail, quash, appeal and revision](https://indiacode.gov.in/handle/123456789/496550) (India Code; confirm proviso numbering against Gazette) - [Kerala High Court Act, 1958 — Section 5 (writ appeals)](https://indiacode.gov.in/handle/123456789/565294) (India Code) - [Limitation Act, 1963 — Articles 114–117](https://indiacode.gov.in/handle/123456789/496389) (India Code) - [Contempt of Courts Act, 1971](https://indiacode.gov.in/handle/123456789/496468) (India Code) - [Kerala High Court — official website](https://highcourt.kerala.gov.in/) - [Kerala courts e-filing and case services](https://ecourt.keralacourts.in/) *General information — not legal advice. Office at High Court Junction, Ernakulam; practice before the High Court of Kerala.* ### Frequently asked questions **I have a problem — how do I know whether I need a writ, bail, quash, or appeal?** Identify the respondent and the stage. Against a public authority on legality grounds, consider a writ under Article 226. After arrest, regular bail under Sections 478 or 480 BNSS. Before arrest, anticipatory bail under Section 482 BNSS. To end an FIR or criminal case without trial, a quash petition under Section 528 BNSS. Against a judgment already passed, an appeal or revision within its limitation period. **Where is the Kerala High Court and how are cases filed there?** The High Court of Kerala sits at Ernakulam. Writ petitions, bail applications, quash petitions, and appeals are filed through the Registry, substantially through the e-filing system, with pleadings as signed PDFs and exhibits marked and affirmed by affidavit. The Registry scrutinises filings and returns defects for cure before numbering. **How long does a High Court matter take in Kerala?** It depends on the relief. Habeas corpus moves in days. Interim protection in writs and bail matters can come at admission within days or weeks. Contested writs and appeals typically take many months to over a year to final hearing. Timelines on this site are ranges from practice, not promises. **What is the time limit for a writ appeal in Kerala?** A writ appeal to a Division Bench under Section 5 of the Kerala High Court Act, 1958 is governed by a 30-day limitation period under Article 117 of the Limitation Act, 1963. Delay can be condoned only on sufficient cause shown, which the court examines strictly. **Can the Kerala High Court hear my case if the authority is in another state?** Yes, if the cause of action arose wholly or partly in Kerala. Article 226(2) permits the High Court to act where part of the cause of action arises within its territory, even if the authority is seated outside it. Residence in Kerala alone, without any part of the cause of action here, is not enough. **Do I need to send a representation before approaching the High Court?** Often yes as a practical matter. Mandamus petitions ordinarily show a demand and a refusal or continued inaction, through a written representation with acknowledgment. Bail and quash petitions similarly benefit from complete paperbooks. The court decides on affidavits, so a fact omitted from the papers effectively does not exist. --- ## Certiorari in the High Court of Kerala: How to Quash an Illegal Order of a Tribunal or Authority URL: https://advaslam.com/writing/writ-certiorari-kerala-high-court/ Author: Adv. K J Muhammed Aslam, Advocate (Bar Council of Kerala, K/001823/2026) Published 8 September 2026 Practice area: High Court writs & procedure Tribunal, DRT or tax order without jurisdiction or natural justice? When certiorari under Article 226 lies in Kerala: Hari Vishnu Kamath tests, 226 vs 227. Certiorari under **Article 226** before the **High Court of Kerala** is the writ that calls for the record and quashes an order of an inferior court, tribunal or quasi-judicial authority where the order was made **without jurisdiction, in excess of jurisdiction, in violation of natural justice, or with a manifest error apparent on the face of the record**. This guide sets out the **Hari Vishnu Kamath four propositions** that still govern the writ, how the High Court distinguishes **Article 226 (original)** from **Article 227 (supervisory)**, and why certiorari is not an appeal in disguise. ## What certiorari examines — and what it does not The 7-judge Bench in ***Hari Vishnu Kamath v. Syed Ahmad Ishaque, (1955) 1 SCR 1104***, summarised by the Constitution Bench in ***Custodian of Evacuee Property, Bangalore v. Khan Saheb Abdul Shukoor, (1961) 3 SCR 855*** and restated in ***Surya Dev Rai v. Ram Chander Rai, (2003) 6 SCC 675***, governs: | Proposition | Certiorari lies where | |---|---| | **1. Errors of jurisdiction** | The tribunal acted **without jurisdiction** or **in excess** of it, or **failed to exercise** a jurisdiction vested in it — want may arise from subject-matter, absence of preliminary proceedings, or illegal constitution | | **2. Illegality in exercise of undoubted jurisdiction** | The tribunal violated **principles of natural justice** or acted in **flagrant disregard of procedure** — e.g., decides without hearing, refuses to hear a party, or ignores mandatory statutory mode | | **3. Supervisory, not appellate** | The High Court **will not review findings of fact** even if erroneous; a court with jurisdiction to decide rightly also has jurisdiction to decide wrongly, and certiorari is not an appeal where the statute provides none | | **4. Manifest error apparent on the face of the proceedings** | The **decision itself discloses a patent legal error** — e.g., based on clear ignorance or disregard of the governing Act/Rules — but **not a mere wrong decision** that needs elaborate reasoning to establish | The record the High Court examines is the **record before the tribunal**. For a tribunal's speaking order, the reasons on the face of the order are the record; for other authorities, the **T.C. Basappa v. T. Nagappa, (1955) 1 SCR 250** definition of patent error applies. ## Who is amenable to certiorari in Kerala? Any **authority or body of persons constituted by law or having legal authority to adjudicate upon rights and enjoined to act judicially or quasi-judicially** — **tribunals and statutory authorities**, not purely administrative acts: * **Amenable:** DRT/DRAT (SARFAESI/RDDBFI), **Kerala Administrative Tribunal** (confirm current constitution/status before filing), Co-operative Arbitration Court, **Revenue Divisional Officer / Land Tribunal**, **GST / Income-tax appellate authorities**, **Consumer fora** (as tribunals), **Labour Court / Industrial Tribunal**, **University tribunals**, **Local Self Government Tribunal**. * **Not amenable by certiorari under 226:** **Civil courts' judicial orders** — after ***Radhey Shyam v. Chhabi Nath, (2015) 5 SCC 423*** (3-judge Bench), civil court orders are amenable to **Article 227** superintendence, not Article 226 certiorari; a petition labelling a civil court order as a 226 certiorari will be treated as 227. The private-body test from *Praga Tools* and *Andi Mukta* still applies: a private person not entrusted with adjudicatory public power is not amenable. ## Certiorari vs appeal vs revision vs Article 227 | Remedy | Nature | What the High Court does | |---|---|---| | **Appeal where statute provides one** (e.g., Sec 18 SARFAESI DRAT, Sec 107 CGST, Sec 509 Municipality 30+30d) | Statutory rehearing on facts and law | Alternative remedy — writ declined unless *CIT v. Chhabil Dass Agarwal (2013) 357 ITR 357 (SC)* exception | | **Revision under CPC Sec 115** (amended 1999 w.e.f. 01.07.2002) | Narrowed to jurisdictional error in civil court orders | Where revision is barred, **Art 227** (not 226 certiorari) is the residual supervisory remedy for civil courts | | **Certiorari under Art 226** | **Original jurisdiction** — calls for record, examines legality | **Quashes**; does not substitute own findings; may remit; no appeal to Division Bench where 227 only | | **Supervisory under Art 227** | **Supervisory, not original** — sparingly, to keep courts/tribunals within bounds | May **quash and issue further directions**; suo motu possible; **no writ appeal under Section 5 of the Kerala High Court Act, 1958** against a pure 227 order (226 original vs 227 supervisory distinction per *Umaji Keshao Meshram v. Radhikabai, (1986) Supp SCC 401*; civil court orders to Art 227 per *Radhey Shyam*, paras 24–25) | Practical consequence for filing in Kerala: **label the petition as under Articles 226 and 227** where the order is from a tribunal (*Surya Dev Rai* custom deprecated but still prevalent), so the court can classify. If the Single Judge decides mainly under **226**, a **writ appeal under Section 5 of the Kerala High Court Act, 1958** to the Division Bench lies; if purely under **227**, it does not. ## Where certiorari succeeds — and where it is refused **Succeeds** where the record shows: * The **DRT/authority acted without jurisdiction** — e.g., SARFAESI Sec 13(4) measure on a non-secured asset, or a **revenue officer** passing a Paddy Land Act order without the **LLMC → DLAC** chain under Sec 9(8). * **Violation of natural justice** — no notice, no hearing, or hearing by a person other than the statutory authority; **occupancy certificate refused** where the statutory hearing under **Rule 20(3) Kerala Municipality Building Rules, 2019** was not given. * **Patent error** — tribunal applied the **repealed** 1999 Building Rules where the 2019 Rules governed, or computed limitation from the wrong trigger date. **Refused** where: * The error is merely **wrong appreciation of evidence** — two views possible on a factual finding is not patent. * **Failure of justice not shown** — certiorari is discretionary; the High Court may refuse even where a technical error exists if no prejudice is made out. * The petitioner suppressed material facts, approached with delay and laches, or seeks rehearing on facts that an appeal would have covered. ## What documents move a certiorari petition Bring: the **impugned order** with its **reasoning**, the **record before the tribunal** (pleadings, evidence, statutory notices with service proof), the **Act/Rules extract** the tribunal allegedly disregarded, and — for building/revenue writs — the **IDO / Master Plan / LLMC report** the order should have considered. Label exhibits to mirror the tribunal's record so the patent error is self-evident. ## Primary sources * [Constitution — Articles 226, 227](https://indiacode.gov.in/document-grid/d5475e8d-1998-4ac8-8694-82f941074bb7) * *Hari Vishnu Kamath v. Syed Ahmad Ishaque*, (1955) 1 SCR 1104 (7-judge Bench); *Custodian of Evacuee Property, Bangalore v. Khan Saheb Abdul Shukoor*, (1961) 3 SCR 855 * *T.C. Basappa v. T. Nagappa*, (1955) 1 SCR 250; *Satyanarayan Laxminarayan Hegde v. Mallikarjun*, (1960) 1 SCR 890 * *Surya Dev Rai v. Ram Chander Rai*, (2003) 6 SCC 675; *Radhey Shyam v. Chhabi Nath*, (2015) 5 SCC 423 * *Umaji Keshao Meshram v. Radhikabai*, (1986) Supp SCC 401 — 226 (original) vs 227 (supervisory) distinction ### Frequently asked questions **When does certiorari lie under Article 226?** Where an inferior court, tribunal or quasi-judicial authority acted without jurisdiction, in excess of jurisdiction, or in violation of principles of natural justice, or where the error is manifest and apparent on the face of the proceedings — e.g., clear disregard of the governing Act or Rules. The writ examines legality, not merits; it quashes, it does not rehear evidence. **What are the four Hari Vishnu Kamath tests for certiorari?** From Hari Vishnu Kamath v. Ahmad Ishaque (1955) 1 SCR 1104 (7-judge Bench), as summarised in Custodian of Evacuee Property v. Khan Saheb Abdul Shukoor (1961) 3 SCR 855 and restated in Surya Dev Rai v. Ram Chander Rai (2003) 6 SCC 675: (1) correcting errors of jurisdiction; (2) where the court acts illegally in exercise of undoubted jurisdiction (e.g., denial of hearing, natural justice); (3) the High Court acts in supervisory, not appellate jurisdiction and will not re-appreciate facts; (4) a manifest error apparent on the face of the record, based on clear ignorance or disregard of law, not a mere wrong decision. **Is certiorari available against a civil court order?** After Radhey Shyam v. Chhabi Nath (2015) 5 SCC 423 (3-judge Bench) correcting Surya Dev Rai on this point, judicial orders of civil courts are amenable to Article 227 supervisory jurisdiction, not Article 226 certiorari. Orders of tribunals and authorities (DRT, KAT, Co-operative Tribunal, Revenue Tribunal, Tax Tribunal) remain amenable to Article 226 certiorari where the Hari Vishnu Kamath tests are met. File under both Articles 226 and 227 where appropriate and let maintainability follow jurisdiction classification. **What is 'error apparent on the face of the record'?** An error that is self-evident on the record without needing lengthy, contested reasoning on points where two views are possible — e.g., the tribunal applied a repealed provision, ignored a mandatory statutory provision, or recorded patent contradictoriness. An error that needs elaborate argument or re-appreciation of evidence is not patent (Satyanarayan Laxminarayan Hegde v. Mallikarjun, (1960) 1 SCR 890). **Can the High Court substitute its own findings in certiorari?** No. The High Court quashes and may remit. It does not substitute its own findings for those of the tribunal. Under Article 227, however, the High Court may both quash and issue further directions as the facts warrant — the distinction Hari Vishnu Kamath drew between annulment under 226 and broader directions under 227. --- ## Habeas Corpus in the High Court of Kerala: When Illegal Detention Can Be Challenged Under Article 226 URL: https://advaslam.com/writing/writ-habeas-corpus-kerala-high-court/ Author: Adv. K J Muhammed Aslam, Advocate (Bar Council of Kerala, K/001823/2026) Published 8 September 2026 Practice area: High Court writs & procedure Illegal detention in Kerala by police, private persons or in child custody? When habeas corpus under Article 226 lies, who can file and what the court checks. Habeas corpus under **Article 226 of the Constitution** before the **High Court of Kerala** is a command to produce a person alleged to be in unlawful custody and to justify the legal foundation for that custody; on production the court enquires whether the detention is in accordance with procedure established by law and, if not, orders release. This guide explains when the writ lies against the State and against private persons, why child-custody habeas is treated as extraordinary, and the **Devu G. Nair 13-point guidelines** that now govern intimate-partner habeas. ## When does habeas corpus lie? Unlike the other four writs, habeas corpus is **not confined to State action**. Under **Article 32** the Supreme Court issues it for violation of a Part III right against the State; under **Article 226** the High Court issues it **for any other purpose as well**, and therefore against **private persons** who illegally detain another. Two elements must coincide: 1. **Detention or confinement** — actual physical restraint on liberty, including police custody beyond remand, confinement in a home, hostel or institution against will, or retention of a person where the holder has no legal authority. 2. **Illegality / without authority of law** — arrest not following the **Bharatiya Nagarik Suraksha Sanhita, 2023 (BNSS)** (e.g., Sections 35–62 arrest procedure — esp. Sec 35 — production before Magistrate within 24 hours under Article 22(2)), custody under an order that is void, or private custody where no guardianship or court order sustains it. The burden is on the **detaining authority or person** to show lawful foundation — not on the detenu to prove illegality (*Icchu Devi Choraria v. Union of India, 1980*). ## How does the Kerala High Court handle habeas — procedure The practice before the High Court of Kerala, Ernakulam, and refined by the Supreme Court's intervention in Kerala habeas matters: 1. **Filing:** Any person with bona fide concern — family, partner, friend, social worker — may file; standing is liberal, and the Supreme Court in *Devu G. Nair* (2024) directed courts not to make a roving enquiry into the relationship when a partner or friend files. 2. **Admission:** The court may order immediate production or, where illegal detention is not yet clear, direct the **District Legal Services Authority** to visit and record a statement — the course the Kerala High Court took on **13 Jan 2023** in the habeas that became *Devu G. Nair*. 3. **Production and in-camera enquiry:** On production the corpus interacts **in person with the judges in chambers**, without the alleged detainer present, with privacy and video-record secured. 4. **Disposal:** Immediate release where free will is to not return to the detainer; no counselling to change mind. The writ is summary — it does not become a regular trial. ## When habeas is used for child custody in Kerala The High Court has repeatedly said custody habeas is **extraordinary**, not a parallel Family Court. * **Maintainable where:** A parent retains a minor **in violation of a custody order** of the Family Court, or with **no authority of law** — even a parent can illegally detain (reported *Sunil Patiram Parteti v. State of Maharashtra*, 2026:BHC-NAG:6720-DB (Bombay HC, Nagpur Bench, 30 Apr 2026); *Somprabha Rana v. State of M.P., 2024*). The court examines illegality first, then may consider welfare. * **Not maintainable where:** The dispute is really about **welfare, preference and competing guardianship claims** that need evidence — who is the better parent, school choice, visiting rights — without a prior finding of illegal detention. The **reported Kerala High Court order 09 Apr 2024 (Division Bench; India Legal report)** dismissed a habeas for a minor boy, holding welfare is paramount and retention by paternal relatives already caring for the child was **not illegal** absent violation of a custody order; remedy is before the Family Court under the **Guardians and Wards Act, 1890** or the **Hindu Minority and Guardianship Act, 1956**. The **Bombay HC 2026** reached the same result where an eight-year-old had lived with maternal relatives since age two and the father waited three years — no illegal detention, habeas not a substitute for custody suit, visitation granted instead. In short: **illegality of custody is the ticket; welfare is what the court does once inside** — and the court will not compel a mature child to live with a parent where that would cause emotional trauma (*Kerala High Court minor-boy order of 09 Apr 2024*). ## The Devu G. Nair binding guidelines — Kerala origin After the Kerala High Court's **13 Jan and 02 Feb 2023** interim orders in a same-sex intimate-partner habeas (DLSA visit while the corpus remained with parents, then a counselling session) were challenged — the Supreme Court issued notice and interim directions on **06 Feb 2023** — the Supreme Court on **11 Mar 2024 in *Devu G. Nair v. State of Kerala and Ors.* (CJI D.Y. Chandrachud)** laid down **13 mandatory minimum guidelines** for all courts dealing with habeas or partner-protection petitions: > (a) priority listing, no adjournment; (b) locus not to be narrowed for partner/friend; (d) corpus produced in person in chambers, private, recorded and secured; (e) detainer not present with corpus during interaction; (g) minority not a threshold to dismiss; (h) empathy, no homophobic/transphobic moral judgment; (i) if the person wishes not to return, **release immediately**; (j) for same-sex / inter-faith / inter-caste partners, grant **ad-interim police protection before** grave-risk threshold; (k) **no counselling or parental-care directions** to change mind; plus age ascertainment, privacy of sexual orientation/gender identity, and swift action against queerphobic conduct. The Supreme Court set aside the Kerala High Court's counselling direction and directed disposal on the judicial officer's ascertainment of voluntary residence. The guidelines are now the **mandatory minimum** in letter and spirit. ## What habeas is not * An **appeal against a valid remand** where the Magistrate had jurisdiction — remedy is bail under BNSS, not habeas. * A shortcut where **Sections 97–98 CrPC / Sections 100–101 BNSS search for wrongfully confined persons** before the Magistrate is the more direct and equally efficacious route for a missing person where FIR is more appropriate. * A forum for **disputed facts on title or building compliance** disguised as custody — the same boundary the Court drew in the writ-for-retaining-wall case (*Ida Sarojam v. State of Kerala*, 2026:KER:14483 (Ker HC, 25 Feb 2026) — writ cannot decide disputed facts). ## What documents move a habeas petition Bring: the detenue's identity proof, the relationship proof, the custody or restraint order complained of (Family Court, Magistrate), the alleged detainer's address, the last production or visitation record, and the **in-camera statement** the court will record. For police detention: arrest memo, grounds of arrest, remand order, CCTV or custody-ledger extract where available. ## Primary sources * [Constitution of India — Articles 21, 22, 32, 226](https://indiacode.gov.in/document-grid/d5475e8d-1998-4ac8-8694-82f941074bb7) * [BNSS, 2023 — Sections 35–62, 100–101](https://indiacode.gov.in/handle/123456789/496550); [BSA, 2023](https://indiacode.gov.in/handle/123456789/496549) * *Devu G. Nair v. State of Kerala and Ors.*, Supreme Court, **11 Mar 2024** (CJI D.Y. Chandrachud) — 13 binding habeas guidelines (SC PDF 11 Mar 2024) * *Icchu Devi Choraria v. Union of India*, (1980) 4 SCC 531 — burden * *Somprabha Rana v. State of M.P.*, 2024 INSC 664 — habeas in child custody is discretionary; even where custody is illegal, the court may decline to disturb it on the child's welfare; reported *Kerala High Court order 09 Apr 2024* (Division Bench; India Legal) — welfare where custody not illegal; *Sunil Patiram Parteti v. State of Maharashtra*, 2026:BHC-NAG:6720-DB (Bombay HC, Nagpur Bench, 30 Apr 2026) — no habeas where 3-year delay, visitation only * [Guardians and Wards Act, 1890 — Sec 7, 25](https://indiacode.gov.in/handle/123456789/496426); [Hindu Minority and Guardianship Act, 1956 — Sec 6](https://indiacode.gov.in/handle/123456789/496394) ### Frequently asked questions **When does habeas corpus lie in the High Court of Kerala?** Where a person is detained or confined without authority of law and the detention is not under a valid court order. Under Article 226 the High Court can issue habeas corpus against the State and, unlike Article 32, also against private persons who illegally detain another. The court examines on production whether the detention has lawful foundation — an arrest without following BNSS procedure, custody beyond remand, or private confinement without legal authority. **Can habeas corpus be used for child custody disputes in Kerala?** Only where the detention is shown to be illegal and without authority of law — for example, a parent retaining a child in violation of a Family Court custody order or without any legal entitlement. Kerala and Bombay High Courts (reported — Kerala HC order 09 Apr 2024; Bombay HC *Sunil Patiram Parteti v. State of Maharashtra*, 2026:BHC-NAG:6720-DB, 30 Apr 2026) treat habeas for minors as extraordinary: welfare is considered, but the threshold is illegal detention; pure custody disputes on welfare that need detailed evidence belong before the Family Court under the Guardians and Wards Act, not a writ. **Who can file habeas corpus?** Not only the detenu. Any person with bona fide concern — family, friend, social worker — may move the court under Article 226. Under Article 32 before the Supreme Court, a Part III right must be shown; under Article 226 before the High Court, the power is for 'any other purpose' as well, so private detention is reachable. The detaining authority bears the burden to justify the detention as per procedure established by law. **What will the court not do in habeas corpus?** Adjudicate disputed facts on title, investigate a purely civil custody welfare claim where detention is not illegal, act as an appeal from a valid remand order, or issue habeas where a statutory remedy (e.g., bail under BNSS) is the appropriate and efficacious course. Habeas is not a substitute for regular custody or criminal process. **What happens on production of the corpus?** The court arranges in-camera interaction, records the person's free will without the alleged detainer present, secures the recording, and disposes swiftly. In intimate-partner matters the Supreme Court in Devu G. Nair v. State of Kerala (Crl. Appeal, 11 Mar 2024, CJI D.Y. Chandrachud) laid down binding 13-point guidelines: priority listing, no adjournment, in-person production, privacy, no side-by-side presence of detainer, no counselling to change mind, and immediate release if the person wishes not to return. --- ## Mandamus in the High Court of Kerala: How to Compel a Public Authority to Act Under Article 226 URL: https://advaslam.com/writing/writ-mandamus-kerala-high-court/ Author: Adv. K J Muhammed Aslam, Advocate (Bar Council of Kerala, K/001823/2026) Published 8 September 2026 Practice area: High Court writs & procedure Panchayat, Municipality, RTO or revenue authority not acting? When mandamus under Article 226 lies in Kerala: legal right, public duty, demand and refusal. Mandamus under **Article 226** before the **High Court of Kerala** is a command to a public authority to perform a **public or statutory duty** it is legally bound to perform and has failed to perform after demand. This guide covers the three classic conditions — legal right, public duty, demand and refusal — where mandamus is most invoked in Kerala (local bodies, passports, RTO, revenue), and where it is **refused** because the duty is discretionary, contractual or already subject to an equally efficacious remedy. ## What must be shown for mandamus? The Supreme Court's formulation is consistent from *Bihar Eastern Gangetic Fishermen Co-op Society v. Sipahi Singh (1977) 4 SCC 145* to the 2026 restatement: 1. **A legal right in the petitioner** — from the Constitution, a statute, statutory rules or regulations, a statutory scheme or binding notification — not a mere expectation, hope or desire. The right must be subsisting on the date of the petition (*Mani Subrat Jain v. State of Haryana, (1977) 1 SCC 486*). 2. **A corresponding legal or public duty on the respondent** — a duty owed to the public or a section of it, capable of judicial enforcement. The duty must be mandatory, not purely discretionary as to whether to act at all. 3. **Failure, refusal or neglect to perform that duty** — after the petitioner has **demanded performance**. The demand-refusal link must be shown by a dated representation with acknowledgement, and silence beyond a reasonable statutory period counts as deemed refusal. Two further filters the Kerala High Court applies at admission: * **No equally efficacious alternative remedy, or exceptional case:** Where a statutory appeal or tribunal remedy exists (e.g., **Tribunal for Local Self Government Institutions** against a Municipality/Panchayat order under **Sec 509 Kerala Municipality Act, 1994 / Sec 276 Kerala Panchayat Raj Act, 1994**, read with **Rule 8(3), Tribunal for the Kerala Local Self Government Institutions Rules, 1999**), the court will ordinarily **decline to entertain** the writ unless the case falls within the *CIT v. Chhabil Dass Agarwal (2013) 357 ITR 357 (SC)* exceptions (no compliance with Act, violation of natural justice, repealed provision, jurisdictional error). Mere pendency is not maintainability. * **Public-law element:** A purely private contractual dispute, even with a government company, does not become a writ because it is labelled constitutional (*Binny Ltd v. Sadasivan*). ## Where mandamus is most invoked in Kerala — with forum choice | Problem you face | Statutory duty the authority owes | Demand you must make first | Alternative remedy if you miss the writ filter | Where writ lies | |---|---|---|---|---| | **Building permit / occupancy certificate refused or silent beyond 30 days** (Municipality/Panchayat) | Consider and dispose under **Kerala Municipality Building Rules, 2019 / Kerala Panchayat Building Rules, 2019** read with **Interim Development Order** — Secretary's 30-day windows (Rr.12–13), deemed permission on Council default (R.14), deemed occupancy certificate (R.20(3)) of KMBR 2019 | Written application → reminder after 30 days (keep acknowledgement) | **509 appeal to Tribunal for LSGIs** — 30 days + one month condonation (Sec 509/276; R.8(3), Tribunal Rules, 1999); after the condonable window, tribunal cannot entertain, writ cannot circumvent limitation | Writ where authority acts as if IDO does not exist or where no appeal lies against inaction; otherwise tribunal first | | **Passport delayed or refused citing FIR / adverse verification** | Decide under **Passports Act Sec 6(2)(f)** + **GSR 570(E) 25.08.1993** + **MEA OMs dated 10.10.2019 (No. VI/401/1/5/2019) & 06.12.2024 (No. VI/405/04/08/2024)** — mere FIR ≠ pending before court | Representation + NOC from court where proceeding is pending (GSR 570) | None equally efficacious — writ is primary where verification delay exceeds statutory ground | **Mandamus** to overrule adverse report where undertaking matches, or to issue for short validity | | **RTO licence suspension / vehicle blacklisting / mParivahan challan** | Act under **Motor Vehicles Act, 1988 Sec 19, 21, 53** with natural justice | Show-cause reply within statutory time | **Appeal to the prescribed appellate authority under Sec 19(3) MV Act (thirty days)** | Writ only on natural-justice / jurisdictional failure, not on facts | | **Thandaper mutation / patta / resumption not done** | Duty of Village Officer / Tahsildar under **Kerala Land Reforms Act / Land Assignment Act / Paddy Land Act 2008 Sec 9** | Written application with survey no., possession proof, tax receipt | **Sec 34 KLR appeal, assignment review** | Writ where officer refuses to act at all or acts without authority of law (Art 300A) | | **Blacklisting / tender exclusion** | No blacklisting without **show-cause + hearing** — *Erusian Equipment (1975)* | Reply to show-cause | **No statutory appeal** — writ is primary on natural justice | Highly maintainable on public-law ground | | **Subsidy / fee committee excess, scholarship not released** | Statutory scheme duty (Fee Regulatory Committee) | Representation to committee | Committee appeal | Writ where committee order violated | The pattern for mandamus is therefore **representation → statutory timeline → alternative-remedy check → writ for 'consider and decide in accordance with law'**. ## What relief will the court actually grant? Where the duty is mandatory and the right crystallised, the court may direct the authority to **issue the permission, certificate or passport** where no further discretion remains (e.g., building in commercial zone with IDO clause 3.16.1.2 permitting residential apartments with commercial space in lower floors — where Ext.P6 reasoning was held unsustainable and quashed in *Suseela v. Thiruvananthapuram Corporation*, WP(C) 28821/2020 (Ker HC, 23 Feb 2022)). Where the duty is to **exercise discretion**, the ordinary relief is a **direction to consider, hear, and pass a reasoned order within a time limit** (e.g., two months in *Suseela*; one month for occupancy in the *Tripunithura* paddy-land case, *S. Umesh Shenoy v. Tripunithura Municipality*, WP(C) 6151/2021, 11 Aug 2022). The court does not substitute its own discretion except in the narrow *Jagannathan* situation where failure to direct the outcome would perpetuate injustice. ## What defeats mandamus? * No legal right — only an expectation of appointment, a non-statutory instruction, or a right not yet crystallised. * No public duty — a private college's contractual dispute, an unaided private body with no statutory public function. * Disputed facts that need evidence — boundary, title, measurement — writ is not a civil suit (*Ida Sarojam v. State of Kerala*, 2026:KER:14483 (Ker HC, 25 Feb 2026) — retaining-wall case dismissed for disputed facts). * Delay and laches, suppression of material facts, or where mandamus would require the court to legislate or formulate policy (*M.B. Majumdar; Saurabh Chaudri*). ## What documents move a mandamus petition Bring: the statute/rule conferring the right, the application filed with date and acknowledgement, the representation/demand with postal proof, the impugned refusal or the calendar showing silence beyond the statutory period, the alternative-remedy order if any, and — for building matters — the IDO, sanctioned Master Plan extract, and Sec 14 Paddy Land Act analysis where paddy/wetland is the ground. ## Primary sources * [Constitution — Articles 226, 32](https://indiacode.gov.in/document-grid/d5475e8d-1998-4ac8-8694-82f941074bb7) * *Bihar Eastern Gangetic Fishermen Co-op Society v. Sipahi Singh*, (1977) 4 SCC 145; *Mani Subrat Jain v. State of Haryana*, (1977) 1 SCC 486; *Director of Settlements AP v. M.R. Apparao*, (2002) 4 SCC 638 * *Andi Mukta Sadguru Shree Muktajee Vandas Swami Suvarna Jayanti Mahotsav Smarak Trust v. V.R. Rudani*, (1989) 2 SCC 691; *Praga Tools Corporation v. C.A. Imanual*, (1969) 1 SCC 585 * *Comptroller & Auditor General of India v. K.S. Jagannathan*, (1986) 2 SCC 679; *Binny Ltd v. V. Sadasivan*, (2005) 6 SCC 657 * [Kerala Municipality Act, 1994 — Sec 509](https://lsgd.kerala.gov.in/wp-content/uploads/2024/08/kerala__municipality__act_1994.pdf); [Kerala Panchayat Raj Act, 1994 — Sec 276](https://indiacode.gov.in/handle/123456789/565097); [Kerala Municipality Building Rules, 2019 — Rr.12–14 and 20(3)](https://noc.fire.kerala.gov.in/assets/uploads/KMBR-2019.pdf); Tribunal for the Kerala Local Self Government Institutions Rules, 1999 — R.8(3) * [Passports Act, 1967 — Sec 6(2)(f)](https://indiacode.gov.in/handle/123456789/495940); **GSR 570(E) 25.08.1993**; **MEA OMs 10.10.2019 (No. VI/401/1/5/2019), 06.12.2024 (No. VI/405/04/08/2024)**; *Mahesh Kumar Agarwal v. UoI, 2025 INSC 1476* * [Motor Vehicles Act, 1988 — Sec 19 (incl. s.19(3) appeal), 21, 53](https://indiacode.gov.in/handle/123456789/619305); [Kerala Conservation of Paddy Land and Wetland Act, 2008 — Sec 14](https://keralaagriculture.gov.in/wp-content/uploads/2021/04/kerala-conservation-of-paddy-land-and-wetland-act-2008.pdf) ### Frequently asked questions **When does mandamus lie under Article 226 in Kerala?** Where the petitioner has a legal right, the respondent owes a corresponding public or statutory duty, and the authority has failed, refused or neglected to perform it after a demand. The duty must be public — owed to the public or a section of it under statute, statutory rule or the Constitution — not a purely private contractual duty. A representation followed by refusal or unreasonable silence is ordinarily the trigger; the High Court then commands the authority to act according to law. **Can mandamus issue against a private body?** Generally not, except where the private body discharges a public function and the dispute has a public-law element. Andi Mukta Sadguru Shree Muktajee Vandas Swami Suvarna Jayanti Mahotsav Smarak Trust v. V.R. Rudani, (1989) 2 SCC 691 holds mandamus may lie against an aided private college performing a public function; Praga Tools Corporation (1969) holds a purely contractual dispute with a government company is not amenable. **Will the High Court direct a discretionary authority to decide in my favour?** No. Where the statute confers genuine discretion, mandamus lies to compel exercise of discretion according to law, not to dictate the outcome. The court may order the authority to consider and decide by a reasoned order, and in a fit case where discretion has wholly failed and injustice would follow, the Supreme Court in Comptroller & Auditor General v. K.S. Jagannathan, (1986) 2 SCC 679 recognises a narrow power to direct the manner, but the ordinary relief is 'consider and decide in accordance with law'. **Do I need to show a demand and refusal before mandamus?** Yes, ordinarily. A dated representation with acknowledgement and the authority's refusal or unreasonable silence is the cheapest evidence in the jurisdiction. The demand-refusal requirement is relaxed where demand would be futile, where refusal is already manifest, or where prolonged silence amounts to refusal in substance — but a written representation should still be filed. **Is mandamus available for a purely contractual claim against the government?** Not as a general enforcement of a private contract. Binny Ltd v. V. Sadasivan (2005) 6 SCC 657 restates mandamus as a public-law remedy; contractual money claims without a public element belong in civil suit or arbitration. Where a contract is statutory or the State's action has a distinct public-law character (arbitrary blacklisting, forfeiture without hearing), mandamus may be available for the public element. --- ## Prohibition in the High Court of Kerala: Stopping a Court or Tribunal from Exceeding Jurisdiction URL: https://advaslam.com/writing/writ-prohibition-kerala-high-court/ Author: Adv. K J Muhammed Aslam, Advocate (Bar Council of Kerala, K/001823/2026) Published 8 September 2026 Practice area: High Court writs & procedure Kerala tribunal or authority acting without jurisdiction? When prohibition under Articles 226 and 227 stops proceedings, and how it differs from certiorari. Prohibition under **Articles 226 and 227** before the **High Court of Kerala** is the writ that **forbids an inferior court, tribunal or quasi-judicial authority from continuing to proceed where it lacks jurisdiction, exceeds it, or proposes to violate natural justice**. Where certiorari quashes an order already passed, prohibition **stops the next step**. This guide covers when prohibition lies in Kerala — before the DRT, DM/CMM under SARFAESI Sec 14, revenue tribunals, and labour fora — and when it will be refused as a disguised appeal. ## What prohibition does — the preventive sister of certiorari The Supreme Court in ***Hari Vishnu Kamath v. Syed Ahmad Ishaque, (1955) 1 SCR 1104*** at para 15 treated prohibition and certiorari as **no fundamental distinction, but successive stages**: > Prohibition is issued **to prohibit** an authority proceeding without jurisdiction; certiorari is issued **to quash** an order passed without jurisdiction. Where the proceedings are still pending, prohibition; where the order is already made, certiorari — and the court will mould a prohibition prayer into certiorari where the order intervenes. Four conditions must coincide: 1. **An inferior court, tribunal or quasi-judicial authority** — not a purely administrative body — is seized of or about to be seized of the matter, and its function requires **hearing and determination of rights** after opportunity. 2. **Want or excess of jurisdiction is apparent** — from subject-matter, preliminary fact, or statutory bar (e.g., Sec 34 SARFAESI ousts civil court, Sec 509 + Rule 8(3) vests the Tribunal for LSGIs). 3. **The error is not merely on merits** — a wrong appreciation of evidence is not want of jurisdiction. 4. **Alternative remedy does not cure a patent jurisdictional defect** where the tribunal proposes to act wholly without authority — but where the alternative can test jurisdiction itself (e.g., Sec 17 DRT), the High Court will ask why that forum was not first approached. ## Where prohibition is invoked in Kerala | Tribunal / authority | Patent want-of-jurisdiction scenario where prohibition is sought | Why prohibition rather than later certiorari | |---|---|---| | **DM / CMM under SARFAESI Sec 14** | Magistrate proposes to **adjudicate borrower vs bank title** or tenant rights, instead of the **ministerial verification** of Sec 14(1) proviso formalities within 30+30 days (*Balkrishna Rama Tarle (Dead) Thr. LRs v. Phoenix ARC (P) Ltd., (2023) 1 SCC 662*) | Adjudication would exceed Sec 14; prohibition to confine to verification | | **DRT / DRAT** where civil court also seized | DRT proposes to decide a **civil title/boundary** dispute that is not a Sec 13(4) measure — Sec 34 bar read in reverse | Civil title needs civil court, not DRT — excess of jurisdiction | | **Revenue Tribunal / RDO under Paddy Land Act Sec 9** | LLMC → DLAC chain not followed; RDO proposes to permit filling beyond 4.04 ares in a panchayat / 2.02 ares in a municipality (residential-building limits under the Paddy Land Act, 2008, as amended in 2018) | Preliminary proceeding absent — lack of jurisdiction | | **Labour Court / Industrial Tribunal** | Tribunal proposes to proceed where reference under **Industrial Disputes Act Sec 10** is invalid, or where contract labour is no longer ID Act workman | Subject-matter bar | | **Co-operative Arbitration Court** | Court proposes to decide where **Sec 69 Kerala Co-operative Societies Act, 1969** bar is not met (money claim not between society and member) | Subject-matter bar | | **Family Court / Magistrate under DV Act** | Magistrate proposes to pass **interim maintenance without jurisdiction** where the PWDV Act Sec 29 appeal is the prescribed correction and inherent powers cannot supplant it (*Titus v. State of Kerala*, 2025 SCC OnLine Ker 4611 (Ker HC, 01 Jul 2025)) | Hierarchy | A common misfire: seeking **prohibition against an administrative tender committee** before hearing — the committee is not at that stage a quasi-judicial adjudicator; the correct writ is **mandamus** to conduct the hearing or **certiorari** after the blacklisting order on natural-justice failure. ## Prohibition vs Article 227 — the correct label in Kerala After ***Radhey Shyam v. Chhabi Nath, (2015) 5 SCC 423***, **civil court judicial orders** are amenable to **Article 227** superintendence, not Article 226 prohibition/certiorari. For **tribunals and statutory authorities** (DRT, KAT, Co-operative Tribunal, Revenue Tribunal), **Article 226 prohibition/certiorari remains**. Where a civil court is **about to proceed wholly without jurisdiction** (e.g., civil suit filed despite **Sec 34 SARFAESI** bar or **Sec 509** Municipality bar after the condonable window), the High Court exercises **Article 227** to keep the court within bounds — not Article 226 — and **no Letters Patent Appeal** lies against a pure 227 order (226 original vs 227 supervisory distinction per *Umaji Keshao Meshram v. Radhikabai, (1986) Supp SCC 401*; civil courts to Art 227 per *Radhey Shyam*, paras 24–25). Practical filing in Kerala: **invoke both Articles 226 and 227** where the respondent is a tribunal, so the Single Judge can classify; where the respondent is a civil court, **invoke Article 227** only. ## What the court examines — and what defeats prohibition The High Court examines ** jurisdiction, not merits** — is there a tribunal, is it properly constituted, does the statute confer subject-matter, and are preliminary proceedings present — and **natural justice** where no procedure is prescribed. It **will not** re-appreciate evidence or correct a mere wrong decision that is within jurisdiction. Prohibition is **discretionary**, not of right. It will be refused where: * the petitioner **submitted to jurisdiction** without objection and now seeks prohibition after participating; * **laches and delay** — moving only after the tribunal's elaborate hearing has concluded and the order is imminent where certiorari after is equally efficacious; * the alternative remedy (e.g., **Sec 17 DRT**) can itself test the jurisdictional question and the defect is not patent; * no failure of justice is shown on the record. Where the order has already been passed by the time the High Court hears the petition, the court will **mould the prohibition prayer into certiorari** and quash, rather than dismiss as infructuous. ## What documents move a prohibition petition Bring: the **notice/proceedings sheet** showing the tribunal's proposed jurisdiction (cause title, subject-matter, relief sought), the **statutory bar extract** (Sec 34 SARFAESI, Sec 509/Rule 8(3), Sec 69 Co-op), the **preliminary-proceeding proof** (absence of Sec 13(2)/13(3A) before Sec 13(4), or absence of LLMC report before DLAC), and the **objection on jurisdiction already filed before the tribunal** with date — showing you did not acquiesce. ## Primary sources * [Constitution — Articles 226, 227](https://indiacode.gov.in/document-grid/d5475e8d-1998-4ac8-8694-82f941074bb7) * *Hari Vishnu Kamath v. Syed Ahmad Ishaque*, (1955) 1 SCR 1104, esp. para 15 (prohibition vs certiorari) * *Surya Dev Rai v. Ram Chander Rai*, (2003) 6 SCC 675 — 226 vs 227 distinction; *Radhey Shyam v. Chhabi Nath*, (2015) 5 SCC 423 — civil courts to 227 * *Umaji Keshao Meshram v. Radhikabai*, (1986) Supp SCC 401 — 226 original vs 227 supervisory * [SARFAESI Act Secs 13, 14, 34](https://indiacode.gov.in/handle/123456789/496260); *Balkrishna Rama Tarle v. Phoenix ARC*, (2023) 1 SCC 662 * [Kerala Municipality Act Sec 509](https://lsgd.kerala.gov.in/wp-content/uploads/2024/08/kerala__municipality__act_1994.pdf); Tribunal Rules 1999 Rule 8(3); [Kerala Panchayat Raj Act Sec 276](https://indiacode.gov.in/handle/123456789/565097) ### Frequently asked questions **When does prohibition lie under Article 226?** Where an inferior court, tribunal or quasi-judicial authority is proceeding or is about to proceed without jurisdiction, in excess of jurisdiction, or in violation of the principles of natural justice where no other procedure is prescribed, and the illegality is apparent. Prohibition is preventive — it forbids continuance — unlike certiorari which quashes after the order. **How is prohibition different from certiorari?** Both correct jurisdictional error. Prohibition issues before or during the proceedings to forbid the tribunal from continuing; certiorari issues after the order to quash it. In practice the High Court may mould relief: where a tribunal has already passed the order by the time the petition is heard, a prohibition prayer is treated as certiorari, and vice versa. Hari Vishnu Kamath (1955) 1 SCR 1104 treats them as successive stages of the same supervisory power. **Can prohibition issue against a pure administrative authority?** Not as prohibition in the strict sense. The writ runs to bodies that adjudicate and are enjoined to act judicially or quasi-judicially — where rights are determined after hearing. Against a purely administrative or executive act that determines no lis (e.g., a tender eligibility scrutiny before hearing), mandamus or certiorari for violation of procedure is the correct writ, not prohibition. **Do I need to wait for the tribunal's final order before moving the High Court?** No — and that is the point of prohibition. Where the tribunal's want of jurisdiction is patent on the record (e.g., SARFAESI Sec 14 Magistrate treating the application as an adjudicatory trial, or a revenue tribunal entertaining a civil title suit), you may move before the error matures. Delay, however, defeats equity — prohibition is discretionary and laches matters. **Is prohibition available against a civil court?** Judicial orders of civil courts are amenable to Article 227 superintendence after Radhey Shyam (2015) 5 SCC 423. Where a civil court assumes jurisdiction it does not have (e.g., entertaining a matter barred by Sec 34 SARFAESI or Sec 509 Municipality Act after tribunal remedy lapsed), Article 227 — not Article 226 prohibition — is the supervisory route, commonly labelled under both Articles 226 and 227. --- ## Quo Warranto in the High Court of Kerala: Challenging an Illegal Appointment to Public Office URL: https://advaslam.com/writing/writ-quo-warranto-kerala-high-court/ Author: Adv. K J Muhammed Aslam, Advocate (Bar Council of Kerala, K/001823/2026) Published 8 September 2026 Practice area: High Court writs & procedure Someone holding public office in Kerala without eligibility? When quo warranto under Article 226 lies, what a public office is and who can file. Quo warranto under **Article 226** before the **High Court of Kerala** asks a person holding a **public office** a single question — **by what warrant do you hold it** — and, where the answer discloses no valid legal title, **ousts the holder**. Unlike mandamus or certiorari, the petitioner need not show a personal legal right; any member of the public with bona fide interest may move. This guide covers what is a public office in Kerala, where the writ lies (university, co-operative, local body and State statutory offices), and where it is **refused** because the office is contractual or the remedy is an election petition. ## What quo warranto tests — title, not wisdom The Supreme Court in ***University of Mysore v. C.D. Govinda Rao, AIR 1965 SC 491*** and ***B. Srinivasa Reddy v. Karnataka Urban Water Supply & Drainage Board, (2006) 11 SCC 731*** frames the test in three steps: 1. **Is there a public office?** Created by the **Constitution, a statute or a statutory rule**, with duties of a public nature, tenure not at mere pleasure, and salary/emoluments from public funds or statutory source. A post created by executive order alone, without statutory foundation, is not enough. 2. **Is the holder qualified in law?** Eligibility under the **statutory qualifications** — age, educational qualification, experience, disqualification bars (e.g., **Kerala Co-operative Societies Act, 1969 Sec 28(2) disqualifications**, **Kerala University Acts** Vice-Chancellor qualifications). The court examines whether the holder **meets the statutory eligibility on the date of appointment**, not whether a better candidate existed. 3. **Is the appointment validly made by the competent authority following mandatory procedure?** Where the procedure is directory, violation does not vitiate title; where it is mandatory and goes to qualification, quo warranto may lie. ## Where quo warranto lies in Kerala | Office (Kerala statute) | Why it is a public office | Common ground of challenge | |---|---|---| | **University statutory offices** — Vice-Chancellor, Pro-Vice-Chancellor, Registrar under **Kerala University Acts** (University of Kerala, Calicut, MG, Cochin, Kannur, KTU) | Created by State statute, public educational function, tenure by statute | Appointment without statutory Search Committee, without UGC Regulations (2018) qualifications, or where Chancellor's procedure under Sec 10 violated | | **Co-operative apex institutions** — President/Director of District/State Co-operative Bank under **Kerala Co-operative Societies Act, 1969** | Statutory corporation, elected/appointed under the Act, public credit function | Disqualification under Sec 28(2), or election in violation of **Kerala Co-operative Societies Rules** — but election dispute normally → **Sec 69 arbitration + Co-op Tribunal** first; quo warranto only where eligibility is patent | | **Local body statutory offices** — President/Chairperson where statute creates the office (e.g., **Kerala Panchayat Raj Act Sec 153**) | Statutory office with public duties, tenure by statute | Holding after disqualification under Sec 30-35 Panchayat Raj Act, or without valid election *where election petition is not the bar* — careful forum choice | | **Public Service / Statutory commissions** — Member of **Kerala Public Service Commission (Art 316)**, Kerala State Commission for Protection of Child Rights | Constitution/statute-created, tenure and removal by Constitution/statute | Over-age, lack of 10-year experience bar, or appointment without consultation where required | | **Government statutory posts** — Director of a statutory corporation (KSEB, KSRTC where statute creates the office) | Created under the **transfer/vesting scheme under the Electricity Act, 2003** or the State Road Transport Corporation Act, read with the corporation's Articles of Association | Appointment without statutory qualification or by incompetent authority | Not a public office for quo warranto: a **Government company** employee (e.g., a contract manager in a Kerala PSU), an **unaided private college** teacher, or a **Devaswom Board** contractual post where tenure is at will — remedy is service law or company law, not quo warranto. ## Where quo warranto is refused — forum and standing filters * **Election petition bar.** Where the enabling statute provides a **specific election petition** (e.g., **Sec 69 Kerala Co-operative Societies Act** for society committee election disputes, **Sec 87 Panchayat Raj Act** for panchayat elections, **Art 329(b)** for legislative elections), the High Court will relegate. Quo warranto is not a parallel election dispute. * **Private office.** Where the institution owes no public duty, *Praga Tools* applies — no quo warranto. * **Disputed facts needing evidence.** Where qualification turns on **contested factual adjudication** (e.g., whether a degree is equivalent, or service length), the court will not conduct a roving enquiry; the statutory authority's fact-finding is ordinarily the forum. * **Mootness / futility.** Where the holder has already **vacated or been superseded** by a fresh valid appointment, the writ is **infructuous** — quo warranto tests the right to continue in a public office, and futility is a recognised ground of refusal (*George Joseph v. S. Chandramohan Nair*, W.P.(C) No. 24963/2008, 20 November 2009; set aside on other grounds in *S. Chandramohan Nair v. George Joseph*, Supreme Court, 5 October 2010). * **Delay and acquiescence.** Quo warranto is not limited by the 30+30-day tribunal bar like a building-permit appeal, but where the appointment was notorious and the petitioner slept for years, the court may decline on **delay and public interest** (continuity of administration). ## Who can file, and what relief follows? Any **member of the public** with bona fide interest may file; the petitioner need not be a rival candidate. The respondent is the **holder**, not the appointing authority (though the authority is typically arrayed as a respondent for record). If the writ succeeds, the High Court **declares the appointment void and ousts the holder**; it does not appoint the petitioner. A consequential mandamus to the appointing authority to fill the vacancy **in accordance with law** may follow, but not a direction to appoint a particular person. ## What documents move a quo warranto petition Bring: the **statute/Rule creating the office** with the **qualifications clause** marked, the **appointment order** with date, the **holder's bio-data / service register** showing disqualification, the **Search Committee / selection minutes** where applicable, and — for university posts — the **UGC Regulations 2018** and Chancellor's notification. ## Primary sources * [Constitution — Articles 226, 316, 329(b)](https://indiacode.gov.in/document-grid/d5475e8d-1998-4ac8-8694-82f941074bb7) * *University of Mysore v. C.D. Govinda Rao*, AIR 1965 SC 491; *B. Srinivasa Reddy v. Karnataka Urban Water Supply & Drainage Board*, (2006) 11 SCC 731 * *Hari Vishnu Kamath v. Syed Ahmad Ishaque*, (1955) 1 SCR 1104; *Praga Tools Corpn. v. C.A. Imanual*, (1969) 1 SCC 585; *Andi Mukta Sadguru*, (1989) 2 SCC 691 * [Kerala Co-operative Societies Act, 1969 — Secs 28, 69](https://indiacode.gov.in/handle/123456789/565177); [Kerala Panchayat Raj Act, 1994 — Secs 30-36, 87, 153](https://indiacode.gov.in/handle/123456789/565097); [Kerala Municipality Act, 1994 — State Election Commission, Kerala](https://www.sec.kerala.gov.in/portal/resources/downloadAttachment/ea78b52a-d647-4d8b-8d01-c741f350943c); [UGC Regulations, 2018](https://www.ugc.gov.in) ### Frequently asked questions **When does quo warranto lie under Article 226 in Kerala?** Where a person holds a public office — a substantive office created by the Constitution, a statute or statutory rule — without being legally qualified or without a valid appointment, and continues to hold it. The court enquires 'by what warrant' and, if the appointment is illegal, ousts the holder. The office must be public, not merely an employment, and the violation must be of statutory or constitutional eligibility, not merely a procedural irregularity that does not go to qualification. **Do I need personal injury to file quo warranto?** No. Unlike mandamus or certiorari, quo warranto does not require the petitioner to show a personal legal right or that the holder caused the petitioner specific injury. Any member of the public with bona fide interest may move the court as a relator — the enquiry is into the legality of the holder's title to the office, not the petitioner's private grievance. Malafide or political motivation, however, is a discretionary ground to decline. **What is a 'public office' for quo warranto?** A substantive office of a public nature created by the Constitution or a statute/statutory rule, with duties of a public character and tenure independent of the pleasure of the appointing authority. A government post, statutory corporation directorship, university statutory office (Vice-Chancellor, Registrar under a State Universities Act), local body statutory office, or co-operative apex office created by statute qualify. A purely contractual employment, even in a government company, where tenure is at will, does not. **Can quo warranto be filed against an elected office (MLA, MP, Panchayat member)?** For disqualification of an MLA/MP, Articles 102-103 (Parliament) and 191-192 (Legislature) provide a distinct constitutional mechanism (Governor on Election Commission opinion), and quo warranto is not the route. For local body elected offices under Kerala Panchayat Raj Act 1994 / Kerala Municipality Act 1994, a question of subsequent disqualification goes to the State Election Commission under Sec 36 / Sec 92 respectively. Quo warranto lies for appointed public offices, not to try a pure election dispute where an election petition is the statutory remedy (Art 329(b) bar for elections). **What will the court not do in quo warranto?** Examine the holder's suitability, merits or comparative qualifications where eligibility is met — the court judges legality of appointment, not wisdom. It will not issue quo warranto where the office is not public, where the appointment has already been superseded by a fresh valid appointment (rendering the writ infructuous), or where disputed facts on eligibility need evidence beyond the record. --- ## SARFAESI Notice Under Section 13(2) in Kerala: Can You Go to the High Court Under Article 226 or Must You Go to DRT? URL: https://advaslam.com/writing/sarfesi-notice-article226-vs-drt-remedy/ Author: Adv. K J Muhammed Aslam, Advocate (Bar Council of Kerala, K/001823/2026) Published 7 September 2026 Practice area: Business, banking & IPR SARFAESI Section 13(2) notice in Kerala? When an Article 226 writ may lie and when to go to DRT under Section 17: Satyawati Tondon, Phoenix ARC, PHR Invent. You have received a demand notice under **Section 13(2)** of the [Securitisation and Reconstruction of Financial Assets and Enforcement of Security Interest Act, 2002 (SARFAESI Act)](https://indiacode.gov.in/handle/123456789/496260) from a bank or ARC in Kerala, threatening possession of your house or business premises in 60 days. The immediate question is not whether the bank is right on the debt, but **where you may challenge it — the High Court of Kerala under Article 226 or the Debts Recovery Tribunal (DRT) under Section 17** — because choosing the wrong forum costs time, interim protection, and sometimes the right itself. The Supreme Court's settled answer, from *[United Bank of India v. Satyawati Tondon (2010) 8 SCC 110](https://indiankanoon.org/doc/175816/)* through *[Phoenix ARC v. Vishwa Bharati (2022) 5 SCC 345](https://indiankanoon.org/doc/186727474/)* to *[PHR Invent Educational Society v. UCO Bank (2024) 6 SCC 579](https://indiankanoon.org/doc/182692120/)*, is that the High Court will **ordinarily not entertain** the writ where the Section 17 remedy is efficacious, and will exercise **self-restraint with greater rigour** for bank dues — interference only in exceptional cases such as total violation of natural justice, jurisdictional error, or fraud/collusion. ## What does a SARFAESI Section 13(2) notice actually do — and what does it not do? [Section 13 SARFAESI](https://indiacode.gov.in/handle/123456789/496260) is a **demand**, not yet a dispossession: * **Section 13(2):** Where a borrower's account is classified as a non-performing asset (NPA), the secured creditor may require the borrower by notice in writing to **discharge liabilities within 60 days** from the date of notice, with details of dues and secured assets. No possession can be taken during those 60 days. * **Section 13(3):** The notice must give details of the amount and the secured assets intended to be enforced. * **Section 13(3A):** If the borrower makes a **representation or objection**, the secured creditor must **consider it, and if not acceptable, communicate reasons within 15 days** of receipt. The reasons must address the objection — a one-line rejection is not compliance. * **Section 13(4):** **Only after** expiry of 60 days and after the 13(3A) stage, the secured creditor may take **measures**: (a) take possession, (b) take over management, (c) assign/lease/sale, (d) right to recover. Each measure must be exercised per the [Security Interest (Enforcement) Rules, 2002](https://indiacode.gov.in/handle/123456789/509770) — including Rule 8 (possession notice, publication in two newspapers) and Rule 8(6)/9 (sale notice). * **Section 14:** Application to the **Chief Metropolitan Magistrate / District Magistrate** for assistance in taking possession is **ministerial** — the Magistrate verifies compliance of formalities under the proviso to Section 14(1) and must pass an order within 30 days (extendable to 60), without adjudicating disputes between borrower and creditor (*Balkrishna Rama Tarle v. Phoenix ARC, 2022 LiveLaw SC 799*). * **Section 17:** **Any person (including borrower)** aggrieved by **any measure under Section 13(4)** may make an application to the **DRT** having jurisdiction within **45 days** from the date of such measure. Sections 17(2)-(3) empower the DRT to examine whether the measure was in accordance with the Act and Rules and to restore management/possession where not. * **Section 18:** Appeal from DRT to **DRAT** within **30 days** (extendable), on **pre-deposit** — 50% of debt due, reducible to 25% for reasons recorded (second proviso to Sec 18(1)). * **Section 34:** **Civil court jurisdiction barred** — no civil court shall have jurisdiction to entertain any suit or proceeding in respect of any matter which the DRT or DRAT is empowered to determine. * **Article 226 of the Constitution:** The writ power is **constitutionally entrenched** — Section 34 cannot oust it — but the Supreme Court treats it as **self-imposed restraint**, not absence of jurisdiction. ## Is a Section 13(2) notice itself challengeable before the DRT or the High Court? **Not yet before the DRT, and ordinarily not before the High Court either.** Section 17 opens only on a **Section 13(4) measure**. A Section 13(2) notice alone does not entitle you to approach the DRT — the statutory response is the **Section 13(3A) representation**. Before the High Court, the same 60-day notice period explains why writs at this stage are treated as premature. The High Court in Kerala routinely declines interim relief against a 13(2) notice, observing that the borrower has not yet availed the 13(3A) objection and that no 13(4) measure has crystallised. The Supreme Court in *Satyawati Tondon* at para 43 deprecates routine High Court interference at the 13(2)/13(4) stage precisely because it frustrates the Act's purpose of expeditious recovery while the borrower takes benefit of an interim order. **Practical step at the 13(2) stage:** File a detailed **13(3A) representation within 60 days** — dispute the NPA classification (90-day overdue, RBI Prudential Norms), quantify the amount, claim set-off or payments, assert that the asset is not a **secured asset** (Section 2(1)(zc)), or that the debt is not a secured debt. Seek **written reasons** if rejected, and preserve the postal proof. This record is the foundation for both the later Section 17 application and, in a rare case, the High Court's natural-justice exception. ## When is Article 226 maintainable in a SARFAESI matter — the Supreme Court's exceptions? The rule and its exceptions come from *[CIT v. Chhabil Dass Agarwal (2014) 1 SCC 603 at para 15](https://indiankanoon.org/doc/51987756/)*, adopted verbatim for SARFAESI in *PHR Invent* and *Varimadugu Obi Reddy v. B. Sreenivasulu (2023) 2 SCC 168*: A writ under Article 226 **will ordinarily not be entertained** where an efficacious alternative remedy exists, but it **may** be entertained where: 1. the statutory authority **has not acted in accordance with the provisions of the enactment** (e.g., no Section 13(2) service, no Section 13(3A) consideration at all); 2. it has acted **in defiance of fundamental judicial procedure**; 3. it has invoked **provisions which are repealed**; or 4. the order is passed in **total violation of principles of natural justice**. To this spine the SARFAESI jurisprudence adds: * **Jurisdictional error** — the asset is not a secured asset, or the creditor is not a secured creditor entitled to invoke SARFAESI (e.g., assignment not valid, debt not secured). * **Fraud or collusion** in a confirmed auction — the only ground on which a confirmed sale can be interfered with after execution of a registered sale certificate (*PHR Invent* at paras 26-27: redemption under Section 13(8) extinguishes on execution of the registered sale deed, not merely on confirmation of sale; for the amended Section 13(8), however, *Celir LLP v. Bafna Motors (Mumbai) Pvt. Ltd.* (2024) 2 SCC 1 holds that the right of redemption is lost on the date the auction notice is published). * **Violation of fundamental rights** in the rare case where the SARFAESI measure itself breaches Article 14/21 and the alternative remedy cannot address it. What is **not** an exception: mere hardship in making the Section 18 pre-deposit, or that the writ has been pending for a long time (*PHR Invent* at paras 23-24 — pendency of the writ does not justify bypassing the alternative remedy), or that the borrower prefers a constitutional forum to avoid fees and proof. Two additional filters the High Court of Kerala applies: * **Against whom?** A writ against an **ARC or a private bank** acting as a secured creditor under SARFAESI is **not maintainable** as a writ against a public authority — the ARC's recovery under contract is not a public function (*Phoenix ARC* at paras 12, 18-19; *Federal Bank v. Sagar Thomas (2003) 10 SCC 733*). The writ route requires a State or instrumentality of the State under Article 12, or a body performing a public duty whose action falls in the domain of public law. * **Civil title disputes.** A writ is **not** a substitute for a civil suit where the core dispute is **title, boundary or encroachment** — the writ court will not adjudicate disputed facts on evidence (*Ida Sarojam v. State of Kerala*, 2026:KER:14483, Kerala HC, 25 Feb 2026, dismissing a wall-permission writ: "A writ court exercising jurisdiction under Article 226 cannot go into these disputed facts, that can be decided only by adducing evidence in a civil proceeding."). ## What is the correct forum at each SARFAESI stage in Kerala — 13(2) demand, 13(4) possession notice, securitisation application? | Stage & notice | Where to go first | Time limit | What you can get | Article 226? | |---|---|---|---|---| | **Section 13(2) demand (60 days)** | **Section 13(3A) representation** to the secured creditor | Within 60 days of 13(2) | Reasons within 15 days if objection not accepted | Writ ordinarily **not maintainable** — no measure yet; 13(3A) is the remedy | | **Section 13(4) possession notice** (Rule 8) | **Section 17 application to DRT Ernakulam** (or competent DRT) | **45 days** from measure | DRT can declare measure not in accordance with Act/Rules, restore possession/management, set aside sale | Writ **only on the 4 exceptions** above — otherwise relegation | | **Section 14 DM/CMM order** (assistance) | Still **Section 17 before DRT** — 14 is ministerial, not adjudicatory | 45 days from resulting possession | DRT examines the underlying 13(4) compliance | No writ to re-adjudicate borrower-creditor dispute before Magistrate | | **Possession taken / auction sale published** | **Section 17 DRT** urgently + **Rule 8(6) & 9** compliance challenge | 45 days; sale challenge before confirmation | Interim stay from DRT on terms; sale set aside where Rule breach goes to root | Post-confirmation writ only for **fraud/collusion** before registered sale deed | | **DRT order adverse** | **Section 18 appeal to DRAT** | **30 days** + pre-deposit **50% (down to 25%)** | DRAT can stay/reverse DRT; can reduce deposit for reasons | Writ against DRT/DRAT order **only** on jurisdictional / natural-justice grounds, not re-argument on merits | | **Tenant in mortgaged property facing eviction** | **Section 17 as "any person"** — tenant can approach DRT; protection under **Section 17(4A) and Harshad Govardhan Sondagar (2014) 6 SCC 1** | Within 45 days of dispossession threat | Lease protection where valid lease pre-dates mortgage (registered) and rent reflects | Writ not a shortcut for tenancy adjudication | | **Civil title / boundary / unauthorised construction** | **Civil suit** before competent civil court | As per Limitation Act | Declaration, injunction, partition | **Writ dismissed** — disputed facts need evidence, not 226 | ## What recent Kerala and Supreme Court guidance tightens this? * **Phrasing the courts use:** "[T]he High Court will ordinarily not entertain a petition under Article 226 if an effective remedy is available... with **greater rigour** in matters involving recovery of taxes, cess, fees and dues of banks and financial institutions" — *Satyawati Tondon* para 43, quoted in *PHR Invent* para 14. * **Re-affirmation chain:** *Kanaiyalal Lalchand Sachdev (2011) 2 SCC 782* → *Mathew K.C. (2018) 3 SCC 85* → *Agarwal Tracom (2018) 1 SCC 626* → *Phoenix ARC (2022)* → *Varimadugu Obi Reddy (2023)* → *South Indian Bank v. Naveen Mathew Philip (SLP 22021/2022, 17 Apr 2023)* → *PHR Invent (2024)* — the Supreme Court has repeatedly **set aside High Court interference** in SARFAESI and imposed costs (₹1 lakh in *PHR Invent*) where writs were entertained despite the DRT route. * **Maintainability vs entertainability:** A Division Bench of the **Kerala High Court (CJ Nitin Jamdar & Justice S. Manu, reported 11 Dec 2024, SCC Online)** clarified the distinction the Supreme Court drew in *Godrej Sara Lee v. E&TOCAA (2023)*: mere availability of an alternative remedy **does not oust jurisdiction** and render a writ **not maintainable**; it is a ground for the court to **decline to entertain** it. Dismissal as "not maintainable" without examining whether an exceptional case is made out is not proper — the court must apply the exceptions test. * **Limitation and forum shopping:** Once the Section 17 application (45 days) and the DRAT appeal (30 days, plus the condonable extension) have lapsed without being filed, the High Court **cannot be used to revive** the statutory remedy — the Supreme Court refused to entertain a writ in exactly that situation in *Assistant Commissioner (CT) LTU Kakinada v. Glaxo Smith Kline Consumer Health Care Ltd.*, 2020 INSC 390. * **Citizen-friendly practice:** Kerala courts have in humanitarian cases (e.g., 85-year-old occupant seeking 10 cents reclamation under the Paddy Land Act) issued writ directions as an exceptional measure, expressly stating **"this need not be treated as a precedent"** — the exception proves the rule. ## What documents and evidence actually move the forum? **For a Section 13(3A) representation and a later Section 17 application — produce the complete chain, not just the last notice:** 1. **Secured debt packet:** Loan agreement, sanction letter, disbursal proof, restructuring/OOTS correspondence, and the account's **NPA classification date** with the bank's 90-day overdue working. 2. **Section 13(2) packet:** The demand notice with **date of service** (postal track, acknowledgement), the amount break-up (principal, interest, penal), and the secured asset description under Section 13(3). 3. **13(3A) packet:** Your representation with date of despatch and acknowledgement, the bank's **reasons** in reply (or proof of no reply within 15 days) — total non-consideration is the natural-justice exception. 4. **Possession packet:** Rule 8 possession notice with date of affixture and publication (two newspapers), inventory/panchnama, Section 14 application and Magistrate order, and photographs of possession. 5. **Sale packet:** Rule 8(6) sale notice (30 days), Rule 9 conditions, valuation report, reserve price, auction notice publication, bidder list, sale certificate and registration date — the **auction-notice publication date** determines whether **Section 13(8) redemption** is still open (amended Section 13(8), as read in *Celir LLP v. Bafna Motors* (2024) 2 SCC 1). 6. **Payment and hardship proof:** Bank statements showing payments, receipts, and the pre-deposit computation for Section 18 DRAT (25-50%) — the DRT/DRAT interim depends on prima facie payment. ## If the bank is a private bank or ARC, does the High Court route help at all? Ordinarily **no** for the SARFAESI measure itself. *Phoenix ARC* holds that the ARC's enforcement as a secured creditor under contract is not the public function that Article 226 reaches. The same reasoning has been applied to private banks acting as secured creditors — the borrower must go to the DRT under Section 17, not to the High Court under Article 226, unless the challenge falls within the public-law exceptions (total jurisdictional failure, natural-justice violation, or a State instrumentality's connected action). ## Related High Court remedy where Article 226 is genuinely maintainable The SARFAESI self-restraint is specific to that Act's code. For **non-SARFAESI bank action** — a **bank-initiated debit freeze on mere suspicion without police requisition**, where the bank acts on its own under RBI KYC Master Direction Clause 59 — the High Court **has** supplied an interim SOP because no effective DRT-type alternative exists: *Abdul Azeez v. Union of India, 2025:KER:88312 (19 Nov 2025, Justice M.A. Abdul Hakhim)* — same-day SMS + registered post with reasons, intimation to jurisdictional Cyber Crime Police, 1-week decision on your explanation, and a **hard 3-month cap** absent authority direction. The Court has since revised these guidelines in *Ajith P.R. v. Union of India* [2026 KHC OnLine 609]: SMS/e-mail intimation on the day of freezing and reasons by registered post within three working days, one month for your explanation and a one-week decision on it, and — if the explanation is not accepted — a written complaint by the bank to the local police instead of the automatic 3-month release. See the companion guide on [bank freeze without police order](https://advaslam.com/writing/bank-freeze-without-police-rbi-kerala-hc-sop/). The contrast illustrates the method: **writ maintainability follows the existence of an alternative**, not the subject (banking) alone. ## Primary sources * [Securitisation and Reconstruction of Financial Assets and Enforcement of Security Interest Act, 2002 — India Code](https://indiacode.gov.in/handle/123456789/496260) (Sections 2(1)(zc), 13, 14, 17, 18, 34) * [Security Interest (Enforcement) Rules, 2002](https://indiacode.gov.in/handle/123456789/509770) (Rules 8, 8(6), 9) * [Recovery of Debts and Bankruptcy Act, 1993](https://indiacode.gov.in/handle/123456789/496321) (DRT structure) * [Constitution of India — Article 226](https://indiacode.gov.in/document-grid/d5475e8d-1998-4ac8-8694-82f941074bb7) * *United Bank of India v. Satyawati Tondon*, **(2010) 8 SCC 110** (AIR 2010 SC 3413) — alternative remedy with greater rigour for bank dues * *CIT v. Chhabil Dass Agarwal*, **(2014) 1 SCC 603** at para 15 — four exceptions despite alternative remedy * *Authorized Officer, State Bank of Travancore v. Mathew K.C.*, **(2018) 3 SCC 85** — stay at 13(4) stage without special reasons deprecated * *Phoenix ARC Pvt Ltd v. Vishwa Bharati Vidya Mandir*, **(2022) 5 SCC 345** — writ against ARC/private bank not maintainable; 13(4) proposed action requires Sec 17 * *Varimadugu Obi Reddy v. B. Sreenivasulu*, **(2023) 2 SCC 168** — pre-deposit avoidance by writ deprecated * *South Indian Bank Ltd v. Naveen Mathew Philip*, SLP (C) 22021-22022/2022, Supreme Court, **17 Apr 2023** — Art 226 not alternative to Tribunal fee/pre-deposit * *PHR Invent Educational Society v. UCO Bank*, **(2024) 6 SCC 579** (SC 10 Apr 2024) — reaffirms Satyawati Tondon, costs ₹1 lakh, redemption extinguishes on registered sale deed; fraud/collusion only exception for confirmed sale * *Celir LLP v. Bafna Motors (Mumbai) Pvt. Ltd.*, **(2024) 2 SCC 1** (2023 INSC 838) — under amended Section 13(8), redemption is lost on publication of the auction notice * *Balkrishna Rama Tarle v. Phoenix ARC*, **2022 LiveLaw SC 799** — Sec 14 is ministerial, 30+30 days * *Harshad Govardhan Sondagar v. International Assets Reconstruction Co.*, **(2014) 6 SCC 1** — tenant protection under 17(4A) * *Godrej Sara Lee Ltd v. Excise and Taxation Officer-cum-Assessing Authority*, **(2023) 109 GSTR 402** — maintainability vs entertainability (adopted by Kerala HC CJ Nitin Jamdar, 11 Dec 2024) * *Assistant Commissioner (CT) LTU Kakinada v. Glaxo Smith Kline Consumer Health Care Ltd.*, **2020 INSC 390** (SC, 6 May 2020) — a writ cannot be entertained once the statutory appeal period and its condonable extension have lapsed ### Frequently asked questions **Can I file a writ petition in the High Court against a SARFAESI Section 13(2) notice?** Generally no. The Supreme Court in United Bank of India v. Satyawati Tondon (2010) 8 SCC 110, reaffirmed in Authorized Officer, State Bank of Travancore v. Mathew K.C. (2018) 3 SCC 85, Phoenix ARC v. Vishwa Bharati (2022) 5 SCC 345 and PHR Invent v. UCO Bank (2024) 6 SCC 579, holds that the High Court will ordinarily not entertain a writ under Article 226 where an efficacious alternative remedy under Section 17 of the SARFAESI Act before the Debts Recovery Tribunal exists, and that rule applies with greater rigour to bank dues. A Section 13(2) notice itself is not yet a measure under Section 13(4) that triggers Section 17 — the objection stage under Section 13(3A) is the first remedy. **When will the High Court still entertain a SARFAESI writ despite the DRT remedy?** Within the well-defined exceptions in CIT v. Chhabil Dass Agarwal (2014) 1 SCC 603 at para 15, adopted for SARFAESI: where the statutory authority has not acted in accordance with the Act, has acted in defiance of fundamental judicial procedure, has invoked a repealed provision, or has passed an order in total violation of principles of natural justice. Fraud, collusion or a jurisdictional error going to the root — for example, the asset is not a secured asset, or the secured creditor is not entitled to invoke SARFAESI — are also recognised, but the High Court examines whether an exceptional case is made out, not merely whether an alternative remedy exists. **What is the remedy against a Section 13(2) notice itself?** Section 13(3A) SARFAESI: on receipt of a Section 13(2) demand notice, the borrower may make a representation or raise an objection within 60 days; the secured creditor must consider it, communicate reasons within 15 days if not acceptable, and the reasons must address the objection. Failure to consider and communicate reasons is a jurisdictional defect that can be raised before the DRT once a Section 13(4) measure follows, and in a rare case of total non-consideration, may form a natural-justice exception before the High Court. **At what stage does the Section 17 DRT remedy become available?** Only upon a measure under Section 13(4) — taking possession, takeover of management, sale/lease/assignment, or right to recover. A Section 13(2) notice and a Section 13(3A) reply are not measures; the Section 14 application to the Chief Metropolitan Magistrate / District Magistrate is ministerial assistance and does not itself trigger Section 17 until possession is taken. The 45-day limitation for an application under Section 17 runs from the date of the 13(4) measure, not from 13(2). See Balkrishna Rama Tarle v. Phoenix ARC (2022) interpreting Section 14 as ministerial. **The bank took symbolic possession and published a sale notice. Can I still get a writ?** The sale and possession are Section 13(4) measures — the ordinary remedy is an application under Section 17 before the DRT within 45 days, with appeal to the DRAT under Section 18 on pre-deposit (25-50%). The High Court in Kerala, following Satyawati Tondon and Phoenix ARC, will normally relegate you to the DRT and not grant interim stay for the asking. Only where an exception is shown — for example, no service of 13(2), no 13(3A) consideration, fraud/collusion in auction, or extinguishment of redemption wrongly denied (PHR Invent at paras 26-27) — will the High Court examine the writ, and even then it may relegate on the ground that the confirmed sale can be interfered with only for fraud or collusion. **Is a writ maintainable against an ARC or a private bank under SARFAESI?** Generally not. Phoenix ARC (2022) 5 SCC 345 holds that an ARC taking SARFAESI measures as a secured creditor is not performing a public function under Article 226; recovery under contract through SARFAESI is a statutory-commercial power, and the aggrieved must avail Section 17. A writ against a private financial institution under SARFAESI is therefore not maintainable despite Article 226's width, subject to the rare public-law exceptions above. --- ## Your Personal Data Was Leaked by a Company: What You Can Do Under the DPDP Act URL: https://advaslam.com/writing/data-breach-victim-rights-dpdp-compensation/ Author: Adv. K J Muhammed Aslam, Advocate (Bar Council of Kerala, K/001823/2026) Published 6 September 2026 Practice area: Data protection & DPDP compliance Company leaked your Aadhaar, phone or health data? DPDP Sections 11-14 rights, Board complaint, IT Act 43A compensation, consumer and civil remedies. A message that your phone number, Aadhaar, email or health record held by a company was accessed without authority — or the discovery that it is circulating — is the victim side of the same breach the company must report within hours. Indian law after the **[Digital Personal Data Protection Act, 2023](https://indiacode.gov.in/handle/123456789/496508)** as phased by the **DPDP Rules, 2025 (G.S.R. 846(E) 13 Nov 2025, phased to 13 May 2027)** gives you **three parallel tracks** that must be started in the right order: **(1) grievance and access before the fiduciary → (2) complaint to the Data Protection Board with Board penalty and directions; and (3) compensation claims under Section 43A IT Act and the Consumer Protection Act where service deficiency is made out**, with civil damages as the common base. ## What three tracks does the victim actually have? | Track | Where you go | What it gives | Legal basis | |---|---|---|---| | **1. Fiduciary → Board** | Grievance officer of the company → Data Protection Board of India | Inquiry, directions to the fiduciary, **penalties up to 250 crore** (safeguards) / 200 crore (breach/children) that establish breach for your other claims | DPDP Sections 11-14, 13, 27-28, 33 plus Rule 7 (breach intimation) and Rule 14 (rights/grievance) | | **2. Compensation tribunal / adjudication** | Adjudicating Officer for **Section 43A IT Act** (negligent handling of sensitive personal data) | **Compensation** to the victim for wrongful loss caused by failure to implement reasonable security (AO jurisdiction is up to **five crore rupees** under Section 46(1A) IT Act; larger claims lie before the competent court) | IT Act Sections 43A and 46(1A) (adjudication), read with SPDI Rules 2011 reasonable security (Section 43A repeal not yet in force) | | **3. Consumer / civil court** | Consumer Commission (CPA 2019) or civil court | **Consumer compensation** where data handling was part of a service and was deficient; **civil damages** for breach of duty/contract | CPA 2019; Contract Act; general law of damages | Under the DPDP framework, **track 1 is the procedural gateway** — Section 13 requires you to first invoke the fiduciary's published grievance mechanism before the Board entertains the complaint. A Board filing that skips the grievance record is premature. ## What rights can you exercise before the fiduciary? Under **DPDP Sections 11-14 read with Rule 14**, a Data Principal (Section 2(j)) may: * **Section 11 — Right to access:** Obtain a summary of the personal data being processed and the identities of the other Data Fiduciaries and Data Processors with whom the personal data has been shared by the fiduciary, with a description of the data so shared — Section 11(1)(b). This is subject to the Section 11(2) exception for sharing with another Data Fiduciary authorised by law to obtain the data, where made on a written request for prevention, detection or investigation of offences or cyber incidents, or for prosecution or punishment of offences. * **Section 12 — Correction and erasure:** Request correction of inaccurate or incomplete data and erasure where the specified purpose is spent or consent withdrawn (subject to legal retention). * **Section 13 — Grievance redressal:** Approach the fiduciary's **published grievance mechanism** (contact, timelines) for any grievance on breach of the Act/Rules or on exercise of rights. **Rule 14 requires the fiduciary to publish how to exercise rights and to respond within 90 days** with a reasoned decision; unresolved grievances may be taken to the Board. The Board's digital office and e-filing will be the channel once operational. * **Section 14 — Nomination:** Nominate another person to exercise rights on death or incapacity. * **Rule 7 — Breach intimation to you:** Where your data was part of a breach, the fiduciary must intimate you **without delay** with nature, extent, mitigation and contact — if you received no intimation, note that omission explicitly in your grievance (it is a separate penalty head under Section 33). **Deliver the grievance in writing by email + registered post**, attach the breach evidence, set a **90-day** clock (per Rule 14), and keep delivery proof. Where the fiduciary's breach concerned **children's data**, the same Section 9 + Rule 10 context from the [children's data guide](https://advaslam.com/writing/dpdp-children-data-parental-consent-guide/) strengthens the penalty case. ## What compensation routes survive the DPDP transition? | Route | When it fits | What to file | Ceiling and proof | |---|---|---|---| | **IT Act Section 43A (repeal by DPDP Section 44(2)(a) not yet in force)** | The company handled **sensitive personal data** (SPDI Rules 2011 categories: password, financial, health, sexual orientation, medical, biometrics) without **reasonable security** (IS/ISO 27001 or other prescribed/code-notified standard) causing **wrongful loss** | Application before the **Adjudicating Officer (State IT Secretary)** under **Section 46(1A) IT Act** | AO jurisdiction is **up to five crore rupees**; claims exceeding that lie before the competent court; proof of negligence + causation + loss | | **Consumer Protection Act, 2019** | The data handling was part of a **consumer service** (telecom, banking, edtech, health app, e-commerce) and the breach is a **deficiency in service** | Consumer complaint before District/State Commission | Compensation for loss, mental agony where made out; no PMLA-style penalty, but respondent must answer service-deficiency standard | | **Civil damages** | Contract or tort where duty and loss are made out independent of sector | Civil suit | General damages; limitation **3 years** from cause | | **DPDP Board consequence** | Establishes breach, penalty and directions that **support** the compensation case — but the Act's text does not itself award direct compensation to the victim | — | Board penalties go to the Consolidated Fund; victim's monetary remedy is via the routes above | **Transition note:** The DPDP Act omits IT Act Section 43A, but the omission — DPDP Section 44(2)(a) — is not yet in force. Under DPDP Sections 38(1) and 38(2), the Act is in addition to other laws and prevails only to the extent of any conflict, so the Section 43A and consumer routes continue alongside a Board complaint. In Kerala, Section 43A adjudication has been the most direct compensation forum for SPDI — e.g., hospital or NBFC leaks — while CPA 2019 has been used where the data breach flows from a paid service. A Board complaint strengthens both, because a **Section 33 penalty finding** is strong evidence of safeguard failure. ## How does DPDP's complaint to the Board actually work? 1. **File the Section 11/13 package first.** Access request (Section 11) + grievance (Section 13) with the breach intimation (Rule 7) and your timeline. Request: confirmation of breach scope, recipients under Section 11(1)(b) (subject to the Section 11(2) exception), and erasure under Section 12 where the purpose is spent. 2. **Wait the published response period (up to 90 days) or until an inadequate reply.** Rule 14 requires the fiduciary to publish timelines and respond with reasons. Preserve the reply — or the absence of reply after 90 days — as the Board's threshold evidence. 3. **Complain to the Board under Sections 27-28** with: grievance record, breach evidence, the access request and reply, and a prayer for inquiry, directions and penalty under Section 33. The Board inquires (digital office, e-hearing), may impose penalty per the Schedule, and may direct the fiduciary to remediate, notify affected principals (Rule 7), and strengthen safeguards (Rule 6). **Appeal** lies to the **Telecom Disputes Settlement and Appellate Tribunal (TDSAT)** under **Section 29** within **60 days**. 4. **Parallel compensation.** File the Section 43A / CPA track **without waiting** for the Board's final order — the claims are not mutually exclusive, but a filed Board complaint makes the safeguard-failure record harder for the respondent to contest. **Heads-up:** DPDP Rules 1,2,17-21 were in force from Gazette publication (Nov 2025); substantive fiduciary duties and penalties under Rules 3,5-16,22,23 phase to **18 months from notification (≈ 13 May 2027, displayed as 14 May 2027 on this site)**. The Board as an adjudicatory body is therefore in a **transition year** — early victim actions should not wait, but should recognise that first disposals will set procedure. ## What proof should you preserve today? * The **breach intimation** from the company (or proof you received none — Rule 7's without-delay intimation is itself an obligation). * Your **grievance email with timestamp and postal acknowledgement**, and any **access request** under Section 11 and its reply. * The **misuse evidence**: phishing/SIM-swap/FI activity, bank statement, and — for device/account proof — **hash-preserved originals** under [Section 63 BSA](https://advaslam.com/writing/electronic-evidence-bsa-section-63-certificate-guide/), not forwarded screenshots. ## Primary sources * [DPDP Act, 2023 — Sections 2(j), 3, 11-14, 13, 27-29, 33 and Schedule; Rules 6,7,14](https://indiacode.gov.in/handle/123456789/496508); [DPDP Rules, 2025 (G.S.R. 846(E) 13 Nov 2025)](https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf); [PIB 17 Nov 2025 backgrounder](https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc20251117695301.pdf) * [IT Act, 2000 — Sections 43, 43A, 46(1A)](https://indiacode.gov.in/handle/123456789/496511); [SPDI Rules, 2011](https://indiacode.gov.in/handle/123456789/510187) (reasonable security) * [Consumer Protection Act, 2019](https://indiacode.gov.in/handle/123456789/496115) * [BSA, 2023 — Section 63](https://indiacode.gov.in/handle/123456789/496549); [Cybercrime.gov.in / 1930](https://cybercrime.gov.in) ### Frequently asked questions **What rights do I have if a company leaked my personal data in India?** Under DPDP Sections 11-14 you have rights to access the personal data and the identities of recipients it was shared with, to correction and erasure, to grievance redressal, and to nominate another person on death or incapacity. Under Section 13 you must first use the fiduciary's published grievance mechanism; if unresolved, you may complain to the Data Protection Board, which can inquire and impose penalties under Section 33 and issue directions. Separately, you may have a claim for compensation under Section 43A IT Act for negligent handling of sensitive personal data (the repeal of Section 43A — DPDP Section 44(2)(a) — is not yet in force), and under the Consumer Protection Act 2019 where the data handling was a service deficiency. **Can I get compensation if my data was leaked?** Compensation is not yet fully codified under DPDP — Section 33 provides penalties to the State and Board directions, not direct monetary compensation to the victim in the Act's text. Victim compensation today runs primarily through Section 43A IT Act (compensation for failure to protect sensitive personal data), civil suit for damages, and the Consumer Protection Act 2019 (service deficiency) where personal data handling was part of a consumer service. The Board's penalty and direction do support your compensation case by establishing breach. **How do I complain to the Data Protection Board under DPDP?** First, file a grievance with the fiduciary's published grievance officer (required under Section 13 DPDP and Rule 14). Preserve delivery proof. If not satisfactorily answered, you may complain to the Board with the grievance record, the Section 11 access request where relevant, and the breach evidence. The Board inquires under Sections 27-28 and may impose penalties under Section 33 (up to 250 crore for safeguard failure, 200 crore for children's/breach duties) and issue directions. Appeals lie to the TDSAT under Section 29 within 60 days. **Does the DPDP Act help if old leaked data was non-digital?** DPDP applies to digital personal data — data in digital form or digitised later where the Act applies (Section 3). A purely paper handling with no digital processing is outside DPDP, but may still be actionable under IT Act 43A where the data was sensitive personal data handled without reasonable security, and under consumer or contract law. Check whether the data entered a digital system at any stage (CRM, app, server) — most modern leaks are digital. **What proof should I keep after a data breach notification?** The breach intimation the company sent (Rule 7 requires it without delay with nature, extent, mitigation and contact), your Section 11 access request and its reply, the grievance filing with timestamp, the bank's or platform's statement showing misuse (phishing, SIM swap, fraud), and any dark-web or haveibeenpwned evidence. Keep hash-preserved originals for Section 63 BSA — forwarded screenshots degrade proof. --- ## Telegram Task Scam and Online Job Fraud: How It Works and How to Recover Money in Kerala URL: https://advaslam.com/writing/telegram-job-task-scam-recovery/ Author: Adv. K J Muhammed Aslam, Advocate (Bar Council of Kerala, K/001823/2026) Published 6 September 2026 Practice area: Cyber crime & IT Act matters Lost money to a Telegram task or job scam? Why Section 66D IT Act and Section 318(4) BNS apply, why chasing deeper levels hurts, and 1930 and bank steps. A Telegram or WhatsApp message offering daily income for simple tasks — rate products, like YouTube videos, "prepay to unlock higher commission" — pays small amounts at first, then asks for larger deposits to "complete the set" or "release the balance," and finally blocks your wallet. This is the **prepaid / rating / online job task scam**, one of the most frequently reported cyber fraud patterns in Kerala in 2024-25, and legally it is not a failed business — it is **cheating by personation using a computer resource** under **[Section 66D IT Act](https://indiacode.gov.in/handle/123456789/496511)** and **[Section 318(4) BNS](https://indiacode.gov.in/handle/123456789/496548)**, with the same **1930/CFCFRMS** hold, **bank-lien** and **Magistrate refund (Sections 497-505 BNSS)** logic as any other UPI fraud. The task narrative is the social engineering; the legal response is the same money-trail response. ## How does the task scam actually operate? | Stage | What you see | What is legally happening | |---|---|---| | **Hook** | Message on Telegram/WhatsApp/Instagram: "Part-time job, earn ₹2,000/day, no investment, train from home" — asks you to join a group with a "receptionist" and a "mentor" | Personation — the "receptionist" is not an HR officer; the brand logos and trade marks are misused — **66D/319** | | **Trust building** | You complete 2-3 simple tasks (rate a hotel, like a video) and a small commission is **credited** to a wallet or UPI — you withdraw once | Inducement — the small credit is the consideration that induces the later delivery under **Sec 318(4) BNS** | | **Escalation** | "Prepay ₹10,000 to unlock Level 2; pay ₹47,000 more to complete the set and withdraw — your balance will then double" | Dishonest inducement to deliver property — the core cheating charge; each UPI you send is a separate delivery | | **Trap** | Balance shows growing in the fake dashboard, but withdrawal is blocked — "pay GST / verification / withdrawal fee / risk fund" | Further cheating under the same sections; later demands under **Sec 308 BNS (extortion)** where threats or reputational harm are added | | **Silence** | Mentor stops responding; group is cleared; Telegram handle disappears | Layering — your UPI has already been layered through mules; **CFCFRMS** may show the amount split and moved within hours | A Kerala variant adds **crypto P2P**: "withdraw in USDT to avoid TDS" — the tainted INR is routed to a [crypto P2P](https://advaslam.com/writing/crypto-p2p-account-frozen-fiu-pmla/) hop, making the trail harder but not impossible. ## Why does paying "one more level" make your case weaker, not stronger? Two reasons: 1. **Each payment is a new delivery procured by cheating.** It does not buy release of the earlier delivery — the earlier delivery is already the offence. The scammer's wallet balance screen is not a bank balance and has no legal significance; it is an image generated to induce the next delivery. 2. **It can be used to argue you were a witting participant in layering.** A person who sends successive amounts despite a growing withdrawal block is harder to distinguish, on paper, from a **money mule** who is knowingly passing funds for commission. Stopping payments and preserving the record is therefore legally protective. ## Which sections apply — and do you need an FIR or is NCRP enough? NCRP/1930 is **not** an FIR — it is the hold/routing step. An **FIR under Section 173 BNSS** (old 154 CrPC) is what commences investigation and grounds later holds and refund orders: | Provision | When it is common in task scams | Cognizable? | |---|---|---| | **BNS Sec 318(4)** (cheating inducing delivery) | Every prepaid task deposit you sent | Yes (up to 7 years) | | **BNS Sec 319** (cheating by personation) | Fake HR / brand impersonation | Yes | | **IT Act Sec 66D** (personation using computer resource) | Fake job/brand via Telegram/website | Yes (Inspector+) | | **IT Act Sec 66C** (identity theft) | OTP / credential misuse where account taken over | Yes | | **BNS Sec 308 / 351** | Threats to release data or demand further payment | Yes for s. 308; s. 351 is non-cognizable | File a **written, signed complaint at the district Cyber Police Station** citing these sections, with the full payment list below. Request **FIR under Sec 173 BNSS**; ask for **Section 94 BNSS** production to the receiving banks and platforms, and — where your own account is now frozen as a mule layer by an earlier victim's 1930 — shift to the [bank-freeze guide](https://advaslam.com/writing/bank-account-frozen-cyber-cell-kerala/) and the [35-vs-94 guide](https://advaslam.com/writing/cyber-cell-notice-section-35-vs-94-bnss/) simultaneously. ## How does recovery actually work — the same money trail as UPI fraud? Recovery follows the same **UPI fraud recovery escalator** already detailed step-by-step in the [UPI fraud guide](https://advaslam.com/writing/upi-fraud-complaint-recovery/): 1. **1930/NCRP immediately** — 1930 call + [cybercrime.gov.in](https://cybercrime.gov.in) filing with every UTR/RRN, beneficiary UPI ID, wallet screenshot and amount; CFCFRMS attempts hop-by-hop holds while the money is still inside the banking system. 2. **Write to your bank the same day** — for any leg that was genuinely unauthorised, cite the RBI circular on limiting customer liability in unauthorised electronic banking transactions (06 Jul 2017); for the payments you were induced to authorise (the usual task-scam pattern), the operative remedy is a recall request and the CFCFRMS hold, not a liability reversal. Request recall and preservation of the remittance trail. For task scams the victim's bank is the *remitting* side; the lien is sought on the **receiving mules**, not your own account. 3. **FIR + investigation** — the cyber cell traces the INR hops; Section 94 BNSS to banks/payment intermediaries, Section 106 BNSS lien on amounts found, Section 193 BNSS progress intimation to you. 4. **Magistrate refund** — victim application for release of **lien-marked amounts** traceable to your UTRs under **Sections 497-505 BNSS** before the jurisdictional Magistrate of the receiving account's bank / the FIR — not the bank-freeze writ track, which fits the opposite posture (your account frozen as recipient). **Why timing dominates:** In task-scam matters, the INR is often split across **several mule accounts within hours** and then withdrawn as cash or routed via [P2P USDT](https://advaslam.com/writing/crypto-p2p-account-frozen-fiu-pmla/). A 1930 call in minute 30 seeks holds on real balances; a complaint on day 10 seeks recovery of what is left. ## What bundle should you prepare — the file that moves first? Bring one PDF that every forum asks for: * Every **UPI transaction with UTR/RRN**, beneficiary UPI ID / account, amount and timestamp — highlight the UTRs in your bank statement. * The **task-group screenshots** with **URLs** and timestamps (preserve original device for [Section 63 BSA hash](https://advaslam.com/writing/electronic-evidence-bsa-section-63-certificate-guide/)). * The **wallet / dashboard balance screen** showing blocked withdrawal — label it as a platform-side image, not a bank balance. * Your **1930 / NCRP numbers** and your bank's written acknowledgement of the recall request. * A one-page **chronology** — first message date, each payment date, the date withdrawal was blocked, and the date of complaint. ## Primary sources * [IT Act, 2000 — Sections 66C, 66D, 66, 78](https://indiacode.gov.in/handle/123456789/496511); [BNS, 2023 — Sections 308, 318, 319, 351, 78](https://indiacode.gov.in/handle/123456789/496548) * [BNSS, 2023 — Sections 35, 94, 106, 173, 497-505](https://indiacode.gov.in/handle/123456789/496550); [BSA — Section 63](https://indiacode.gov.in/handle/123456789/496549) * I4C / NCRP at [cybercrime.gov.in](https://cybercrime.gov.in) and 1930; [RBI circular 06 Jul 2017 on limited liability for unauthorised electronic banking transactions](https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=11040) * Kerala State Police Cyberdom / district Cyber Cells (2024-25 task-scam advisories) ### Frequently asked questions **Is a Telegram task scam a cyber crime and which sections apply?** Yes. Prepaid tasks, rating tasks and online job offers that induce payment for commission are typically Section 66D IT Act (cheating by personation using computer resource) and Section 318(4) BNS (cheating inducing delivery of property) — both cognizable — together with Section 66C IT Act where OTP or account access is abused, and Section 319 BNS (cheating by personation). The same sections that govern UPI fraud apply, and the 1930/CFCFRMS hold route is the same first step. **Will I get my money back if I paid into a Telegram task scheme?** Recovery depends on whether amounts are still in the banking chain. An immediate 1930 call or NCRP filing at cybercrime.gov.in can place holds/liens on amounts that have not yet been withdrawn or layered beyond reach — the same CFCFRMS mechanism as UPI fraud. Once funds are layered through multiple mule accounts and withdrawn as cash or crypto, recovery shifts to the criminal investigation and a Magistrate application under Sections 497-505 BNSS for lien-marked amounts — the UPI fraud recovery escalator. **The scammer says paying one more level will release all previous money. Should I pay?** No. The 'pay to release' demand is the defining escalation mechanic of the fraud and paying deeper levels increases loss and can create a separate evidentiary issue. Preserve the task-app screenshots, wallet balances, transaction UTRs and UPI IDs, stop payments, and report immediately via 1930/NCRP and a signed written complaint at the district Cyber Police Station. **Can the scammers be traced if the Telegram account has no real number?** Tracing runs via the money trail and device trail, not the Telegram handle alone. CFCFRMS follows the INR hops even from the second or third layer, and the investigation can issue Section 94 BNSS production orders to banks, payment intermediaries and, where legally available, to the platform under the IT Rules 2021. Success is not guaranteed — especially where funds move to offshore VDA wallets — but the money trail is better evidence than the handle. **Should I approach the High Court writ route as with a bank freeze?** Generally no at the start. The writ/lien track fits where your own account was frozen as a suspected recipient (Section 106 BNSS). Where you are the victim whose money was siphoned into task-scam mules, the route is: 1930/NCRP immediate hold, FIR under 173 BNSS, and victim refund application under 497-505 BNSS before the jurisdictional Magistrate where the holds sit — the UPI fraud recovery guide maps that sequence. --- ## Cyber Complaint Filed on 1930 or NCRP but No Action? How to Escalate in Kerala URL: https://advaslam.com/writing/cyber-complaint-filed-no-action-escalation/ Author: Adv. K J Muhammed Aslam, Advocate (Bar Council of Kerala, K/001823/2026) Published 5 September 2026 Practice area: Cyber crime & IT Act matters 1930 or cybercrime.gov.in complaint, no FIR or update? Escalate via SP/CP written complaint, CPGRAMS and Magistrate direction under Section 175(3) BNSS. A 12-digit NCRP number and a "status: pending" screen are not the end of a cyber complaint in Kerala — they are the point where many files stall. The national pipeline that actually moves a financial fraud case is **1930 / NCRP (CFCFRMS hold + routing to State/District cyber cell) → written complaint / FIR at the jurisdictional police / district Cyber Police Station → investigation and possible court application for frozen money**. When that middle step is missing or silent, the file needs escalation — and escalation is a **paper chain**, not a phone follow-up: **Superintendent / Commissioner in writing → CPGRAMS / State Police portal → Magistrate direction under Section 175(3) BNSS**. ## What happens after you dial 1930 or file at cybercrime.gov.in? | Stage | What happens | Who acts | What you get | |---|---|---|---| | **1930 call or NCRP filing** | CFCFRMS traces the UPI/IMPS trail hop-by-hop and places **holds/liens** on amounts still in the banking chain; complaint routed to the State where the fraud is investigated | I4C/MHA system; receiving banks; State nodal | **NCRP acknowledgment** and 1930 reference, with a transaction trail | | **Written complaint at district Cyber Police Station** | Station examines the NCRP reference, records a **written complaint / general diary**, and where a **cognizable offence** is disclosed (e.g., BNS 318(4) cheating, BNS 319 personation, IT Act 66C/66D) registers **FIR under Section 173 BNSS** | Station House Officer / Cyber Inspector (Sec 78 IT Act rank) | **FIR number**, Section list, copy on request | | **Investigation** | Notice under Sec 35(3) BNSS (appearance) or summons to produce under Sec 94 BNSS, seizure under Sec 106 BNSS, device/data collection, report under Sec 193 BNSS | Investigating Officer | Progress updates on request (Sec 193 BNSS victim intimation) | | **Court refund track** | Victim application for release of lien-marked amount under **Sections 497-505 BNSS** (old 451-459 CrPC) before the jurisdictional Magistrate | Magistrate of the FIR's jurisdiction | Release order where trail is proved | A common gap: the victim files at NCRP and waits, but never files the **written, signed complaint** at the police station that grounds an FIR. An NCRP reference alone does not always convert into an investigation — the signed written complaint closes that gap. ## What does the law require — when must police register an FIR? The **mandatory-FIR rule** from *[Lalita Kumari v. Govt. of U.P., (2014) 2 SCC 1](https://indiankanoon.org/doc/10239019/)* (Constitution Bench) holds: where the information discloses a **cognizable offence**, the police **shall** register an FIR under **Section 154 CrPC / now Section 173 BNSS** — preliminary inquiry is permitted only for limited categories, and delay beyond 7 days requires reasons. One BNSS caveat: under **Section 173(3) BNSS**, for offences punishable with three years or more but less than seven years, the officer in charge may, with the prior permission of an officer not below the rank of Deputy Superintendent of Police, conduct a preliminary enquiry to ascertain a prima facie case within fourteen days. Cyber fraud involving cheating under BNS 318(4) (punishable up to seven years) falls outside that three-to-seven-year window, so a victim's written disclosure of such a fraud triggers the Section 173 duty without discretion to "examine and decide later"; where the facts disclose only IT Act 66C/66D (up to three years), the Section 173(3) preliminary-enquiry option can apply. Where the offence is **non-cognizable** (e.g., certain simple intimidation or defamation alone), the police may need a **Magistrate's direction** to investigate under Section 174 BNSS. ## How should you escalate when the file is silent — the correct order? ### Level 1 — Fix the base: a written, acknowledged complaint at the right station File at the **district Cyber Police Station** (every revenue district in Kerala has one) or the station whose **cyber cell** covers the transaction. Hand over a **signed** representation with: NCRP/1930 numbers, crime-type (e.g., Telegram task scam, UPI phishing), transaction details with UTR/RRN, bank statement with disputed debits highlighted, screenshots with URLs/timestamps (preserved for [Section 63 BSA](https://advaslam.com/writing/electronic-evidence-bsa-section-63-certificate-guide/)), and a prayer for **FIR under Section 173 BNSS** where cognizable. Take a **dated acknowledgement stamp**. The written complaint is not a formality — it is the document later magistrates and SPs call for first. ### Level 2 — Written escalation to the district head If 2-3 weeks pass without FIR or meaningful action despite acknowledgement, send a **written complaint to the District Police Chief (SP/Commissioner)** under the supervisory chain recognised in *[Sakiri Vasu v. State of U.P., (2008) 2 SCC 409](https://indiankanoon.org/doc/1836621/)* — which treats inaction on a complaint as amenable to supervisory direction, and now maps to BNSS Chapter XIII supervision. Send by **registered post + email**, enclosing the NCRP number, the station's acknowledgement, and the earlier complaint. Ask for: registration under Section 173 where cognizable, transfer to the district cyber cell where needed, and progress intimation under **Section 193(3)(ii) BNSS** (IO shall inform progress to informant/victim by any means including electronic communication). ### Level 3 — CPGRAMS / State Police portal (supervisory, not judicial) File a grievance on **CPGRAMS (pgportal.gov.in)** and the **Kerala Police complaint portal** citing the same numbers. CPGRAMS routes to the State nodal and creates a tracked timeline. Treat it as a **parallel supervisory push**, not an investigation trigger — it helps where the file is stuck between desks, not where FIR registration itself is refused after acknowledged disclosure of a cognizable offence. ### Level 4 — Magistrate direction under Section 175(3) BNSS Where registration or investigation is still refused despite acknowledged written disclosure of a cognizable offence, move the **jurisdictional Magistrate** (JMFC/ACJM where the victim resides or where part of the cause occurred, per Zero-FIR logic under Section 173(1) BNSS) for a **direction under Section 175(3) BNSS (successor to Section 156(3) CrPC)**. The Court may: * call for a **status report** from the SHO, * direct **registration and investigation** where cognizable offence is disclosed, * or, where the complaint discloses only a non-cognizable offence or the facts already constitute a complaint case, treat it as a **complaint under Section 223 BNSS** (old 200 CrPC) and proceed accordingly. Attach the full chain: **NCRP/1930 references → station acknowledgement → SP/CP representation with postal proof → CPGRAMS ID → preservation file**. The petition's strength is not drafting flair but **proof that the police were given the chance to act and did not**. **Scope note:** Section 175(3) BNSS itself requires the application to be **supported by an affidavit** (made under Section 173(4)), and the Magistrate considers the police officer's submission before ordering investigation. File the affidavit with documents; do not rely on an unsworn transmission. ## What records actually move a file in Kerala practice? The bundle that both a supervising SP and a Magistrate look for is the same: 1. **Identifiers:** NCRP acknowledgement, 1930 reference with date/time, FIR/complaint number if any, and the bank's CFCFRMS lien/UTR numbers. 2. **Money trail:** Bank statement (highlight disputed debits), UPI transaction details with UTR, beneficiary name/UPI ID, and — for P2P or task-scam layers — the exchange/P2P order book (see [crypto P2P guide](https://advaslam.com/writing/crypto-p2p-account-frozen-fiu-pmla/)) or task-app screenshots. 3. **Evidence preserved for Section 63 BSA:** Original-device exports with **hash**, not forwarded copies — hash + certificate will be needed if the case proceeds. 4. **Chronology:** Dates of NCRP, written complaint, acknowledgements, and escalation letters — a one-page dated timeline. A repeated mistake is quoting only a **cybercrime.gov.in ticket** in escalation with no **signed station complaint** — the ticket is a routing number, not an FIR predicate. ## What this escalation does not do * It does not **convert a civil debt recovery into a cyber crime.** Where money was lent voluntarily and recovery is the real dispute, the FIR track is misused — use the civil or consumer route ([how to respond to a legal notice](https://advaslam.com/writing/how-to-respond-legal-notice/); [civil-consumer practice](https://advaslam.com/practice/civil-consumer/)). * It does not **guarantee an arrest or immediate refund.** Investigation and arrest follow the BNS/BNSS standards; the refund of lien-marked money is a separate Magistrate application under Sections 497-505 BNSS (see [UPI fraud guide](https://advaslam.com/writing/upi-fraud-complaint-recovery/)). ## Primary sources * [BNSS, 2023 — Sections 173, 174, 175(3), 193, 35, 94, 503](https://indiacode.gov.in/handle/123456789/496550); [BNS, 2023](https://indiacode.gov.in/handle/123456789/496548); [IT Act — Sec 78](https://indiacode.gov.in/handle/123456789/496511) * *Lalita Kumari v. Govt. of U.P.*, **(2014) 2 SCC 1** (FIR mandatory for cognizable); *Sakiri Vasu v. State of U.P.*, **(2008) 2 SCC 409** (supervisory route) * *[Satender Kumar Antil v. CBI](https://indiankanoon.org/doc/13959070/)* line on Section 35/41A and physical service (21 Jan & 16 Jul 2025 orders; the 16 Jul 2025 order is 2025 INSC 909) * I4C / NCRP at [cybercrime.gov.in](https://cybercrime.gov.in) and 1930 helpline (Ministry of Home Affairs) * [BSA, 2023 — Section 63](https://indiacode.gov.in/handle/123456789/496549); [Constitution — Articles 21, 226](https://indiacode.gov.in/document-grid/d5475e8d-1998-4ac8-8694-82f941074bb7) ### Frequently asked questions **Is a 1930 or NCRP complaint the same as an FIR?** No. A 1930 call or NCRP filing at cybercrime.gov.in triggers the CFCFRMS hold/follow-the-money chain and a reference number, but an FIR under Section 173 BNSS (old 154 CrPC) is a separate, jurisdictional police record that commences investigation. Cyber cells often act on the NCRP reference before FIR, but a victim seeking investigation, seizure and court refund of frozen money will usually need the FIR as well. **How long should I wait before escalating a cyber complaint?** For financial fraud, act within days, not months — the banking trail cools while a file sits. If a written FIR complaint at the jurisdictional or district Cyber Police Station has drawn no action for 2-3 weeks despite acknowledgement, escalate in writing to the District Police Chief / Commissioner, and then to the jurisdictional Magistrate under Section 175(3) BNSS (old 156(3) CrPC). Keep every acknowledgement — the escalation chain is paper-driven. **Can a Magistrate direct police to register an FIR or investigate my cyber complaint?** Yes. Under Section 175(3) BNSS (successor to Section 156(3) CrPC), a Magistrate empowered to take cognizance may order investigation — including registration where a cognizable offence is disclosed — after examining the complaint and calling for a report if needed. The Supreme Court's Lalita Kumari (2014) rule — mandatory FIR for cognizable offences — and Sakiri Vasu (2008) supervisory route remain the framework, with BNSS 2023 renumbering. **What number or status should I quote when escalating?** Your NCRP acknowledgement number (cybercrime.gov.in), the 1930 call reference and date, the written complaint/FIR number if given, and the bank's CFCFRMS lien or transaction reference numbers. Attach the transaction screenshot with UTR/RRN, your bank statement, and the preservation file — each escalation forum asks for the same core packet. **Should I file RTI to know what happened to my cyber complaint?** RTI can seek status information from the police's public information officer where permissible, but investigation details may be exempted under Section 8(1)(h) RTI Act where disclosure would impede investigation. RTI is a supplementary transparency tool — not a substitute for the Section 175(3) BNSS Magistrate route or the SP/CP supervisory complaint where investigation has stalled. --- ## Instagram or Social Media Account Hacked in Kerala? How to Recover It Under the IT Rules URL: https://advaslam.com/writing/instagram-hacked-account-recovery-it-rules/ Author: Adv. K J Muhammed Aslam, Advocate (Bar Council of Kerala, K/001823/2026) Published 5 September 2026 Practice area: Cyber crime & IT Act matters Instagram hacked? IT Rules 2021 route: 7-day grievance, 2-hour impersonation track, 3-hour government-notice takedown and the FIR sections that apply. Your Instagram — or Facebook, X or Gmail — now shows a different email and phone, and the in-app "forgot password" loop fails because the recovery path has been replaced. This is not a help-desk ticket alone; under the **[Information Technology Act, 2000](https://indiacode.gov.in/handle/123456789/496511)** it is commonly **identity theft and personation** (Sections **66C** and **66D**, plus **66**), and under the **[IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 as amended 10 Feb 2026 (in force 20 Feb 2026)](https://egazette.gov.in)** the platform has **time-bound grievance and takedown duties** — including a **2-hour** path where the hijack is used for impersonation. Two tracks filed together — **platform grievance + police complaint** — recover more accounts than either alone. ## Which provisions actually govern an account hijack? | Track | Provision | What it does | Clock | |---|---|---|---| | **Crime** | **IT Act Sec 66C** (identity theft) | Fraudulent/dishonest use of your **electronic signature, password or any other unique identification feature** | FIR → investigation by Inspector+ (Sec 78) | | | **IT Act Sec 66D** (cheating by personation using computer resource) | Cheating by personation **using a computer resource** — the hacker posting as you | Up to 3 years + ₹1 lakh, cognizable, bailable | | | **IT Act Sec 66** (computer-related offence via 43) | Dishonest access/damage to your computer resource (the account) | Up to 3 years / ₹5 lakh | | | **BNS Sec 308, 318, 351** | Extortion, cheating and intimidation where ransom or fraud follows the hijack | 308: up to 7 years | | **Platform** | **IT Rules 2021 Rule 3(2)** — grievance | Resident Grievance Officer: general **7 days**, unlawful-content **36 hours**, impersonation/morphed/nudity **2 hours** (post-Feb 2026) | From your grievance | | | **Rule 3(1)(d)** — takedown on actual knowledge | **3 hours** for unlawful content from actual knowledge via **court order or authorised government notification** | From order/notification, not from grievance | | | **Rule 4** — SSMI duties (>50 lakh users) | Significant social media intermediaries (Meta, X, Google) must publish monthly transparency reports, enable voluntary user verification, and act faster on impersonation — the route that makes the 2-hour path credible | Continuous | Section 79 IT Act safe harbour for intermediaries depends on due diligence — Rule 3 compliance is that due diligence. ## How should you file the platform grievance so it triggers the 2-hour track? Where the hijack is used to **impersonate you** (posting from your account, DM-ing your contacts), frame the grievance explicitly as **impersonation under Rule 3(2)(b) / Rule 4** — that engages the **2-hour** user-grievance path. Include: 1. **Account identification:** Exact handle/URL (`https://instagram.com/your.handle`), account creation email/phone, and your government ID proof. 2. **Hijack timeline:** Date/time you lost access, the new recovery email/phone showing replacement, and the first impersonation post or DM with **URL** (not just screenshot). 3. **Label the category:** Write "Complaint under **Rule 3(2) and Rule 4** — impersonation / unauthorised access to user account (IT Rules 2021 as amended 10 Feb 2026) — request 2-hour handling as impersonation." Citing the rule and the time track is not advocacy — it is the correct head for prioritisation. 4. **Preserve for Section 63 BSA:** Export the impersonation post's URL and metadata; keep the original-device export with hash — see [Section 63 BSA guide](https://advaslam.com/writing/electronic-evidence-bsa-section-63-certificate-guide/). 5. **File in two places:** The platform's **grievance form + email to the published Resident Grievance Officer** (every SSMI must publish name and contact), and — where the hack is part of a fraud — a parallel **government-notified** track (police or MeitY-authorised agency) is what starts the **Rule 3(1)(d) 3-hour** clock. Your grievance alone does not trigger 3(1)(d). A common failure: reporting via the in-app "Report a problem" with no URL, no impersonation label, and no grievance-officer email — the ticket is then triaged as low priority and the 2-hour path is never engaged. ## How does the police complaint fit — and where do you file it in Kerala? File a **written, signed complaint at the district Cyber Police Station** (every Kerala revenue district has one) or the station whose cyber cell covers the account, citing **IT Act 66C/66D/66** and — where ransom or impersonation harm is made out — **BNS 308/319/351** (and **POCSO** where a minor's intimate image is involved). Attach: account URL, timeline, the impersonation post URLs, the hijack email/phone change screenshot, and the platform grievance acknowledgement. Request an **FIR under Section 173 BNSS** where cognizable ingredients are disclosed — Lalita Kumari remains the mandatory-FIR rule — and, if the account is used to freeze others' money, note the **Section 106 BNSS / 503 BNSS** implications for lien. For escalation where a filed NCRP/1930 reference draws no FIR, use the chain in the [NCRP escalation guide](https://advaslam.com/writing/cyber-complaint-filed-no-action-escalation/) — SP/CP written representation → CPGRAMS → Magistrate direction under **Section 175(3) BNSS**. ## What about accounts used to impersonate you rather than hijack yours? Where a **different** account clones your name and photo to scam your contacts, the same **Rule 3(2)(b) 2-hour impersonation** and **Rule 3(1)(d) 3-hour** tracks apply, and the crime sections shift emphasis to **66D** (personation) and **319 BNS** (cheating by personation), plus **66E / 67 / 351** where morphed images are used. File both the **platform impersonation report** (with both URLs — yours and the fake) and the police complaint. Courts in Kerala and the Delhi High Court have granted **John Doe / Ashok Kumar** injunctions and disclosure of subscriber data where impersonation is used for fraud — the written grievance with URLs is the pre-condition for that route. ## What reduces recovery time — a short checklist * **Enable two-factor authentication (TOTP app, not SMS alone)** before hijack, and keep a backup code offline. * **Do not click recovery links sent by the impersonator** — they phish the replacement credentials. * **Keep the original-device proof** — the date your recovery email changed, as recorded on the device and by the platform's security email, is the best timestamp for the investigation. * **Do not transfer money to the hijacker** for "return" of the account — use the police + government-notified takedown track instead. ## Primary sources * [IT Act, 2000 — Sections 43, 66, 66C, 66D, 69A, 78, 79](https://indiacode.gov.in/handle/123456789/496511) * [IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 as amended 10 Feb 2026 (in force 20 Feb 2026)](https://egazette.gov.in) — Rules 3(1)(d), 3(2), 4 * [BNSS, 2023 — Sections 35, 94, 173, 175, 193](https://indiacode.gov.in/handle/123456789/496550); [BSA, 2023 — Section 63](https://indiacode.gov.in/handle/123456789/496549) * [BNS, 2023 — Sections 308, 318, 319, 351](https://indiacode.gov.in/handle/123456789/496548) ### Frequently asked questions **My Instagram was hacked and the recovery email changed. What is the legal route beyond the in-app form?** Use the IT Rules 2021 legal track in parallel to the in-app recovery. File a grievance with the platform's Resident Grievance Officer under Rule 3(2) (now 7-day resolution; 36 hours for unlawful-content and 2 hours for impersonation/morphed-image cases), provide the account URL, your ID proof, and the hijack evidence. Intermediaries must also remove or disable access to unlawful content within 3 hours of actual knowledge via a court order or authorised government notification under Rule 3(1)(d) (down from 36 hours after the 10 Feb 2026 amendment); the 2-hour removal for non-consensual impersonation is the Rule 3(2)(b) user-grievance track. **Which sections apply when a social media account is hacked?** Commonly: IT Act Section 66 (computer-related offence via dishonest use), Section 66C (identity theft — fraudulent use of your password/electronic signature/unique identifier), Section 66D (cheating by personation using computer resource where the hacker impersonates you), and where ransom is demanded, BNS Sections 308 (extortion) and 351 (criminal intimidation). The IT Rules 3(1)(d) and 4 (for SSMIs) then supply the platform-due-diligence duties. **How long must Instagram or Facebook take to act on my hacking complaint?** Under Rule 3(2) as amended 10 Feb 2026 (in force 20 Feb 2026): general grievances in 7 days (down from 15), unlawful-content grievances in 36 hours (down from 72), and complaints about impersonation, morphed images, nudity or child safety in 2 hours (down from 24). The separate Rule 3(1)(d) clock — 3 hours for unlawful content — runs from actual knowledge via a court order or authorised government notification, not from your grievance alone; the 2-hour impersonation/morphed track is Rule 3(2)(b). File both tracks. **Can I file an FIR for a hacked Instagram account in Kerala?** Yes, where the ingredients of cheating, impersonation, identity theft or extortion are made out — which a hijacked account typically is. File a written complaint at your district Cyber Police Station citing IT Act 66C/66D/66 and BNS 308/318/319, with the account URL, timeline, and preserved screenshots with hash for Section 63 BSA. Cybercrime.gov.in allows confidential filing as well, but the district FIR is what grounds investigation under BNSS. **The hacker is extorting me to pay to get the account back. Should I pay?** No. Payment rarely restores control and funds the next impersonation. Preserve the extortion demand (chat, UPI ID, phone number), file the platform grievance and the police complaint, and let the Rule 3(1)(d) / investigation track operate. Paying also complicates proving extortion under Section 308 BNS. --- ## Crypto P2P and UPI Amount Frozen: Why Your Bank or Exchange Account Was Blocked and How to Respond URL: https://advaslam.com/writing/crypto-p2p-account-frozen-fiu-pmla/ Author: Adv. K J Muhammed Aslam, Advocate (Bar Council of Kerala, K/001823/2026) Published 4 September 2026 Practice area: Cyber crime & IT Act matters P2P USDT proceeds or crypto UPI flagged and account frozen? PMLA and FIU-IND reporting, Section 194S TDS, Section 106 BNSS lien and the Kerala writ route. A UPI credit from a crypto P2P buyer — typically a USDT sale on an exchange — has landed in your bank account, and the account is now under a debit freeze citing a cyber cell requisition. The trade itself is **not banned**, but two regulatory overlays intersect on the same rupee: **PMLA reporting as a virtual digital asset (VDA) service** and **Section 106 BNSS seizure** where the rupee is already flagged as suspected stolen property in a prior fraud's money trail. The first explains why the exchange enforces KYC and files STRs; the second explains why your bank was instructed to hold the amount. Treat them together and the de-freeze path becomes clear. ## How is crypto regulated in India today — and what does FIU-IND have to do with it? | Year / instrument | What it did | Where to verify | |---|---|---| | **Finance Act, 2022 — Sections 115BBH & 194S Income-tax Act** | VDA income taxed at **30% + surcharge/cess** from 01 Apr 2022; **1% TDS under Sec 194S** on VDA transfer from 01 Jul 2022 | [Income-tax Act, 2025 — e-Gazette](https://egazette.gov.in/WriteReadData/2025/265620.pdf) (from 1 April 2026: Section 194(1), Table Sl. No. 4 and Section 393(1), Table Sl. No. 8(vi)) | | **07 Mar 2023 — PMLA Gazette notification (Ministry of Finance)** | **VDA service providers** (exchange between VDA and fiat, VDA-to-VDA, transfer, safekeeping, issuance participation) declared **reporting entities** under PMLA Sec 2(1)(wa) | [PMLA Gazette 07 Mar 2023 — S.O. 1072(E)](https://egazette.gov.in/WriteReadData/2023/244184.pdf) | | **PMLA Sec 12, 12A + Maintenance of Records Rules, 2005** | Registered VDA providers must **KYC clients**, maintain records and **file STRs/ CTRs/ CCRs** with FIU-IND | [PMLA Sec 12](https://indiacode.gov.in/handle/123456789/496293) | | **Dec 2023 – Jan 2024 — FIU-IND offshore action** | FIU issued compliance show-cause to offshore VDA exchanges serving Indian users without registration; several URLs blocked via **MeitY blocking orders under Sec 69A IT Act** until registration; later phased compliance/penalties | [FIU-IND press releases Dec 2023–Jan 2024](https://fiuindia.gov.in) | | **RBI position** | No ban on holding or trading VDAs, but regulated entities (banks) must do **enhanced due diligence**; repeated RBI Financial Stability messaging warns on VDA risks | [RBI Financial Stability Reports 2022–2024](https://www.rbi.org.in) | A Kerala trader therefore faces no "crypto is illegal" charge, but faces a fully documented **KYC → STR → requisition** pipeline: the exchange's KYC and transaction monitoring flags the INR leg, the fraud victim's 1930 report in another state's case flags the same UPI amount, and the cyber cell's CFCFRMS follow-the-money reaches the P2P seller's bank as layer 2 or 3. ## Why does a P2P sale freeze more often than an exchange spot trade? Because the INR leg is **peer-to-peer, not exchange-pooled**. On an exchange spot trade, the buyer pays the exchange and the exchange pays you — one regulated ledger. On P2P, the buyer sends UPI directly to your bank account against the USDT release — your bank sees an **inbound UPI from an individual who may be a mule**, carrying whatever taint that person's own account carries. Layering frauds exploit exactly this: the mule's tainted balance is "cleaned" by buying USDT via P2P, leaving the seller's bank as the next CFCFRMS hop. The freeze amount is usually **the specific UPI credit**, but older bank practice blocked the entire account. The Kerala High Court's **Dr. Sajeer v. RBI line (WP(C) No. 12960 of 2023, and the orders following it)** now pushes practice to a **lien limited to the disputed credit**, with the balance operational — the same relief sought in the [bank-freeze guide](https://advaslam.com/writing/bank-account-frozen-cyber-cell-kerala/). ## What should you do in the first week — the file that gets acted on? Prepare **five packets**, because five different forums will ask for the same material: 1. **Freeze identification.** Bank's written freeze note — requisition reference, NCRP acknowledgment, cyber cell name and crime number, date and lien amount — and the bank statement highlighting the disputed UPI credit. 2. **Exchange P2P packet.** Order ID, ad/posting ID, counterparty UID and verification level, quantity and price, timestamp, full chat export, and — for on-chain legs — the blockchain transaction hash and explorer link. Export as PDF with metadata; preserve the original device for [Section 63 BSA hash](https://advaslam.com/writing/electronic-evidence-bsa-section-63-certificate-guide/). 3. **KYC/AML posture.** Exchange KYC level (CKYC/PAN/Aadhaar), FIU-registered exchange confirmation, and bank KYC. This shows reporting-entity compliance, not intent to launder. 4. **Tax posture — but no false comfort.** Filed ITR showing 115BBH computation and 194S TDS deposit evidence (Form 26QE / exchange TDS statement). Tax compliance supports bona fides but **does not** sanitise a tainted counterparty's funds — be candid about that. 5. **Narrative + undertaking.** Three to four sentences: who the buyer was (as known from the P2P ad), why the trade occurred, how the price was set, when the UPI arrived relative to the USDT release; plus a written undertaking to keep the disputed amount available and to cooperate. Send packet 1-5 to the **investigating officer** (email *and* registered post) with a copy to your bank's nodal officer and FIU cell, seeking a **lien limited to the disputed amount** and release of the balance. Give the representation **2-4 weeks**; then escalate per the three remedies escalator in the bank-freeze guide: **Section 503 BNSS before the jurisdictional Magistrate** (where the FIR is registered) and **Article 226 writ before the Kerala High Court** where the freeze is disproportionate — both already charted step-by-step there and not repeated here. ## How does tax interact with the freeze — does paying 30% protect you? No. Tax and crime-trail are separate legal tracks under the Finance Act, 2022 vs PMLA/BNS: * **Tax track:** 30% flat tax (115BBH), no loss set-off, no expense deduction beyond acquisition cost, plus 1% TDS (194S) and reporting. Advance tax applies where Annual VDA gains warrant it. * **Crime-trail track:** If the rupees you received are the subject matter of a fraud complaint in the CFCFRMS, the amount is suspect property under **Section 106 BNSS** regardless of tax payment. The investigating cell does not adjudicate tax; it follows the money. The Court's de-freeze order therefore typically **preserves a lien on the disputed amount** rather than returning it immediately — tax compliance supports your bona fides for the non-disputed balance, not for release of the tainted credit itself. ## What reduces recurring risk if you continue P2P? * **Screen the buyer inside the exchange before release:** High completion rate, verified KYC level, account age, price near market — not a premium that prices in taint. * **Invoice each trade.** A UPI credit you can match to a P2P order ID within minutes is a credit you can get released; anonymous "UPI collect" style receipts are the hardest to defend. * **Segregate accounts.** Keep P2P collections in a dedicated current account, distinct from salary and working-capital accounts — a freeze then stops one stream, not the business. * **Sweep balances daily** and maintain the five-year transaction records Section 12 of the PMLA requires your exchange to keep — your own mirror records should match. * **Know the GST boundary:** Under current CBIC guidance, crypto **is not** currency; GST treatment of platform fees and VDA activities has been separately clarified — do not conflate VDA tax with GST on exchange fees, and keep fee invoices. ## Primary sources * [PMLA, 2002 — Sections 2(1)(wa), 12, 12A](https://indiacode.gov.in/handle/123456789/496293); [PMLA (Maintenance of Records) Rules, 2005](https://fiuindia.gov.in/files/AML_Legislation/notification.html) * Finance Act, 2022 amending the Income-tax Act, 1961 — Sections 115BBH, 194S (CBDT Circulars on 194S TDS on VDAs); successor provisions in the [Income-tax Act, 2025](https://egazette.gov.in/WriteReadData/2025/265620.pdf) from 1 April 2026 * Gazette notification **07 Mar 2023** — VDA services as PMLA reporting entities; [FIU-IND press releases Dec 2023–Mar 2024](https://fiuindia.gov.in) on offshore VDA compliance * [IT Act, 2000 — Section 69A blocking](https://indiacode.gov.in/handle/123456789/496511) * [BNSS, 2023 — Sections 35, 94, 106, 503, 528; Article 226](https://indiacode.gov.in/handle/123456789/496550) * [BSA, 2023 — Section 63](https://indiacode.gov.in/handle/123456789/496549) * *Dr. Sajeer v. RBI* (Kerala High Court, WP(C) No. 12960 of 2023) and the orders following it on lien-limited de-freeze — cross-referenced in bank-freeze guide ### Frequently asked questions **Why was my bank account frozen after a crypto P2P sale?** A buyer paid you with funds already flagged in the CFCFRMS/NCRP chain — often from a prior UPI or loan-app fraud — and the amount is treated as suspected stolen property under Section 106 BNSS (old 102 CrPC). The investigating cyber cell in that buyer's fraud case issued a requisition to your bank to debit-freeze or lien-mark the amount. Being in the money trail does not make you an accused, but the account stays held until the trail is verified. See the full freeze guide for the police-ordered route. **Is crypto legal in India and why does my exchange ask for KYC?** Trading in crypto / virtual digital assets (VDAs) is not prohibited, but it is regulated as a reporting activity. Since 07 Mar 2023 (PMLA Gazette notification), VDA service providers — exchanges, custodians, transfer facilitators — are reporting entities under the Prevention of Money-laundering Act, 2002, must register with FIU-IND, conduct KYC under the PMLA Maintenance of Records Rules, and file STRs and CTRs. Offshore VDA exchanges serving the Indian market were issued FIU compliance show-cause notices (Dec 2023) and several were blocked on MeitY orders (Jan 2024) until registration. KYC is therefore not optional. **What taxes apply to crypto P2P trades in India?** Since 01 Apr 2022: income from transfer of VDAs is taxed at a flat 30% plus surcharge and cess under Section 115BBH Income-tax Act, with no deduction except cost of acquisition and no set-off of losses from other income (and VDA losses cannot be set off inter-VDA). Since 01 Jul 2022: 1% TDS under Section 194S on transfer of VDA — including P2P sales — to be deducted by the payer/exchange and deposited, with Form 26QE reporting by the buyer in peer-to-peer cases. From 1 April 2026 the Income-tax Act, 1961 is replaced by the Income-tax Act, 2025, which carries the same 30% rate in Section 194(1) (Table: Sl. No. 4) and the 1% TDS in Section 393(1) (Table: Sl. No. 8(vi)). Compliance does not legalise the underlying money trail — a tax-paid P2P sale can still be frozen if the counterparty's funds are tainted. **Can a pre-arrest notice under Section 35 BNSS come on WhatsApp for a crypto case?** No — the same rule applies. Supreme Court (Satender Kumar Antil, 21 Jan & 16 Jul 2025, 2025 LiveLaw SC 751) held Section 35 BNSS notices cannot be served via WhatsApp/email; they require physical service under Chapter VI BNSS. Section 94 BNSS requisitions (to banks/exchanges) may be electronic. If a crypto investigation cites Section 35, insist on proper service and respond within the bank SOP or police-notice track — see the 35-vs-94 guide. **What documents help get a crypto P2P freeze released?** The 1930/NCRP or bank requisition reference, the exchange P2P order book (order ID, ad ID, counterparty UID, price, quantity, chat), the blockchain transaction hash where applicable, your KYC and FIU-compliant exchange statements showing the INR leg, the bank statement highlighting the disputed credit, tax filings showing 115BBH/194S compliance, and a hash-preserved export of chat for Section 63 BSA. The Kerala High Court practice for police-ordered freezes (Dr. Sajeer line) is to limit the lien to the disputed amount — the same de-freeze with lien route applies whether the underlying trade was P2P or a marketplace sale. --- ## Loan App Harassment and Recovery Threats: RBI Digital Lending Rules and Your Legal Options URL: https://advaslam.com/writing/loan-app-harassment-rbi-digital-lending/ Author: Adv. K J Muhammed Aslam, Advocate (Bar Council of Kerala, K/001823/2026) Published 4 September 2026 Practice area: Cyber crime & IT Act matters Loan app agents calling contacts, morphing photos or threatening you? RBI Digital Lending Directions 2025, IT Act and BNS sections, and the complaint route. A loan app that accesses your contacts, downloads your gallery, morphs a photo, then threatens to send it to your family on WhatsApp unless you pay — and a recovery agent who calls before 8 a.m., after 7 p.m., or posts in your social feed — is not a civil recovery. Under the **[RBI Guidelines on Digital Lending (02 Sep 2022)](https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=12382)** consolidated into the **[Reserve Bank of India (Digital Lending) Directions, 2025 (08 May 2025, DOR.STR.REC.19/21.07.001/2025-26)](https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=12848)** read with the **[RBI Outsourcing circular on Recovery Agents (12 Aug 2022)](https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=12378)**, plus **[Sections 66C, 66D, 66E, 67 of the IT Act](https://indiacode.gov.in/handle/123456789/496511)** and **[Sections 308, 351, 78, 336 BNS](https://indiacode.gov.in/handle/123456789/496548)**, that conduct is harassment, is prohibited, and has a defined complaint route. ## What do the RBI digital lending rules actually require? The framework distinguishes **Regulated Entities (REs)** — banks, NBFCs, co-op banks, housing finance companies — from **Lending Service Providers (LSPs)** and **Digital Lending Apps (DLAs)** who act as the RE's agents. Five rules are decisive in harassment complaints: | RBI rule | What it says | Paragraph | |---|---|---| | **No pool accounts** | All disbursal and repayment must be **directly between borrower's bank account and RE's bank account** — no pass-through or pool account of LSP/DLA. Fees to LSPs are paid **by the RE, not by you**. | 2022 Para 3; 2025 Direction 9(i)-(iii) | | **Key Fact Statement before contract** | Standardised **KFS** with **APR**, all fees, penal charges, tenor, repayment schedule, **cooling-off / look-up period**, recovery mechanism, **grievance officer** details, and privacy policy must be provided before execution; digitally signed documents must flow to you on email/SMS. | 2022 Annex I Para 4-5; 2025 Direction 8 | | **Cooling-off** | At least **1 day** for all loans (board-fixed, disclosed in KFS); exit by paying principal + proportionate APR without penalty; the RE may retain a disclosed one-time processing fee. (The 3-day/1-day tenor split was the 2022 regime.) | 2022 Para 8; 2025 Direction 10 | | **Data minimisation** | Collection by DLAs/LSPs must be **need-based with prior explicit consent and audit trail**. DLAs must **desist from accessing contacts, call logs, files, media** beyond one-time camera/microphone/location for onboarding with explicit consent. Consent must be granular, revocable, purpose-disclosed, and deletable on demand; data stored only in India. | 2022 Para 10-11; 2025 Directions 12–13 | | **Grievance + liability** | RE must have a **nodal grievance officer** (displayed on RE, LSP and DLA, and in the KFS) and a DLA complaint facility; **outsourcing does not dilute** the RE's obligations — RE remains liable for LSP acts/omissions; if unresolved in **30 days**, escalate to **RB-IOS**. | 2022 Para 6, 12; 2025 Directions 5(vii), 11; reaffirmed 14 Feb 2023 FAQs | | **Recovery agent duties** | RE must communicate the **recovery agent's details by email/SMS before the agent contacts you** (14 Feb 2023 FAQs), and under the 12 Aug 2022 recovery-agent circular agents **must not** intimidate, harass, humiliate, call before 8 a.m. or after 7 p.m., threaten or send inappropriate messages on mobile/social. | FAQs 14 Feb 2023; Circular DOR.ORG.REC.65/21.04.158/2022-23 | A genuine RE-backed loan leaves a KFS, an APR, and a direct bank-to-bank payment trail. A loan app that offers money on WhatsApp, takes a contact-list permission, and demands repayment to a personal UPI ID fails at least three of these tests — a marker that the lender may be **unregulated**, with lending legally conductible only by entities regulated by RBI or permitted under other law (2022 Press Release para 3). ## Which criminal provisions apply to the harassment? The same conduct that violates the RBI framework often violates the IT Act and BNS simultaneously — the FIR commonly carries a mix: | Conduct | Primary sections | What they cover | |---|---|---| | Accessing contacts / gallery without valid consent, sharing personal data with third parties | IT Act Sec 72A; DPDP Act, 2023 ss.4 & 6 (consent-based processing, phasing in from 2027) | Disclosure in breach of lawful contract with intent/knowledge of wrongful loss — since 30 Nov 2023 a civil penalty of up to ₹25 lakh, not an offence (Jan Vishwas Act, 2023) | | Morphing your photo, creating a fake nude or threat image | IT Act Sec 66E (privacy), 66D (personation), 67/67A (obscene/sexually explicit electronic content); BNS Sec 336 (forgery), Sec 78 (stalking of a woman) | 66E: up to 3 years/₹2 lakh; 67A: 5 years first/7 years subsequent; BNS 78: up to 3-5 years | | Sending that image to your contacts or threatening to | IT Act Sec 67/67A; BNS Sec 308 (extortion: fear to deliver money), Sec 351 (criminal intimidation), Sec 78 | Extortion: up to 7 years (10 if fear of death or grievous hurt) — coercing debt payment by threats falls here | | Repeated abusive calls on phone/social | BNS Sec 351; 12 Aug 2022 circular (8am-7pm rule); IT Rules 3(2) grievance | Bar on intimidation and odd-hour calls | | Impersonating police or court to threaten arrest | IT Act Sec 66D; BNS Sec 319 (cheating by personation), 308 | See [digital arrest guide](https://advaslam.com/writing/digital-arrest-scam-india-what-to-do/) for the same pattern | A separate **takedown clock** now applies to morphed images: under the **IT (Intermediary Guidelines) Rules 2021 as amended 10 Feb 2026 (in force 20 Feb 2026)**, intermediaries must remove or disable access to unlawful content — including non-consensual nudity or morphed imagery — **within 3 hours** of actual knowledge via a court order or authorised government notification under Rule 3(1)(d), and must remove or disable such content **within 2 hours** of your user grievance under Rule 3(2)(b). File the platform grievance with URLs alongside the police complaint. ## What should you do step by step — the order that matters? 1. **Preserve first.** Screenshot the threats, the morphed image, the app permission screen showing contact/gallery access, the KFS if any, the UPI/repayment demand, and the call log with times. Keep the original device — see [Section 63 BSA guide](https://advaslam.com/writing/electronic-evidence-bsa-section-63-certificate-guide/). 2. **Stop paying to "remove" the image.** Payment confirms leverage and rarely ends the demand. 3. **Write to the RE's nodal grievance officer** (name and contact must be on the RE/LSP/DLA and in the KFS). Attach the preserved material, cite the Guidelines paragraphs, and demand cessation of contact-list use and harassment. Keep delivery proof. 4. **File a cyber complaint** at [cybercrime.gov.in](https://cybercrime.gov.in) and 1930, and a written complaint at the jurisdictional police / district Cyber Police Station citing the sections above. Cybercrime.gov.in allows confidential reporting. 5. **File a platform grievance** with each platform hosting the morphed image/content — cite IT Rules 2021 Rule 3(1)(d) (3-hour court/government track) and Rule 3(2)(b) (2-hour user-grievance track for nudity, morphed or impersonation content). 6. **If unresolved in 30 days, escalate to RB-IOS** at [cms.rbi.org.in](https://cms.rbi.org.in) against the RE (not the LSP). The ombudsman route is record-based — the written grievance and the 30-day lapse are the foundation. ## What if the lender is not an RBI-regulated entity at all? Then the RBI framework's RE-centric route is incomplete — the entity sits in the **third category** of the 10 Aug 2022 Press Release: lending not by an RE or under other law, for which the Working Group recommended legislative and institutional intervention. The remedy is primarily criminal and platform-based: police (Sections 308, 351, 78, 66C-E), IT Rules takedown, and reporting the app to **MeitY / Google Play / Sachet** (sachet.rbi.org.in) as an unauthorised lending app. Do not assume an app on the Play Store is an RE — the KFS and direct RE-to-you bank trail are the verification tests. ## Primary sources * [RBI Guidelines on Digital Lending (02 Sep 2022, DOR.CRE.REC.66/21.07.001/2022-23)](https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=12382) * [RBI (Digital Lending) Directions, 2025 (08 May 2025, DOR.STR.REC.19/21.07.001/2025-26)](https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=12848) * [RBI Recovery Agents circular (12 Aug 2022, DOR.ORG.REC.65/21.04.158/2022-23)](https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=12378) * [RBI Press Release: Recommendations of WGDL — Implementation (10 Aug 2022)](https://www.rbi.org.in/Scripts/BS_PressReleaseDisplay.aspx?prid=54187) * [IT Act, 2000 — Sections 66C, 66D, 66E, 67, 67A, 72A](https://indiacode.gov.in/handle/123456789/496511) * [BNS, 2023 — Sections 78, 308, 336, 351](https://indiacode.gov.in/handle/123456789/496548) * [BNSS, 2023 — Sections 35, 94](https://indiacode.gov.in/handle/123456789/496550); [BSA, 2023 — Section 63](https://indiacode.gov.in/handle/123456789/496549) * [IT (Intermediary Guidelines) Rules, 2021 as amended 10 Feb 2026](https://egazette.gov.in/WriteReadData/2026/269993.pdf) (Rule 3(1)(d) — 3-hour court/government takedown; Rule 3(2)(b) — 2-hour user-grievance removal) * [Reserve Bank – Integrated Ombudsman Scheme, 2026 (in force 1 July 2026, replacing the 2021 Scheme) — RBI FAQs](https://www.rbi.org.in/commonman/Upload/English/FAQs/PDFs/RBIOS01072026.pdf); [Sachet](https://sachet.rbi.org.in) ### Frequently asked questions **Are loan apps allowed to call my contacts or morph my photos?** No. RBI's Guidelines on Digital Lending (02 Sep 2022) and the comprehensive Reserve Bank of India (Digital Lending) Directions, 2025 (08 May 2025) mandate need-based, consent-driven data collection — DLAs must desist from accessing contacts, call logs, files and media beyond one-time camera/microphone/location for onboarding with explicit consent. Unlawful sharing of contact and gallery data additionally attracts the civil penalty under IT Act Section 72A; harassment, morphed-photo threats and contact-shaming attract IT Act Sections 66C, 66D and 66E and BNS Sections 75 (sexual harassment), 78 (stalking), 308 (extortion) and 351 (criminal intimidation). **What must a loan app disclose before I take a digital loan?** A standardised Key Fact Statement (KFS) with APR (annual percentage rate), all fees, penal charges, loan tenor, repayment schedule, cooling-off or look-up period, grievance redressal officer details, recovery mechanism and a privacy policy must be provided before contract execution. Disbursal and repayment must be directly between your bank account and the Regulated Entity — no pool or pass-through account of the lending service provider. **What is the cooling-off period for a digital loan?** Under the 2025 Directions, the period is fixed by the lender's board and must be at least one day for every digital loan, whatever the tenor: you may exit by paying principal and proportionate APR without penalty. The RE may retain a reasonable one-time processing fee if you exit during the cooling-off period, provided this is disclosed upfront in the KFS. For borrowers continuing after the cooling-off period, pre-payment remains available under extant RBI guidelines. **Who is responsible when a recovery agent harasses me?** The Regulated Entity (bank,NBFC,co-op) is fully responsible for its lending service provider and DLA. Outsourcing does not dilute the RE's obligations (2025 Directions: outsourcing shall in no manner dilute statutory/regulatory obligations; RE remains liable for acts/omissions of LSP). RBI's 12 Aug 2022 recovery-agent circular additionally bars intimidation, harassment, calling before 8 am or after 7 pm, and public humiliation. Complaints go to the RE's nodal grievance officer, and unresolved complaints (30 days) to the RBI Integrated Ombudsman (RB-IOS). **What criminal complaints can be filed for loan app threats?** Depending on facts: Section 308 BNS (extortion), Section 351 BNS (criminal intimidation), Section 78 BNS (stalking including electronic stalking of a woman), Section 79 BNS (word, gesture or act intended to insult the modesty of a woman), Section 336 BNS (forgery where morphed images are used), and IT Act Sections 66C (identity theft), 66D (personation), 66E (privacy violation for intimate/morphed images), 67/67A (obscene/sexually explicit electronic content), plus IT Rules 2021 clocks — Rule 3(1)(d) (3-hour removal of unlawful content on court order or authorised government intimation) and Rule 3(2)(b) (2-hour removal for nudity, morphed imagery or impersonation on user grievance). --- ## Got a Notice from Cyber Cell Under Section 35 or 94 BNSS? What It Means and How to Respond URL: https://advaslam.com/writing/cyber-cell-notice-section-35-vs-94-bnss/ Author: Adv. K J Muhammed Aslam, Advocate (Bar Council of Kerala, K/001823/2026) Published 3 September 2026 Practice area: Cyber crime & IT Act matters Section 35(3) vs 94 BNSS cyber cell notice: appearance vs documents, 7-year rule, arrest risk and how to reply, as the Supreme Court clarified in July 2025. A message titled "Show Cause / Notice / Summon" from a cyber cell mentioning **Section 35(3) BNSS** or **Section 94 BNSS** is not the same thing — and responding as if it is creates the very risk the notice was designed to avoid. **Section 35(3) BNSS** (old Section 41A CrPC) is a **notice of appearance** that protects you from arrest if you comply; **Section 94 BNSS** (old Section 91 CrPC, now expanded to electronic devices) is a **summons to produce documents or devices**. One compels your presence, the other compels material. The Supreme Court's **21 January and 16 July 2025 orders in *Satender Kumar Antil v. CBI* (2025 LiveLaw SC 751)** made two points definitive: Section 35 notice is the **rule** for offences up to seven years, and it **cannot be served on WhatsApp**. ## How do Section 35 and Section 94 BNSS compare in one view? | Feature | **Section 35(3) BNSS** — Notice of appearance | **Section 94 BNSS** — Summons to produce | |---|---|---| | **Old law** | Sections 41 & 41A CrPC consolidated into one Sec 35 | Section 91 CrPC (now expressly includes electronic communication / devices) | | **Purpose** | Require a person to **appear and cooperate** where arrest not required | Require a person to **produce a document, electronic record or device** likely to contain digital evidence | | **When used** | Cognizable offences, especially **punishable up to 7 years** where Arnesh Kumar / Satender Kumar Antil applies | Any investigation/inquiry/trial where a document/thing is necessary or desirable | | **Form of service** | **Physical service only** — WhatsApp/email invalid (SC 16 Jul 2025) — Chapter VI BNSS | **Physical *or* electronic form** (Sec 94(1) expressly so) | | **What compliance means** | Appear on date/place, cooperate; Sec 35(4)-(5) shield against arrest while compliant | Produce the document/thing at stated time/place; deemed complied if you cause production without personal attendance (Sec 94(2)) | | **Non-compliance** | Can ground arrest under Sec 35(6), subject to any court order | Can lead to coercive steps under BNSS; separate non-compliance provisions | | **Arrest risk** | Directly engaged — compliance is the shield | Indirect — failure to produce can be treated as non-cooperation in the broader case | | **Cyber example** | "Your account credited ₹47,000 on 12 Mar 2025 — appear on 09 Sep 2025" | "Produce account statement 01 Jan – 31 Aug 2025 and device IMEI 35-XXXX" | ## Is a Section 35 BNSS notice bad news or good news? **Good news, if you handle it correctly.** The Supreme Court in *Satender Kumar Antil v. CBI* (21 Jan 2025, confirmed 16 Jul 2025) framed Section 35 as a **liberty-protecting filter**: > For offences punishable up to seven years, **notice under Section 35(3) is the rule, arrest is the exception** — the officer must have reason to believe you committed the offence *and* be satisfied arrest is necessary for a statutory purpose (prevent further offence, proper investigation, tampering, threat to witnesses, or securing presence), with reasons recorded under the proviso to Section 35(1). Section 35(3)-(6) then sets the sequence: * **Sec 35(3):** Officer issues notice directing you to appear before him at a specified place. * **Sec 35(4):** It is your **duty to comply** with the notice terms. * **Sec 35(5):** If you comply and continue to comply, you **shall not be arrested** for the offence in the notice, unless the officer, for reasons recorded, forms the opinion that you ought to be arrested. * **Sec 35(6):** If you **fail to comply** with the notice at any time, or are unwilling to identify yourself, the officer may arrest you for the offence mentioned in the notice, subject to any order a competent court has passed. Two limits added by the BNSS text are often missed: **Section 35(7)** bars arrest of a person above 60 or infirm in offences punishable with less than three years without prior approval, and the **proviso** requires written reasons for *both* arrest and non-arrest. ## How must a Section 35 notice be served — and what about WhatsApp? The **Delhi High Court** (*Rakesh Kumar v. Vijayanta Arya (DCP)*, 2021 SCC Online Del 5629; *Amandeep Singh Johar v. State (NCT of Delhi)*, 2018 SCC Online Del 13448) and then the **Supreme Court (16 Jul 2025, 2025 INSC 909, IA 63691/2025)** settled this after a wave of WhatsApp "notices": * **Sections 63-64 BNSS** (court summons) *do* allow electronic service when bearing the court's seal. * **Section 71 BNSS** (witness summons) expressly allows electronic service. * **Section 35 BNSS deliberately omits** electronic service. The Legislature *did* allow electronic communication for investigations elsewhere — **Section 94(1)** (summons to produce may be "in physical form *or in electronic form*") and **Section 193(3)** (police report forwarded electronically to Magistrate) — but **consciously excluded** Section 35. * The Court held: non-compliance with a court summons does not immediately affect liberty; **non-compliance with a Section 35 notice can lead to arrest under Section 35(6)** and therefore engages **Article 21**. Electronic service of a liberty-affecting executive notice is not a valid substitute. **What that means for you:** A PDF on WhatsApp titled "Section 35 Notice" with no physical service is **legally deficient**. Preserve the message, note the mode of delivery, but respond on the basis that you have *knowledge* of the case and seek proper service and time to appear — do not ignore it as if it were nothing, and do not treat the WhatsApp itself as valid service. ## What does a Section 94 BNSS summons actually cover now? Section 94(1) is materially wider than old Section 91: > "Whenever any Court or any officer in charge of a police station considers that the production of **any document, electronic communication, including communication devices, which is likely to contain digital evidence** or other thing is necessary or desirable... such Court may issue a summons or such officer may, by a **written order, either in physical form or in electronic form**, require the person... to attend and **produce it**, or to produce it, at the time and place stated." Highlights: * **Devices are expressly in scope.** Old Section 91's "document or other thing" was read to include devices; Section 94 says so, removing ambiguity. * **Electronic form is valid.** Unlike Section 35, a Section 94 order *may* be sent electronically and still be valid. * **Section 94(2) convenience:** You are deemed to have complied if you cause the document/thing to be produced without attending personally — useful where the bank statement or log can be sent with acknowledgement rather than a personal visit. * **Preserved limits:** Section 94(3) carries forward the protections of **Sections 129-130 BSA** and the Bankers' Books Evidence Act — privileged or statutorily protected material retains its protection. In cyber freezes, Section 94 is the workhorse: the cyber cell sends a Section 94 order to the bank for the account statement and to you for the invoice trail. Complying cleanly with Section 94 is often what gets the freeze limited to the disputed amount. ## How should you respond — the correct sequence for a cyber cell notice? ### Step 0 — Read the paper, not the panic Identify: crime number / NCRP acknowledgement, sections invoked (IT Act/BNS), date/place to appear, officer and rank, and whether the paper says **Section 35** or **Section 94**. Check the mode of service — envelope with seal vs WhatsApp image. Note limitation: appearance is at the **jurisdictional police station of the investigating cell**, often in another state for cyber cases — which is where counsel's role begins. ### Step 1 — Do not ignore; do not volunteer a confession * For **Section 35**: You have a **duty to comply** (Sec 35(4)) and a **shield while compliant** (Sec 35(5)). Ignoring is the fastest way to create a 35(6) arrest ground. * For **Section 94**: Decide whether to produce personally or cause production under Sec 94(2). Keep copies and get acknowledgement. * In both, remember **Article 20(3)** against self-incrimination. Cooperation means attending, producing what is sought, and answering identifying information — not signing a pre-written statement or unlocking a device without a lawful seizure memo. ### Step 2 — Preserve, don't destroy Do not delete chats, format the device, or "test" the account. Destruction can become a separate obstruction allegation and destroys exculpatory material. Preserve the transaction trail (invoice, delivery proof, KYC) — the same bundle that secures a [lien-limited de-freeze](https://advaslam.com/writing/bank-account-frozen-cyber-cell-kerala/). ### Step 3 — Produce with procedure If police seek a phone or laptop, insist on a **seizure memo**, **hash value** (SHA-256) and **acknowledgement**, and that the search follows BNSS safeguards. The electronic record will later need a **Section 63 BSA certificate** — see the [electronic evidence guide](https://advaslam.com/writing/electronic-evidence-bsa-section-63-certificate-guide/) — so chain-of-custody and hash at seizure are not formalities. ### Step 4 — Consider anticipatory bail where appropriate Where the notice cites non-bailable sections carrying more than seven years (e.g., Section 111 BNS organised crime, Section 64 BNS rape), or where custody is likely, seek **anticipatory bail under Section 482 BNSS** (formerly Section 438 CrPC) before the first appearance. For up-to-seven-year matters with a cooperative 35(3) posture, the notice itself is often the protection — counsel can advise which track fits. ## Primary sources * [Bharatiya Nagarik Suraksha Sanhita, 2023 — Sections 35, 63-64, 71, 94, 173, 175, 179, 193, 482, 503](https://indiacode.gov.in/handle/123456789/496550) * [Constitution of India — Article 21](https://indiacode.gov.in/document-grid/d5475e8d-1998-4ac8-8694-82f941074bb7) * *Satender Kumar Antil v. CBI*: Supreme Court directions 21 Jan 2025 & **16 Jul 2025, 2025 INSC 909 (IA 63691/2025)** — Section 35 only physical service; notice as rule for ≤7-year offences; standing orders to follow the Delhi High Court guidelines in *Rakesh Kumar v. Vijayanta Arya (DCP)* (2021) and *Amandeep Singh Johar* (2018) * [Bharatiya Sakshya Adhiniyam, 2023 — Section 63](https://indiacode.gov.in/handle/123456789/496549) * [Information Technology Act, 2000 — Sections 66C, 66D, 78](https://indiacode.gov.in/handle/123456789/496511) (rank for investigation) * [Bharatiya Nyaya Sanhita, 2023](https://indiacode.gov.in/handle/123456789/496548) (cheating, personation, extortion, organised crime) ### Frequently asked questions **What is the difference between Section 35 BNSS and Section 94 BNSS notice?** Section 35(3) BNSS (old Section 41A CrPC) is a notice of appearance — police ask a person to appear and cooperate where arrest is not immediately required, typically for offences punishable up to seven years where compliance shields against arrest. Section 94 BNSS (old Section 91 CrPC, now expanded) is a summons to produce a document or thing — including electronic records and devices — for investigation. Section 35 compels your presence; Section 94 compels production of material, and Section 94 orders may now be issued in physical or electronic form. **Does a Section 35 BNSS notice mean I will be arrested?** Not by itself. Section 35(3) is designed to avoid arrest where cooperation suffices. If you comply and continue to cooperate, Section 35(5) BNSS protects against arrest unless the officer, for reasons recorded, is of the opinion that you ought to be arrested. Non-compliance, however, removes that shield and can be grounds for arrest under Section 35(6). Supreme Court (Satender Kumar Antil v. CBI, 21 Jan 2025 → 16 Jul 2025, 2025 INSC 909) treats Section 35 notice as the rule for up-to-seven-year offences, arrest as the exception. **Can a Section 35 BNSS notice be sent on WhatsApp?** No. The Supreme Court (Satender Kumar Antil directions, 21 Jan 2025 and 16 Jul 2025, 2025 LiveLaw SC 751) held that Section 35 notices cannot be served through WhatsApp or email — they must be served in the manner prescribed under BNSS Chapter VI (personal service). Conscious legislative omission of electronic service for Section 35 — while Sections 94(1) and 193(3) expressly allow electronic communication — was held to reflect intent to protect liberty under Article 21. A WhatsApp-only 35 notice is legally deficient. **Can police demand my phone or laptop under Section 94 BNSS?** Section 94(1) expressly covers electronic communications including communication devices likely to contain digital evidence. Police may by written order (physical or electronic) require you to produce devices or records, but seizure must follow BNSS procedure — seizure memo, hash, and later certification under Section 63 BSA. You may be deemed to have complied by producing the document or thing instead of attending personally (Section 94(2)). Do not hand over devices casually without a memo and hash. **Should I ignore a cyber cell notice if the case is from another state?** No. Jurisdiction does not invalidate a genuine notice. Under Section 173 BNSS and cybercrime practice, complaints registered via NCRP can be investigated by the originating state's cell even where your account is in Kerala. Ignoring converts a cooperative 35(3) posture into a 35(6) arrest risk. Respond in writing, engage counsel where the FIR is registered, and seek anticipatory bail under Section 482 BNSS if arrest is genuinely apprehended. --- ## Bank Froze Your Account Without Any Police Complaint: RBI Rules and the Kerala High Court SOP URL: https://advaslam.com/writing/bank-freeze-without-police-rbi-kerala-hc-sop/ Author: Adv. K J Muhammed Aslam, Advocate (Bar Council of Kerala, K/001823/2026) Published 2 September 2026 Practice area: Cyber crime & IT Act matters Bank froze your account without police or court order? RBI Master Direction, the Kerala High Court 8-point SOP (revised 14 July 2026) and de-freeze steps. Your account suddenly shows "debit freeze" but your branch says no police or cyber cell has asked for it — the bank imposed it on its own after flagging transactions as suspicious. This is not a [Section 106 BNSS police seizure](https://advaslam.com/writing/bank-account-frozen-cyber-cell-kerala/) and the remedy is not the same. Under the [RBI Master Direction on KYC (as updated 2025)](https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=11566) read with the [Prevention of Money-laundering Act, 2002](https://indiacode.gov.in/handle/123456789/496293) and clarified by the **Kerala High Court's binding interim SOP of 19 November 2025** in *Abdul Azeez v. Union of India*, 2025:KER:88312 (W.P.(C) Nos. 32516 & 32291/2024, Justice M.A. Abdul Hakhim), a bank may impose that freeze — as originally framed, a temporary, reviewable measure with same-day notice, a one-week decision on your explanation, and a three-month outer limit. **Update (July 2026):** On 14 July 2026, in *Ajith P.R. v. Union of India*, 2026:KER:52379 (WP(C) No. 48300 of 2025), Justice M.A. Abdul Hakhim revised the *Abdul Azeez* guidelines after noting that mule-account holders were benefiting from the automatic three-month release. The revised guidelines, set out below, replace that release with a police complaint by the bank. ## Why did my bank freeze my account when no police complaint exists? Banks flagged a sharp rise in **money mule accounts** after UPI scale — accounts used to layer fraud proceeds. As **reporting entities** under Section 2(1)(wa) PMLA, banks must monitor transactions and report suspicion. The RBI Master Direction on KYC requires: * ongoing monitoring and identification of unusual or large transactions (Clause 2.10, 2012 Circular), * enhanced due diligence for suspicious patterns, * reporting of Suspicious Transaction Reports (STRs) to FIU-IND, and * Clause 59 (2016/2025 Master Direction): banks must diligently identify money mule accounts and take **"appropriate action, including reporting to FIU-IND."** What Clause 59 does **not** spell out is whether "appropriate action" includes freezing without a police requisition. The RBI told the Kerala High Court it has **not** authorised such freezing except for KYC non-compliance or on receipt of a statutory order, and that freezing is primarily on competent-authority requisition (including under BNSS or BUDS Act). The High Court therefore faced petitions where **South Indian Bank had frozen accounts for over a year on suspicion alone**, with no law-enforcement order even after the bank had informed RBI — funds inaccessible, business paralysed. The same pattern repeats in other districts: a high-value UPI inflow, a profile mismatch with declared income, an algorithmic alert, and a debit freeze without prior notice. ## What did the Kerala High Court actually decide on 19 November 2025? The Court reached a balanced, purposive answer in *Abdul Azeez* (2025:KER:88312): > A bank **may** impose an immediate **debit freeze** (block outflows, preserve the credit balance) **without prior notice** where it has **reasonable grounds** to suspect fraud, money laundering or mule use — as a necessary adjunct to PMLA Section 12AA(3) enhanced monitoring and Clause 59 "appropriate action" — **but the power is strictly time-bound and procedural**. The Court rejected two extremes: that banks are "silent spectators" who must watch suspected laundering continue, and that they may act as law-enforcement agencies imposing indefinite freezes on internal alerts. The absence of a specific RBI SOP was held to **not** mean banks are powerless; it means the Court must supply an interim protocol until the RBI notifies one under **Section 35A of the Banking Regulation Act, 1949**. ## What was the original 8-point SOP? The *Abdul Azeez* judgment laid down the following interim guidelines (para 27), pending an SOP from the RBI. They applied to bank-initiated suspicion freezes in Kerala until the July 2026 revision described in the next section: | Step | What must happen | Deadline | |---|---|---| | **1. Freeze permitted** | Bank may impose a **debit freeze** on reasonable suspicion without prior notice | Immediate | | **2. Same-day notice to you** | Bank must intimate freezing **with reasons for suspicion** by **SMS and registered post on the date of freezing itself** | Same day | | **3. Intimation to authorities** | Bank must send the freeze with reasons to the **jurisdictional Cyber Crime Police Authority** and all authorities required under RBI guidelines, and ensure receipt | Promptly, and prove delivery | | **4. Your right to explain** | You may submit a written explanation with documents to the bank | No statutory bar, but quickly (days) | | **5. Bank decides in one week** | On receipt, the bank's appropriate authority must **consider and pass orders within one week**, communicate them, and **de-freeze if satisfied** | 7 days from your explanation | | **6. Authority direction prevails** | If cyber police or other competent authority issues an order, the bank must **comply immediately** and inform you | Immediate | | **7. Three-month cap** | If no explanation or unsatisfactory explanation, the bank may continue **only for three months from the last delivery to the authorities**. If **no authority communicates within three months**, the bank **must lift the freeze**, allow you to deal with the credit balance, and then either permit operation or demand closure | 3 months | | **8. Challenge** | If the bank rejects your explanation without valid reason, you may challenge it **before the appropriate legal forum** (writ under Article 226) | — | **Practical note:** The petitioners in *Abdul Azeez* had offered documents showing genuine business, but the bank had **not informed the local cyber police**, only RBI. The Court directed South Indian Bank to now intimate the authorities and decide afresh per the SOP. ## What changed in July 2026 — the revised guidelines In *Ajith P.R. v. Union of India* (14 July 2026), the Court noted that banks were being compelled to release suspected mule accounts once three months passed without a police response, and revised the guidelines as follows: | Step | What must happen | Deadline | |---|---|---| | **1. Freeze permitted** | Bank may impose a **debit freeze** on reasonable suspicion without prior notice | Immediate | | **2. Notice to you** | Intimation by **SMS/email on the date of freezing**, and the **reasons for suspicion by registered post** | Same day; registered post within 3 working days | | **3. Your explanation** | You may submit an explanation; the bank must **decide within one week** of receiving it and **unfreeze if satisfied** | Explanation within 1 month of the bank's communication | | **4. Police complaint** | If no explanation is received within one month, or it is unsatisfactory, the bank must file a **written complaint with the SHO of its local police station**, with a copy to you | As early as possible | | **5. FIR** | The SHO must **register an FIR**, including for **Section 111 BNS** (organised crime), and investigate | Immediately on the complaint | | **6. Operation of the account** | Where the bank has complained to the police, the account is operated **according to the police's directions**; if permitted, the bank may allow operation or demand closure | — | | **7. Challenge** | If the bank illegally rejects your explanation, you may challenge it **in accordance with law** | — | ## How is this different from the other two freeze types? | Freeze type | Who orders | Legal basis | Must bank inform you same day? | Cap | Your leverage | |---|---|---|---|---|---| | **Police / cyber cell** | Investigating officer via bank requisition | Section 106 BNSS, reported to Magistrate | Bank often delays; request it in writing | No statutory cap — challenge via representation, Section 503 BNSS, Article 226 | Lien limited to disputed amount — see [complete Kerala guide](https://advaslam.com/writing/bank-account-frozen-cyber-cell-kerala/) | | **Bank suo motu (suspicion)** | Bank itself on internal alert | Clause 59 Master Direction, PMLA reporting duties, Kerala High Court guidelines (*Abdul Azeez*, revised in *Ajith P.R.*) | **Yes — SMS/email same day; reasons by registered post within 3 working days** | No automatic release since July 2026 — unresolved cases go to the police | Written explanation within one month → decision in 7 days | | **KYC / non-PAN** | Bank under RBI KYC circulars | Clause 38-39 Master Direction (KYC) | Prior notice required before partial/full freeze | Phased before closure | Update KYC and seek de-freeze | Identifying the type is the first advocacy step — get the bank's written reason. If it cites an NCRP acknowledgment or crime number, treat it as police-ordered; if it cites "suspicious transactions" or "profile mismatch" with no crime number, invoke the Kerala High Court guidelines as revised in July 2026. ## What should you do in the first week? 1. **Get the freeze order in writing.** Ask the branch for the dated communication with the **reason for suspicion**, the account number, the date of freeze, whether it is debit freeze or full freeze, and the name of the noticing department. 2. **File a concise written explanation within 3-5 days.** Attach: account statement highlighting the questioned credits with invoices or contract, GST or business proof, KYC, and a request that the bank consider and decide within one week as the High Court's guidelines require. The revised guidelines allow one month from the bank's communication — do not use all of it. 3. **Keep proof of delivery.** Registered post acknowledgement and email to the nodal/grievance cell. If the reasons for suspicion have not reached you, ask for them in writing — the revised guidelines require them by registered post within three working days of the freeze. 4. **Do not route fresh business through others' accounts** while frozen — the bank may cite fresh suspicion for a new freeze. 5. **If rejected or no decision in 7 days, escalate.** File a grievance with the bank's nodal officer and, if unresolved for 30 days, the **Reserve Bank – Integrated Ombudsman Scheme** at cms.rbi.org.in; in parallel, consider a writ petition under **Article 226** before the High Court of Kerala citing *Abdul Azeez* and *Ajith P.R.* and seeking a decision on your explanation under the revised guidelines. ## What if the freeze is really a KYC freeze? Then the SOP above does not apply — the KYC freeze follows a different phased notice-and-freeze-then-closure sequence. A branch that labels a suspicion freeze as KYC without a KYC deficiency is misapplying the Direction. That distinction — suspicion vs KYC non-compliance — is itself a ground of challenge. ## Primary sources * *Abdul Azeez v. Union of India & Ors.*, W.P.(C) Nos. 32516 & 32291/2024, **2025:KER:88312** (Kerala High Court, Justice M.A. Abdul Hakhim, 19 Nov 2025) — [judgment text on Indian Kanoon](https://indiankanoon.org/doc/28988923/); [LiveLaw report](https://www.livelaw.in/high-court/kerala-high-court/guidelines-freezing-suspicious-accounts-rbi-frame-sop-310857); a certified copy can be obtained through the Kerala High Court's judgment portal ([highcourt.kerala.gov.in](https://highcourt.kerala.gov.in/)) * *Ajith P.R. v. Union of India & Ors.*, WP(C) No. 48300 of 2025, **2026:KER:52379** (Kerala High Court, Justice M.A. Abdul Hakhim, 14 July 2026) — revised guidelines — [judgment text on Indian Kanoon](https://indiankanoon.org/doc/49490617/) * [RBI Master Direction on KYC (as updated)](https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=11566) (Clauses 2.10, 38-39, 59 money mule, STR to FIU-IND) * [Banking Regulation Act, 1949 — Section 35A](https://indiacode.gov.in/handle/123456789/496222) * [Prevention of Money-laundering Act, 2002 — Sections 2(1)(wa), 12, 12AA](https://indiacode.gov.in/handle/123456789/496293) * [Constitution of India — Articles 226, 300A](https://indiacode.gov.in/document-grid/d5475e8d-1998-4ac8-8694-82f941074bb7) * [Reserve Bank – Integrated Ombudsman Scheme, 2021](https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=12124) and [CMS](https://cms.rbi.org.in) ### Frequently asked questions **Can my bank freeze my account without a police or court order?** In a narrow situation, yes — but only as a temporary protective measure. The Kerala High Court in Abdul Azeez v. Union of India (W.P.(C) Nos. 32516 & 32291/2024, 2025:KER:88312, 19 Nov 2025, Justice M.A. Abdul Hakhim) held that a bank as a reporting entity under PMLA and under RBI's KYC Master Direction may impose an immediate debit freeze without prior notice where it has reasonable grounds to suspect money mule or fraud use, originally subject to same-day notice to you, intimation to cyber police, a one-week review of your explanation, and a 3-month cap if no authority acted. On 14 July 2026, in Ajith P.R. v. Union of India (WP(C) No. 48300 of 2025, 2026:KER:52379), the same Judge revised those guidelines: notice by SMS/email the same day and reasons by registered post within three working days, one month for your explanation, a decision within one week, and — if there is no explanation or the bank is not satisfied — a written complaint by the bank to the SHO of its local police station, who must register an FIR. **How is this different from a cyber cell freeze under Section 106 BNSS?** A Section 106 BNSS freeze is police-ordered — the investigating officer seizes the account as property linked to an offence and must report to the jurisdictional Magistrate. A bank-initiated freeze is the bank acting on its own suspicion under RBI's Master Direction on KYC and PMLA Clause 59 'appropriate action' — no FIR, no requisition exists yet. The remedies differ: for a police freeze you move the investigating officer, Magistrate under Section 503 BNSS or High Court under Article 226; for a bank freeze you first submit your explanation under the Kerala High Court's guidelines. **How long can a bank keep my account frozen on its own?** Under the original Abdul Azeez guidelines of 19 November 2025, at most three months from the last date the freeze was intimated to the authorities. The revised guidelines in Ajith P.R. v. Union of India (14 July 2026) no longer provide that automatic release: if the bank is satisfied with your explanation it must unfreeze within a week; if you give no explanation within one month, or the bank is not satisfied, it must file a written complaint with the SHO of its local police station, and operation of the account then follows the police's directions. **What should I do the day I discover a bank-initiated freeze?** Get the freeze reason in writing from the branch, file a written explanation with transaction proofs within days, and keep proof of delivery. Do not ignore the freeze — under the July 2026 revised guidelines, if no explanation is received within one month, or it is not satisfactory, the bank must file a written complaint with the local police, and the SHO must register an FIR. **Is a bank freeze without notice legal under Article 300A?** Article 300A provides no person shall be deprived of property save by authority of law. The petitioners in Abdul Azeez argued that the bank's indefinite, unilateral freeze violated Article 300A. The Court held that a temporary debit freeze on reasonable suspicion, with notice and a review of the account holder's explanation, falls within the 'appropriate action' contemplated by Clause 59 of the RBI KYC Master Direction, and directed the RBI — which has powers under Section 35A of the Banking Regulation Act, 1949 — to frame a Standard Operating Procedure. --- ## CERT-In 6-Hour vs DPDP 72-Hour Breach Reporting: Which Clock Applies to Your Business? URL: https://advaslam.com/writing/cert-in-6-hour-vs-dpdp-72-hour-breach-reporting/ Author: Adv. K J Muhammed Aslam, Advocate (Bar Council of Kerala, K/001823/2026) Published 1 September 2026 Practice area: Data protection & DPDP compliance India has two breach clocks that both apply: CERT-In's 6 hours and DPDP Rule 7's 72 hours. Who reports to whom, when each starts, and one playbook for both. India's breach-reporting regime is not one clock but two — and the most common compliance mistake Kerala businesses make is preparing for only one of them. The [CERT-In Directions dated 28 April 2022](https://www.cert-in.org.in/Directions70B.jsp) under Section 70B(6) of the IT Act require reporting of specified cyber incidents, including data breaches, to CERT-In within **six hours** of noticing them. The [DPDP Rules, 2025](https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf) — Rule 7 — require notification of every personal data breach to the [Data Protection Board of India](https://www.meity.gov.in) without delay, with a detailed report within **72 hours**, plus notification to each affected individual without delay. Where a personal data breach is also a cyber incident, **both duties apply in parallel** on different clocks to different authorities. ## What are the two breach duties, in one table? | Feature | CERT-In Directions (28 April 2022) | DPDP Act + Rule 7 (G.S.R. 846(E), 13 Nov 2025) | |---|---|---| | **Legal basis** | [Section 70B(6) IT Act, 2000](https://indiacode.gov.in/handle/123456789/496511) | [Sections 2(u), 8(5), 8(6) DPDP Act, 2023](https://indiacode.gov.in/handle/123456789/496508) + Rule 7 DPDP Rules, 2025 | | **Who must report** | Service providers, intermediaries, data centres, body corporates, government organisations — the Directions' broad covered-entity definition | Every Data Fiduciary (any person determining the purpose and means of processing digital personal data) — Section 2(i) DPDP Act | | **What triggers the duty** | Cyber incidents listed in Annex I to the Directions — expressly includes data breach, data leak, attacks on digital payment systems, compromise of critical systems, malware, IoT attacks, and others | Every personal data breach — Section 2(u): any unauthorised processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises the confidentiality, integrity or availability of personal data. No threshold | | **Clock starts** | On noticing the incident or being brought to notice of it | On becoming aware of the personal data breach | | **Deadline to CERT-In / Board** | **Within 6 hours** (report to the extent available; supplement later) | **Without delay** — initial intimation to Board describing nature, extent, timing and likely impact; **detailed report within 72 hours** of becoming aware (extendable only on Board's written allowance on good-cause request) | | **Deadline to affected individuals** | No direct individual-notification duty under the Directions | **Without delay** — each affected Data Principal must be informed in concise, clear, plain language through their user account or registered contact details, covering what happened, likely consequences, mitigation and a contact person | | **Form and channel** | CERT-In incident reporting form at cert-in.org.in; email incident@cert-in.org.in; phone 1800-11-4949 | As prescribed by the Rules and Board procedure — intimation to Board and to individuals through usual contact channels | | **Confidentiality defence** | On one interpretive view, reporting as a statutory duty overrides confidentiality clauses in contracts (Section 81 IT Act, FAQ Q22 May 2022) — treated here as interpretation; FAQ Q30 itself supports only extent-available reporting with later supplementation | Same interpretive position — statutory duty overrides contractual confidentiality | | **Penalty for failure to report** | [Section 70B(7) IT Act](https://indiacode.gov.in/handle/123456789/496511): imprisonment up to one year, or fine up to one crore rupees (raised from one lakh by the Jan Vishwas Act, 2023, w.e.f. 30 Nov 2023), or both | Section 8(6) read with Section 33 and the Schedule: up to **two hundred crore rupees** per breach, plus up to **two hundred and fifty crore rupees** exposure for the underlying failure of reasonable security safeguards under Section 8(5) | ## Who exactly must report under each regime? **CERT-In** casts a deliberately wide net. The Directions apply to intermediaries (which under Section 2(1)(w) of the IT Act includes social media platforms, hosting providers, ISPs, cloud services and many SaaS providers), data centres, body corporates (which under Section 43A of the IT Act means any company or firm handling sensitive data), and government organisations. In practice, any Kerala business that runs a website handling user data, uses a cloud provider, or operates an app is within the covered-entity description, and the FAQs confirm that even service providers without a physical presence in India but serving users in India are covered. **DPDP** turns on a different test — whether the entity is a **Data Fiduciary** under Section 2(i): a person who alone or with others determines the purpose and means of processing personal data. A company deciding what customer data to collect and why is a fiduciary. A vendor processing purely on instructions is a Data Processor under Section 2(k), but the fiduciary remains responsible under Section 8(1) for the processor's compliance. There is no turnover or headcount threshold. A two-person startup processing digital personal data is a fiduciary for the data it controls. The overlap is therefore large: most Data Fiduciaries that suffer a breach are also covered entities under the CERT-In Directions. The result is dual reporting, not a choice between the two. ## What counts as a reportable incident under each? **Under CERT-In**, the trigger is whether the event falls in Annex I. The list is longer than most teams realise and was deliberately expanded in 2022. It includes, among others: data breach, data leak, unauthorised access to IT systems or data, attacks on internet-of-things devices, attacks on digital payment systems, compromise of critical information infrastructure, phishing or identity theft, malware or ransomware, denial-of-service, and scanning or probing of systems. The FAQs clarify that incidents meeting criteria such as severe nature, impact on safety, or large-scale or frequent occurrence should be reported within the six-hour window. **Under DPDP**, the trigger is whether there is a **personal data breach** under Section 2(u). That definition is intentionally wide: any unauthorised processing of personal data, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises the confidentiality, integrity or availability of personal data. It covers a misdirected email containing personal data, an accidental S3 bucket exposure, and a ransomware encryption of a customer database alike. The Rules add no de minimis exception — every breach triggers the notification duties, unlike the GDPR where the authority notification can be excused where the breach is unlikely to result in a risk to rights and freedoms. ## How do the clocks actually work in a real incident? An example helps because the two clocks start at the same conceptual moment — awareness — but run to different deadlines with different content: * **T+0 — detection.** Your SOC or an engineer notices a database has been exposed, or a customer reports receiving another customer's invoice. You are now aware for both regimes. * **T+0 to T+6 hours — CERT-In window.** File the CERT-In incident report with whatever facts are available: incident type, time of detection, affected systems, brief description, contact person. The Directions and the May 2022 FAQs expressly contemplate that you report to the extent available within six hours and supplement with additional details within reasonable time. Do not wait for a forensics report to send the first notification. * **T+0 without delay — DPDP individual and Board initial notifications.** Rule 7 requires you to inform each affected Data Principal without delay, in plain language, through their user account or registered contact details — what happened, likely consequences, mitigation done, steps they can take, and a contact person. In parallel, send the Board an initial intimation without delay describing the breach's nature, extent, timing and likely impact. * **T+72 hours — DPDP detailed report to Board.** Within 72 hours of becoming aware, submit the detailed particulars to the Board: facts, circumstances, causes, findings on the person responsible, mitigation, remedial steps to prevent recurrence, and a summary of intimations sent to individuals. The Board may extend this only if you make a written request showing good cause — do not assume an automatic extension. A common mistake is to treat the 72-hour report as the first notification. It is not — the without-delay intimations to individuals and to the Board are due immediately, and the 72-hour filing is the detailed follow-up. Another mistake is to inform only the Board and assume individuals will learn from it. Rule 7 requires separate, direct intimation to each affected individual. ## How should a Kerala business build one playbook for both? The efficient approach is not two separate runbooks but one integrated breach-response plan with both notifications built into the same timeline, owned by named roles and rehearsed before an incident: 1. **Pre-incident — designate and publish.** Name the CERT-In point of contact and the DPDP grievance contact (Section 8(9) DPDP Act) and publish them. Ensure ICT system logs are retained for at least **180 days** within India and systems are synced to Indian NTP time — both are CERT-In Directions requirements — and that Rule 6 DPDP security safeguards (encryption or masking, access controls, logging for one year, backups) are in place. 2. **Detection to 6 hours — contain, assess, report to CERT-In.** Containment and preservation come first, but the six-hour report goes in parallel. Keep a one-page CERT-In reporting template pre-filled with entity details so the on-call engineer only adds incident-specific facts. 3. **Without delay — notify individuals and the Board under DPDP.** Keep plain-language breach-notification templates in English and Malayalam so the without-delay notice to affected Data Principals does not stall on drafting. The initial Board intimation should use the fields CERT-In already requires plus the DPDP-specific points: purpose for which the breached data was collected, categories of data and data principals affected, and likely consequences for individuals. 4. **72-hour — detailed Board report.** Prepare a second template for the detailed report covering causes, findings, mitigation, preventive steps and a log of individual intimations. File within 72 hours even if forensics is incomplete, noting what remains under investigation — you can supplement, but you cannot miss the deadline. 5. **Post-incident — document everything.** Under Section 6(10) of the DPDP Act the burden of proving notice and consent in related matters sits on the fiduciary, and Section 33(2) makes mitigation and good-faith response a factor in penalty decisions. A dated, logged response file is itself a mitigation factor. For the substantive preparation that the 72-hour clock assumes — consent logs, retention schedules, vendor contracts — see [the DPDP countdown for Indian businesses](https://advaslam.com/writing/dpdp-act-deadline-businesses/) and for the platform duties that sit alongside breach handling, the guides on [sextortion reporting and takedown](https://advaslam.com/writing/sextortion-blackmail-kerala-legal-remedies/) and [synthetically generated information labelling](https://advaslam.com/writing/deepfake-sgi-it-rules-2026-labelling-takedown/). ## Primary sources * [Information Technology Act, 2000 — India Code](https://indiacode.gov.in/handle/123456789/496511) (Section 70B, Section 43A, Section 2(1)(w)) * [CERT-In Directions dated 28 April 2022 under Section 70B(6) and FAQs dated 18 May 2022 — cert-in.org.in](https://www.cert-in.org.in/Directions70B.jsp) (six-hour reporting, 180-day log retention, NTP sync, five-year subscriber data retention) * [Digital Personal Data Protection Act, 2023 — India Code](https://indiacode.gov.in/handle/123456789/496508) (Sections 2(i), 2(k), 2(u), 8(5), 8(6), 33 and the Schedule) * [Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E), 13 November 2025) — MeitY](https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf) (Rule 6 on security safeguards, Rule 7 on breach notification, Rule 14 on rights and grievance) * [AZB & Partners summary of DPDP Rules enforcement timelines — Mondaq, 21 November 2025](https://www.mondaq.com/india/privacy-protection/1708314/update-indias-digital-personal-data-protection-framework-comes-into-effect) (phased commencement: Rule 7 from ≈13 May 2027 (displayed as 14 May 2027 on this site)) ### Frequently asked questions **Do I need to report a data breach under both CERT-In Directions and the DPDP Act?** Yes, where both apply. CERT-In Directions dated 28 April 2022 require reporting of specified cyber incidents — including data breaches and data leaks — to CERT-In within six hours of noticing them. DPDP Rule 7 requires notification of every personal data breach to the Data Protection Board without delay, with a detailed report within 72 hours, and notification to each affected Data Principal without delay. The two duties run in parallel to different authorities on different clocks, and compliance with one does not excuse the other. **When does the CERT-In 6-hour clock start?** Within six hours of noticing the incident or being brought to notice of it. The FAQs issued in May 2022 (Q30) clarify that you report to the extent information is available within six hours and supplement later within reasonable time. The clock is not from the breach occurrence, which may have been earlier, but from awareness. On one interpretive view, based on FAQ Q22 read with Section 81 of the IT Act, a statutory reporting duty overrides conflicting contractual confidentiality clauses — but that override is an interpretation, not express Directions text, and Q30 itself supports only extent-available reporting with later supplementation. **When does the DPDP 72-hour clock start?** From when the Data Fiduciary becomes aware of the personal data breach. Rule 7 requires intimation to each affected Data Principal without delay in clear, plain language, an initial intimation to the Data Protection Board without delay describing the nature, extent, timing and likely impact, and a detailed report to the Board within 72 hours of becoming aware, extendable only if the Board allows a written request showing good cause. **What is the penalty for failing to report a breach under the DPDP Act?** Failure to notify the Board or affected Data Principals of a personal data breach under Section 8(6) of the DPDP Act carries a penalty of up to two hundred crore rupees, imposed by the Data Protection Board after inquiry and hearing under Section 33, weighing factors under Section 33(2) including gravity, duration, data type, repetition, gains and mitigation. Non-compliance with CERT-In Directions can attract punishment under Section 70B(7) of the IT Act — imprisonment up to one year, fine up to one crore rupees (raised from one lakh by the Jan Vishwas (Amendment of Provisions) Act, 2023, w.e.f. 30 November 2023), or both. **Does every small breach need to be reported under the DPDP Act?** Yes. Unlike the GDPR, which has a risk-to-rights threshold for notification to the authority, DPDP Rule 7 has no materiality filter in its text — every personal data breach as defined in Section 2(u), which includes unauthorised processing and accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access that compromises the confidentiality, integrity or availability of personal data, triggers the notification duties. There is no exception for small or low-risk breaches in the notified text. --- ## Deepfakes and Synthetically Generated Information in India: The IT Amendment Rules, 2026 Labelling and 3-Hour Takedown URL: https://advaslam.com/writing/deepfake-sgi-it-rules-2026-labelling-takedown/ Author: Adv. K J Muhammed Aslam, Advocate (Bar Council of Kerala, K/001823/2026) Published 1 September 2026 Practice area: Cyber crime & IT Act matters IT Amendment Rules, 2026 (in force 20 Feb 2026) on synthetically generated information: exclusions, labelling, user declaration, 3-hour or 2-hour takedown. India's first binding deepfake regime is not an advisory — it is the [Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 notified on 10 February 2026](https://egazette.gov.in/WriteReadData/2026/269993.pdf) and **in force from 20 February 2026**, which insert a definition of **synthetically generated information (SGI)** into the [IT Rules, 2021](https://www.meity.gov.in/static/uploads/2026/02/550681ab908f8afb135b0ad42816a1c9.pdf) and attach **labelling and provenance duties, user-declaration and verification, and a three-hour or two-hour takedown clock** to it. An intermediary that knowingly permits prohibited SGI, or that fails to label and trace lawful SGI, risks losing its **safe harbour under Section 79 of the IT Act, 2000**. ## What is SGI — and what is not? The definition was deliberately narrowed from the October 2025 draft after industry feedback, and misunderstanding the scope is the most common error in commentary that still cites the draft. **SGI under [Rule 2(1)(wa) as inserted 10 February 2026](https://egazette.gov.in/WriteReadData/2026/269993.pdf):** > Audio, visual or audio-visual information which is artificially or algorithmically created, generated, modified or altered using a computer resource, in a manner that such information appears to be real, authentic or true and depicts or portrays any individual or event in a manner that is, or is likely to be perceived as indistinguishable from a natural person or real-world event. The Government's FAQ emphasises that the test is **content-centric, not method-centric** — SGI is about whether the output realistically appears like a real person or real-world event and is capable of deceiving viewers, whether the tool was labelled AI, generative AI or otherwise. **Expressly excluded — not SGI even though a computer was used:** * Text-only content. * Routine or good-faith editing, formatting, enhancement, technical correction, colour adjustment, noise reduction, transcription, translation, compression, and preparation of documents, presentations, PDFs, educational or training materials, research outputs — where the substance, context or meaning is **not materially altered or misrepresented**. * Tools for improving accessibility, clarity, quality, translation, description, searchability or discoverability — again, where material substance is not manipulated to deceive. * Accessibility tools such as text-to-speech and speech-to-text. A cropped, colour-corrected photograph is not SGI. A synthetic video of a Kerala public figure appearing to announce a policy they never announced is — even if the creator says a non-AI tool was used. ## What SGI is prohibited outright? The Amendment Rules prohibit an intermediary from allowing SGI that falls in defined high-risk categories. The categories track — and are enforced alongside — existing criminal provisions: | Prohibited SGI category | Parallel criminal provision where also violated | Platform exposure (separate) | |---|---|---| | Child sexual abuse material | [Section 67B IT Act](https://indiacode.gov.in/handle/123456789/496511) + POCSO Act | Loss of safe harbour under Section 79 IT Act where due diligence fails | | Non-consensual nudity, obscene or sexually explicit material, morphed intimate imagery | Sections 66E, 67, 67A IT Act; Sections 75, 77 BNS | Loss of safe harbour under Section 79 IT Act where due diligence fails | | SGI that invades privacy through impersonation or manipulation | Sections 66C, 66D IT Act; Sections 319, 353 BNS | Loss of safe harbour under Section 79 IT Act where due diligence fails | | SGI that creates false documents or electronic records | Sections 336, 340 BNS | Loss of safe harbour under Section 79 IT Act where due diligence fails | | SGI that enables creation of explosives, arms or ammunition | Explosive Substances Act; BNS provisions on public safety | Loss of safe harbour under Section 79 IT Act where due diligence fails | | SGI that falsely and deceptively depicts a natural person or real-world event | Sections 353 (false information), 356 (defamation) BNS | Loss of safe harbour under Section 79 IT Act where due diligence fails — s.79 is a safe-harbour/exposure analysis, not a criminal provision | | Unlawful SGI more generally | Rule 3(1)(b) unlawful categories + BNS/IT Act as applicable | Loss of safe harbour under Section 79 IT Act where due diligence fails | Where SGI also constitutes a criminal offence, the platform's takedown duty and the criminal investigation run in parallel — removal does not replace the FIR, and the FIR does not replace the need for rapid removal. ## What must intermediaries do — the three layers of duty? ### Layer 1 — Every intermediary (Rule 3) Duties that apply to **all intermediaries** as defined in [Section 2(1)(w) IT Act](https://indiacode.gov.in/handle/123456789/496511) — which includes social media, video-sharing, messaging, hosting, search and cloud services that host or transmit user content: | Duty | What the Rules now require | |---|---| | **User awareness every three months** — Rule 3(1)(c) | Inform users at least once every three months (up from once a year) through terms, privacy policy or other means that non-compliance with platform rules on SGI — creation, modification, hosting, dissemination of unlawful information — can result in suspension or termination, content removal, and potential penalties and reporting under POCSO or BNSS | | **Proactive prevention** — Rule 3(3) (SGI-enabling intermediaries) | Deploy **reasonable and appropriate technical measures**, including automated tools, to prevent generation or sharing of prohibited SGI — not merely to react after it is reported | | **Labelling and provenance for lawful SGI** — Rule 3(3) (SGI-enabling intermediaries) + Rule 4(1A) (SSMIs) | Ensure that SGI that is not prohibited is **prominently labelled** as synthetic or AI-generated — clearly visible in visual displays, prefixed prominently in audio — and **embedded with permanent metadata or provenance markers** including a unique identifier of the computer resource used to generate or alter the content; platforms must not enable suppression or removal of those markers | | **Takedown on actual knowledge** — Rule 3(1)(d) | Remove or disable access to unlawful information — including unlawful SGI — within **three hours** of actual knowledge through a **court order** or a **notification from the appropriate government or its authorised agency** (down from 36 hours) | | **Individual-complaint fast track** — Rule 3(2)(b) | Remove or disable access within **two hours** on individual complaints involving private-area/nudity/sexual act/impersonation including morphed imagery (down from 24 hours) | | **Grievance redressal** — Rule 3(2) | Acknowledge complaints within 24 hours; **resolve general grievances within seven days** (down from 15 days); **unlawful-content grievances within 36 hours** (down from 72 hours) | The three-hour clock under Rule 3(1)(d) runs from **actual knowledge** through the two specified channels — a court order or an authorised government notification — not from a generic user report under Rule 3(2). The separate two-hour clock under Rule 3(2)(b) runs from an individual complaint involving private-area/nudity/sexual act/impersonation including morphed imagery. For the brand owner, the practical path is to file the Rule 3(2) grievance with specific URLs and proof immediately and, where the SGI is actively causing harm, to pursue the court order or government notification that triggers the three-hour Rule 3(1)(d) clock. The **Sahyog portal** — upheld as a takedown route in X Corp v. Union of India, W.P. No. 7405 of 2025 (Karnataka High Court, 24 September 2025) — is part of the government-notification ecosystem that starts that clock. ### Layer 2 — Intermediaries that offer SGI-enabling tools (Rule 3(3)) Where the intermediary provides a computer resource that **enables creation, generation, modification or large-scale dissemination** of SGI — generative AI tools, video and image editors, voice-cloning services — the Rules add product-level duties: warn users against generating prohibited SGI, ensure product design does not nudge users toward prohibited SGI, and be able to restrict or suspend repeat misuse. Product flows, interfaces and user declarations must be designed for compliance, not merely for engagement. ### Layer 3 — Significant social media intermediaries (SSMIs — Rule 4(1A), threshold 50 lakh registered users in India) Additional duties for **SSMIs**: * Require users to **declare** whether uploaded or shared content constitutes SGI. * Deploy **reasonable technical measures to verify** the correctness of declarations **before** publication or display, and reject uploads where the declaration is missing or verification suggests non-compliance. * Ensure confirmed SGI is **clearly and prominently labelled** as synthetic so recipients can easily identify it. * Maintain provenance and traceability records, including first-originator information where required under Rule 4, so harmful SGI can be traced to its source. Failure by an SSMI to take reasonable steps against unlawful SGI can be treated as a failure to exercise due diligence, with loss of safe harbour under Section 79 IT Act and exposure to liability for user content — the consequence the February 2026 amendment was designed to make credible. ## How does SGI outside the Rules — deepfake harms in court — get addressed? The Amendment Rules regulate **intermediary distribution**, not authorship or damages. Where a deepfake harms a person, the civil and criminal tracks available alongside the Rules include: * **IT Act — Sections 66C (identity theft), 66D (personation), 66E (privacy), 67/67A/67B (obscenity)** — the standard charges for impersonation and intimate-image deepfakes. * **BNS — Sections 353 (false information causing panic or enmity), 336 (forgery of electronic record), 319 (cheating by personation), 356 (defamation), 75/77 (sexual harassment, voyeurism). Consider Section 111 (organised crime) only where its ingredients are made out on the facts — seek advice before invoking it.** * **Privacy and publicity rights** — courts have granted interim relief in deepfake and personality-rights cases on privacy and publicity grounds even before the 2026 Rules, including orders restraining impersonation and directing platform takedown and disclosure. * **Copyright — Section 51 Copyright Act** — where the deepfake reproduces protected expression (voice, performance, footage) beyond the idea. At the Supreme Court's hearing on 28 July 2026 in the suo motu digital-arrest and deepfake cognizance (originating October 2025), the Bench observed that the [IT Act, 2000](https://indiacode.gov.in/handle/123456789/496511) — enacted before smartphones and UPI — needs to define digital arrest and deepfakes as standalone offences with asset-freezing powers on prima facie material, indicating that further legislative definition may follow the current Rules-based regime. ## What should a Kerala platform, business or creator do now? | Who you are | Concrete steps | |---|---| | **Platform or app that hosts user content in India** | Update terms to cover SGI expressly; implement the three-month awareness notice cycle; deploy labelling and metadata embedding; build the three-hour and two-hour escalation path with round-the-clock coverage; document reasonable technical measures for the safe-harbour file | | **SSMI (50 lakh+ users)** | Add SGI declaration at upload, verification before publication, and prominent labelling for confirmed SGI; ensure product design does not nudge toward prohibited SGI | | **AI tool provider** | Warn against prohibited SGI categories in-product, log generation with provenance, and build suspension for repeat misuse | | **Business that is a Data Fiduciary** | Treat training data that includes personal data as processing under the DPDP Act — lawful basis, Section 5 notice, Section 6 consent, Rule 6 safeguards and Rule 7 breach duties apply to model data (see the [CERT-In vs DPDP breach guide](https://advaslam.com/writing/cert-in-6-hour-vs-dpdp-72-hour-breach-reporting/) and the [DPDP countdown guide](https://advaslam.com/writing/dpdp-act-deadline-businesses/)) | | **Creator** | Where you use synthetic media, label it clearly as synthetic — the carve-out for satire, art and research protects clearly labelled, non-deceptive uses, not undisclosed impersonation | ## Primary sources * [Information Technology Act, 2000 — India Code](https://indiacode.gov.in/handle/123456789/496511) (Sections 2(1)(w), 66C, 66D, 66E, 67, 67A, 67B, 79, 79A) * [IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 as updated to 10 February 2026 — MeitY](https://www.meity.gov.in/static/uploads/2026/02/550681ab908f8afb135b0ad42816a1c9.pdf) and [Amendment Rules notified 10 February 2026, G.S.R. 120(E) — Gazette of India](https://egazette.gov.in/WriteReadData/2026/269993.pdf) (Rules 2(1)(wa), 3(1)(b), 3(1)(c), 3(1)(d), 3(2), 4) * [Government FAQ on the Amendment Rules, 2026 — MeitY (February 2026)](https://www.meity.gov.in/static/uploads/2025/10/065b6deb585441b5ccdf8be42502a49c.pdf) * X Corp v. Union of India, W.P. No. 7405 of 2025 (Karnataka High Court, 24 September 2025) on the Sahyog portal * Supreme Court suo motu cognizance on digital arrest and deepfakes — proceedings from October 2025, hearing on 28 July 2026 (reported by LiveLaw, ETV Bharat, BOOM) ### Frequently asked questions **What is synthetically generated information (SGI) under the IT Amendment Rules, 2026?** Under Rule 2(1)(wa) as inserted on 10 February 2026, SGI is audio, visual or audio-visual information that is artificially or algorithmically created, generated, modified or altered using a computer resource in a manner that it appears to be real, authentic or true and depicts or portrays any individual or event in a manner that is, or is likely to be perceived as, indistinguishable from a natural person or real-world event. The Government's FAQ clarifies the focus is on content that realistically appears like a real person or real-world event and is capable of deceiving viewers — whether or not the method was labelled AI. **Does every AI-edited image count as SGI?** No. The Amendment Rules expressly exclude routine or good-faith editing, formatting, enhancement, technical correction, colour adjustment, noise reduction, transcription, translation, compression, preparation of documents and presentations, and accessibility tools such as text-to-speech — where the substance, context or meaning of the content is not materially altered or misrepresented. An AI filter that adjusts colour is not SGI; an AI-generated video of a person saying something they never said is. **What must platforms do for SGI under the IT Amendment Rules, 2026?** Since 20 February 2026, intermediaries must: inform users at least every three months that directing creation of unlawful SGI and sharing prohibited SGI is not allowed and what consequences follow (Rule 3(1)(c) and (ca)); deploy reasonable technical measures to prevent generation or sharing of prohibited SGI; require users to declare whether content is SGI and verify declarations (for SSMIs under Rule 4(1A)); prominently label confirmed SGI as synthetic or AI-generated with embedded metadata or provenance identifiers under Rule 3(3) (SGI-enabling intermediaries) and Rule 4(1A) (SSMIs); ensure labels and identifiers cannot be suppressed or removed; and remove unlawful content within three hours of actual knowledge via a court order or authorised government notification under Rule 3(1)(d) — with a separate two-hour track under Rule 3(2)(b) for individual complaints involving private-area/nudity/sexual act/impersonation including morphed imagery. **What is the takedown timeline for deepfakes and fake content in India now?** Three hours for unlawful information — including unlawful SGI — on receipt of actual knowledge through a court order or a notification from the appropriate government or its authorised agency under Rule 3(1)(d) (down from 36 hours). Two hours under Rule 3(2)(b) for individual complaints involving private-area/nudity/sexual act/impersonation including morphed imagery (down from 24 hours). For user grievances, the general window is seven days (down from 15 days) and 36 hours for unlawful-content grievances. The Sahyog portal is an established route for government takedown directions, upheld in X Corp v. Union of India, W.P. No. 7405 of 2025 (Karnataka High Court, 24 September 2025). **What SGI is prohibited outright?** An intermediary must not allow SGI that is obscene or sexually explicit, that invades privacy through impersonation or manipulation, that constitutes child sexual abuse material, that creates false documents or electronic records, that enables creation of explosives, arms or ammunition, or that falsely and deceptively depicts a natural person or real-world event. The prohibition sits alongside criminal liability under Sections 66C, 66D, 66E, 67, 67A and 67B of the IT Act and Sections 75, 77, 318, 319, 336, 353 and 356 of the BNS where the same content also violates those provisions. **Are satire, art and research using SGI allowed?** The Rules carve out good-faith uses: accessibility tools, academic research, testing and experimentation without deceptive intent, and creative works, satire or artistic expression involving synthetic media — provided the content is clearly labelled as synthetic and does not otherwise violate Rule 3(1)(b) or other applicable laws. Labelling and non-deceptiveness are the conditions; the carve-out is not a licence to deceive even in satire. --- ## Digital Arrest Scam in India: What It Is, Why It Is Fake, and What to Do URL: https://advaslam.com/writing/digital-arrest-scam-india-what-to-do/ Author: Adv. K J Muhammed Aslam, Advocate (Bar Council of Kerala, K/001823/2026) Published 1 September 2026 Practice area: Cyber crime & IT Act matters Digital arrest is not a legal procedure in India but extortion by impersonation. IT Act 66C/66D, BNS 318/308/351, why BNSS notices cannot come on WhatsApp. There is no such thing as digital arrest in Indian law. Every call, video call, WhatsApp message or email that claims you are under digital arrest by the CBI, ED, police, customs, TRAI or a court — and demands money to avoid being arrested — is a single, well-documented scam: impersonation plus extortion carried out over a computer resource. The correct sections are [Section 66C and Section 66D of the Information Technology Act, 2000](https://indiacode.gov.in/handle/123456789/496511), read with [Sections 318, 319, 308 and 351 of the Bharatiya Nyaya Sanhita, 2023](https://indiacode.gov.in/handle/123456789/496548). The Supreme Court has been monitoring digital arrest scams in a suo motu proceeding since October 2025 (Suo Motu Writ Crl. 3/2025, 17 Oct 2025, Surya Kant + Bagchi JJ.) and has repeatedly warned the public that no investigative agency conducts arrests over video calls. ## What does a digital arrest scam actually look like? The pattern is almost identical in every complaint, which is itself a clue that it is organised, not official: 1. A call or WhatsApp call from a number claiming to be from a courier company, TRAI, bank or police, saying a parcel in your name contains drugs or your Aadhaar has been misused. 2. The call is transferred to a person in police or CBI uniform on video, often with a fake backdrop of an office, who says an FIR or arrest warrant exists against you and you must stay on camera for verification. 3. You are told not to disconnect, not to tell family, and to transfer money to designated accounts for verification or to avoid arrest — sometimes styled as a refundable security deposit or a penalty. 4. The pressure lasts hours. Victims are kept on video while they arrange transfers, which is why the fraud succeeds even with educated complainants. A genuine investigation never works this way. A summons is in writing, identifies the case number and officer, cites a specific legal provision, and gives you time to respond through counsel. It is never issued by a police officer on a personal mobile video call demanding an immediate UPI transfer. ## Why is a WhatsApp or video-call notice not a real BNSS notice? Investigating officers have two standard written tools under the [Bharatiya Nagarik Suraksha Sanhita, 2023](https://indiacode.gov.in/handle/123456789/496550): * **Section 35 BNSS** (formerly Section 41A CrPC) — notice of appearance where arrest is not required for offences punishable with up to seven years. It requires the officer to record reasons and serve the notice in the prescribed manner so the person can appear and cooperate. * **Section 94 BNSS** (formerly Section 91 CrPC) — summons to produce a document or electronic record. Both are served through the modes the Code prescribes and leave a paper trail in the case diary. In January 2025 the Supreme Court, applying the [Satender Kumar Antil](https://indiankanoon.org/doc/112016767/) line of orders, clarified that a Section 35 notice cannot be served by WhatsApp, SMS or email alone — it must be served in the manner the Code contemplates. A PDF on WhatsApp bearing a police logo, or a video-call order to stay at home, has no legal status. If you receive one, treat it as evidence of the scam, not as a notice to be obeyed. The same reasoning exposes the video arrest itself. No provision of the BNSS authorises an officer to keep a person under observation over a video call, to restrict them to a room, or to demand money over the phone. Detention without following the arrest procedure under Sections 43 to 60 BNSS and production before a magistrate within 24 hours under Article 22(2) of the Constitution is unlawful. ## Which laws does a digital arrest scam violate? A single digital arrest episode typically triggers both the IT Act and the BNS, because the call uses a computer resource and involves cheating and coercion: | Act | Section | What it covers in a digital arrest | Maximum punishment | |---|---|---|---| | IT Act | [Section 66C](https://indiacode.gov.in/handle/123456789/496511) | Fraudulent use of another person's identity feature — the scammer uses the name, logo or identity of CBI, ED or police | Up to 3 years and fine up to one lakh rupees | | IT Act | [Section 66D](https://indiacode.gov.in/handle/123456789/496511) | Cheating by personation using a computer resource — pretending to be a public servant over phone or video | Up to 3 years and fine up to one lakh rupees | | BNS | [Section 318(4)](https://indiacode.gov.in/handle/123456789/496548) (formerly Section 420 IPC) | Cheating and dishonestly inducing delivery of property — the money transfer itself | Up to 7 years and fine | | BNS | [Section 319(2)](https://indiacode.gov.in/handle/123456789/496548) (formerly Section 419 IPC) | Cheating by personation | Up to 5 years or fine or both | | BNS | [Section 308](https://indiacode.gov.in/handle/123456789/496548) (formerly Sections 384 to 389 IPC) | Extortion — putting a person in fear to deliver money — the digital arrest threat itself | Up to 7 years (up to 10 years where fear is of death or grievous hurt, Section 308(5), or of an accusation of an offence punishable with death, life or up to 10 years, Section 308(7)) | | BNS | [Section 351](https://indiacode.gov.in/handle/123456789/496548) (formerly Section 506 IPC) | Criminal intimidation — threat of arrest or harm | Up to 2 years, 7 years if threat of death or grievous hurt | | BNS | [Section 111](https://indiacode.gov.in/handle/123456789/496548) | Organised crime — where two or more persons as a syndicate engage in continuing unlawful activity (cognizable, 3+ years; more than one charge-sheet in ten years with cognizance taken) | Minimum 5 years to life and minimum ₹5 lakh fine; rarely fits an isolated scam alone | Sections 66C and 66D are cognizable and attract investigation under Section 78 of the IT Act by an officer of Inspector rank or above. In Kerala that typically means the district Cyber Police Station. ## What should you do during and immediately after the call? The steps that protect both your money and your later complaint are counterintuitive — disconnecting feels rude when a uniform is on screen, but it is the correct legal response: 1. **End the call.** Say nothing about your bank balances. Do not argue about jurisdiction or ask for proof — argument keeps you on the line, which is the scammer's goal. 2. **Do not transfer money, share OTPs, install screen-sharing apps (AnyDesk, TeamViewer) or share Aadhaar, PAN or DigiLocker details.** No agency collects a verification amount over UPI or asks for remote access to your phone. 3. **Preserve evidence immediately.** Screenshot the caller ID, the video-call screen if you can without re-engaging, the UPI IDs or account numbers mentioned, and the chat. Note times. Do not delete anything — a deleted chat is lost corroboration. 4. **Call 1930 or file at [cybercrime.gov.in](https://cybercrime.gov.in) within minutes.** The operator registers the fraud on the Citizen Financial Cyber Frauds Reporting and Management System (CFCFRMS), which alerts the recipient banks in the transaction chain. This is the fastest and usually only victim-initiated system that can place a hold on money still inside the banking system, and it works on a clock measured in hours. 5. **Write to your bank the same day** giving the transaction reference, the amount, and the 1930 or NCRP acknowledgment number. Ask the bank to attempt a recall and to note the date of your intimation. For unauthorised debits the RBI limited-liability framework runs on a three-working-day clock from your notification, so a dated written complaint matters. 6. **File a written FIR** at your local police station or the district Cyber Police Station. Under Section 173 BNSS (formerly Section 154 CrPC) an FIR for a cognizable offence can be registered at any station irrespective of where the offence occurred — the statutory Zero FIR — including by electronic communication. If the scammers have already obtained a copy of your Aadhaar or a signature, consider placing a transaction alert with your bank and monitoring your CIBIL report for a short period, since identity misuse sometimes continues as a second attempt under Section 66C. ## How do you report a digital arrest scam so the report actually moves? A report that helps the investigation and preserves a later application for refund of frozen money has five parts — the same set that a magistrate will look for under ss.497/503 BNSS (as applicable) when you seek release of a held amount: 1. The 1930 or NCRP acknowledgment number and the time the incident was reported. 2. Your bank statement highlighting the debits, with the 12-digit UPI reference numbers for each transfer. 3. The numbers, UPI IDs, account numbers and any QR codes the scammers gave you. 4. Screenshots and call logs, with hash values preserved if possible — electronic records will later need a certificate under Section 63 of the Bharatiya Sakshya Adhiniyam, 2023 (the successor to Section 65B of the Evidence Act), so preserving the original device matters. 5. A short, dated narrative of what was said, in the order it happened, without embellishment. Keep a single PDF bundle and reuse it for the bank, the police and, if needed, the court. Consistency across forums is itself protective — contradictions in later retellings are what defence counsel exploit. ## Has the Supreme Court actually addressed digital arrest? Yes, and the fact that it has taken the phenomenon up suo motu is itself a measure of scale. In October 2025 the Supreme Court registered suo motu cognizance (Suo Motu Writ Crl. 3/2025, 17 Oct 2025, Surya Kant + Bagchi JJ.) after reports of elderly victims losing over one crore rupees to callers impersonating the CBI, Intelligence Bureau and the Supreme Court itself, issuing notice to the Union (MHA), the CBI and Haryana authorities. On 27 Oct 2025 the Court mooted entrusting investigation to the CBI on a pan-India basis and sought FIR details from States/UTs. For the public, the practical takeaway from that proceeding is simple: no statute recognises digital arrest as a lawful arrest today. ## How can families and businesses reduce the risk? No precaution eliminates a well-executed impersonation call, but these reduce both the odds and the damage: 1. **A family code word.** Digital arrest scammers isolate the victim and forbid contact with family. A pre-agreed check — a single message to a family member before any transfer — breaks the isolation the scam depends on. 2. **Verify independently.** If a caller claims to be from any agency, disconnect and call that agency's published landline or visit the nearest police station. No genuine officer objects to verification. 3. **Treat any demand for money on a call as a hard stop.** No court, police unit, customs office or TRAI official collects money over a phone or video call. That single rule, if internalised, defeats the entire scam. 4. **Limit screen-sharing.** Train staff and family never to install remote-access tools on the instruction of a caller, no matter the logo on screen. 5. **Report fast, even if embarrassed.** The CFCFRMS window is measured in hours. Delay out of shame is the mechanism by which a recoverable fraud becomes an unrecoverable one. ## Primary sources * [Information Technology Act, 2000 — India Code](https://indiacode.gov.in/handle/123456789/496511) (Sections 66C, 66D, 78, 79) * [Bharatiya Nyaya Sanhita, 2023 — India Code](https://indiacode.gov.in/handle/123456789/496548) (Sections 308, 318, 319, 351, 111) * [Bharatiya Nagarik Suraksha Sanhita, 2023 — India Code](https://indiacode.gov.in/handle/123456789/496550) (Sections 35, 43, 94, 173, 497, 503) * [Bharatiya Sakshya Adhiniyam, 2023 — India Code](https://indiacode.gov.in/handle/123456789/496549) (Section 63 on electronic evidence) * [National Cyber Crime Reporting Portal — cybercrime.gov.in](https://cybercrime.gov.in) and the 1930 helpline (Indian Cyber Crime Coordination Centre, Ministry of Home Affairs) * Supreme Court suo motu cognizance on digital arrest scams — Suo Motu Writ Crl. 3/2025, order 17 Oct 2025 (Surya Kant + Bagchi JJ., notice to Union/MHA, CBI, Haryana) with CBI-entrustment mooted 27 Oct 2025 (reported by Medianama 28 Oct 2025; The Hindu 27 Oct 2025) ### Frequently asked questions **Is digital arrest a real legal procedure in India?** No. No statute — not the Bharatiya Nagarik Suraksha Sanhita, 2023, the IT Act, 2000, or any other law — recognises a procedure called digital arrest. Police, CBI, ED, customs or a court never arrest or interrogate a person over a video call, never demand money to avoid arrest, and never conduct an investigation by keeping you on camera for hours. Every digital arrest call is impersonation and extortion under Section 66D of the IT Act and Sections 319 and 308 of the Bharatiya Nyaya Sanhita. **What should I do if I receive a digital arrest call?** Disconnect without arguing, do not transfer money or share OTPs or Aadhaar details, preserve the caller number, UPI IDs and screenshots, and report immediately on the National Cyber Crime Reporting Portal (cybercrime.gov.in) or the 1930 helpline. If money has been transferred, the 1930 report is the fastest and usually only victim-initiated mechanism that can attempt to freeze it in the banking chain while you file a written complaint at your local or cyber police station for an FIR. **Can a police notice under Section 35 BNSS come on WhatsApp or email?** No. The Supreme Court has clarified that a notice under Section 35 BNSS (which replaced Section 41A CrPC for offences punishable with up to seven years) must be served in the manner prescribed by the Code — not by WhatsApp, SMS, email or video call. Any WhatsApp or email purporting to be a Section 35 notice or a digital arrest order is fake and should be treated as part of the scam. **What punishment do digital arrest scammers face?** A digital arrest scheme typically attracts Section 66C (identity theft) and Section 66D (cheating by personation using a computer resource) of the IT Act — each up to three years and fine up to one lakh rupees — together with Section 318(4) BNS (cheating, up to seven years), Section 319(2) BNS (cheating by personation, up to five years), Section 308 BNS (extortion, up to seven years; up to ten years where the fear is of death or grievous hurt under Section 308(5), or of an accusation of an offence punishable with death, life imprisonment or up to ten years under Section 308(7)), and Section 351 BNS (criminal intimidation). Where an organised syndicate meets the Section 111 BNS ingredients (two or more persons, continuing unlawful activity with more than one charge-sheet in ten years and cognizance taken, minimum five years to life and minimum ₹5 lakh fine), Section 111 can apply — it rarely fits an isolated scam standing alone. **Can I get my money back after a digital arrest fraud?** Recovery depends almost entirely on speed. If you report through 1930 or cybercrime.gov.in within the first few hours, the Citizen Financial Cyber Frauds Reporting and Management System (CFCFRMS) can hold the amount in the recipient accounts and a magistrate can later order its release under ss.497/503 BNSS (as applicable). Once the money is withdrawn as cash or layered through multiple mule accounts, recovery becomes far harder and depends on the criminal case or a civil claim against traceable beneficiaries. --- ## DPDP Act and Children's Data in India: Verifiable Parental Consent, Tracking Bans and What EdTech Must Change URL: https://advaslam.com/writing/dpdp-children-data-parental-consent-guide/ Author: Adv. K J Muhammed Aslam, Advocate (Bar Council of Kerala, K/001823/2026) Published 1 September 2026 Practice area: Data protection & DPDP compliance DPDP Act Section 9 treats anyone under 18 as a child. Verifiable parental consent, the tracking and targeted-ad ban, Rule 10 verification and a checklist. Under the [Digital Personal Data Protection Act, 2023](https://indiacode.gov.in/handle/123456789/496508), a child is anyone who has not completed 18 years of age — [Section 2(f)](https://indiacode.gov.in/handle/123456789/496508) — and before processing a child's personal data a business must obtain **verifiable consent of a parent or lawful guardian** under [Section 9(1)](https://indiacode.gov.in/handle/123456789/496508), while [Section 9(2)](https://indiacode.gov.in/handle/123456789/496508) and [Section 9(3)](https://indiacode.gov.in/handle/123456789/496508) prohibit — with only narrow, notified exceptions — processing likely to cause detrimental effect on a child's well-being, tracking, behavioural monitoring and targeted advertising directed at children. Breach of these duties carries a penalty of up to **two hundred crore rupees**. ## Why is children's data the highest-risk DPDP obligation for most Kerala businesses? Because the age threshold catches far more users than teams expect, and the prohibitions go to product design, not just paperwork. A business that thinks of its users as young adults — a learning app, a gaming platform, a social community, a health or counselling service — often discovers that a large share of its registered base is under 18. Under Section 9, every one of those users must be handled through parental consent, and every tracking and ad-targeting decision must be re-examined. Kerala is not an edge case here. KSUM-backed edtech, healthtech and gaming startups in Kochi and Thiruvananthapuram, tuition centres and schools that run apps and CRMs, and consumer apps with nationwide reach all process children's data. The startup exemption power in Section 17(3) does not extend to Section 9 at all; the relaxations are the classes and purposes prescribed under Section 9(4), set out in the Fourth Schedule to the Rules, and any age-based exemption the Central Government notifies under Section 9(5) for a fiduciary whose processing of children's data is verifiably safe. The obligation applies in full from **14 May 2027** — the date the 18-month tranche of the [DPDP Rules, 2025](https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf) (G.S.R. 846(E), 13 November 2025) commences, together with the [Section 33 penalty regime](https://indiacode.gov.in/handle/123456789/496508). The Board's powers and inquiry procedure are set by the Act itself (Sections 27 and 28) — content that treats May 2027 as distant is underestimating the engineering time an age-gating and consent redesign actually takes. ## What does verifiable parental consent mean under Rule 10? Section 9(1) states the principle. Rule 10 of the DPDP Rules, 2025 supplies the method, and its design is deliberately more demanding than a checkbox: * **What must be verified:** that the person giving consent for the child's data is actually the parent or lawful guardian, and that the child is indeed a child. The fiduciary must be able to demonstrate this verification if the Board asks. * **How verification is done:** by relying on identity and age details the fiduciary already holds about the parent or guardian, or on details voluntarily provided and then verified — Rule 10 contemplates checking through means such as **Digital Locker** (under the IT Act framework) or a **virtual token issued by an authorised entity**. The token approach is designed so the fiduciary does not need to collect and store a parent's full identity document where a tokenised confirmation suffices. * **Parallel for persons with disabilities:** Rule 11 applies a similar verifiable-consent scheme where the Data Principal has a lawful guardian under the Rights of Persons with Disabilities Act framework. What does not satisfy the rule: a self-declared I am 18 checkbox, a pre-ticked parental consent box, or an email link that anyone with access to the child's email can click. The word verifiable in Section 9(1) was chosen to exclude exactly those patterns. ## What is banned outright — and what falls in the narrow exemptions? Two prohibitions in Section 9 apply in addition to the parental-consent requirement, and they apply even where parental consent for general processing has been obtained: * **Section 9(2)** — no processing of personal data of a child that is likely to cause any **detrimental effect on the well-being** of the child. Detriment is not defined exhaustively in the Act and will be shaped by the Board and by sectoral guidance, but the plain meaning covers physical, mental and social well-being. * **Section 9(3)** — no **tracking or behavioural monitoring** of children, and no **targeted advertising directed at children**. This is an absolute bar on the product patterns most consumer apps monetise: profiling for ad targeting, recommendation engines that track a child's behaviour across sessions, and personalised ad delivery to children. The **Fourth Schedule**, read with **Rule 12**, then carves out a small set of exempted classes of fiduciaries and purposes — Part A covers clinical establishments, mental health establishments and healthcare professionals (health services only), allied healthcare professionals, educational institutions (tracking/behavioural monitoring for educational activities or child safety only), crèche or child day-care carers, and transport engaged by such institutions; Part B covers purposes such as legal duties in the interests of the child, subsidies/benefits under Section 7(b), email-account creation, real-time location for safety, filtering detrimental content from children, and age-confirmation/Rule 10 due diligence — each purpose-bound and class-bound. The key point for most businesses: the exemption is purpose-bound and class-bound. An edtech that processes a child's data to deliver a lesson may fall within the educational purpose in its teaching function, but that does not exempt the same company's ad network from the Section 9(3) ban on targeted advertising to children on the same app. Each processing purpose must be tested separately. ## What must a Kerala school, college, edtech or consumer app actually build? The practical work is product and data-architecture work, not just a policy update. A realistic implementation sequence for a team starting in late 2026: 1. **Map where children are.** Identify every flow where an individual under 18 can be a Data Principal — registration, marketing lists, analytics, support tickets, payment flows. If age is not collected today, that is itself the gap — you cannot route children through parental consent if you do not know who they are. 2. **Design age-gating.** Build a verification step at registration or at the point data is first collected that determines age in a verifiable way. For mixed-age apps, this means a neutral age gate before any personal data beyond the gate itself is processed, with under-18 users diverted to the parental-consent flow rather than the standard onboarding. 3. **Build the parental-consent flow under Rule 10.** Implement the verification against identity details already held or against voluntarily provided details checked via Digital Locker or an authorised virtual token. Log the consent with the particulars Section 6(10) requires the fiduciary to be able to prove — who consented, when, on what notice, for what purposes. 4. **Strip tracking and targeted ads for children.** Audit every SDK, analytics event and ad call that fires for a child user. Disable behavioural monitoring and targeted advertising for children entirely unless the specific processing falls within a Fourth Schedule / Rule 12 exemption and has been documented as such with legal review. 5. **Rewrite the notice for parents.** The [Section 5 notice](https://indiacode.gov.in/handle/123456789/496508) — itemised, in clear language, available in English and the Eighth Schedule languages the parent chooses, including Malayalam — must precede the consent request. A privacy policy link does not satisfy Section 5. 6. **Set retention and erasure.** Section 8(7) requires erasure once consent is withdrawn or the specified purpose is no longer served, unless retention is required by law. For large e-commerce, gaming and social media intermediaries with thresholds in the Third Schedule, Rule 8 adds a three-year inactivity clock. Build the deletion job, not just the written retention schedule. 7. **Train support.** A parent who writes in to withdraw consent under Section 6(4) — withdrawing must be as easy as giving it — must have that withdrawal honoured and logged, and a child who contacts support must not be social-engineered around the gate. ## How does this interact with other laws schools and apps already follow? DPDP Section 9 sits on top of, not instead of, existing duties: * **IT Act and intermediary duties.** A platform that hosts user-generated content is also subject to the [IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021](https://indiacode.gov.in/handle/123456789/510236) as amended on 10 February 2026, which accelerates takedown for CSAM and non-consensual intimate imagery involving children to two hours on a complaint under Rule 3(2)(b) (previously twenty-four hours). DPDP verifiable consent and IT Act takedown are cumulative. * **Education-specific regulation.** School and college data handling is also shaped by affiliation-board and state guidelines, but none of those displaces the DPDP requirement — a CBSE or Kerala state-board affiliation does not exempt an institution from being a Data Fiduciary for the digital personal data it processes. * **BSA evidence.** Consent logs that prove verifiable parental consent was obtained will, if disputed, be electronic records that need a [Section 63 BSA certificate](https://indiacode.gov.in/handle/123456789/496549) (new 65B) to be admissible. Design the log with hash and dual-signature certification in mind from the start — see the [electronic evidence guide](https://advaslam.com/writing/electronic-evidence-bsa-section-63-certificate-guide/). ## Primary sources * [Digital Personal Data Protection Act, 2023 — India Code](https://indiacode.gov.in/handle/123456789/496508) (Sections 2(f), 5, 6, 8, 9, 10, 33 and the Schedule) * [Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E), 13 November 2025) — MeitY](https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf) (Rules 3, 6, 7, 8, 10, 11, 12, 14, First, Third and Fourth Schedules) * [PIB backgrounder and press release on notification of the DPDP Rules (14 and 17 November 2025)](https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc20251117695301.pdf) * [IT (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 (G.S.R. 120(E), 10 February 2026) — Gazette of India](https://egazette.gov.in/WriteReadData/2026/269993.pdf) (Rules 3(1)(d), 3(2) — two-hour takedown for CSAM and non-consensual imagery) * [Bharatiya Sakshya Adhiniyam, 2023 — India Code](https://indiacode.gov.in/handle/123456789/496549) (Section 63 on electronic evidence certificates) ### Frequently asked questions **Who is a child under the DPDP Act, 2023?** Anyone under 18 years of age. Section 2(f) of the DPDP Act, 2023 defines a child as an individual who has not completed 18 years. This is stricter than the GDPR, where a child can be 13 to 16 depending on the member state, and the US COPPA, where a child is under 13. Indian businesses must apply the 18-year threshold for all DPDP purposes. **What is verifiable parental consent under the DPDP Act?** Section 9(1) requires a Data Fiduciary to obtain verifiable consent of the parent or lawful guardian before processing any personal data of a child. Rule 10 of the DPDP Rules, 2025 prescribes the verification manner: the fiduciary must rely on identity and age details it already holds, or on details voluntarily provided and checked through means such as Digital Locker or a virtual token issued by an authorised entity, so that the person giving consent is actually the parent or guardian. **Can a business track children or show them targeted ads under the DPDP Act?** No, except within narrow, notified exemptions. Section 9(2) prohibits processing likely to cause detrimental effect on the well-being of a child. Section 9(3) prohibits tracking or behavioural monitoring of children and targeted advertising directed at children. The Fourth Schedule, read with Rule 12, exempts only limited classes and purposes such as healthcare, education, childcare and real-time safety — not general commercial targeting. **What is the penalty for violating children's data obligations?** Up to two hundred crore rupees per breach under the Schedule to the DPDP Act, read with Section 33, imposed by the Data Protection Board after inquiry and hearing weighing factors under Section 33(2). This is one of the highest penalty bands in the Act, alongside the penalty for failing to maintain reasonable security safeguards. **Does an edtech app need parental consent if the user says they are 18?** The Act requires the fiduciary to actually verify, not merely ask. Relying on a self-declared checkbox that the user is 18, without a verifiable parental-consent step where the user is in fact a child, does not satisfy Section 9(1) read with Rule 10. The business needs an age-gating design that checks age in a verifiable way and routes under-18 users through parental consent before any processing. --- ## Cross-Border Data Transfers Under the DPDP Act: What Section 16 and Rule 15 Actually Allow URL: https://advaslam.com/writing/dpdp-cross-border-data-transfer-section-16/ Author: Adv. K J Muhammed Aslam, Advocate (Bar Council of Kerala, K/001823/2026) Published 1 September 2026 Practice area: Data protection & DPDP compliance DPDP Act Section 16 allows data transfers abroad unless the Government restricts notified countries. Sectoral exceptions (RBI) and transfer clauses explained. Cross-border transfer of personal data under the [Digital Personal Data Protection Act, 2023](https://indiacode.gov.in/handle/123456789/496508) is **permitted by default** — [Section 16(1)](https://indiacode.gov.in/handle/123456789/496508) allows transfer outside India unless the Central Government by notification restricts transfers to a notified country or territory, and [Rule 15 of the DPDP Rules, 2025](https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf) (G.S.R. 846(E), 13 November 2025) carries that permissive design forward. This article explains the default rule, the two restriction powers that qualify it, the sectoral exceptions that sit outside the DPDP Act, and the contract and disclosure work a Kerala business should do now — before any restriction is notified. ## What is the default position — ban, adequacy, or permission? India chose permission with a blacklist, not a ban or an adequacy whitelist. The legislative history matters because most teams assume one of the two other models: * **Ban / localisation by default** — data must stay in India unless an exception allows export (the model some earlier drafts contemplated). The DPDP Act as enacted rejected this. * **Adequacy whitelist** — data may flow only to countries the Government has declared adequate (the GDPR Chapter V approach). The DPDP Act rejected this as well. * **Permission with blacklist — what the Act actually does.** Section 16(1) provides that the Central Government may, by notification, restrict transfer to any country or territory outside India. Until such a notification for a destination exists, transfer to that destination is not prohibited by Section 16. Rule 15 of the DPDP Rules, 2025 sits alongside this restriction power: the Rules themselves list neither a whitelist nor a blacklist; instead, the Government may, by general or special order, specify requirements in respect of making personal data available to a foreign State, or to any person or entity under the control of, or any agency of, such a State. > **Practical distinction:** Law — Section 16's permissive default — is not the same as advice that every transfer is advisable without safeguards. The Act permits; prudent contracting, security and disclosure are still required by Sections 8, 5 and 6. No general Section 16 restriction to specific countries had been notified as of August 2026. That makes the present task for businesses preparatory: build transfers on a lawful basis, disclose them, and keep the contractual and technical ability to comply quickly if a restriction for a destination you use is later notified. ## What are the two restriction powers, and how do they differ? | Feature | Section 16 (general) | Rule 13(4) read with Rule 15 (SDF-specific) | |---|---|---| | **Whose data** | Any personal data transferred outside India by any Data Fiduciary | Personal data and traffic data of a notified Significant Data Fiduciary, as specified by the Government on a committee recommendation | | **Trigger** | Notification by the Central Government restricting transfers to a notified country or territory outside India | Direction to a specific notified SDF or SDF class to keep specified data within India | | **Default** | Transfer allowed unless restricted | Transfer allowed unless this SDF-specific direction says otherwise for the specified data | | **Scope** | Destination-based — all fiduciaries transferring to that country are affected | Fiduciary-based and data-category-based — only that SDF and only the specified personal data and traffic data | | **Example** | A future order restricting transfer of personal data to Country X for all fiduciaries | A direction requiring notified healthtech or fintech SDFs to keep health or financial data and associated traffic data within India | | **Status as of Aug 2026** | No general restriction notified | No SDF class notified, so no SDF localisation direction could have been made | A Kerala SaaS that replicates a customer database from Mumbai to a US region for analytics is therefore governed in the first instance by Section 16: the transfer is allowed today, but the business should have a contractual path to repatriate or re-route the flow if Country X were later restricted. ## How do sectoral rules interact with Section 16? DPDP is not the only transfer rule in the room. Three sectoral frameworks continue to operate in parallel and can be stricter than the DPDP default: * **Payments.** The [RBI circular dated 6 April 2018 on Storage of Payment System Data](https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=11244) requires that all data relating to payment systems — including end-to-end transaction details and information collected or processed as part of a payment instruction — be stored in systems located only in India. This is a binding sectoral localisation independent of DPDP. A fintech that assumes DPDP's permissive default overrides the RBI storage requirement is mistaken. * **Insurance, securities and telecom.** IRDAI, SEBI and DoT impose data-handling and retention conditions for regulated data that include system-location and access requirements. Those conditions persist alongside DPDP. * **Government access.** Section 17(1)(a) DPDP Act exempts processing necessary for enforcing any legal right or claim; Section 17(2)(a) exempts processing by a notified instrumentality of the State in the interests of sovereignty and integrity of India, security of the State, public order or preventing incitement to any cognizable offence; and Section 17(2)(b) covers research, archiving or statistical processing subject to prescribed standards. Those exemptions can affect availability and access, but they do not create a general exemption from the sectoral storage mandates. The correct mental model is cumulative: the most restrictive applicable rule governs the specific data, and DPDP's permissive default fills the space where no sectoral rule imposes a stricter condition. ## What must the Section 5 notice and Section 6 consent say about transfers? Neither Section 5 nor Section 6 creates a standalone transfer-consent, but both shape what a compliant transfer looks like: * **Section 5 notice.** The notice given before or at the time of seeking consent must be itemised and in clear, plain language, available in English and the Eighth Schedule languages the Data Principal chooses (including Malayalam for Kerala users). It must describe the personal data and the specified purpose. Where the purpose involves processing outside India — for example, analytics, support or model training in a foreign region — the purpose description should make that transparent. A notice that says data is processed to provide analytics without disclosing that analytics occurs outside India is not inaccurate under Section 16, but it is weaker disclosure than a notice that transparently describes the processing location where material to the user's understanding. * **Section 6 consent.** Consent must be free, specific, informed, unconditional and unambiguous by clear affirmative action. If the purpose for which consent is sought includes cross-border processing, the specificity requirement means the consent cannot be a bundled, vague authorisation for unspecified future transfers — it must be tied to the described purpose. Withdrawal must be as easy as giving consent (Section 6(4)), which means a transfer that continues after withdrawal of consent for that purpose is no longer on a valid basis. ## What contract terms cover cross-border transfers in practice? The transfer itself is operational; the contract is what makes it governable. For every processor or sub-processor outside India that handles personal data on your behalf, align the agreement with these DPDP anchors: 1. **Purpose and scope tie to the notice and consent.** The agreement should recite the specified purpose from the Section 5 notice and prohibit processing beyond it. This is the Article 28 GDPR equivalent that Indian vendor contracts increasingly need — not because the DPDP Act copies GDPR, but because purpose limitation under Section 8(1) and Section 4 requires it. 2. **Sub-processing controls.** No onward transfer or sub-engagement without prior authorisation, with the same obligations flowed down. This is essential where a US analytics provider sub-processes through its own foreign sub-processors. 3. **Security floor under Rule 6.** Encryption or masking, access controls, logging for at least one year, monitoring and backups — the Rule 6 minimum — must be contractually required of every processor, including foreign ones. DPDP's highest penalty band — up to two hundred and fifty crore rupees — sits on failure of reasonable security safeguards (Section 8(5)). 4. **Breach timelines that let you meet Rule 7.** The processor must notify you of any personal data breach without delay and in any event within a time that lets you meet your own without-delay intimations to affected individuals and to the Board and your detailed 72-hour report. A processor clause that allows notification in 72 hours fails this test — you need notification in hours, not days. For the dual-clock problem where CERT-In's six-hour duty also applies, see the [CERT-In 6-hour vs DPDP 72-hour guide](https://advaslam.com/writing/cert-in-6-hour-vs-dpdp-72-hour-breach-reporting/). 5. **Erasure and return.** Section 8(7) erasure once consent is withdrawn or the purpose is no longer served (unless retention is required by law), plus Rule 8 timelines and the Third Schedule three-year clock for large e-commerce, gaming and social media fiduciaries. The contract must require certified deletion and return on termination and on your instruction, and must address backups and logs. 6. **Restriction-readiness.** An undertaking to comply promptly with any future restriction under Section 16 or direction under Rule 13(4) — including repatriation or re-routing of data — and to cooperate with audits. Build the clause now so a later notification does not require renegotiation under time pressure. 7. **Rights assistance.** Technical and organisational assistance to fulfil Data Principal rights under Sections 11 to 14 and grievance redressal under Section 13 within the Rule 14 ninety-day window. ## How should a Kerala business handle transfers today, before any restriction? A practical posture that satisfies the current permissive default while preserving agility: 1. **Map transfer destinations.** For every personal-data flow, record where data is stored and where it is processed — including failover regions, support access from outside India, and analytics copies — not only the primary region. 2. **Check sectoral constraints first.** If the data is payment system data or otherwise subject to a sectoral storage mandate, that mandate governs regardless of DPDP's default. 3. **Ensure notice and consent cover the destination purpose.** Update the Section 5 notice to transparently describe processing purposes that involve outside-India systems, and ensure Section 6 consent is specific to those purposes. 4. **Harden processor contracts** against the seven points above, and keep a register of foreign processors and sub-processors with their locations and purposes — the record the Board would ask for first. 5. **Monitor for notifications.** Section 16 and Rule 13(4) actions appear as Gazette notifications and press releases from MeitY. Assign ownership for monitoring them — the DPO or the contact person published under Section 8(9) is the natural owner — and keep a written playbook for repatriation or re-routing if a destination you use is restricted. ## Primary sources * [Digital Personal Data Protection Act, 2023 — India Code](https://indiacode.gov.in/handle/123456789/496508) (Sections 2(i), 4, 5, 6, 8, 10, 16, 17 and the Schedule) * [Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E), 13 November 2025) — MeitY](https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf) (Rules 3, 6, 7, 8, 13, 15) * [RBI Circular on Storage of Payment System Data (6 April 2018)](https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=11244) * [PIB backgrounder and press release on notification of the DPDP Rules (14 and 17 November 2025)](https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc20251117695301.pdf) ### Frequently asked questions **Does the DPDP Act ban transferring personal data outside India?** No. Section 16(1) of the DPDP Act, 2023 states that the Central Government may, by notification, restrict transfer of personal data to a country or territory outside India — which means the default is permissive. Cross-border transfer is allowed unless the Government has issued such a notification for a destination (Rule 15 provides the general-or-special-order machinery for requirements on making data available to a foreign State). No such general restriction had been notified as of August 2026. **Do I need consent to transfer personal data outside India under the DPDP Act?** The DPDP Act does not add a separate consent for transfer as a distinct legal basis. If the processing — including the transfer — is covered by valid consent for the specified purpose under Section 6 or by a legitimate use under Section 7, and the general conditions of Section 16 and Rule 15 are met (no applicable restriction to that destination), no additional transfer-specific consent is required. The Section 5 notice should, however, describe that the data may be transferred and the purpose for which. **If my Kerala startup stores data on AWS Mumbai but analytics runs in the US, is that a cross-border transfer under the DPDP Act?** Yes. Moving personal data from systems in India to systems outside India — including to a foreign region of the same cloud provider for processing or analytics — is a transfer outside India for Section 16 purposes. It is permitted by default unless the destination is restricted by a Government notification under Section 16 or a localisation direction under Rule 13(4) for Significant Data Fiduciaries, but you must still have a lawful basis under Sections 4 to 7, provide the Section 5 notice, and ensure the transfer is covered by your disclosed purposes and by appropriate contractual protections with the processor. **Can the Government require data to stay in India under the DPDP Act?** Yes, in two ways. Under Section 16(1) the Government can, by notification, restrict transfer to specific countries or territories. Separately, under Rule 13(4), the Government can, on a committee recommendation, direct a notified Significant Data Fiduciary to keep such personal data and traffic data as it specifies within India. The second power is SDF-specific and targeted; the first is general. Neither had been exercised by general notification as of August 2026. **Does RBI's requirement that payment data be stored in India still apply after the DPDP Act?** Yes. The DPDP Act does not override sectoral localisation that already exists. The RBI circular of 6 April 2018 requiring storage of payment system data in India continues to operate independently of the DPDP framework. A business handling payment data must comply with both — the RBI storage requirement and the DPDP Act's general conditions on processing and transfer. **What clauses should cross-border processor contracts include for DPDP compliance?** At minimum: scope and purpose limitation tied to the Section 5 notice and Section 6 consent, a prohibition on sub-processing without authorisation, the Rule 6 security safeguards floor (encryption or masking, access controls, logging for one year, backups), breach-notification timelines that let you meet the Rule 7 72-hour Board duty, erasure and return on termination under Section 8(7) and Rule 8, audit rights, and a commitment to comply with any future Section 16 restriction or Rule 13(4) direction that may apply to the data. --- ## Significant Data Fiduciaries Under the DPDP Act: Who They Are and What Extra Duties They Carry URL: https://advaslam.com/writing/dpdp-significant-data-fiduciary-sdf-obligations/ Author: Adv. K J Muhammed Aslam, Advocate (Bar Council of Kerala, K/001823/2026) Published 1 September 2026 Practice area: Data protection & DPDP compliance How Significant Data Fiduciaries are designated under DPDP Act Section 10 and their extra duties: DPO, auditor, DPIA, algorithmic due diligence, localisation. A Significant Data Fiduciary (SDF) under the [Digital Personal Data Protection Act, 2023](https://indiacode.gov.in/handle/123456789/496508) is not a status a business chooses — it is a designation the Central Government makes under [Section 10](https://indiacode.gov.in/handle/123456789/496508) on risk-based factors, and once notified the fiduciary carries five extra statutory duties on top of the baseline that every Data Fiduciary carries: a board-answerable [Data Protection Officer in India](https://indiacode.gov.in/handle/123456789/496508), an independent data auditor, an annual [Data Protection Impact Assessment (DPIA)](https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf) and audit with reporting to the Board, algorithmic due diligence, and a possible data-localisation direction for notified categories of data. No SDF class had been notified as of August 2026, which makes the current window the time to prepare, not the time to wait. ## How does a business become an SDF? The process is entirely governmental, which surprises teams that expect a registration threshold like significant social media intermediary status under the IT Rules. Under [Section 10(1) DPDP Act](https://indiacode.gov.in/handle/123456789/496508) the Central Government may notify any Data Fiduciary or class of Data Fiduciaries as an SDF having regard to: * Volume and sensitivity of personal data processed. * Risk to the rights of Data Principals. * Potential impact on the sovereignty and integrity of India, electoral democracy, security of the State and public order. The Government can notify by category — for example, all e-commerce entities above a user threshold, or all fiduciaries processing certain sensitive data — or by naming a specific fiduciary. Assessment is as the Government determines on the Section 10(1) factors. The practical consequence for Kerala businesses is that SDF status is not limited to Big Tech. A healthtech handling health data (which is personal data of high sensitivity), a fintech processing financial data at volume, or an adtech platform whose profiling affects rights at scale could be designated as part of a class even without the headcount of a social media intermediary. The [Kerala Startup Mission](https://startupmission.kerala.gov.in) cohort — particularly startups that have scaled beyond Kerala to a pan-India user base — should assess SDF readiness as a risk scenario, not as a distant hypothetical. ## What are the five extra SDF duties? ### 1. Data Protection Officer in India, answerable to the board Under [Section 10(2)(a) DPDP Act](https://indiacode.gov.in/handle/123456789/496508), a notified SDF must appoint a **Data Protection Officer based in India** who is the contact point for grievance redressal and who is **answerable to the board of directors** (or the governing body for non-corporate fiduciaries). The DPO is not a compliance-department delegate with an email alias — the statute places the role at board level so that data protection decisions have board visibility and accountability. The DPO details must be published under Section 8(9) (general fiduciary duty to publish business contact information) and must be the channel through which Data Principals can exercise their Section 13 grievance rights against the SDF. ### 2. Independent data auditor Under [Section 10(2)(b)](https://indiacode.gov.in/handle/123456789/496508) and Rule 13, a notified SDF must appoint an **independent data auditor** — an external, qualified auditor, not an internal team — to audit its compliance with the Act and Rules. The independence requirement is substantive: an auditor who is also a vendor providing the SDF's data-processing infrastructure would not satisfy the independence test. The auditor's access must be sufficient to verify processing activities, security safeguards and cross-border handling, and the audit findings feed the DPIA and the Board reporting below. ### 3. Data Protection Impact Assessment and periodic audit — at least every 12 months Under [Section 10(2)(c)](https://indiacode.gov.in/handle/123456789/496508) and Rule 13, a notified SDF must conduct a **Data Protection Impact Assessment** and a periodic **audit** and report **significant observations** to the [Data Protection Board of India](https://www.meity.gov.in). The periodicity is at least **once every 12 months** from the date of notification as an SDF (or from the previous assessment). The DPIA must assess the risks of the SDF's processing to Data Principal rights, the safeguards in place, and the effectiveness of security and governance controls. Rule 13 requires that the significant observations from the DPIA and audit be placed before the Board — not merely retained internally — so the assessment has regulatory visibility from the start. ### 4. Algorithmic due diligence Under [Rule 13(3) DPDP Rules, 2025](https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf), an SDF must undertake **due diligence to verify that its algorithms and other technical means do not pose risks to the rights of Data Principals**. For Kerala businesses building recommendation, pricing, hiring, credit-scoring or content-moderation algorithms, this is the provision that connects data protection to AI governance: a model that profiles or ranks individuals using personal data must be checked that it does not discriminate, misclassify or otherwise infringe rights. The duty complements — but is separate from — the [IT Amendment Rules, 2026](https://egazette.gov.in) duties on synthetically generated information and the emerging AI governance discussion at MeitY. ### 5. Possible data-localisation direction Under [Rule 13(4) DPDP Rules, 2025](https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf) read with Rule 15, the Central Government may, on the recommendation of a committee constituted for Rule 13, direct a notified SDF to ensure that such **personal data and associated traffic data** as it specifies is **not transferred outside India** and is **kept within India**. No such specification had been made as of August 2026. The general DPDP position on cross-border transfer under [Section 16](https://indiacode.gov.in/handle/123456789/496508) and Rule 15 is permissive by default — transfer is allowed unless the Government by notification restricts flows to specific countries — but the SDF localisation power under Rule 13(4) is an additional, targeted power that can require an SDF to keep notified data categories in India even where Section 16 would otherwise permit transfer. For a full treatment of cross-border rules, see the [cross-border data transfer guide](https://advaslam.com/writing/dpdp-cross-border-data-transfer-section-16/). ## What stays the same — the baseline every fiduciary carries regardless of SDF status? SDF duties are additive. Every Data Fiduciary, whether or not notified as significant, must from **May 2027** (the 18-month tranche of the DPDP Rules, G.S.R. 846(E), 13 November 2025) comply with: * **Section 5 notice** — itemised, plain-language notice before consent, in English and Eighth Schedule languages chosen by the Data Principal, including Malayalam for Kerala users. * **Section 6 consent** — free, specific, informed, unconditional and unambiguous consent by clear affirmative action, with withdrawal as easy as giving it, and the fiduciary bearing the burden of proof under Section 6(10). * **Section 8 security and breach** — [reasonable security safeguards](https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf) under Rule 6 (encryption or masking, access controls, logging for one year, monitoring and backups) and breach notification under [Rule 7](https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf) — without-delay intimation to affected individuals and to the Board, with a detailed report within 72 hours. * **Section 8(7) erasure** — erasure once consent is withdrawn or the specified purpose is no longer served, unless retention is required by law, with Rule 8 adding a three-year inactivity clock for large e-commerce, gaming and social media fiduciaries named in the Third Schedule. * **Section 9 children's data, Sections 11 to 14 Data Principal rights, Section 13 grievance redressal, and Section 14 nomination.** A Kerala business that waits for an SDF notification to begin this baseline work will find that the 12-month SDF clock then starts on top of unfinished baseline work — the position where penalties compound. The schedule in [the DPDP countdown guide](https://advaslam.com/writing/dpdp-act-deadline-businesses/) treats the baseline as the current priority for precisely this reason. ## What should a Kerala business do now if it might become an SDF? A practical pre-notification programme that does not waste effort if the business is never notified, but that avoids a scramble if it is: 1. **Map and classify data sensitivity.** Not every data field carries the same SDF risk. Tag personal data by sensitivity — health, financial, biometric, location — and by volume, so the Section 10(1) factors can be self-assessed against realistic Government criteria. 2. **Identify a board-answerable DPO candidate.** Even before formal SDF status, designating a senior person with board access and publishing their contact satisfies the spirit of Section 8(9) and means the Section 10(2)(a) appointment is a formalisation, not a fresh hire and induction in 2027. 3. **Scope the independent auditor.** Engage in early conversations with qualified data auditors about scope, access and independence, so the first Section 10(2)(b) audit can be commissioned without a procurement cycle that consumes half the 12-month window. 4. **Run a DPIA pilot on the highest-risk processing.** Pick one high-volume or high-sensitivity flow — for example, an AI-driven recommendation or a health-data pipeline — and run a DPIA using the Rule 13 structure. The pilot builds the methodology, the evidence file and the Board-reporting format before the statutory deadline. 5. **Document algorithmic logic.** For any algorithm that materially affects Data Principals, record the purpose, training data governance, evaluation for rights risks, and human-oversight points. This file serves both Rule 13(3) algorithmic due diligence and, where relevant, the forthcoming AI governance expectations. 6. **Scenario-plan localisation.** Identify which data categories would be operationally difficult to keep within India if a Rule 13(4) direction were made — for example, analytics pipelines that currently replicate to a foreign region — and design a feasible localisation path, even if not yet executed. ## Primary sources * [Digital Personal Data Protection Act, 2023 — India Code](https://indiacode.gov.in/handle/123456789/496508) (Sections 2(i), 2(k), 6, 8, 9, 10, 11 to 16, 18 to 33 and the Schedule) * [Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E), 13 November 2025) — MeitY](https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf) (Rules 3, 6, 7, 8, 10 to 15, First and Third Schedules) * [PIB press release and backgrounder on notification of the DPDP Rules (14 and 17 November 2025)](https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc20251117695301.pdf) * [AZB & Partners summary of DPDP Rules enforcement timelines — Mondaq, 21 November 2025](https://webiis10.mondaq.com/india/privacy-protection/1708314/update-indias-digital-personal-data-protection-framework-comes-into-effect) (SDF duties from May 2027) * [DPDP Act and Rules phased compliance note — CADP, G.S.R. 846(E) text](https://cadp.in/resources/official-texts/dpdp-rules-2025/) (Rule 13 twelve-month DPIA cycle) ### Frequently asked questions **What is a Significant Data Fiduciary under the DPDP Act?** A Data Fiduciary or class of Data Fiduciaries notified by the Central Government under Section 10 of the DPDP Act, 2023 on the basis of factors including volume and sensitivity of personal data processed, risk to the rights of Data Principals, potential impact on electoral democracy, security of the State and public order. Notification is by the Government, not self-declared, and no SDF class had been notified as of August 2026. **What extra obligations does an SDF have?** Under Section 10 read with Rule 13 of the DPDP Rules, 2025, a notified SDF must appoint a Data Protection Officer based in India answerable to the board, appoint an independent data auditor, conduct a Data Protection Impact Assessment and a periodic audit at least once every 12 months with significant observations reported to the Board, exercise due diligence under Rule 13(3) that its processing including algorithmic software does not risk Data Principal rights, and under Rule 13(4) keep such personal data and traffic data as the Government may specify, on a committee recommendation, within India. **Does SDF status depend on company size or turnover alone?** No. Section 10(1) lists volume and sensitivity of personal data and risk to rights as factors, alongside impact on electoral democracy, security of the State and public order. Size, turnover and user count are indicators the Government weighs, but the statute frames the test as a risk-based designation, and the notification can be class-based — for example, all fiduciaries of a certain type — not only company-by-company. **What is the penalty for breaching SDF obligations?** Up to one hundred and fifty crore rupees per breach under the Schedule to the DPDP Act, read with Section 33, imposed by the Data Protection Board after inquiry and hearing weighing the factors in Section 33(2). **Can a Kerala startup be designated as an SDF?** Yes, if it falls within a notified class or is individually notified. The Act applies pan-India and notification turns on data-related risk factors, not geography or incorporation state. A Kerala SaaS, healthtech or fintech handling sensitive personal data at scale or affecting rights at scale could be designated as part of a class even if it is not among the largest platforms by headcount. There is no small-business or startup exemption from SDF designation in the Act. --- ## Electronic Evidence in Indian Courts After 1 July 2024: Section 63 BSA and the Certificate That Decides Cases URL: https://advaslam.com/writing/electronic-evidence-bsa-section-63-certificate-guide/ Author: Adv. K J Muhammed Aslam, Advocate (Bar Council of Kerala, K/001823/2026) Published 1 September 2026 Practice area: Cyber crime & IT Act matters WhatsApp chats, screenshots, CDRs and CCTV in Indian courts now fall under Section 63 BSA (new 65B): the dual-certificate rule, hash and preservation. After 1 July 2024, every screenshot, WhatsApp chat, call detail record, CCTV clip, server log and email printout tendered in an Indian court is governed not by Section 65B of the old Evidence Act but by [Section 63 of the Bharatiya Sakshya Adhiniyam, 2023](https://indiacode.gov.in/handle/123456789/496549) — and the difference that decides cases is the certificate in Section 63(4), which the Supreme Court has held is mandatory for admissibility of secondary electronic evidence. An electronic record filed without the correct certificate, with the wrong signatory, or without a hash is liable to be excluded at trial no matter how compelling it looks on paper. ## What is an electronic record under the BSA, and why does Section 63 exist? The [Bharatiya Sakshya Adhiniyam, 2023](https://indiacode.gov.in/handle/123456789/496549) (BSA) defines an electronic record in the same technology-neutral way the Evidence Act did — information generated, sent, received or stored in electronic form, including data, images, sound and video stored on a computer resource. A computer resource is itself defined broadly under Section 2(1)(k) of the [IT Act, 2000](https://indiacode.gov.in/handle/123456789/496511) to include computers, computer systems, computer networks, data and software. Section 63 BSA exists because electronic records are inherently replicable. Unlike a signed paper contract, where the original can be examined for ink and handwriting, a screenshot can be cropped, a chat can be edited in a forwarded copy, and a CCTV file can be re-encoded. Section 63 therefore does two things: it declares that information contained in an electronic record printed on paper or stored on optical or magnetic media is deemed to be a document and is admissible without proof of the original, **but only if** the four conditions in Section 63(2) and the certificate in Section 63(4) are satisfied. Those conditions are the bridge between the digital world and the courtroom. ## What are the four conditions for admissibility under Section 63(2)? Before reaching the certificate, Section 63(2) requires the court to be satisfied on four matters about the computer that produced the record: 1. The computer output containing the information was produced by the computer during the period over which the computer was used regularly to store or process information for the purposes of activities regularly carried on by the person having lawful control over its use. 2. During that period, information of the kind contained in the electronic record was regularly fed into the computer in the ordinary course of those activities. 3. Throughout the material part of that period the computer was operating properly — or, if not, the malfunction did not affect the production of the electronic record or the accuracy of its contents. 4. The information contained in the electronic record reproduces or is derived from information fed into the computer in the ordinary course of those activities. In practice, the certificate is how these four conditions are spoken to on oath. A bare printout that asserts these conditions in argument but does not carry a certificate fails at the threshold. ## What must the Section 63(4) certificate contain, and who signs it? Section 63(4) BSA, read with the Schedule to the Adhiniyam, prescribes a certificate that must: * Identify the electronic record and describe the manner in which it was produced. * Give particulars of the device and the process that generated the record sufficient to show the four conditions above. * Confirm that the device was operating properly during the relevant period. * Enclose a **hash value** of the electronic record — the cryptographic fingerprint that ties the copy tendered to the specific data that existed on the device. * Be signed by **two persons**: the person in charge of the computer resource or the management of the relevant activities (Part A of the Schedule form), and an **expert** — ordinarily an Examiner of Electronic Evidence notified under [Section 79A of the IT Act, 2000](https://indiacode.gov.in/handle/123456789/496511) (Part B of the Schedule form). The BSA's dual-signature design is the main change from the Evidence Act era. Under Section 65B(4), a single certificate by the person in charge sufficed on the text, though courts often looked for expert support on authenticity. Under Section 63(4), the Schedule form makes the expert's hash report an integral part of the certificate. On 22 May 2026 the Supreme Court upheld Section 63(4) against a constitutional challenge, calling the hash value an "electronic fingerprint" and holding that Part B is not confined to a Section 79A Examiner — a person with special skill in computer science or cyber forensics may sign it where the court is satisfied on unimpeachable material, though the Court kept that question of law open (*Pune Bar Association v. Union of India*, WP(C) No. 599 of 2026, decided 22 May 2026; 2026 SCC OnLine SC 1297). Consistent with [Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal (2020) 7 SCC 1](https://indiankanoon.org/doc/172105947/), the practical advice for 2025–2026 filings is: * File the complete certificate — person in charge plus expert with hash — with the document when it is tendered; tendering a person-in-charge-only certificate and expecting to supply the expert component later is not a strategy, because Khotkar curability is not an entitlement, and * The certificate can be filed late — at any stage before evidence is closed — and the court can summon the certifier, as Khotkar recognised, so a party that discovers the omission is not automatically shut out, but relying on indulgence is not a strategy. ## What did Anvar and Khotkar actually hold, and do they still govern the BSA? Yes — the reasoning of both decisions governs Section 63 BSA because the language is carried forward: * **[Anvar P.V. v. P.K. Basheer (2014) 10 SCC 473](https://indiankanoon.org/doc/187283766/)** held that Section 65B is a complete code for electronic evidence, that compliance with its conditions and certificate is mandatory, and that secondary electronic evidence without a certificate is inadmissible and cannot be cured by oral evidence. * **[Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal (2020) 7 SCC 1](https://indiankanoon.org/doc/172105947/)** clarified that the certificate must ordinarily accompany the electronic record when it is tendered, that it can in appropriate cases be filed later before the trial concludes, and that the court has the power to summon the person who gave the certificate. The BSA's Section 63 is avowedly Section 65B in new numbering with the certificate requirement tightened, not diluted. Every High Court that has addressed the point since July 2024 has applied Anvar and Khotkar to Section 63. Citing Section 65B in a pleading filed today is not wrong in substance — judges know the lineage — but citing Section 63 BSA is the correct current form and signals that the pleader is working with the law as it stands after 1 July 2024. ## How should you preserve electronic evidence so it survives Section 63? The rules that matter are not courtroom rules first — they are preservation rules in the first days after an incident, because a badly preserved record cannot be redeemed by a good certificate later. For complainants, accused persons, businesses and advocates in Kerala: 1. **Keep the original device.** The phone, laptop or DVR that holds the original data is the best evidence (primary evidence under Section 57 BSA). A printout or export is secondary evidence that needs Section 63. If the device is lost or overwritten, the strongest mode of proof is gone. 2. **Do not edit, crop or annotate the original before seizure or imaging.** Give the investigating officer the clean originals; keep annotated copies separately for your own reference. An edited screenshot where the clock or URL is cropped out is weaker than the untouched original. 3. **Preserve in the app, not only as forwarded images.** A WhatsApp chat forwarded to another number is a copy of a copy. Keep the chat on the original handset, back up with the app's own export, and let the forensic image be taken from the primary source. 4. **Get the certificate at the time of tender.** If you are the party relying on the record, ensure the certificate in the Schedule form — with device particulars, hash and both signatures — accompanies the document when it is filed. If you receive a certificate from a service provider (for example, a 65B/63 certificate from a bank for a CDR or from a platform for server logs), check that it identifies the specific record, not the system in general. 5. **For magistrate courts, prepare for the hash question.** Under the BSA, the hash report is not an optional technical annexure — it is part of the proof that the copy tendered is of the specific data that existed on the device. Budget time for an examiner under Section 79A of the IT Act where the volume or technical complexity warrants it. ## How does Section 63 apply in the cyber matters this practice handles? Three contexts come up repeatedly: * **Bank-freeze cases.** The account statement, the NCRP acknowledgment, the 1930 call log and the requisition letter from the cyber cell are all electronic records. They are typically proved as secondary copies and should carry Section 63 certificates from the bank or the agency, which is why the first-week step in [the bank-freeze guide](https://advaslam.com/writing/bank-account-frozen-cyber-cell-kerala/) is to get the freeze details in writing with reference numbers — that writing is what makes the later certificate possible. * **Sextortion and image-based abuse.** The chat, the images and the call records are electronic records that must survive Section 63 to prove the threat and the demand. Preserving the original device and its chat, as described in the [sextortion guide](https://advaslam.com/writing/sextortion-blackmail-kerala-legal-remedies/), is the preservation step that makes the certificate achievable. * **UPI fraud.** The UPI transaction logs, the CFCFRMS trail and the bank's lien-marking messages are electronic records. An application for release of a frozen amount under Sections 497 to 505 BNSS that annexes a bank statement without a certificate risks an avoidable evidentiary gap — the guidance in [the UPI fraud recovery guide](https://advaslam.com/writing/upi-fraud-complaint-recovery/) to keep transaction reference numbers and to write to the bank on day one is, in evidentiary terms, the groundwork for the Section 63 certificate the court will later look for. ## Primary sources * [Bharatiya Sakshya Adhiniyam, 2023 — India Code](https://indiacode.gov.in/handle/123456789/496549) (Section 57 on primary evidence, Section 63 on admissibility of electronic records, Schedule Form of certificate) * [Information Technology Act, 2000 — India Code](https://indiacode.gov.in/handle/123456789/496511) (Section 2(1)(k) computer resource, Section 79A Examiner of Electronic Evidence) * [Anvar P.V. v. P.K. Basheer (2014) 10 SCC 473](https://indiankanoon.org/doc/187283766/) * [Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal (2020) 7 SCC 1](https://indiankanoon.org/doc/172105947/) * [Bharatiya Nagarik Suraksha Sanhita, 2023 — India Code](https://indiacode.gov.in/handle/123456789/496550) (Section 94 summons to produce electronic records) ### Frequently asked questions **What replaced Section 65B of the Evidence Act?** Section 63 of the Bharatiya Sakshya Adhiniyam, 2023 (BSA), which came into force on 1 July 2024 replacing the Indian Evidence Act, 1872. Section 63 carries forward the substance of Section 65B — the special procedure for proving electronic records — with a tightened certificate requirement in Section 63(4) and a prescribed form in the Schedule that now contemplates a hash value and dual signatures. **Is a Section 63 certificate mandatory for every electronic record?** Yes, where the electronic record is proved by secondary evidence — a printout, a forwarded copy, a screenshot, a CDR, a CCTV clip on a pen drive. The Supreme Court in Anvar P.V. v. P.K. Basheer (2014) and Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal (2020) held that the certificate is a mandatory condition for admissibility and that a trial court cannot dispense with it. If the original device or original electronic record itself is produced and proved in the ordinary way, the Section 63 route is not needed, but in practice most records are copies that require the certificate. **Who must sign the Section 63 certificate under the BSA?** Section 63(4) of the BSA, read with the Schedule, contemplates a certificate signed by both the person in charge of the computer resource or communication device (or the person managing the relevant activity) and an expert — ordinarily an Examiner of Electronic Evidence notified under Section 79A of the IT Act, 2000, though in May 2026 the Supreme Court observed that a person shown to have special skill in computer science and cyber forensics may also sign, keeping that question open — enclosing a hash report of the record. As advice: file the complete certificate with both signatures and a hash when the record is tendered. Arjun Panditrao Khotkar permits late filing before evidence closes, but that curability is not an entitlement to tender an incomplete certificate — an incomplete filing risks exclusion. **Can a Section 63 certificate be filed late?** Yes, within limits. In Arjun Panditrao Khotkar the Supreme Court held that the certificate can be filed at any stage before the evidence is concluded, and the court can summon the certifier where necessary, so a prosecution or party that discovers the defect is not automatically shut out. But reliance on late filing is risky — the certificate should accompany the document when it is tendered, and a party that tenders electronic evidence without any certificate risks having the core of its case excluded. **Does forwarding a WhatsApp chat weaken its evidentiary value?** Yes. A forwarded copy or a screenshot of a forwarded message is a copy of a copy — at two removes from the original data on the device and the server. It is harder to certify, easier to challenge for tampering, and weaker corroboration than the original chat on the original device with its metadata and hash preserved. Preserve the original device, keep the chat in the app, and let the certificate be prepared from the primary source. --- ## Can You Patent Software and AI in India? Section 3(k) and the CRI Guidelines 2025 Explained URL: https://advaslam.com/writing/patent-computer-related-inventions-cri-guidelines-2025/ Author: Adv. K J Muhammed Aslam, Advocate (Bar Council of Kerala, K/001823/2026) Published 1 September 2026 Practice area: Business, banking & IPR Section 3(k) Patents Act excludes computer programmes per se, not all software. The technical effect and contribution test under the CRI Guidelines 2025. Not every programme is excluded — [Section 3(k) of the Patents Act, 1970](https://indiacode.gov.in/handle/123456789/495964) excludes a **computer programme per se, mathematical method, business method or algorithm**, but the [CGPDTM Guidelines for Examination of Computer-Related Inventions (CRIs) 2025 dated 29 July 2025](https://ipindia.gov.in/frontend/pdf/patents/guidelines/GUIDELINES%20FOR%20EXAMINATION%20OF%20COMPUTER%20RELATED%20INVENTIONS%20%28CRIs%29%20-%202025.pdf) — the first revision since 2017 — reaffirm that a **computer-implemented invention demonstrating a technical effect and technical contribution** can be patentable, with **no requirement of novel hardware** and with both system and method claims available if the specification fully supports them. For Kerala AI, blockchain and quantum startups that had filings rejected under the old approach for lacking hardware recitation, the 2025 Guidelines change the drafting exercise. ## What does Section 3(k) actually exclude? The text is four limbs joined by or, each with its own scope: > **Section 3(k) — what are not inventions:** "a mathematical or business method or a computer programme per se or algorithms" | Limb | What it means | Effect | |---|---|---| | **Mathematical method** | A method of calculation or formula — however implemented | Excluded as an abstract method | | **Business method** | A method of doing business — for example, a trading strategy, pricing model or marketing method | Excluded even if computer-implemented; automating a known business process on a generic computer does not make it patentable | | **Computer programme per se** | The programme itself as an abstract set of instructions — the per se qualifier is decisive | A bare programme without a disclosed technical effect or technical application is excluded; a programme that delivers a technical effect beyond itself is not per se | | **Algorithms** | An abstract procedure or set of rules for solving a problem, narrowly defined in the Guidelines | An algorithm claimed in the abstract is excluded; where the algorithm produces a concrete technical effect disclosed in the specification, the claim is examined as a whole | The Joint Parliamentary Committee that inserted per se in 2002 did so to preserve patentability for programmes with an ancillary technical application — the Guidelines' entire structure is built on that distinction. ## What did the CRI Guidelines 2025 change from 2017? The 2017 Guidelines left examiners and applicants arguing past each other about whether hardware recitation was needed. The **CRI Guidelines 2025 (29 July 2025)** consolidate a decade of High Court guidance and settle three points: 1. **Structured examination — inventive concept first.** The examiner must identify the inventive concept of the claim as a whole, not dissect the claim into hardware and software parts and reject the software part in isolation. The question is whether the claim, read with the specification, is to a computer programme per se or to a **technical application** producing a **technical effect**. 2. **Novel hardware not required.** Reaffirming [Ferid Allani v. Union of India (2019) Delhi High Court](https://indiankanoon.org/doc/90686424/), [Microsoft Technology Licensing v. Assistant Controller (Delhi High Court, C.A. 29/2022, 2023)](https://indiankanoon.org/doc/52362832/), [Microsoft Technology Licensing v. Assistant Controller (Madras High Court, 2024)](https://indiankanoon.org/doc/125847157/), [Raytheon Company v. Controller General (2023) Delhi High Court](https://indiankanoon.org/doc/118178741/) and [BlackBerry Limited v. Controller of Patents (C.A. 318/2022, 30 August 2024) Delhi High Court](https://indiankanoon.org/doc/24328013/) (capability enhancement of a device avoids Section 3(k) even without new hardware; the companion BlackBerry appeal, C.A. 229/2022, was refused), the Guidelines state that a technical contribution can lie in improved functionality, not only in a new physical component. 3. **AI disclosure standard.** For AI and machine-learning inventions, the specification must disclose the **model architecture, training methodology and parameters, and validation or test results** showing the technical effect — for example, improved processing speed, enhanced security, reduced latency, or control of an industrial process. A claim that recites a generic neural network producing a business result without disclosing how the technical system is improved fails the test. The Guidelines include an **Annexure I** of illustrative allowable and non-allowable claims per Section 3(k) limb — the most practical part of the document for drafters — and frame the assessment around a **technical solution to a technical problem yielding a technical effect** (the Guidelines' technical effect and technical contribution test). ## How does the technical effect test work in practice? A quick decision tree that mirrors the Guidelines' logic: ``` Claim as filed └─> Identify the inventive concept (what does the claim actually contribute?) └─> Is the contribution only a business method / abstract algorithm / programme per se with no disclosed technical effect? ├─ Yes → Section 3(k) exclusion applies — not patentable └─ No → Does the specification disclose a technical effect and technical contribution beyond the programme itself? ├─ Yes, credibly disclosed and supported by description and results │ → Not a programme per se — proceed to novelty, inventive step │ and industrial applicability (Sections 2(1)(j), 2(1)(ja), 2(1)(ac)) └─ No, or effect asserted only in argument, not in specification → Excluded — amend to disclose the effect or face objection ``` **Examples that illustrate the line:** * **Patentable (if disclosed):** An image-processing pipeline that reduces bandwidth by 40 percent through a disclosed compression and edge-detection sequence, with architecture, training data governance and comparative test results in the specification — technical effect in network utilisation and processing speed. * **Patentable (if disclosed):** A semiconductor fabrication control system where an ML model adjusts process parameters in real time to improve yield, with control-loop disclosure — technical effect in industrial process control. * **Not patentable:** A claim to a method of calculating loan eligibility scores by weighting credit factors, implemented on a generic computer and described only by the business rules — business method, excluded even though a computer is recited. * **Not patentable:** A claim to an algorithm for sorting search results by popularity, without disclosure of how the underlying retrieval system is technically improved — algorithm per se. > **Law vs interpretation:** Section 3(k) is the statutory exclusion. Whether a particular claim crosses into technical effect is interpretation by examiners and courts on the specification as filed — which is why the specification's disclosure, not the claim's wording alone, decides the case. ## What should a Kerala startup put in the specification? The specification is where the technical-effect case is won or lost. Under the 2025 Guidelines, an AI, blockchain or quantum filing should include: * **Technical problem statement** — what existing technical system, device or process is deficient and how the deficiency is technical, not commercial (latency, accuracy, resource consumption, security). * **Technical solution** — how the invention solves that problem through a computer-related implementation, described as a system and, where appropriate, as a method — both claim forms are allowable if supported. * **Architecture, training and parameters** — for AI, the model architecture, training methodology, parameters and evaluation methodology, not a bare reference to a neural network. * **Test results and comparative data** — before-and-after measurements showing the technical effect (speed, accuracy, resource use, yield) so the effect is not merely asserted in prosecution. * **Hardware context without hardware novelty** — describe the computing environment in which the effect is achieved; do not fabricate a new hardware component to satisfy a supposed hardware requirement that the Guidelines say does not exist. For Kochi startups using KSCSTE's IP facilitation services — the Patent Information Centre – Kerala (PIC-Kerala), a TIFAC-DST satellite centre, and the Intellectual Property Rights Information Centre – Kerala (IPRICK), the State's nodal IPR agency, through which KSCSTE empanels IP firms for subsidised drafting and filing and offers free prior-art search (confirm eligibility and scope with the Kerala State Council for Science, Technology and Environment before relying on it) — the 2025 Guidelines are particularly relevant because a significant number of earlier CRI refusals turned on the absence of hardware recitation — the ground the new Guidelines expressly correct. ## How does this sit with copyright, trademark and trade secret? A technology business rarely needs one IP right in isolation: * **Copyright — Section 2(o) Copyright Act** — protects the specific code expression automatically (see the [software copyright guide](https://advaslam.com/writing/software-copyright-startup-kerala-guide/)). Copyright does not protect the inventive idea the code implements. * **Patent — Section 3(k) Patents Act as interpreted by the CRI Guidelines 2025** — protects the inventive technical solution where the technical-effect test is met, for 20 years from filing, subject to examination. * **Trademark — Trade Marks Act, 1999** — protects the brand through which the solution is sold (see the [online trademark infringement guide](https://advaslam.com/writing/trademark-infringement-online-domain-phishing-indrp/)). * **Trade secret — contract and confidence** — protects undisclosed know-how that is not published in the patent specification (see the [trade secrets and NDA guide](https://advaslam.com/writing/trade-secrets-nda-protection-startups-india/)). Publication in a patent specification ends secrecy — choose the portfolio accordingly. ## Primary sources * [Patents Act, 1970 — India Code](https://indiacode.gov.in/handle/123456789/495964) (Sections 2(1)(j), 2(1)(ja), 2(1)(ac), 3(k), 10 on specification) * [CGPDTM Guidelines for Examination of Computer-Related Inventions (CRIs) 2025 — IP India, 29 July 2025](https://ipindia.gov.in/frontend/pdf/patents/guidelines/GUIDELINES%20FOR%20EXAMINATION%20OF%20COMPUTER%20RELATED%20INVENTIONS%20%28CRIs%29%20-%202025.pdf) (Annexure I illustrative claims; AI disclosure standard) * [Ferid Allani v. Union of India (2019) Delhi High Court](https://indiankanoon.org/doc/90686424/); [Microsoft Technology Licensing v. Assistant Controller (Delhi High Court, C.A. 29/2022, 2023)](https://indiankanoon.org/doc/52362832/); [Microsoft Technology Licensing v. Assistant Controller (Madras High Court, 2024)](https://indiankanoon.org/doc/125847157/); [Raytheon Company v. Controller General (2023) Delhi High Court](https://indiankanoon.org/doc/118178741/); [BlackBerry Limited v. Controller of Patents (C.A. 318/2022, 30 August 2024) Delhi High Court](https://indiankanoon.org/doc/24328013/) ### Frequently asked questions **Can software be patented in India at all?** Yes, but not as a computer programme per se. Section 3(k) of the Patents Act, 1970 excludes a mathematical or business method or a computer programme per se or algorithms. As clarified by the CGPDTM Guidelines for Examination of Computer-Related Inventions (CRIs) 2025 dated 29 July 2025 — consolidating Ferid Allani v. Union of India (2019), Microsoft Technology Licensing v. Assistant Controller (Delhi HC 2023, C.A. 29/2022; and Madras HC 2024) and Raytheon/BlackBerry (Delhi HC) — a programme that delivers a technical effect or technical contribution beyond the programme itself, such as improving a device, process or technical system, can be patentable if the specification discloses that effect. **What is the technical effect test under the CRI Guidelines 2025?** The Guidelines apply a structured test: identify the inventive concept, determine whether the claim is to a computer programme per se or to a technical application producing a technical effect, and assess whether the specification discloses a technical effect and technical contribution — for example, improved processing speed, enhanced security, control of an industrial process, or capability enhancement of a device. Both system and method claims can be allowable if fully supported, and novel hardware is not required. Pure business methods and abstract algorithms remain excluded. **Does an AI model need new hardware to be patentable in India?** No. The CRI Guidelines 2025 reaffirm that novel hardware is not required. What is required is disclosure in the specification that the invention produces a technical effect — the Guidelines' examples include network optimisation, image-processing pipelines and semiconductor control. An AI-related application must disclose the model architecture, the training methodology and parameters, and validation or test results showing the technical improvement. **Is a business method patentable if it is implemented on a computer?** No. A business method remains excluded under Section 3(k) even if computer-implemented, unless the claim as a whole demonstrates a technical effect beyond the business method itself. Merely automating a known business process on a generic computer does not cross the Section 3(k) bar. **How does copyright for code relate to patent for the same product?** They protect different things. Copyright under Section 2(o) of the Copyright Act protects the specific expression of the code as a literary work automatically on creation. Patent — if granted — protects the inventive technical solution that the code implements. A startup typically needs both: copyright for the code expression, patent for the technical effect where the CRI test is met, trademark for the brand, and trade secret for undisclosed know-how. --- ## Sextortion and Image-Based Blackmail in India: Laws, Evidence, and What to Do First URL: https://advaslam.com/writing/sextortion-blackmail-kerala-legal-remedies/ Author: Adv. K J Muhammed Aslam, Advocate (Bar Council of Kerala, K/001823/2026) Published 1 September 2026 Practice area: Cyber crime & IT Act matters Sextortion in India falls under IT Act Sections 66E, 67, 67A and BNS Sections 308 and 351. Preserving evidence, reporting, takedown and bail provisions. Sextortion and image-based blackmail in India are prosecuted as a combination of privacy violation, obscenity and extortion — principally [Sections 66E, 67 and 67A of the Information Technology Act, 2000](https://indiacode.gov.in/handle/123456789/496511) together with [Sections 308 (extortion) and 351 (criminal intimidation) of the Bharatiya Nyaya Sanhita, 2023](https://indiacode.gov.in/handle/123456789/496548) — and the correct first step is not negotiation or payment but immediate preservation of evidence and a confidential report to the cyber cell. This guide explains the sections that actually apply, how to report without making the images more public, how platform takedown now works on a 3-hour (court/government direction) / 2-hour (user grievance for intimate imagery) clock, and how electronic evidence must be handled so it survives in court. ## Which laws cover sextortion and image-based abuse? Sextortion in Kerala almost never involves a single section. FIRs are structured in layers because the conduct has three distinct elements — the image, the threat, and the demand — each with its own provision: **The image layer — the IT Act:** * **Section 66E — violation of privacy.** Intentionally capturing, publishing or transmitting the image of a private area of any person without consent, in circumstances violating privacy. Punishment: up to three years or fine up to two lakh rupees or both. This is the provision drafted specifically for intimate-image abuse and is the closest fit where an image is captured or shared without consent. * **Section 67 — publishing or transmitting obscene material in electronic form.** First conviction up to three years and fine up to five lakh rupees; subsequent conviction up to five years and fine up to ten lakh rupees. * **Section 67A — publishing or transmitting material containing a sexually explicit act.** First conviction up to five years and fine up to ten lakh rupees; subsequent conviction up to seven years. Where the blackmailer threatens to publish or has published an explicit image or video, Sections 67 and 67A are the standard charges. * **Section 67B — child sexual abuse material.** Where the victim is under 18, Section 67B (creating, collecting, browsing, downloading or facilitating sexually explicit material depicting children) applies: first conviction up to five years and fine up to ten lakh rupees, subsequent conviction up to seven years and fine up to ten lakh rupees. It operates alongside the [Protection of Children from Sexual Offences Act, 2012](https://indiacode.gov.in/handle/123456789/496004). **The threat and demand layer — the BNS:** * **Section 308 BNS** (formerly Sections 383 to 389 IPC) — **extortion.** Putting a person in fear of injury to dishonestly induce delivery of money or valuable security. Sextortion demands — pay or your images will be sent to your contacts — fit this definition directly. Punishment: up to seven years, or fine, or both; up to ten years and fine if the fear is of death or grievous hurt. * **Section 351 BNS** (formerly Section 506 IPC) — **criminal intimidation.** Threatening to cause injury to reputation or to publish defamatory or harmful material. Every threat to circulate an intimate image to family, employer or social media contacts is charged here as well. * **Section 77 BNS** (formerly Section 354C IPC) — **voyeurism**, and **Section 78 BNS** (formerly Section 354D IPC) — **stalking**, including electronic stalking and monitoring of a woman's use of the internet or electronic communication. These apply where the offender obtained or collected intimate images by watching, recording or persistently pursuing the victim online. Where the offender created a fake profile to establish contact, an additional charge of **Section 66D of the IT Act** (cheating by personation using a computer resource) is commonly added. ## What should you do in the first hour? Shame and panic are the mechanisms the offence exploits. Acting on a short, private checklist breaks that mechanism and preserves the options that disappear if you delay: 1. **Stop communicating and do not pay.** Payment does not delete images held by the offender; it confirms the blackmail works. Screenshot the final demand and then cease contact — do not delete the chat, do not block before preserving. 2. **Preserve the evidence exactly as it is.** Keep the chat in the original app, keep the images or videos the offender sent (including any sample they used as proof), note the phone numbers, profile URLs, UPI IDs and payment accounts mentioned, and keep the original device. Under Section 63 of the Bharatiya Sakshya Adhiniyam, 2023 the original device and its hash are what make an electronic record admissible later. 3. **Do not delete images from your own phone in the belief this helps.** Your copy may be the only provable record of what was threatened. Let the investigation handle deletion after seizure. 4. **Report confidentially.** File at [cybercrime.gov.in](https://cybercrime.gov.in) — the portal has a specific category for cyber crime against women and children and allows reporting with identity disclosure confined to law enforcement — or call 1930, or go to the district Cyber Police Station. In Kerala, each police district has a Cyber Police Station, and FIRs under Section 173 BNSS can be registered at any station (Zero FIR) irrespective of where the offender is located. 5. **Tell one trusted person.** Isolation is what makes sextortion effective. A family member, counsellor or advocate who knows the facts can handle communication with the police and the platform so you do not have to carry it alone. A note on what not to do: do not attempt to negotiate the offender down, do not agree to a video call to prove compliance, and do not install any app the offender asks you to install. ## How does reporting stay confidential? Two sets of provisions protect victims who report intimate-image offences: * **Identity protection.** Section 72 of the BNS (formerly Section 228A IPC) punishes disclosure of the identity of a victim of offences under ss.64–71 only. Police standing orders in Kerala require cyber cells to record intimate-image complaints without public display of the complainant's name, and the Cyber Crime Portal is designed so that the complainant's identity is visible only to the investigating unit, not to the public. * **IT Act privacy.** Section 66E itself is built around consent and privacy — the prosecution must not itself violate the privacy it is meant to protect. Courts routinely direct that intimate images seized as case property be kept in sealed cover and not reproduced in charge sheets circulated beyond the court. None of this requires you to make the images more public. The investigation needs to see the material once, under controlled handling, so it can be hashed, certified and used to seek takedown. Delaying the report out of fear that the police will circulate the images misunderstands the procedure and costs the narrow window in which platform takedown is most effective. ## How quickly must platforms remove intimate images now? The timeline has been shortened twice and is now among the strictest in Indian law. Under the [IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021](https://www.meity.gov.in/static/uploads/2026/02/550681ab908f8afb135b0ad42816a1c9.pdf) as amended by the [Amendment Rules notified on 10 February 2026](https://egazette.gov.in/WriteReadData/2026/269993.pdf) and in force from 20 February 2026: * **Two-hour user-grievance removal for non-consensual nudity and morphed images.** On a complaint by the individual (or someone on their behalf) under Rule 3(2)(b), the intermediary must remove or disable access to content exposing that individual's private area, showing nudity or a sexual act, or impersonating them, including morphed imagery, within **two hours** (down from 24 hours before the 2026 amendment). * **Three-hour takedown on court or government direction for any unlawful content.** On actual knowledge via a court order or authorised government notification under Rule 3(1)(d), any unlawful content — including extortionate messages and synthetically generated impersonation — must be removed within **three hours** (down from 36 hours). * **Grievance redressal in two hours for sensitive complaints.** A grievance relating to non-consensual intimate imagery must be acknowledged and acted on within **two hours** of receipt by the platform's Grievance Officer under Rule 3(2)(b) (down from 24 hours). General grievances must be resolved within seven days. For content that qualifies as **synthetically generated information (SGI)** — for example, a morphed or AI-generated intimate image — the 2026 amendment adds labelling and provenance duties. Intermediaries that offer SGI generation tools must deploy technical measures to prevent creation or sharing of prohibited SGI (which expressly includes non-consensual intimate imagery) and must prominently label lawful SGI; significant social media intermediaries must also require users to declare whether content is SGI. Failure to take reasonable steps against prohibited SGI is treated as a failure of due diligence, which can cost the platform its safe harbour under Section 79 of the IT Act. In practice, file the platform grievance in parallel with the police complaint, citing Rule 3(1)(d) (3-hour court/government-direction track) and Rule 3(2)(b) (2-hour user-grievance track for nudity/morphed/impersonation) and attaching the specific URLs. Do not rely on a generic report button alone — a written grievance to the published Grievance Officer with URLs and timestamps starts the 2-hour grievance clock in a provable way. ## What evidence does a Kerala court actually need? Every intimate image, chat and call record in a sextortion case is an electronic record, and its admissibility is governed by [Section 63 of the Bharatiya Sakshya Adhiniyam, 2023](https://indiacode.gov.in/handle/123456789/496549), which replaced Section 65B of the Indian Evidence Act from 1 July 2024: * **Section 63(4) requires a certificate** identifying the electronic record, describing the manner in which it was produced, and confirming that the device was operating properly, with a hash value of the record enclosed. * The BSA now requires the certificate to be signed by **both** the person in charge of the device or activity and an **expert** (an Examiner of Electronic Evidence under Section 79A of the IT Act), in the form prescribed in the Schedule. * The Supreme Court in [Anvar P.V. v. P.K. Basheer (2014) 10 SCC 473](https://indiankanoon.org/doc/187283766/) and [Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal (2020) 7 SCC 1](https://indiankanoon.org/doc/172105947/) held that the certificate is a mandatory condition for admissibility of secondary electronic evidence — a printout or forwarded copy without it is liable to be excluded. The court can, however, accept a delayed certificate and can summon the certifier. What this means for a complainant: * Keep the original phone or device. A screenshot forwarded to another phone is a copy of a copy — harder to certify than the original chat on the original device. * Do not edit, crop or annotate the original screenshots before handing them over; give the investigation the clean originals and keep annotated copies separately. * Allow the police to seize or image the device lawfully so the hash can be taken. A private screen recording made after the fact is weaker evidence than a forensically imaged original. * Preserve CDR-relevant details — the offender's numbers, profile handles and UPI IDs — because provider records will be summoned under Section 94 BNSS to corroborate the chat. ## Can a sextortion case be compromised or quashed? Sextortion is not a compoundable private dispute. Section 77A of the IT Act permits compounding only for offences punishable with up to three years where the statute allows it, and expressly excludes offences affecting the socio-economic conditions of the country and offences committed against a woman or a child — which covers the typical sextortion fact pattern under Sections 66E, 67 and 77A's own bars. Attempted private settlements where the complainant is paid to withdraw are not recognised as compounding, and a High Court asked to quash under Section 528 BNSS (formerly Section 482 CrPC) applies a stricter test in sexual and extortion offences than in property disputes. The practical route for a complainant who genuinely wishes to close the matter is to place the facts before the court and let the court decide, not to sign a private compromise deed. An overview of quashing before the Kerala High Court is at the guides on [IT Act offences](https://advaslam.com/writing/it-act-offences-explained/) and [High Court litigation](https://advaslam.com/practice/high-court-litigation/). ## Primary sources * [Information Technology Act, 2000 — India Code](https://indiacode.gov.in/handle/123456789/496511) (Sections 66C, 66D, 66E, 67, 67A, 67B, 72, 79) * [Bharatiya Nyaya Sanhita, 2023 — India Code](https://indiacode.gov.in/handle/123456789/496548) (Sections 72, 77, 78, 308, 351) * [Bharatiya Sakshya Adhiniyam, 2023 — India Code](https://indiacode.gov.in/handle/123456789/496549) (Section 63, replacing Section 65B Evidence Act) * [Bharatiya Nagarik Suraksha Sanhita, 2023 — India Code](https://indiacode.gov.in/handle/123456789/496550) (Sections 94, 173, 528) * [IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 as updated 6 April 2023 and amended 10 February 2026 — MeitY](https://www.meity.gov.in/static/uploads/2026/02/550681ab908f8afb135b0ad42816a1c9.pdf) (Rules 3(1)(d), 3(2), 4 for SGI) * [Anvar P.V. v. P.K. Basheer (2014) 10 SCC 473](https://indiankanoon.org/doc/187283766/) and [Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal (2020) 7 SCC 1](https://indiankanoon.org/doc/172105947/) on Section 65B/63 certificates * [National Cyber Crime Reporting Portal — cybercrime.gov.in](https://cybercrime.gov.in) (women and children reporting category) ### Frequently asked questions **What laws apply to sextortion in India?** Sextortion is typically charged under Section 66E (violation of privacy — capturing or transmitting an image of a private area without consent), Section 67 (obscene material in electronic form) and Section 67A (sexually explicit act) of the IT Act, 2000, together with Section 308 (extortion), Section 351 (criminal intimidation) and Sections 77 (voyeurism) or 78 (stalking) of the Bharatiya Nyaya Sanhita, 2023. Where the victim is under 18, Section 67B of the IT Act and the POCSO Act, 2012 also apply. **Should I pay the blackmailer to make the images go away?** No. Paying does not delete images — it confirms you will pay again and the demands almost always escalate. It also creates a transaction trail the offender uses as leverage. The correct step is to stop communication, preserve everything as it is, and report immediately through the National Cyber Crime Reporting Portal (cybercrime.gov.in) or 1930, and at your district Cyber Police Station, so a takedown and investigation can begin. **Will filing a complaint make the images public?** A complaint does not publish the images. Police and cyber cells are required to handle intimate-image cases with confidentiality, and Section 228A of the Indian Penal Code — now Section 72 of the BNS, which covers victims of the offences listed in BNS ss.64-71 — together with Section 66E of the IT Act protects the victim's privacy. The Cyber Crime Portal allows reporting with identity disclosure confined to law enforcement. Delay out of fear of publicity is the reason most sextortion cases are never investigated in time for takedown. **Can intimate images be taken down from platforms quickly?** Yes, and the law now requires speed. Under the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 as amended on 10 February 2026, intermediaries must remove or disable access to any unlawful content within 3 hours of actual knowledge via a court order or authorised government notification under Rule 3(1)(d); and must remove or disable access to content showing an individual's private area, nudity or sexual acts, or impersonation including morphed imagery, within 2 hours of that individual's complaint under Rule 3(2)(b). Intermediaries that offer tools for creating synthetically generated information must also deploy technical measures to prevent non-consensual intimate imagery classified as prohibited synthetically generated information from being generated or shared. **Is a screenshot of the chat enough evidence?** A screenshot helps but it is not self-proving. Under Section 63 of the Bharatiya Sakshya Adhiniyam, 2023 (which replaced Section 65B of the Evidence Act), an electronic record such as a chat, screenshot or video needs a certificate describing how it was produced and confirming the device was working properly, with a hash value, signed by the person in charge of the device and an expert. Preserve the original device, keep the chat in the app rather than only as forwarded images, and let the certificate be prepared properly for the investigation and trial. --- ## Software Copyright for Kerala Startups: How Your Code Is Protected and How Founders Lose It URL: https://advaslam.com/writing/software-copyright-startup-kerala-guide/ Author: Adv. K J Muhammed Aslam, Advocate (Bar Council of Kerala, K/001823/2026) Published 1 September 2026 Practice area: Business, banking & IPR Software is a literary work under Section 2(o) Copyright Act, 1957. What is protected, Section 48 registration, source code deposit and assignment mistakes. Software in India is protected as a **literary work** under [Section 2(o) of the Copyright Act, 1957](https://indiacode.gov.in/handle/123456789/496733) from the moment the code is written — no registration is needed for the right to exist — but the reason Kerala startups should still register under [Section 44](https://indiacode.gov.in/handle/123456789/496733) and get the [Section 48](https://indiacode.gov.in/handle/123456789/496733) certificate is that registered title is **prima facie evidence in every court**, and the reason many founders lose ownership anyway is that payment without a written assignment under [Sections 18 and 19](https://indiacode.gov.in/handle/123456789/496733) does not transfer copyright. ## What does the Copyright Act actually protect in software? | Element | Legal position | Source | |---|---|---| | **Source code and object code** | Both are literary works under Section 2(o). Protection covers the specific expression — the code as written — not the underlying idea, algorithm or functionality (idea-expression dichotomy) | Section 2(o) Copyright Act | | **Structure, sequence and organisation (SSO)** | Courts recognise that non-literal copying of SSO and program architecture can infringe where protectable expression is appropriated, assessed qualitatively not quantitatively | Delhi High Court IPD jurisprudence | | **Databases and compilations** | Tables and compilations including computer databases are literary works | Section 2(o) | | **What is not protected** | Ideas, algorithms, methods, functional concepts and elements dictated by technical necessity remain outside copyright — they may be patentable (see the [CRI Guidelines guide](https://advaslam.com/writing/patent-computer-related-inventions-cri-guidelines-2025/)) or protectable as trade secrets if kept confidential | Patents Act Section 3(k); trade secret principles | The Berne Convention foundation matters: because copyright arises automatically on creation, a Kochi startup's code is protected the same day it is committed, even before any filing. The question is not whether protection exists, but whether the startup can **prove chain of title quickly** when it needs an injunction or when an investor asks for it. ## How does software copyright registration work — Form XIV, fee and deposit? Registration is online through the Copyright Office (DPIIT) at copyright.gov.in via **Form XIV** for literary works. There is a single Copyright Office in New Delhi; unlike trademarks, there are no regional registries. | Step | What to do | |---|---| | **1. Identify the work** | Each distinct work needs a separate application and fee — your core source code, your UI artwork and your user manual are three works, not one. Each major version can be registered separately. | | **2. Prepare the deposit** | Under Rule 70(5) of the Copyright Rules, 2013 and the Copyright Office's e-filing instructions, deposit at least the first 10 and last 10 pages of source code (or the entire source code if it is less than 20 pages), with no blocked-out or redacted portions — confirm the current deposit instructions on copyright.gov.in before filing. You do not upload the entire codebase. | | **3. Pay the fee** | Under the Second Schedule to the Copyright Rules, 2013 (as amended in 2021), the statutory fee for a literary work (including software) is five hundred rupees per work, regardless of applicant type — there is no separate company slab; the two-thousand-rupee slab applies only to artistic works used or capable of being used in relation to goods or services (Section 45). Confirm the current schedule before filing. | | **4. Diary and examination** | The Office issues a diary number, examines the application, and keeps it open for the mandatory 30-day post-filing objection period. If no objection is raised and the application is otherwise in order, the Office proceeds to registration. | | **5. Certificate** | The Register and the certificate are prima facie evidence under Section 48 — the practical burden shifts, and the other side must disprove your title rather than you building it from Git logs and invoices at the interim stage. | A copyright notice in source files and on the product UI — for example, © 2026 [Your Company Pvt Ltd] — is optional under Berne, but it is a notice to the world that the work is claimed, and it helps in licensing and enforcement correspondence. ## Why do founders lose software IP even after paying for the code? Because [Section 17](https://indiacode.gov.in/handle/123456789/496733) makes the **author** the first owner, and then draws a sharp line between employees and everyone else: * **Employees — contract of service.** Where a work is made by an employee in the course of employment under a contract of service, the **employer** is the first owner in the absence of an agreement to the contrary. An employment contract with a clear IP-assignment clause covers this, and every employee who touches the codebase should have one signed before their first commit. * **Contractors, freelancers, agencies — contract for service.** Ownership **stays with the author** unless there is a signed, written assignment that satisfies [Section 18](https://indiacode.gov.in/handle/123456789/496733) (assignment) and [Section 19](https://indiacode.gov.in/handle/123456789/496733) (mode of assignment). Paying the invoice does not transfer copyright. Without the assignment, the agency that built the MVP may legally own the code the business now runs on, licenses to customers, and shows to investors. Section 19 has statutory defaults that quietly claw rights back if drafting is sloppy: * If the assignment does not specify a **duration**, it is presumed to be **five years**. * If it does not specify a **territory**, it is presumed to be **limited to India**. * Rights not **exercised within one year** of assignment can lapse back to the assignor. The provenance bundle a well-run startup keeps — signed employment and contractor assignments before work begins, commit history showing who wrote what, version-tagged deposits — is diligence material in every funding round precisely because acquirers and investors know how often title is defective. ## What about AI-assisted code — who is the author? [Section 2(d)(vi) Copyright Act](https://indiacode.gov.in/handle/123456789/496733) defines the author of a computer-generated literary, dramatic, musical or artistic work as the person who causes the work to be created — language that predates modern generative AI and was not designed for it. Whether code substantially generated with AI assistance satisfies the originality and human-authorship requirements under Indian law is not yet settled by statute or by a binding Supreme Court decision, and the DPIIT Working Paper on Generative AI and Copyright (Part 1, December 2025 — mandatory blanket licence with statutory remuneration proposed, open for stakeholder consultation) and the Delhi High Court's decision on interim relief in [ANI Media Pvt Ltd v. OpenAI](https://delhihighcourt.nic.in/app/showFileJudgment/ABL24072026SC10282024_171649.pdf) (interim injunction refused 24 July 2026; appeal admitted with notice on 15 September 2026, next hearing December 2026) form the current policy backdrop. The prudent course for founders today is to treat AI-assisted output as potentially weaker title, to keep human-authored records of prompts, review and modification, and to avoid reliance on a supposed consensus that has not formed. This question is distinct from the [synthetically generated information labelling duties under the IT Amendment Rules, 2026](https://advaslam.com/writing/deepfake-sgi-it-rules-2026-labelling-takedown/), which regulate distribution and transparency, not copyright authorship. ## What happens when software copyright is infringed? ### Civil remedies — Section 55 onwards The owner can seek **injunction** (including urgent interim injunction), **damages or account of profits**, and **delivery-up and destruction** of infringing copies. The Delhi High Court's Intellectual Property Division (IPD) is a frequent and experienced forum for software-copyright actions. Courts assess substantial copying **qualitatively** — even a small portion can infringe if it appropriates the essential or distinctive protectable expression of the original — and the limitation period for a suit is three years from each fresh act of infringement. Platform overlap matters: where the infringement is online — a cloned SaaS frontend, a pirated download mirror, a dataset scraped for model training — the same act may also be **trademark infringement** and attract **platform takedown** under the IT Rules. For online enforcement strategy, see the [online trademark infringement guide](https://advaslam.com/writing/trademark-infringement-online-domain-phishing-indrp/) and for the injunction practice that has developed around online piracy, the discussion of **Dynamic+ and Dynamic++ injunctions** (building on UTV Software v. 1337X and Universal City Studios v. Dotmovies.baby) — orders that bind ISPs, DoT and MeitY to block not only named sites but their future mirrors and redirects in real time, deployed in the December 2025 Warner Bros. and 2026 JioStar IPL orders. ### Criminal liability — Sections 63, 63A, 63B, 65A * **Section 63** — knowing infringement or abetment: not less than six months extending up to three years and fine not less than fifty thousand rupees extending up to two lakh rupees. In [Knit Pro International v. State of NCT of Delhi (2022)](https://indiankanoon.org/doc/180042115/) the Supreme Court held this offence (Section 63) is **cognizable and non-bailable**. * **Section 63B** — knowing use of an infringing copy of a computer programme on a computer: imprisonment of not less than seven days extending up to three years and fine of not less than fifty thousand rupees extending up to two lakh rupees; where the programme was not used for gain or in the course of trade or business, the court may, for adequate and special reasons, impose no imprisonment and a fine extending up to fifty thousand rupees. A startup running cracked enterprise software across team machines falls in this section. The Knit Pro holding on cognizability and bail is on Section 63; treat any parity argument for Section 63B as an inference from that ruling, not a decision on the point. * **Sections 65A, 65B** — circumvention of technological protection measures and tampering with rights management information (inserted in 2012) — relevant where DRM or licensing controls are bypassed. ## Practical checklist for a Kerala startup 1. **Assign before the first commit.** Every employee, co-founder, contractor, freelancer and agency signs an IP assignment compliant with Sections 18 and 19 — specifying duration, territory and rights — before work begins, not after. 2. **Add copyright notices** to source files and product UI. 3. **Register key versions** — Form XIV for each major version of core code, plus separate registrations for UI artwork and documentation. 4. **Maintain the provenance bundle** — signed agreements, commit history, contributor records, version-tagged deposits. 5. **Layer trade-secret protection** for the parts of the stack that must stay confidential — NDAs, access controls and audit trails — because copyright protects expression that is disclosed, while secrecy protects what is not. See the [trade secrets and NDA guide](https://advaslam.com/writing/trade-secrets-nda-protection-startups-india/). 6. **Use the Section 2(o) / Section 3(k) boundary correctly.** Copyright for code expression, patent for technical effect where the [CRI Guidelines 2025](https://advaslam.com/writing/patent-computer-related-inventions-cri-guidelines-2025/) test is met, trademark for brand, trade secret for undisclosed know-how — a portfolio, not a single filing. ## Primary sources * [Copyright Act, 1957 — India Code](https://indiacode.gov.in/handle/123456789/496733) (Sections 2(o), 2(d)(vi), 13, 14, 17, 18, 19, 44, 48, 51, 55, 63, 63B, 65A) * [Copyright Rules, 2013 — Second Schedule (fees)](https://copyright.gov.in/Copyright_Rules_2013/second_schedule.html) * [Copyright Office — E-filing at copyright.gov.in (Form XIV, diary, 30-day objection period)](https://copyright.gov.in) * [Knit Pro International v. State of NCT of Delhi (2022) — Supreme Court on Section 63 as cognizable and non-bailable](https://indiankanoon.org/doc/180042115/) * Patents Act, 1970 Section 3(k) and CGPDTM CRI Guidelines 2025 (29 July 2025) — for the copyright/patent boundary ### Frequently asked questions **Is software protected by copyright in India automatically?** Yes. Software — source code and object code — is a literary work under Section 2(o) of the Copyright Act, 1957 and is protected automatically from the moment it is created, provided it is original, without any need for registration. India is a Berne Convention member, so the right arises on creation. **Should a Kerala startup register its software copyright if protection is automatic?** Yes, for practical reasons. Under Section 48, the Register of Copyrights and the registration certificate are prima facie evidence of ownership and particulars in every court. That evidentiary weight shortens the path to interim relief in an infringement case and materially helps in investment, acquisition and licensing diligence. Registration is not a precondition of the right, but it is a strategic instrument for proving it. **How much source code do I need to deposit for software copyright registration?** The Copyright Office's e-filing instructions and Rule 70(5) of the Copyright Rules, 2013 (as amended in 2021) require at least the first 10 and last 10 pages of source code — or the entire source code if it is less than 20 pages — with no blocked-out or redacted portions. The 'first 25 and last 25 pages' convention often quoted is US Copyright Office practice, not the Indian rule. Confirm the current deposit instructions on copyright.gov.in before filing. You do not upload the entire codebase. **If I paid a freelancer to build my app, do I own the copyright?** Not by payment alone. Under Section 17 of the Copyright Act the author — the person who wrote the code — is the first owner. For employees, the employer is the first owner where the work is made in the course of employment under a contract of service. For contractors, freelancers and agencies, ownership stays with the author unless there is a signed, written assignment under Sections 18 and 19. Without that assignment, the contractor may legally own the code your business runs on. **What is the criminal punishment for software piracy in India?** Knowing infringement under Section 63 is punishable with imprisonment of not less than six months extending up to three years and fine of not less than fifty thousand rupees extending up to two lakh rupees. Knowing use of an infringing copy of a computer programme on a computer under Section 63B is punishable with imprisonment of not less than seven days extending up to three years and fine of not less than fifty thousand rupees extending up to two lakh rupees — except that where the programme was not used for gain or in the course of trade or business, the court may, for adequate and special reasons, impose no imprisonment and a fine extending up to fifty thousand rupees. In Knit Pro International v. State of NCT of Delhi (Crl.A. 807/2022, decided 20 May 2022) the Supreme Court held that an offence under Section 63 is cognizable and non-bailable. **Is using cracked enterprise software in a startup an offence?** Yes, if done knowingly. Section 63B specifically criminalises knowing use of an infringing copy of a computer programme on a computer. A startup running unlicensed enterprise software across its team's machines is within that description, and the criminal liability sits alongside civil remedies of injunction, damages and delivery-up under Section 55. --- ## Trade Secrets and NDAs for Indian Startups: Protecting What You Don't Publish URL: https://advaslam.com/writing/trade-secrets-nda-protection-startups-india/ Author: Adv. K J Muhammed Aslam, Advocate (Bar Council of Kerala, K/001823/2026) Published 1 September 2026 Practice area: Business, banking & IPR India has no Trade Secret Act. Startups protect know-how via contracts (Section 27 Contract Act), IT Act Sections 43A and 72, BNS breach of trust, NDAs. India has **no standalone Trade Secret Act**, so the protection a Kerala startup has for its undisclosed know-how — pricing models, customer lists, training datasets, process know-how, source code that is not published — depends not on registration but on whether the business creates confidentiality by **contract** under the [Indian Contract Act, 1872](https://indiacode.gov.in/handle/123456789/496413) and by **conduct** through access controls, with statutory support from [Section 43A and Section 72 of the IT Act, 2000](https://indiacode.gov.in/handle/123456789/496511) and — where entrustment and misappropriation are made out — [Section 316 of the Bharatiya Nyaya Sanhita, 2023](https://indiacode.gov.in/handle/123456789/496548). An NDA signed after disclosure, or a non-compete so broad it is void under [Section 27 Contract Act](https://indiacode.gov.in/handle/123456789/496413), is not protection — it is paperwork that fails when tested. ## How is a trade secret defined when there is no Trade Secret Act? No statute supplies a definition, so courts and commentators apply the classic three-part test drawn from TRIPS Article 39 and Indian breach-of-confidence jurisprudence: | Element | What the business must show | |---|---| | **Secrecy** | The information is not generally known or readily accessible to persons who normally deal with that kind of information | | **Commercial value because it is secret** | The information has economic value precisely because it is not public — a customer list, a trained model's weights, a process yield — and disclosure would erode that value | | **Reasonable steps to keep it secret** | The holder took measures that a reasonable business would take to preserve confidentiality — NDAs, need-to-know access, marking, technical controls, exit procedures | A business that cannot show the third element — reasonable steps — fails even where the first two are made out. A pitch deck emailed without an NDA, a codebase accessible to every intern, and a customer database downloadable to personal devices are not trade secrets in practice, because no reasonable steps were taken to keep them secret. The DPDP Act reinforces this logic from the data side: [Rule 6 DPDP Rules, 2025](https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf) requires encryption or masking, access controls and logging — the same controls that support a trade-secret claim. ## What laws actually protect trade secrets in India? | Source | What it does | Limit | |---|---|---| | **Contract — Sections 27, 73, 74 Contract Act, 1872** | Enforces NDAs, confidentiality clauses, non-solicitation and — where reasonable — limited post-contract restraints; damages for breach under Sections 73 and 74 | Section 27 voids agreements in **restraint of trade** — a blanket non-compete preventing a former employee from working in the same field anywhere is typically void; non-disclosure is distinct and generally enforceable | | **Equity — breach of confidence** | Injunction and damages where confidential information was imparted in circumstances importing confidence and was misused — available even without a written NDA where the circumstances show confidence | Requires proof of the confidential character and the circumstances of disclosure | | **IT Act — Section 43A** | Compensation for negligent failure to implement reasonable security practices where wrongful loss or gain results from handling of sensitive personal data — relevant where the trade secret includes personal data | Civil compensation; complements DPDP Section 8(5) safeguards (up to two hundred and fifty crore rupees for safeguard failure) | | **IT Act — Section 72** | Penalty for breach of confidentiality and privacy by a person who has secured access to electronic records under the IT Act — penalty up to five lakh rupees (substituted for imprisonment and fine by the Jan Vishwas (Amendment of Provisions) Act, 2023) | Applies where access was obtained under IT Act powers or duties; narrower than Section 72A's contractual disclosure route | | **IT Act — Section 72A** | Penalty for disclosure of personal information in breach of a lawful contract, intending or knowing wrongful loss or gain — penalty up to twenty-five lakh rupees (substituted for imprisonment and fine by the Jan Vishwas (Amendment of Provisions) Act, 2023) | Requires a lawful contract and the mental element of wrongful loss or gain | | **BNS — Section 316 (criminal breach of trust)** | Punishment where property is entrusted and dishonestly misappropriated or converted — invoked where an employee or partner entrusted with data or materials misappropriates them | Requires entrustment and dishonest misappropriation — not every NDA breach qualifies | | **BNS — Section 336 (forgery), Section 353 (statements conducing to public mischief)** | Where misuse involves fabrication of records or misrepresentation | Fact-specific | > **Practical observation:** Most startup trade-secret disputes are won or lost on contract and on evidence of reasonable steps, not on the criminal provisions. The criminal track is fact-heavy and is not a substitute for a well-drafted NDA and an access-control programme. ## What makes an NDA enforceable — and what makes it fail under Section 27? Section 27 Contract Act — every agreement by which anyone is restrained from exercising a lawful profession, trade or business of any kind is to that extent void — is the provision founders fear and counterparties invoke. The fear is partly misplaced because courts distinguish: * **Non-disclosure — generally enforceable.** An obligation not to disclose specific confidential information is a restraint on **disclosure**, not on the ability to carry on a trade. It is not the restraint Section 27 targets. * **Non-compete — closely scrutinised and often void post-employment.** A clause that says a former employee cannot work for any competitor anywhere for two years is a restraint on trade and is typically void under Section 27. A narrowly drawn restraint — for example, not to solicit the employer's customers with whom the employee actually dealt, for six months, within a defined territory where the employer operates — has a better chance, but remains difficult. During employment, reasonable exclusivity and non-compete terms are more readily enforced; post-employment, the bar is higher. * **Non-solicitation — more readily enforced where reasonable.** Not to solicit employees or customers of the former employer, limited in time, scope and geography, tied to genuine confidential relationships. An NDA that fails usually fails for one of these reasons: 1. **Signed after disclosure.** The information was already shared before the NDA existed — there was no confidential basis at the time of sharing. 2. **No definition of confidential information.** A clause that says everything is confidential is not credible; a schedule of categories with exclusions (publicly available information, independently developed information, information rightfully received from a third party without breach) is. 3. **Unreasonable duration or geography.** Perpetual confidentiality for every casual disclosure is harder to enforce than a defined period tied to the sensitivity of the information and the commercial context. 4. **No return-or-delete obligation.** The NDA allows the recipient to retain copies indefinitely, which undermines the secrecy claim. 5. **No injunctive-relief acknowledgement.** The agreement does not acknowledge that breach would cause irreparable harm for which damages are inadequate — the language that supports an interim injunction. ## What should a Kerala startup's NDA and confidentiality programme actually contain? ### The NDA — clauses that matter 1. **Definition and exclusions.** Define confidential information by categories relevant to the startup — code, datasets, models, customer lists, financials, roadmaps — and list exclusions (public domain through no breach, independently developed, rightfully received from a third party). 2. **Purpose limitation.** State the specific purpose of disclosure (evaluation of a partnership, employment, investment diligence) and prohibit use beyond that purpose. 3. **Standard of care.** Require at least the same care the recipient uses for its own confidential information, and in any event reasonable care — including technical safeguards where the information is electronic. 4. **No licence or assignment.** Clarify that disclosure does not transfer ownership — copyright stays with the author or employer under Sections 17 to 19 of the Copyright Act (see the [software copyright guide](https://advaslam.com/writing/software-copyright-startup-kerala-guide/)), and patent rights are not licensed by the NDA. 5. **Duration.** A confidentiality period appropriate to the information — often two to five years for general commercial information, longer or indefinite for true trade secrets where the parties genuinely intend perpetual secrecy and the information qualifies. 6. **Return or certified deletion.** On termination or on demand, return or certify deletion of confidential information and copies, including from backups where technically feasible, with a written certificate of deletion. 7. **Residual knowledge.** Address whether general skills and knowledge retained in unaided memory are excluded — a point that matters for employee mobility and that should be addressed explicitly rather than left to argument. 8. **Personal-data handling.** Where confidential information includes personal data, require compliance with the DPDP Act — lawful basis, purpose limitation, Rule 6 security safeguards, Rule 7 breach notification — so the NDA and the DPDP processor obligations reinforce each other (see the [DPDP countdown guide](https://advaslam.com/writing/dpdp-act-deadline-businesses/) and the [cross-border transfer guide](https://advaslam.com/writing/dpdp-cross-border-data-transfer-section-16/)). 9. **Remedies.** Acknowledge irreparable harm and the availability of injunctive relief in addition to damages under Sections 73 and 74 Contract Act, and provide for governing law and dispute resolution (arbitration in Kochi is common for startups). 10. **Reasonable post-employment restraints.** If sought, draw non-compete and non-solicitation narrowly — limited customers, limited geography, short duration — so they have a chance of surviving Section 27 scrutiny, and consider garden-leave or notice-period mechanisms during employment where appropriate. ### The programme — conduct that proves reasonable steps An NDA without a programme is a contract without evidence. The reasonable-steps file a court or an investor looks for: * **Marking.** Confidential documents and repositories marked as such — not every email, but every genuinely sensitive disclosure. * **Need-to-know access.** Role-based access, least privilege, and logging of who accessed what — the same controls Rule 6 DPDP requires for personal data, applied to trade secrets. * **Onboarding and exit.** Confidentiality acknowledgements at joining, periodic reminders, and a structured exit process that revokes access, collects devices, and reminds the departing person of surviving obligations in writing. * **Vendor handling.** Every contractor, agency and cloud provider signs confidentiality and data-processing terms before access — not after — with sub-processing controls where personal data is involved. * **Logging for proof.** Access logs retained for at least the periods the business has chosen (the DPDP Rule 6 minimum is one year for personal-data logs; the CERT-In Directions require 180 days for ICT logs) so that misuse can be reconstructed and proved under [Section 63 BSA](https://advaslam.com/writing/electronic-evidence-bsa-section-63-certificate-guide/) if needed. ## How do trade secret, copyright, patent and DPDP fit together? For a typical Kerala SaaS or healthtech startup, the portfolio is: * **Trade secret** — for undisclosed know-how, pricing, customer insights, and model weights that must stay confidential and that derive value from secrecy. * **Copyright** — for code expression and documentation automatically under Section 2(o) Copyright Act, strengthened by Form XIV registration and the Section 48 certificate. * **Patent** — for the inventive technical solution where the [Section 3(k) and CRI Guidelines 2025](https://advaslam.com/writing/patent-computer-related-inventions-cri-guidelines-2025/) technical-effect test is met, accepting that publication in the specification ends secrecy for that invention. * **Trademark** — for the brand (see the [online trademark infringement guide](https://advaslam.com/writing/trademark-infringement-online-domain-phishing-indrp/)). * **DPDP compliance** — for personal data within the know-how (customer data, user data) under the DPDP Act and Rules, with the same technical controls serving both trade-secret and data-protection purposes. ## Primary sources * [Indian Contract Act, 1872 — India Code](https://indiacode.gov.in/handle/123456789/496413) (Sections 27, 73, 74) * [Information Technology Act, 2000 — India Code](https://indiacode.gov.in/handle/123456789/496511) (Sections 43A, 72, 72A) * [Bharatiya Nyaya Sanhita, 2023 — India Code](https://indiacode.gov.in/handle/123456789/496548) (Sections 316, 336) * [Copyright Act, 1957 — India Code](https://indiacode.gov.in/handle/123456789/496733) (Sections 2(o), 17, 18, 19, 48) * [Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025 (G.S.R. 846(E), 13 November 2025) — MeitY](https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf) (Section 8(5), Rule 6) * [Bharatiya Sakshya Adhiniyam, 2023 — India Code](https://indiacode.gov.in/handle/123456789/496549) (Section 63 — proving electronic logs) ### Frequently asked questions **Is there a Trade Secret Act in India?** No. India has no codified Trade Secret Act. Trade secrets are protected through a combination of contract law (the Indian Contract Act, 1872 — especially Section 27 on agreements in restraint of trade), equitable breach of confidence, Section 43A and Section 72 of the IT Act, 2000 on data handling and confidentiality, and — where entrustment and dishonest misappropriation are made out — criminal breach of trust under Section 316 of the Bharatiya Nyaya Sanhita, 2023. Protection therefore depends on how well the business creates confidentiality by contract and by conduct. **Are NDAs enforceable in India?** Yes, where they are reasonable. A non-disclosure obligation — not to disclose confidential information — is generally enforceable as a restraint on disclosure, distinct from a restraint on trade or employment. What courts scrutinise under Section 27 of the Contract Act is a restraint on carrying on a lawful profession or trade: a blanket non-compete that prevents a former employee from working in the same field anywhere is typically void under Section 27, while a narrowly drawn non-disclosure and non-solicitation that protects genuine confidential information is enforceable. Reasonableness of time, geography and scope decides the outcome. **Can I protect my startup idea as a trade secret?** An idea alone, without more, is hard to protect — trade secret protection attaches to information that is secret, has commercial value because it is secret, and is subject to reasonable steps to keep it secret. A bare idea disclosed without a confidentiality arrangement, without markers of secrecy and without access controls, rarely meets that test. An idea embodied in a plan, model, codebase, dataset or process that is shared only under a signed NDA and with need-to-know access can be. **What should a startup NDA include to be effective?** A clear definition of confidential information and exclusions, the purpose of disclosure, the standard of care and permitted uses, the duration of confidentiality, return or certified deletion on termination, the treatment of residual knowledge, the handling of personal data where relevant, and — where post-employment restraints are sought — narrowly drawn non-compete and non-solicitation clauses that are reasonable in time, scope and geography so they can survive Section 27 scrutiny. The NDA should be signed before disclosure, not after. **What is the difference between trade secret and patent for a startup?** A patent — if granted — gives a 20-year monopoly in exchange for public disclosure of the invention in the specification. A trade secret lasts as long as secrecy is maintained, but gives no monopoly against independent invention or reverse engineering. Choose patent where the advantage is in the inventive solution and disclosure is acceptable (see the CRI Guidelines guide for software and AI); choose trade secret where the advantage depends on non-disclosure and the information can be kept confidential in practice. --- ## Online Trademark Infringement in India: Fake Websites, Phishing Domains and How to Take Them Down URL: https://advaslam.com/writing/trademark-infringement-online-domain-phishing-indrp/ Author: Adv. K J Muhammed Aslam, Advocate (Bar Council of Kerala, K/001823/2026) Published 1 September 2026 Practice area: Business, banking & IPR Online trademark infringement under Section 29 Trade Marks Act: phishing domains, marketplace clones, keyword misuse, and INDRP, UDRP, IT Rules takedowns. A fake website that copies a brand's name, logo and look to sell counterfeits or steal credentials is **trademark infringement** under [Section 29 of the Trade Marks Act, 1999](https://indiacode.gov.in/handle/123456789/495962) and, where it uses a deceptive domain, a **domain-name dispute** recoverable through **INDRP** (.in) or **UDRP** (gTLDs) — and the same act is also **phishing** punishable under [Sections 66C and 66D of the IT Act, 2000](https://indiacode.gov.in/handle/123456789/496511). The removal route, since 20 February 2026, runs on a **three-hour clock** under [Rule 3(1)(d) of the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 as amended on 10 February 2026](https://egazette.gov.in/WriteReadData/2026/269993.pdf), triggered by a court order or an authorised government notification. ## What counts as online trademark infringement under Section 29? The elements of infringement under [Section 29 Trade Marks Act](https://indiacode.gov.in/handle/123456789/495962) translate directly to online conduct: | Section 29 element | How it applies online | |---|---| | **Registered mark** | The plaintiff holds a registered trademark — word, device, shape, sound or combination — capable of distinguishing goods or services (Section 2(1)(zb)) | | **Identical or deceptively similar mark** | The fake site uses the same mark or a mark likely to deceive or cause confusion (Section 2(1)(h)) — for example, hdfcbank-login.com, amaz0n-deals.in, or a cloned logo and colour scheme | | **In the course of trade, without authorisation** | Operating a site, listing, advertisement, social handle or domain that offers goods or services or collects data under the mark, without the proprietor's licence | | **For identical or similar goods or services, with likelihood of confusion or association** | The classic case — counterfeits or lookalike services of the same type — but also Section 29(4): a well-known mark is protected even for **dissimilar** goods or services where use without due cause takes **unfair advantage** of or is **detrimental to** the distinctive character or repute of the mark | | **Modes that expressly include online use** | Affixing to goods or packaging, offering for sale, **advertising** (Section 29(6), 29(8)), **import/export**, use as a **trade or corporate name** (Section 29(5)), and use on business papers and in **advertising** — all of which cover domain names, marketplace listings, sponsored ads and social commerce | Two extensions courts routinely apply online: * **Domain name as trademark.** Since Yahoo! Inc. v. Akash Arora ((1999) 19 PTC 201 (Del)) and [Satyam Infoway Ltd v. Siffynet Solutions (2004) 6 SCC 145](https://indiankanoon.org/doc/1630167/), a domain name that incorporates a mark functions as a trademark. A deceptively similar domain that diverts customers is not merely a technical address — it is trademark use. * **Keyword and sponsored-ad misuse.** Bidding on a competitor's mark as a keyword, or using it in sponsored listings in a manner that creates confusion, has been treated as trademark use in advertising under Section 29, with recent High Court jurisprudence examining marketplace and search-algorithm facilitation — now increasingly described as e-infringement through platform architecture. > **Law vs interpretation:** Section 29 sets the statutory test (registered mark, deceptive similarity, course of trade, likelihood of confusion). Whether a specific domain, listing or keyword bid creates that likelihood is interpretation by courts on the facts — including the Delhi High Court's current reference to a Larger Bench (Hindustan Unilever v. Kwick Living, 2026) on territorial jurisdiction for online trademark disputes, which does not change the substantive infringement test but affects where suit can be filed. ## How does a phishing domain combine trademark and cybercrime? A phishing clone — for example, a fake KYC page for a Kerala cooperative bank — is rarely just a trademark case. The same page typically violates both regimes at once: * **Trade Marks Act — Section 29 infringement and Section 27(2) passing off** for the brand misuse. * **IT Act — Section 66C (identity theft)** for fraudulent use of the brand's identity feature and **Section 66D (cheating by personation using a computer resource)** for pretending to be the brand through a computer resource. Each carries up to three years and fine up to one lakh rupees. * **BNS — Section 318(4) (cheating), Section 319(2) (cheating by personation), Section 308 (extortion) where payment is extracted under threat**, and Section 336 (forgery of electronic record) where fake documents are generated. A Kerala business that treats the phishing page as only an IT support ticket and not as an IP enforcement matter leaves the infringement remedy — injunction, damages, domain transfer and platform blocking — unused. Both tracks should be pursued together: a criminal complaint for investigation and a civil/domain action for removal and recovery. ## What are the practical takedown and recovery routes? ### Route 1 — INDRP for .in domains, UDRP for gTLDs | Forum | Domains | What the complainant must prove | Remedy | Typical timeline | |---|---|---|---|---| | **INDRP** (NIXI, under the .IN Registry) | .in, .भारत, and Indian ccTLDs | (i) Domain identical or confusingly similar to a mark in which complainant has rights, (ii) registrant has no rights or legitimate interests, (iii) domain registered or used in bad faith, or for an illegal/unlawful purpose (clause 4(c)) | Transfer or cancellation of the domain | 2 to 3 months (practitioner estimate), decided on papers | | **UDRP** (WIPO and other ICANN providers) | .com, .net, .org and other gTLDs | Same three-element structure as INDRP (ICANN UDRP para 4(a); in UDRP the bad-faith element is conjunctive — registered and used in bad faith) | Transfer or cancellation | 2 to 3 months | INDRP is cheaper than UDRP and is the natural route for phishing domains targeting Indian consumers with .in lookalikes. Evidence should include the trademark registration certificate, screenshots of the infringing site showing the mark as used, WHOIS, and any customer complaints or credential-theft reports. Where WHOIS is privacy-masked, the INDRP provider can direct the registrar to disclose the underlying registrant. ### Route 2 — Intermediary takedown under Rule 3(1)(d) — three hours on actual knowledge Under [Rule 3(1)(d) IT Rules as amended 10 February 2026](https://egazette.gov.in/WriteReadData/2026/269993.pdf) (in force 20 February 2026), an intermediary that receives **actual knowledge** through a **court order** or a **notification from the appropriate government or its authorised agency** must remove or disable access to unlawful information — which includes trademark-infringing and phishing content — within **three hours** (down from 36 hours). Sensitive complaints involving impersonation or non-consensual imagery go faster — within two hours. For brand owners without a court order, the **grievance mechanism under Rule 3(2)** is the parallel channel: every intermediary must appoint a Resident Grievance Officer, acknowledge complaints within 24 hours, and **resolve them within seven days** (down from 15 days), with a **36-hour** track for unlawful-content grievances and a **two-hour** track for nudity and morphed imagery. In practice, file both: a Rule 3(2) grievance with specific URLs and proof of registration, and — where the phishing is active — a police complaint that can generate the government notification that triggers the three-hour Rule 3(1)(d) clock. The Karnataka High Court's 2025 decision in X Corp v. Union of India, upholding the Sahyog portal as a Section 79(3)(b) takedown route (Karnataka HC, 24 September 2025), is part of this ecosystem. ### Route 3 — Civil injunction including Dynamic+ orders Where phishing is not a single domain but a network of rotating mirrors — a pattern the Delhi High Court addressed in [Dabur India Ltd v. Ashok Kumar (2025:DHC:11862, pronounced 24 December 2025)](https://delhihighcourt.nic.in/app/showFileJudgment/PMS24122025SC1352022_193906.pdf) — the remedy that has matured since [UTV Software v. 1337X (Delhi HC, 2019)](https://indiankanoon.org/doc/42620136/) and [Universal City Studios v. Dotmovies.baby (Delhi HC, 2023)](https://indiankanoon.org/doc/120572287/) is the **Dynamic+ and Dynamic++ injunction**: an order that binds ISPs, DoT and MeitY to block not only named sites but their future mirrors and redirects in real time, without a fresh suit for each new domain. Deployed in the December 2025 Warner Bros. order and the 2026 JioStar IPL order for copyright, the same architecture is sought in trademark phishing where the defendant rotates domains to evade blocking. Courts also increasingly direct registrars to lock and suspend infringing domains within 72 hours and to disclose registrant data in sealed cover. ### Route 4 — Criminal complaint File at [cybercrime.gov.in](https://cybercrime.gov.in) and at the district Cyber Police Station under Sections 66C and 66D IT Act read with Sections 318, 319 and 336 BNS. The complaint should annex the trademark certificate, the phishing URLs, screenshots with URLs and timestamps preserved for [Section 63 BSA certification](https://advaslam.com/writing/electronic-evidence-bsa-section-63-certificate-guide/), and the INDRP or platform grievance reference where already filed. Under Section 78 IT Act, investigation of Sections 66C and 66D is by an officer of Inspector rank or above. ## Can a Kerala business handle a cross-border infringer? Often, but with planning. A large share of phishing infrastructure is hosted outside India, uses privacy-masked WHOIS, and accepts payment through foreign gateways. Three points matter: * **Jurisdiction for online infringement.** The Delhi High Court's 2026 reference to a Larger Bench in [Hindustan Unilever v. Kwick Living (CS(COMM) 904/2026, reference order dated 25 August 2026)](https://indiankanoon.org/doc/54794195/) — whether IP suits are governed solely by Section 20 CPC or by Section 134 Trade Marks Act / Section 62 Copyright Act, and what purposeful-availment test applies for online accessibility — means forum choice should be pleaded carefully. For a Kerala plaintiff, the cause of action where the brand is used to target Kerala consumers and where confusion occurs in Kerala is part of the jurisdictional pleading, but the evolving Larger Bench guidance should be checked before filing. * **Cross-border takedown.** Rule 3(1)(d) and grievance duties apply to intermediaries that provide services to users in India, even without a physical presence in India. Foreign-hosted phishing domains can still be addressed through INDRP (where the domain is .in), UDRP, and registrar and hosting-provider abuse channels, alongside the Indian injunction and criminal complaint. * **Evidence from outside India.** Foreign server logs and registrar data that are electronic records will need to satisfy [Section 63 BSA](https://advaslam.com/writing/electronic-evidence-bsa-section-63-certificate-guide/) if tendered in an Indian court — which means planning for a certificate with device particulars, hash and dual signatures rather than relying on forwarded screenshots alone. ## Primary sources * [Trade Marks Act, 1999 — India Code](https://indiacode.gov.in/handle/123456789/495962) (Sections 2(1)(h), 2(1)(zb), 27(2), 29, 134) * [Information Technology Act, 2000 — India Code](https://indiacode.gov.in/handle/123456789/496511) (Sections 66C, 66D, 78, 79) * [Bharatiya Nyaya Sanhita, 2023 — India Code](https://indiacode.gov.in/handle/123456789/496548) (Sections 318, 319, 336) * [IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 as amended 10 February 2026 — Gazette of India, G.S.R. 120(E)](https://egazette.gov.in/WriteReadData/2026/269993.pdf) (Rules 3(1)(d), 3(2), 4) * Yahoo! Inc. v. Akash Arora ((1999) 19 PTC 201 (Del)); [Satyam Infoway Ltd v. Siffynet Solutions (2004) 6 SCC 145](https://indiankanoon.org/doc/1630167/) * [INDRP Policy and Rules of Procedure — NIXI (.IN Registry)](https://www.registry.in/domaindisputeresolution) and [UDRP Rules — ICANN/WIPO](https://www.wipo.int/amc/en/domains/guide/) * [Dabur India Ltd v. Ashok Kumar (2025:DHC:11862)](https://delhihighcourt.nic.in/app/showFileJudgment/PMS24122025SC1352022_193906.pdf) on dynamic injunctions and registrar disclosure ### Frequently asked questions **Is a fake website using my brand name trademark infringement under Section 29?** Yes, where the use is in the course of trade without authorisation and the mark is identical or deceptively similar for identical or similar goods or services such that confusion or association is likely. Section 29(1) to (9) of the Trade Marks Act, 1999 covers affixing to goods, packaging, import/export, advertising and use as a trade or corporate name. A phishing clone that copies a registered mark to sell counterfeits or collect credentials is classic infringement, and even well-known marks are protected for dissimilar goods under Section 29(4) where unfair advantage or dilution is shown. **Can I get a phishing .in domain taken down through INDRP?** Yes. For .in and .भारत domains, the .IN Domain Name Dispute Resolution Policy (INDRP) administered by NIXI is the dedicated route, modelled on the UDRP. The complainant must show the domain is identical or confusingly similar to a mark in which it has rights, the registrant has no rights or legitimate interests, and the domain was registered or used either in bad faith or for an illegal/unlawful purpose (registry.in, INDRP clause 4(c)). INDRP is decided on papers, and practitioners estimate a two-to-three-month timeline; it can order transfer or cancellation. For .com and other gTLDs, the UDRP through WIPO applies. **Can I force a platform or intermediary to remove a fake listing using my trademark?** Yes, via two parallel duties. Under Rule 3(1)(d) of the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 as amended on 10 February 2026, an intermediary that receives actual knowledge through a court order or a notification from the appropriate government or its authorised agency must remove or disable access to unlawful information — including trademark-infringing and phishing content — within three hours. Separately, every platform's grievance mechanism under Rule 3(2) must resolve complaints within seven days, and within two hours for sensitive categories that overlap where phishing involves impersonation. **Is trademark infringement online still infringement if the goods are never delivered and it is just a phishing page to steal OTPs?** Yes. Section 29 is not limited to completed sales of counterfeit goods. Use of an identical or deceptively similar mark in the course of trade to deceive — including a phishing page that collects credentials under a cloned brand — is use for the purpose of infringement, and it also attracts Section 66C (identity theft) and Section 66D (cheating by personation) of the IT Act and Sections 318 and 319 of the BNS. The civil infringement and the cybercrime can be pursued together. **Do I need a registered trademark to act against a fake website?** Registration helps materially — it gives the Section 29 infringement action and the prima facie title that supports interim injunctions and INDRP/UDRP complaints — but an unregistered mark can be protected through passing off under Section 27(2) of the Trade Marks Act and through Sections 66C/66D of the IT Act where phishing is involved. Registration is, however, the position of strength for every enforcement route. --- ## Bank Account Frozen by a Cyber Cell in Kerala: Remedies and Release URL: https://advaslam.com/writing/bank-account-frozen-cyber-cell-kerala/ Author: Adv. K J Muhammed Aslam, Advocate (Bar Council of Kerala, K/001823/2026) Published 16 August 2026 Practice area: Cyber crime & IT Act matters Bank account frozen by cyber cell in Kerala: Section 106 BNSS explained, lien limits, Magistrate release and the Article 226 High Court writ route. If a cyber cell has frozen your bank account in Kerala, the freeze is almost always an investigative step under [Section 106 of the Bharatiya Nagarik Suraksha Sanhita, 2023](https://indiacode.gov.in/handle/123456789/496550) (formerly Section 102 CrPC), triggered by a cyber fraud complaint filed somewhere in India — not a finding of guilt against you. It can be challenged, and there are three escalating remedies: a written representation to the investigating officer, an application to the jurisdictional Magistrate under Section 503 BNSS (formerly Section 457 CrPC), and a writ petition before the High Court of Kerala under Article 226. The Kerala High Court has repeatedly held that freezing should be confined to the disputed amount, so the practical goal in most cases is a lien over that amount with the rest of the account released. This guide walks through why freezes happen, what to do in the first week, and how each remedy works. ## Why has a cyber cell frozen my bank account? Almost every freeze of this kind begins with a complaint on the [National Cybercrime Reporting Portal](https://cybercrime.gov.in) (NCRP) or the 1930 cyber fraud helpline. A victim anywhere in India reports that money was taken from them — a fake trading app, a UPI scam, a phishing link. The complaint enters the Citizen Financial Cyber Fraud Reporting and Management System (CFCFRMS), run by the Indian Cyber Crime Coordination Centre (I4C) under the Ministry of Home Affairs. The system traces the money hop by hop: from the victim's account to a first-layer account, then onward as the fraudster splits and moves the funds. The Government has described the 1930 helpline and this reporting system in [official releases](https://www.pib.gov.in/Pressreleaseshare.aspx?PRID=1814120®=3&lang=2). Every account the money touches — layer one, layer two, sometimes layer five — gets flagged. The investigating cyber cell, often in a different State, then sends your bank a requisition to freeze the account. The bank complies, usually without notice to you, and you discover the freeze when a payment bounces or the app shows a hold. The key point: the freezing police station acted on a money trail, not on any assessment of you. Your account may be in the chain only because a stranger paid you with tainted money for a perfectly genuine sale. ## What law allows the police to freeze a bank account? The power comes from Section 106 BNSS (formerly Section 102 CrPC), which lets any police officer seize property "alleged or suspected to have been stolen" or found in circumstances creating suspicion of an offence. The Supreme Court settled in [State of Maharashtra v. Tapas D. Neogy (1999)](https://indiankanoon.org/doc/491816/) that a bank account is "property" for this purpose, so a freeze instruction to the bank is a valid mode of seizure — provided the account has a direct link to the offence under investigation. Two statutory safeguards matter to you: 1. **Report to the Magistrate.** Section 106(3) BNSS requires the officer to report the seizure "forthwith" to the Magistrate having jurisdiction. A freeze that was never reported is procedurally vulnerable. 2. **Attachment needs a court order.** Where the police claim the money is *proceeds of crime* and want it attached or forfeited, Section 107 BNSS requires an application to the Magistrate, a 14-day show-cause notice to the account holder, and a judicial order. In *Headstar Global Pvt. Ltd. v. State of Kerala*, Crl.M.C. No. 3740 of 2025 (2025:KER:39285, 17 June 2025), the Kerala High Court [quashed a debit freeze](https://24law.in/story/kerala-high-court-unfreezes-company-bank-account-police-must-seek-magistrate-approval-under-section-107-bnss-to-attach-proceeds-of-crime), holding that police cannot unilaterally freeze a third-party account on a proceeds-of-crime theory; they must follow the Section 107 route through the Magistrate. The distinction is practical, not academic. If the police letter to your bank reads like an attachment of proceeds of crime rather than a seizure of suspect property, *Headstar Global* gives you a direct ground of challenge. Banks can also freeze suspected money-mule accounts on their own under their anti-money-laundering obligations, without any police requisition. For those bank-initiated freezes, the framework is the Kerala High Court's interim SOP in *Abdul Azeez v. Union of India*, W.P.(C) Nos. 32516 & 32291 of 2024 (2025:KER:88312, 19 November 2025): same-day notice to the customer by SMS and registered post with the reasons for suspicion, intimation to the jurisdictional Cyber Crime Police, a decision within one week on the customer's explanation, and a hard three-month cap absent any authority direction. If your freeze came from the bank rather than the police, that framework is your first lever — it is set out in the companion guide on [bank freezes without a police complaint](https://advaslam.com/writing/bank-freeze-without-police-rbi-kerala-hc-sop/). ## What is the difference between a full freeze, a debit freeze and a lien? The words on the bank's noting decide how much of your money is actually blocked, so get the exact term in writing. | Restriction | What it means | Typical source | |---|---|---| | **Full freeze** | No debits or credits; account is dead | Broad police requisition, older bank practice | | **Debit freeze** | Credits come in, nothing goes out | Standard cyber cell requisition wording | | **Lien / hold on a specific amount** | Only the disputed sum is blocked; the balance operates normally | Court-directed practice; increasingly the Kerala norm | The Kerala High Court has pushed practice firmly toward the third option. In *Dr. Sajeer v. Reserve Bank of India*, WP(C) No. 12960 of 2023 ([interim orders reported on IndianKanoon](https://indiankanoon.org/doc/154747928/); the 25 September 2023 decision is reported at 2024 (1) KLT 826), Justice Devan Ramachandran asked why traders' entire accounts should stay frozen when the police requisition itself named the exact suspect credit, and [directed banks to confine the freeze](https://www.livelaw.in/high-court/kerala-high-court/kerala-high-court-bank-account-freezing-order-limit-proceeds-of-crime-240587) to the amounts mentioned in the requisitions, with the police directed to confirm within eight months whether continuation was needed. That principle now runs through Kerala practice. As recently as *Kunnamangalam Co-operative Rural Bank Ltd. v. Inspector of Police* (2026:KER:15537; reported 2 March 2026), the Court [held that police requisitions must not paralyse banking operations](https://www.verdictum.in/court-updates/high-courts/kerala-high-court/ms-kunnamangalam-co-operative-rural-bank-ltd-v-inspector-of-police-2026ker15537-bank-free-mirror-account-cooperative-bank-1609057) and confined the lien to the specific fraud-linked amount, leaving the co-operative bank's pooled mirror account otherwise operational. ## Why do innocent people end up with frozen accounts? Because the money trail is mechanical. CFCFRMS flags every account the money passes through, and the system cannot distinguish a mule account from a genuine merchant. In practice, the people caught most often are: - **Small merchants and shopkeepers** paid by UPI for real goods — the buyer paid with defrauded money. - **Secondhand sellers** on OLX, Facebook Marketplace or Instagram who received payment from a stranger. - **Salary and family accounts** that received a transfer traceable, several hops back, to a fraud. - **Businesses with high UPI volume**, where one tainted credit of a few thousand rupees freezes an account holding lakhs. In practice, I see freezes where the disputed credit is under ₹5,000 and the blocked balance is a hundred times that. That mismatch — a small tainted credit paralysing an entire account — is precisely the disproportionality the Kerala High Court has been correcting since *Dr. Sajeer*. Being flagged does not make you an accused; most account holders in the chain are never named in the FIR at all. ## What should I do first after discovering the freeze? Resist the urge to argue at the branch counter. Work through these steps in the first week: 1. **Get the freeze details in writing from the branch.** Ask for: the name and address of the freezing authority, the requisition or reference number, the date of the freeze, the amount covered, and whether it is a full freeze, debit freeze or lien. Banks sometimes resist; a short written request citing the account holder's right to know why their property is restrained usually works. 2. **Note the NCRP acknowledgment number.** The bank's instruction typically quotes an NCRP/CFCFRMS acknowledgment number. That number identifies the underlying complaint and the investigating cyber cell. 3. **Check whether an FIR exists.** If the requisition names an FIR or Crime Number, obtain a copy — FIRs are public documents available from the police station or the State police website. 4. **Preserve your side of the transaction.** Invoices, delivery proof, order screenshots, chat records, the buyer's number — everything that shows the credit was genuine consideration. 5. **Do not ignore police contact.** If the investigating officer calls or issues a notice under Section 179 BNSS (formerly Section 160 CrPC) or Section 94 BNSS (formerly Section 91 CrPC), respond, on record. Cooperation, documented in writing, is later your best evidence of bona fides. 6. **Do not "test" the account** with repeated transfers, and do not route business funds through friends' accounts in the meantime — both look bad in an investigation file. If your loss runs the other way — money was taken *from* you — the reporting steps are different; see [how to file a UPI fraud complaint and recover funds](https://advaslam.com/writing/upi-fraud-complaint-recovery/). ## How do I get the investigating officer to lift the freeze? The first remedy is a written representation to the investigating officer of the cyber cell that issued the requisition — often in another State. It costs little, and even when it fails, it builds the record that every later forum will read. A representation that actually gets acted on has five parts: 1. **Identification of the freeze**: account number, bank, requisition reference, NCRP acknowledgment number, date. 2. **The transaction story**: who paid you, why, and when — told in three or four sentences, with the credit matched to an invoice or sale. 3. **Documents**: account statement highlighting the credit, invoice or delivery proof, KYC, GST registration if a business. 4. **The specific request**: restrict the freeze to the disputed amount (name the figure) and release the balance; or lift the freeze entirely if the credit is explained. 5. **An undertaking** to keep the disputed amount available and to cooperate with the investigation. Send it by email *and* registered post to the investigating officer, with a copy to the district cyber cell and to your bank's nodal officer. Ask the bank, in writing, to seek the police's confirmation on whether continued freezing is required — the *Dr. Sajeer* directions expect exactly that dialogue between bank and police. Give this route two to four weeks. If the officer is unresponsive — common with out-of-state cyber cells handling thousands of flagged accounts — escalate rather than wait. ## Can a Magistrate order release of the frozen amount? Yes. This is the standard statutory remedy, and it flows from the seizure-reporting requirement. - **Section 503 BNSS (formerly Section 457 CrPC)** applies where property seized by police is *not* produced before a court during inquiry or trial — the exact position of a frozen account. The Magistrate to whom the seizure was reported may order delivery of the property "to the person entitled to the possession thereof", on conditions. - **Section 497 BNSS (formerly Section 451 CrPC)** applies once the property is before a court during inquiry or trial, and allows interim custody orders on similar logic. The application goes to the **Magistrate having jurisdiction over the investigating police station** — which, for an out-of-state freeze, means a court in that State, not in Kerala. That is the route's main practical burden: engaging counsel where the FIR is registered, filing through them, and attending if required (courts increasingly permit appearance through counsel alone for such applications). A Section 503 application typically annexes the same documents as the representation, plus an affidavit of ownership of the account and the funds. Relief commonly comes with conditions: a bond, an undertaking to produce the amount if directed, or continuation of a lien over the disputed sum. Use this route when the investigating State is accessible and the FIR is identifiable. When it is not — or when the freeze itself is procedurally bad — Kerala account holders have a better forum at home. ## When should I move the Kerala High Court under Article 226? This is the remedy specific to Kerala that most general guides miss. The High Court of Kerala, sitting at Ernakulam, has developed a consistent body of orders on cyber-cell freezes, and for many account holders it is the fastest effective forum. **Jurisdiction.** Under [Article 226(2) of the Constitution](https://indiacode.gov.in/document-grid/d5475e8d-1998-4ac8-8694-82f941074bb7), a High Court may exercise writ jurisdiction where the cause of action arises "wholly or in part" within its territory, even if the authority being challenged sits outside it. Your bank account is maintained at a branch in Kerala; the freeze operates on you in Kerala; the bank implementing it is in Kerala. That part of the cause of action ordinarily grounds the Kerala High Court's jurisdiction even where the freezing cyber cell is in Gujarat, Rajasthan or Delhi. The bank and the out-of-state investigating officer are both made respondents. **Grounds.** The petitions that succeed usually plead one or more of: - **Disproportionality** — the entire account is frozen though the requisition names a small specific credit (*Dr. Sajeer*). - **No Section 106(3) report** — the seizure was never reported forthwith to the jurisdictional Magistrate. - **Wrong provision** — the freeze is really an attachment of alleged proceeds of crime, which required the Section 107 BNSS procedure before a Magistrate (*Headstar Global*). - **Unresponsive investigation** — representations acknowledged by no one, no FIR details forthcoming, freeze continuing indefinitely without review. **The relief pattern.** The Kerala High Court's characteristic order is not a simple quashing. It de-freezes the account **subject to a lien over the disputed amount** — the investigation's interest in the traced money is preserved, and the account holder's business survives. *Dr. Sajeer* set the template; *Kunnamangalam Co-operative Rural Bank* (2026) applied it down to the rupee, restricting the lien to the documented fraud-linked sum. Where the freeze is procedurally unsustainable, as in *Headstar Global*, the Court lifts it entirely and leaves the police to the Section 107 route. A note on form: *Headstar Global* was a Crl.M.C. under Section 528 BNSS (formerly Section 482 CrPC, the High Court's inherent powers), while *Dr. Sajeer* and the co-operative bank line were writ petitions under Article 226. Which vehicle fits depends on whether the challenge targets the freeze order and Magistrate proceedings (Crl.M.C.) or the ongoing administrative restraint on the account (writ). An advocate can assess which applies to a given freeze. For what filing a writ actually involves — pleadings, interim orders, timelines — see [how a writ petition works in the Kerala High Court](https://advaslam.com/writing/writ-petition-high-court-kerala/). ## How long does each route take, and what should I expect? Timelines vary with the court's board and the police response, but the realistic ranges in current practice are: | Route | Realistic timeline | Typical outcome | |---|---|---| | Representation to investigating officer | 2–6 weeks, often no response | Lien-limiting or release if the cell is responsive | | Section 503 BNSS application (out-of-state Magistrate) | 1–3 months including engagement of local counsel | Conditional release; bond or undertaking | | Article 226 writ / Crl.M.C., Kerala High Court | Admission and interim orders within days to weeks; disposal commonly 1–3 months | De-freeze with lien over disputed amount | Three expectations worth setting honestly. First, the disputed amount itself usually stays blocked until the investigation or trial resolves — courts protect the victim's traceable money. Second, no forum will move without your documents; the account statement and transaction proof do more work than any legal argument. Third, if a second complaint flags the same account later, the cycle can restart — which is why the prevention practices below matter. ## What documents should I have ready? One set, assembled once, serves all three routes: 1. Bank's written confirmation of the freeze, with requisition reference and NCRP acknowledgment number. 2. Account statement for the relevant period, disputed credit highlighted. 3. Proof of the underlying transaction: invoice, bill, delivery record, courier receipt, marketplace listing, chat with the payer. 4. KYC documents for the account; GST registration and business proof if applicable. 5. Copy of the FIR, if identifiable. 6. All correspondence with the investigating officer and the bank, with proof of dispatch. 7. A short sworn statement of the transaction story — drafted once, reused in the representation, the Section 503 application and the writ affidavit. ## Will I be arrested because fraud money reached my account? An innocent recipient is rarely arrested, and the law is on your side on principle. Cheating under Section 318(4) BNS (formerly Section 420 IPC) requires dishonest inducement; the [Information Technology Act, 2000](https://indiacode.gov.in/handle/123456789/496511) offences of identity theft (Section 66C) and cheating by personation using a computer resource (Section 66D) target the fraudster, not the merchant who was paid. What creates risk is conduct after the freeze: ignoring notices, giving inconsistent accounts, or letting your account be used again. A working overview of the IT Act offences is at [IT Act offences explained](https://advaslam.com/writing/it-act-offences-explained/), and the broader defence-side practice is described at [cyber crime practice](https://advaslam.com/practice/cyber-crime/). If you knowingly rented out your account or passed on funds for a commission, the analysis changes entirely — that is money-mule conduct, and it is prosecuted. Take legal advice promptly before responding to any notice in that situation. ## How can businesses receiving UPI payments reduce the risk? No practice eliminates the risk of a tainted credit, but these reduce both the odds and the damage: 1. **Separate accounts.** Keep UPI collections in a dedicated current account, distinct from the account holding working capital and salary payments. A freeze then stops one stream, not the business. 2. **Invoice everything.** A credit you can match to a numbered invoice within minutes is a credit you can get released. Cash-style anonymous UPI receipts are the hardest to defend. 3. **Know your buyer on high-value sales.** For secondhand sales and large orders from strangers, keep the chat, the listing and the buyer's number. 4. **Act inside the bank's window.** Under the *Abdul Azeez* framework, a bank freezing on its own must give you same-day reasons and decide within one week on your explanation. Answer promptly, with documents — silence or an unsatisfactory explanation lets the freeze run to the three-month cap. 5. **Sweep balances.** Regular transfers to a non-collection account limit how much a future freeze can trap. 6. **Report your own losses fast.** If your business is ever the victim, report on [cybercrime.gov.in](https://cybercrime.gov.in) or 1930 immediately — the same CFCFRMS chain that froze your account is what recovers money when you are on the other side of it. ## Primary sources - [Bharatiya Nagarik Suraksha Sanhita, 2023 — full text, India Code](https://indiacode.gov.in/handle/123456789/496550) (Sections 106, 107, 497, 503, 528) - [Constitution of India — Article 226](https://indiacode.gov.in/document-grid/d5475e8d-1998-4ac8-8694-82f941074bb7) - [Information Technology Act, 2000 — India Code](https://indiacode.gov.in/handle/123456789/496511) - [State of Maharashtra v. Tapas D. Neogy, Supreme Court, 16 September 1999 — IndianKanoon](https://indiankanoon.org/doc/491816/) - [Dr. Sajeer v. Reserve Bank of India, WP(C) No. 12960 of 2023, Kerala High Court — IndianKanoon](https://indiankanoon.org/doc/154747928/); the 25 September 2023 decision is reported at 2024 (1) KLT 826 ([LiveLaw report](https://www.livelaw.in/high-court/kerala-high-court/kerala-high-court-bank-account-freezing-order-limit-proceeds-of-crime-240587)) - [Headstar Global Pvt. Ltd. v. State of Kerala, Crl.M.C. No. 3740 of 2025, 2025:KER:39285 — case report](https://24law.in/story/kerala-high-court-unfreezes-company-bank-account-police-must-seek-magistrate-approval-under-section-107-bnss-to-attach-proceeds-of-crime) - [Kunnamangalam Co-operative Rural Bank Ltd. v. Inspector of Police, 2026:KER:15537 — Verdictum report](https://www.verdictum.in/court-updates/high-courts/kerala-high-court/ms-kunnamangalam-co-operative-rural-bank-ltd-v-inspector-of-police-2026ker15537-bank-free-mirror-account-cooperative-bank-1609057) - [Abdul Azeez v. Union of India, W.P.(C) Nos. 32516 & 32291 of 2024, 2025:KER:88312, Kerala High Court, 19 November 2025 — LiveLaw report](https://www.livelaw.in/high-court/kerala-high-court/guidelines-freezing-suspicious-accounts-rbi-frame-sop-310857) - [National Cybercrime Reporting Portal — cybercrime.gov.in](https://cybercrime.gov.in) - [PIB: Cyber Frauds Helpline 1930 and CFCFRMS](https://www.pib.gov.in/Pressreleaseshare.aspx?PRID=1814120®=3&lang=2) - [RBI Master Directions on Fraud Risk Management in Commercial Banks, 15 July 2024](https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=12702) ### Frequently asked questions **Can a cyber cell freeze my entire bank account for one UPI credit?** The police power under Section 106 BNSS (formerly Section 102 CrPC) extends to the account as 'property', but the Kerala High Court has repeatedly held that the freeze should be confined to the disputed amount. In Dr. Sajeer v. Reserve Bank of India, WP(C) No. 12960 of 2023, the Court directed banks to limit freezes to the amount mentioned in the police requisition, leaving the rest of the account operable. If your whole account is blocked for a small credit, you can seek a lien-limited freeze through a representation, a Magistrate application or a writ petition. **How do I find out which police station froze my bank account?** Ask your branch, in writing, for the freezing authority's name, the requisition or reference number, the date and the amount covered. The bank acts only on a written requisition or an NCRP/CFCFRMS instruction, so this record exists. Most freezes trace back to a complaint on cybercrime.gov.in or the 1930 helpline, and the acknowledgment number in the bank's records identifies the investigating cyber cell, which is often in another State. **How long does a cyber cell freeze on a bank account last?** Section 106 BNSS sets no expiry date, which is why freezes drag on unless the account holder acts. The seizure must be reported forthwith to the jurisdictional Magistrate under Section 106(3), and the account holder can apply to that Magistrate for release under Section 503 BNSS (formerly Section 457 CrPC). In Dr. Sajeer, the Kerala High Court also directed police to tell banks within eight months whether continued freezing was necessary, refusing to let freezes run indefinitely by default. **Can I file a writ petition in the Kerala High Court if the cyber cell that froze my account is in another State?** Yes, in most cases. Under Article 226(2) of the Constitution, a High Court can act where the cause of action arises wholly or in part within its territory, and your account and branch being in Kerala normally supplies that part of the cause of action. The Kerala High Court has entertained a long line of such petitions and has typically ordered de-freezing of the account subject to a lien over the disputed amount. **Will I be arrested because fraud money reached my account?** Receiving a traced credit does not by itself make you an offender. Cheating under Section 318(4) BNS (formerly Section 420 IPC) and the IT Act offences all require dishonest intention or knowledge, which an innocent merchant or seller lacks. Respond to any police notice, supply your invoices and transaction records, and take legal advice promptly if you are summoned; ignoring the investigation is what converts an innocent recipient into a suspect on paper. **What documents do I need to get a frozen account released?** The core set is: the bank's written confirmation of the freeze with the requisition reference, your account statement highlighting the disputed credit, proof of the underlying transaction (invoice, delivery record, chat or listing for a sale), your KYC documents, and copies of any correspondence with the investigating officer. For a Magistrate application or writ petition, an affidavit explaining the transaction and an undertaking to keep the disputed amount available are usually added. --- ## The DPDP countdown: what Indian businesses must do before 14 May 2027 URL: https://advaslam.com/writing/dpdp-act-deadline-businesses/ Author: Adv. K J Muhammed Aslam, Advocate (Bar Council of Kerala, K/001823/2026) Published 16 August 2026 Practice area: Data protection & DPDP compliance DPDP Act compliance explained: the DPDP Rules 2025 timeline, the 14 November 2026 Consent Manager date, and obligations and penalties from 14 May 2027. Indian businesses must comply with the core obligations of the [Digital Personal Data Protection Act, 2023](https://indiacode.gov.in/handle/123456789/496508) by 14 May 2027, when its consent, notice, security, breach-reporting and erasure provisions — and penalties of up to ₹250 crore — become enforceable. The [DPDP Rules, 2025](https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf) were published in the Gazette of India on 14 November 2025 and phase in over eighteen months. One earlier date matters for a narrow group: the Consent Manager framework under Rule 4 takes effect on 14 November 2026. This article sets out the verified timeline, the obligations that bite, and a realistic nine-month plan to meet them. ## When exactly does the DPDP Act apply to my business? It already partly applies. The commencement notification, G.S.R. 843(E), is dated 13 November 2025 but was published in the Gazette on 14 November 2025, together with the Rules, and the phased periods run from publication. The [PIB backgrounder](https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc20251117695301.pdf) confirms the 14 November 2025 notification date. | Date | What takes effect | |---|---| | 14 November 2025 | Definitions (s. 2), Data Protection Board provisions (ss. 18–26), and specified miscellaneous provisions — ss. 35, 38, 39, 40, 41, 42 and 43, plus 44(1) and (3) (ss. 36 and 37 come with the 18-month tranche); Rules 1, 2 and 17–21 | | 14 November 2026 | Consent Manager registration: s. 6(9), s. 27(1)(d) and Rule 4 with the First Schedule | | 14 May 2027 | Everything else: ss. 3–5, s. 6(1)–(8) and (10), ss. 7–17, s. 27 (except s. 27(1)(d)), ss. 28–34, 36 and 37, and s. 44(2); Rules 3, 5–16, 22 and 23; the s. 33 penalty regime | Two practical notes. First, the Data Protection Board of India exists on paper — a fully digital body, which the Government's notification backgrounder says will consist of four members, with its enabling provisions in force — but it was not yet functioning as an operational adjudicator as of August 2026. Second, the runway may shrink. In January 2026 MeitY floated compressing the eighteen-month window to twelve months for key obligations, [seeking industry feedback by early February 2026](https://www.business-standard.com/technology/tech-news/meity-may-cut-compliance-timeline-for-key-dpdp-rules-to-12-months-126012201293_1.html). No amending notification had been gazetted as of August 2026, so 14 May 2027 remains the operative date — but a business that plans to finish in April 2027 is betting against a proposal already on the table. Treat late 2026 as the safer internal target. ## Is my business a Data Fiduciary under the DPDP Act? Almost certainly, if it has an app, a website with sign-ups, or a CRM. Section 2(i) defines a Data Fiduciary as any person who, alone or with others, "determines the purpose and means of processing of personal data". A company deciding what customer data to collect and why is a fiduciary. A vendor processing that data purely on the company's instructions is a Data Processor under s. 2(k) — but the fiduciary remains responsible for the processor's compliance under s. 8(1). The Act applies to digital personal data processed within India, and to processing abroad connected with offering goods or services to people in India (s. 3). It does not apply to purely personal or domestic processing, or to data the individual has themselves made publicly available. There is no small-business turnover threshold. Section 17(3) allows the Central Government to exempt notified classes of fiduciaries — expressly including DPIIT-recognised startups — from some obligations such as notice, data-sharing disclosures and s. 11 access requests, but no such notification had been issued as of August 2026. Plan on full compliance and treat any startup exemption as a bonus. ## What must my consent notice contain under Rule 3? From 14 May 2027, every consent request must be accompanied or preceded by a standalone notice that a reader can understand without hunting through a privacy policy. Under s. 5 of the Act and Rule 3, the notice must: 1. Itemise the personal data being collected — not "we collect your information", but the actual list. 2. State the specific purpose of processing, and describe the goods, services or uses enabled by it. 3. Give a direct communication link, and plain-language instructions, for withdrawing consent. 4. Explain how the user can exercise their rights and complain to the Data Protection Board. 5. Be available in English or any of the twenty-two Eighth Schedule languages the user opts for. Consent itself must be free, specific, informed, unconditional and unambiguous, given by clear affirmative action (s. 6(1)). Bundled consent fails: the Act's own illustration invalidates a telemedicine app demanding contact-list access. The parity rule in s. 6(4) is the one most product teams miss — withdrawing consent must be as easy as giving it was. A one-tap sign-up paired with an email-us-to-withdraw flow will not survive scrutiny. Under s. 6(10), the burden of proving notice and consent sits on the fiduciary, which is why consent logs matter as much as consent screens. ## What security safeguards does Rule 6 actually require? Section 8(5) requires "reasonable security safeguards", and Rule 6 converts that into a named minimum floor. Every fiduciary must have, at least: 1. Encryption, obfuscation, masking, or virtual tokens mapped to the personal data. 2. Access controls on the computer resources used for processing. 3. Logs, monitoring and review giving visibility into who accessed personal data, to detect and investigate unauthorised access. 4. Retention of those logs for one year, unless another law requires longer. 5. Data backups and measures for continued processing if confidentiality, integrity or availability is compromised. 6. Contract clauses obliging every Data Processor to maintain the same safeguards. This is the obligation carrying the Act's highest penalty — up to ₹250 crore — so it deserves the earliest engineering attention. Notably, s. 44(2) of the DPDP Act omits s. 43A of the Information Technology Act, 2000, the old compensation provision for negligent data handling; the DPDP regime replaces it. The IT Act's offence provisions continue to operate separately — see [the IT Act offences explained](https://advaslam.com/writing/it-act-offences-explained/). ## What happens after a data breach — and what is the 72-hour rule? Rule 7 sets a two-track intimation duty, and it runs on awareness, not convenience. On becoming aware of a personal data breach: 1. **Affected users, without delay.** Each affected Data Principal must be informed through their user account or registered contact details, in concise, clear and plain language: what happened, the likely consequences for them, mitigation measures taken, safety steps they can take, and a contact person. 2. **The Board, without delay.** An initial intimation describing the breach's nature, extent, timing and likely impact. 3. **The Board, within 72 hours.** A detailed report covering the facts, circumstances, causes, mitigation, findings on the person responsible, remedial steps to prevent recurrence, and a summary of the intimations sent to users. The Board may allow a longer period only on a written request. Note the design: there is no materiality threshold and no "risk of harm" filter in the text — the definition of personal data breach in s. 2(u) is wide, covering unauthorised processing and accidental disclosure or loss of access. Failing to notify carries a penalty of up to ₹200 crore, separate from the ₹250 crore exposure for the underlying safeguard failure. A written breach-response runbook, with the 72-hour clock built in and owners named, is the only realistic way to comply at 2 a.m. on a holiday. ## How long can I keep customer data, and when must I erase it? The default rule in s. 8(7) is purpose-based: erase personal data once consent is withdrawn or the specified purpose is no longer served, unless retention is required by another law — RBI KYC record-keeping, tax and company-law retention periods being common examples. Rule 8 then adds a hard clock for large platforms via the Third Schedule: | Class of Data Fiduciary | Threshold (registered users in India) | Erasure trigger | |---|---|---| | E-commerce entity | 2 crore or more | 3 years from the user's last engagement | | Online gaming intermediary | 50 lakh or more | 3 years from the user's last engagement | | Social media intermediary | 2 crore or more | 3 years from the user's last engagement | At least 48 hours before erasure, the fiduciary must tell the user their data will be deleted unless they log in or otherwise engage. Rule 8 also requires retention of personal data, traffic data and processing logs for a minimum of one year for specified state purposes. Smaller businesses are not off the hook — the purpose-based erasure duty in s. 8(7) applies to everyone from 14 May 2027, so every business needs a written retention schedule and a working deletion job, not just a policy PDF. ## What are the rules for users under 18? Section 9 treats everyone under eighteen as a child. Before processing a child's data, a fiduciary must obtain verifiable consent of a parent or lawful guardian. Rule 10 specifies how verification works: relying on identity and age details the fiduciary already holds, or details voluntarily provided and checked through means such as Digital Locker or a virtual token issued by an authorised entity. Rule 11 applies a parallel scheme for persons with disabilities who have lawful guardians. Three conduct rules follow. Processing likely to cause detrimental effect on a child's well-being is prohibited (s. 9(2)). Tracking, behavioural monitoring and targeted advertising directed at children are prohibited (s. 9(3)). The Fourth Schedule, via Rule 12, exempts narrow classes and purposes — healthcare, education, real-time safety and similar — from the consent and tracking bars. For everyone else building consumer apps, the practical question is age-gating architecture, and the penalty for getting it wrong is up to ₹200 crore. ## What extra duties do Significant Data Fiduciaries have? Section 10 lets the Central Government notify fiduciaries or classes of them as Significant Data Fiduciaries (SDFs), weighing volume and sensitivity of data, risk to individuals, and factors like electoral democracy and security of the State. No SDF class had been notified as of August 2026, though reporting around the January 2026 MeitY consultation indicated large technology, social media and financial-sector companies are the intended first wave. Once notified, an SDF must, under s. 10 and Rule 13: 1. Appoint a Data Protection Officer based in India, answerable to the board of directors, as the grievance contact point. 2. Appoint an independent data auditor. 3. Conduct a Data Protection Impact Assessment and an audit once every twelve months, with significant observations reported to the Board. 4. Exercise due diligence to verify that its technical measures, including algorithmic software, do not pose risks to Data Principals' rights. 5. Keep any personal data and related traffic data specified by the Central Government, on a committee's recommendation, within India (the localisation mechanism sits in Rule 13(4), read with the Rule 15 transfer framework — s. 10(2) ends at clause (c)(iii)). Breach of SDF duties carries a penalty of up to ₹150 crore. Mid-size companies should watch the notification criteria: an SDF designation can arrive by class, and the MeitY proposal contemplates SDF obligations applying from the amendment's notification rather than after a grace period. ## What rights machinery must be in place for Data Principals? Sections 11 to 14 give individuals rights to access a summary of their data and the identities of everyone it was shared with, to correction, completion, updating and erasure, to grievance redressal, and to nominate another person to act on death or incapacity. Rule 14 requires the fiduciary to publish how these rights are exercised, and Rule 14(3) requires the response period published under the grievance redressal system to be no more than ninety days. Under s. 13, every fiduciary needs a readily available grievance mechanism with published response timelines, and an individual must exhaust it before complaining to the Board. That makes the humble grievance inbox a genuine legal defence layer: a documented, timely response can end a matter that an ignored email escalates into a Board inquiry. The same discipline applies when a grievance arrives dressed as a lawyer's letter — see [how to respond to a legal notice](https://advaslam.com/writing/how-to-respond-legal-notice/). ## What penalties apply, and who imposes them? The Schedule to the Act, read with s. 33, sets ceilings per breach. The Board imposes penalties after inquiry and hearing, weighing gravity, duration, repetition, gains made, and mitigation under s. 33(2). Appeals lie to the TDSAT within sixty days (s. 29). | Breach | Maximum penalty | |---|---| | Failure to take reasonable security safeguards — s. 8(5) | ₹250 crore | | Failure to notify the Board or affected users of a breach — s. 8(6) | ₹200 crore | | Breach of children's data obligations — s. 9 | ₹200 crore | | Breach of Significant Data Fiduciary obligations — s. 10 | ₹150 crore | | Breach of a Data Principal's duties — s. 15 | ₹10,000 | | Breach of a voluntary undertaking accepted under s. 32 | Up to the penalty for the underlying breach | | Any other breach of the Act or Rules | ₹50 crore | Section 32's voluntary undertaking mechanism is worth remembering: the Board can accept a remediation commitment that bars further proceedings on the same facts, which will likely become the pragmatic exit for first-time, good-faith lapses. ## What does a realistic 9-month compliance plan look like? For a small or mid-size company starting now, three quarters of steady work is enough — provided each quarter has named owners and the work is documented as it happens, because s. 6(10) makes records the proof of compliance. **Quarter 1 (September–November 2026): know your data.** 1. Map every system holding personal data — app databases, CRM, analytics, payroll, marketing lists, spreadsheets. 2. Record, for each dataset: what is collected, why, the lawful basis (consent or a s. 7 legitimate use), where it is stored, who accesses it, and which vendors touch it. 3. Classify your role — fiduciary or processor — for each flow, and list every Data Processor contract. 4. Run a gap analysis against ss. 5–13 and Rules 3–14, and fix the priority order. **Quarter 2 (December 2026–February 2027): rebuild the user-facing layer.** 1. Rewrite notices to the Rule 3 itemised standard, with Eighth Schedule language support scoped. 2. Re-engineer consent flows for affirmative action, granular purposes, and withdrawal parity under s. 6(4), with consent logging. 3. Stand up the grievance channel, publish response timelines, and publish the s. 8(9) contact point. 4. Write the retention schedule, build the deletion jobs, and design age-gating and parental-consent flows if minors can use the service. **Quarter 3 (March–May 2027): harden and rehearse.** 1. Implement the Rule 6 floor — encryption or masking, access controls, logging with one-year retention, backups. 2. Amend processor contracts to pass down security and erasure obligations. 3. Adopt a breach-response runbook and run one tabletop drill against the 72-hour clock. 4. Train customer-facing and engineering teams, and close the file with a dated compliance record before 14 May 2027. ## Where do Kerala startups stand in all this? Nothing in the Act turns on geography within India, but the practical exposure of Kerala's technology cluster is real: SaaS, fintech and health-tech companies at Infopark Kochi and Technopark Thiruvananthapuram typically process data of users across India and abroad, which places them squarely within s. 3, and several already sit inside GDPR-driven contractual frameworks that make DPDP alignment an incremental project rather than a fresh build. In practice, I see the consent-withdrawal parity rule and the retention schedule cause the most rework, because both cut into product and infrastructure rather than paperwork. The constitutional footing is worth remembering too — the framework implements the privacy right recognised in [Justice K.S. Puttaswamy v. Union of India](https://indiankanoon.org/doc/91938676/). Where board-level sign-off or contract redrafting is needed, an advocate can map the obligations onto the company's actual data flows and vendor stack; an overview of that kind of work is at [data protection practice](https://advaslam.com/practice/data-protection/). ## Primary sources - [Digital Personal Data Protection Act, 2023 — official text (India Code)](https://indiacode.gov.in/handle/123456789/496508) - [Digital Personal Data Protection Rules, 2025 — official text (MeitY)](https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf) - [PIB backgrounder: DPDP Rules, 2025 notified (17 November 2025)](https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc20251117695301.pdf) - [PIB press release on notification of the DPDP Rules, 2025](https://www.pib.gov.in/PressReleasePage.aspx?PRID=2190014) - [Gazette of India (e-Gazette portal) — G.S.R. 843(E) and G.S.R. 846(E)](https://egazette.gov.in) - [Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1 — Indian Kanoon](https://indiankanoon.org/doc/91938676/) - [Ministry of Electronics and Information Technology](https://www.meity.gov.in) ### Frequently asked questions **When does the DPDP Act become enforceable for businesses?** The core obligations — notice, consent, security safeguards, breach reporting, retention limits and Data Principal rights — become enforceable on 14 May 2027, eighteen months after the DPDP Rules, 2025 were published in the Gazette on 14 November 2025. The definitional and Data Protection Board provisions are already in force, and the Consent Manager registration framework under Rule 4 takes effect on 14 November 2026. The Section 33 penalty regime also begins on 14 May 2027. **What are the penalties for not complying with the DPDP Act?** The Schedule to the Act sets penalty ceilings for each breach: up to ₹250 crore for failing to take reasonable security safeguards, up to ₹200 crore for failing to notify the Board or affected users of a data breach, up to ₹200 crore for breaching children's data obligations, and up to ₹150 crore for a Significant Data Fiduciary's breach of its additional duties. Any other breach of the Act or Rules can attract up to ₹50 crore. Penalties are imposed by the Data Protection Board after an inquiry and hearing, with appeals to the TDSAT within sixty days. **Does the DPDP Act apply to small businesses and startups?** Yes. Any business that decides why and how digital personal data is processed — which includes almost any company running an app, website, CRM or customer database — is a Data Fiduciary under Section 2(i), regardless of size. Section 17(3) lets the Central Government exempt notified classes of Data Fiduciaries, including recognised startups, from some obligations such as notice and data-sharing disclosures, but no such exemption notification had been issued as of August 2026. **What must a company do within 72 hours of a data breach under the DPDP Rules?** Rule 7 creates a two-track duty. Each affected user must be informed without delay, in plain language, through their user account or registered contact details, describing the breach, its likely consequences, mitigation steps and a contact person. The Data Protection Board must receive an initial intimation without delay and a detailed report within seventy-two hours of the company becoming aware of the breach, extendable only if the Board allows a written request. **Is parental consent required for users under 18 in India?** Yes. Section 9 of the DPDP Act defines a child as anyone under eighteen and requires verifiable consent of a parent or lawful guardian before processing a child's data, with verification done under Rule 10 using identity details already held, or identity and age details confirmed through means such as Digital Locker. Tracking, behavioural monitoring and targeted advertising directed at children are prohibited, subject to narrow exemptions in the Fourth Schedule for purposes like health and education. Breaches attract penalties of up to ₹200 crore. **What is a Consent Manager and what happens on 14 November 2026?** A Consent Manager is an interoperable platform, registered with the Data Protection Board, through which individuals can give, manage, review and withdraw consent across Data Fiduciaries. Rule 4 and the First Schedule — which require a Consent Manager to be an Indian-incorporated company meeting conditions including a minimum net worth of ₹2 crore — take effect on 14 November 2026, twelve months after the Rules were published. Ordinary businesses do not need to register; only entities wanting to operate as Consent Managers do. --- ## Received a Legal Notice? How to Respond, Step by Step URL: https://advaslam.com/writing/how-to-respond-legal-notice/ Author: Adv. K J Muhammed Aslam, Advocate (Bar Council of Kerala, K/001823/2026) Published 16 August 2026 Practice area: Legal drafting & documents How to respond to a legal notice in India: deadlines by notice type, what a strong reply contains, and the real consequences of ignoring one. A legal notice is a demand letter sent by or on behalf of the opposite party — it is not a court order, and receiving one does not mean a case has been filed against you. What it usually means is that a case *will* be filed unless the dispute is resolved within the window the notice states. The safe sequence is: read it fully, diary the deadline, identify the statute it invokes, preserve your documents, and take legal advice before replying — because your reply becomes evidence. The tightest deadline in Indian law is the cheque-dishonour notice under [Section 138 of the Negotiable Instruments Act 1881](https://indiankanoon.org/doc/1823824/), which gives the drawer just 15 days from receipt to pay. ## What exactly is a legal notice — and what is it not? A legal notice is a formal letter, usually on an advocate's letterhead, sent by registered post with acknowledgment due, by courier, or by email. It narrates the sender's version of the dispute, makes a specific demand, and states what proceedings will follow if the demand is not met. It is **not** a summons, an FIR, a warrant, or a judgment. No court or police officer has examined the claims in it. Everything in a legal notice is, at this stage, one side's assertion. At the same time, a notice is often a **statutory precondition** — a step the law forces the sender to take before filing. Three common examples: the demand notice under Section 138 of the [Negotiable Instruments Act 1881](https://indiacode.gov.in/handle/123456789/496318) must precede any cheque-bounce complaint; a suit against the Government or a public officer generally cannot be filed until two months after a notice under Section 80 of the [Code of Civil Procedure 1908](https://indiacode.gov.in/handle/123456789/496430); and a commercial suit of ₹3 lakh or more must ordinarily pass through pre-institution mediation under Section 12A of the [Commercial Courts Act 2015](https://indiacode.gov.in/handle/123456789/496498). So a notice signals that the sender is laying the procedural foundation for a real case — which is exactly why it deserves a considered response rather than panic. ## What should I do in the first 48 hours after receiving a legal notice? The triage sequence is the same whatever the notice says. 1. **Read the whole notice, twice.** The operative demand is usually in the last two or three paragraphs; the numbered paragraphs before it are the sender's story. Note what is being demanded, by when, and under which sections. 2. **Diary the deadline.** Count from the date you *received* the notice, not the date printed on it. Keep the envelope — the postal seal proves the date of delivery. 3. **Identify the statute it invokes.** Section 138 NI Act, Section 80 CPC, breach of contract, consumer deficiency — the statute decides your real deadline and what the next proceeding will look like. 4. **Preserve every document.** Agreements, invoices, the cheque and bank memo, ledgers, emails, WhatsApp threads. Do not delete anything: a deleted message discovered later damages you far more than an awkward one explained early. 5. **Do not call the sender or their advocate in anger.** Calls are routinely recorded, and an intemperate remark can surface in court as your admission. All communication from this point should be in writing and deliberate. 6. **Take legal advice before replying.** Carry the notice and every related document to the consultation. A reply drafted on full facts is worth far more than a fast one. ## How much time do I have to reply to a legal notice? The honest answer: it depends on the statute behind the notice. This table covers the notice types that arrive most often in practice. | Notice type | Legal basis | Your effective window | What follows if unresolved | |---|---|---|---| | Cheque dishonour | Proviso (c) to s.138, NI Act 1881 | **15 days from receipt** to pay the cheque amount | Criminal complaint within 1 month of the 15-day window lapsing — s.142(1)(b) NI Act | | Notice before suing the Government | s.80 CPC 1908 | Government/officer gets **2 months** before suit | Civil suit against the State or officer | | Breach of contract / money recovery | ss.73–74, [Indian Contract Act 1872](https://indiacode.gov.in/handle/123456789/496413); the notice's own terms | Deadline stated in the notice, commonly 7–30 days | Civil suit; 3-year limitation under Article 55, [Limitation Act 1963](https://indiacode.gov.in/handle/123456789/496389) | | Consumer grievance | [Consumer Protection Act 2019](https://indiacode.gov.in/handle/123456789/496115) | As stated in the notice (no statutory pre-complaint notice exists) | Complaint before a Consumer Commission via [e-Jagriti](https://e-jagriti.gov.in) within 2 years — s.69 | | Commercial dispute of ₹3 lakh+ | s.12A, Commercial Courts Act 2015 | As stated | Pre-institution mediation, then a commercial suit | | Family (divorce, maintenance) | Personal law statutes; s.144 BNSS 2023 (formerly s.125 CrPC) for maintenance | As stated | Petition before the Family Court | | Employment (dues, termination) | Contract terms and labour statutes | As stated | Labour authority proceedings or a civil claim | Two points about the cheque-notice timeline, because it is the one people most often get wrong. First, the *sender* is also on a clock: the demand notice must be issued within 30 days of the bank's return memo, and the cheque must have been presented within its validity period — proviso (a) and (b) to Section 138. A notice sent late makes the eventual complaint vulnerable. Second, refusing the postman does not help. Under Section 27 of the General Clauses Act 1897, a correctly addressed registered letter is deemed served, and the Supreme Court in *C.C. Alavi Haji v. Palapetty Muhammed* (2007) held that a Section 138 notice returned "unclaimed" or "refused" is deemed served on the drawer. ## What does a good reply to a legal notice contain? A good reply answers the notice **paragraph by paragraph** — admit, deny, or explain each numbered allegation. This mirrors the discipline the CPC will later demand: under Order VIII Rule 5, allegations not specifically denied in a written statement may be taken as admitted. A reply drafted with that discipline becomes the skeleton of your future defence. The core habits: - **Admissions discipline.** Admit only what is genuinely undisputed — dates, the existence of a contract, receipt of goods. Deny everything contested, with a one-line reason. Remember the trap in Section 18 of the Limitation Act 1963: a signed written acknowledgment of liability starts a *fresh* limitation period, and the Explanation to that section says an acknowledgment can count **even if it is coupled with a refusal to pay**. "I owe the amount but will not pay now" is a gift to the sender. - **Without-prejudice framing.** If you want to explore settlement, put figures in a separate communication marked "without prejudice". Section 21 of the Bharatiya Sakshya Adhiniyam 2023 (formerly Section 23, Indian Evidence Act 1872) protects admissions made on the express condition that evidence of them is not to be given. - **Counter-demands.** If the sender owes you money, delivered defective work, or breached first, say so now and quantify it. A reply can double as a counter-notice, and raising the counter-claim at this stage makes it far harder to dismiss later as an afterthought. - **Sober tone.** No abuse, no threats. A defamatory or threatening reply creates fresh liability and reads badly in front of a judge. What a bad reply does is the mirror image: it casually admits the debt, over-explains, makes a provably false statement that follows you through the litigation, answers a demand the notice never made, or issues from the wrong person (the director personally instead of the company, or vice versa). In practice, I see more cases damaged by a hasty reply than by a late one. ## When is it better not to reply at all? Rarely — but it happens, and it should be a decision, not a drift. Considered silence can make sense when the claim is plainly time-barred and any reply risks a Section 18 acknowledgment; when the notice is a fishing expedition and a detailed reply would hand the sender facts and documents they do not yet have; or when the notice is one of a mass mailing with no serious claim behind it. The risks of silence are real, though. A court later reads the pre-suit correspondence, and an unanswered, specific commercial demand can colour how your defence is received. And for a Section 138 notice, understand what actually stops prosecution: **payment within 15 days**, not the reply. A reply is not legally mandatory even there — but a reply denying the debt puts your defence on record early, and magistrates do notice when a defence surfaces for the first time at trial. Strategic silence is a tool for an advocate to recommend on full facts, not a default. ## What happens if I ignore a legal notice? Nothing automatic — and everything eventual. By notice type: - **Cheque dishonour.** The offence under Section 138 is complete the moment the 15-day window lapses without payment. The complaint follows within one month (s.142(1)(b), extendable for sufficient cause). Once the case is on file, the trial court can direct interim compensation of up to 20% of the cheque amount under Section 143A, the statutory presumptions under Sections 118 and 139 operate against the drawer, and conviction carries up to two years' imprisonment or a fine up to twice the cheque amount, or both. One procedural cushion exists under the new criminal codes: for complaints filed after 1 July 2024, the proviso to Section 223(1) of the Bharatiya Nagarik Suraksha Sanhita 2023 (formerly Section 200 CrPC) requires the Magistrate to give the proposed accused an opportunity of being heard before taking cognizance — a second chance to be heard, but a far costlier one than replying to the notice. - **Civil and contract claims.** The sender files a suit; you receive a court summons; and ignoring *that* leads to an ex parte decree. A written statement is due within 30 days of the summons, extendable to 90 days (120 days in commercial suits) under Order VIII Rule 1 CPC. - **Consumer claims.** The consumer files on the e-Jagriti portal (operational from 1 January 2025, unifying e-Daakhil and other legacy portals); Consumer Commissions can award refund, compensation, and costs, and their orders are enforceable like decrees. - **Limitation keeps running — for the sender.** Your silence does not extinguish the claim; only limitation does. Most money and contract claims live for three years (Articles 55 and 113, Limitation Act 1963). Silence merely means the dispute reaches you next as litigation, on the sender's timing. ## Can I draft my own reply, or do I need an advocate? You can lawfully draft and sign your own reply, and for simple matters it is a reasonable choice — a security-deposit dispute, a small consumer grievance, a factual denial of a claim that never happened. Respond paragraph-wise, keep a signed copy, send it by registered post with acknowledgment due (email in parallel), and preserve the proof of dispatch. A professionally drafted reply earns its place when the stakes or the framing get serious: money claims of size, notices with criminal colour (recovery notices routinely add cheating under Section 318(4) of the Bharatiya Nyaya Sanhita 2023, formerly Section 420 IPC), property and tenancy disputes, employment severance, and matrimonial notices. The reason is structural — the reply is the first draft of your written statement or defence, and [legal drafting](https://advaslam.com/practice/drafting/) at this stage decides which admissions, denials, and counter-claims you carry into court. The same goes for choosing the forum if you are the one with the counter-claim: a [civil suit and a consumer complaint](https://advaslam.com/practice/civil-consumer/) have very different costs, timelines, and remedies. ## What happens after the reply is sent? Three paths, in roughly descending order of frequency. 1. **Negotiation.** A substantial share of disputes end at the notice-and-reply stage, because both sides have now seen each other's documents and weaknesses. Settlements reached here should be recorded in writing. 2. **Mediation or Lok Adalat.** For commercial suits of ₹3 lakh and above, Section 12A of the Commercial Courts Act makes pre-institution mediation compulsory unless urgent interim relief is sought — the process runs up to three months (extendable by two), and that period is excluded from limitation. Courts can also refer pending suits to mediation or Lok Adalat under Section 89 CPC, and the Consumer Protection Act 2019 (Chapter V) builds mediation cells into the consumer forums. 3. **Filing.** If the sender files, you receive a summons with a copy of the plaint or complaint, and the timelines in the previous section take over. If the notice came *from* you against a government department and two months pass without response, the suit can proceed — or, where the grievance concerns illegal state action, a [writ petition before the High Court](https://advaslam.com/writing/writ-petition-high-court-kerala/) may be the more direct remedy. The consistent theme: a legal notice is the opening move of a structured process, and every stage of that process rewards the party who responded early, in writing, and with discipline. ## Primary sources - [Negotiable Instruments Act, 1881 — India Code](https://indiacode.gov.in/handle/123456789/496318) - [Section 138, Negotiable Instruments Act — Indian Kanoon](https://indiankanoon.org/doc/1823824/) - [Code of Civil Procedure, 1908 — India Code](https://indiacode.gov.in/handle/123456789/496430) - [Limitation Act, 1963 — India Code](https://indiacode.gov.in/handle/123456789/496389) - [Indian Contract Act, 1872 — India Code](https://indiacode.gov.in/handle/123456789/496413) - [Consumer Protection Act, 2019 — India Code](https://indiacode.gov.in/handle/123456789/496115) - [Commercial Courts Act, 2015 — India Code](https://indiacode.gov.in/handle/123456789/496498) - [e-Jagriti — official portal for filing consumer complaints](https://e-jagriti.gov.in) ### Frequently asked questions **How many days do I have to reply to a legal notice in India?** There is no single statutory deadline — the window depends on the statute the notice invokes. A cheque-dishonour notice under Section 138 of the Negotiable Instruments Act gives you 15 days from receipt to pay; most contract and recovery notices set their own deadline, typically 7 to 30 days. Treat the date printed in the notice as real, because the sender can file proceedings the day it lapses. **What happens if I ignore a legal notice?** Nothing happens automatically, but the sender becomes free to file whatever the notice threatened — a criminal complaint, a civil suit, or a consumer complaint. For a Section 138 cheque notice, ignoring it is the worst option: the offence is complete once the 15-day payment window lapses, and prosecution can follow within a month. In later litigation, a court may also note that you never denied the claim when you had the chance. **Can I reply to a legal notice myself without a lawyer?** Yes — a reply signed by you personally is legally valid, and for simple factual disputes it can be enough. The risk is not validity but content: an unguarded admission in your reply can be used as evidence, and under Section 18 of the Limitation Act 1963 a signed acknowledgment of liability restarts the limitation clock against you. For notices involving significant money, property, or criminal allegations, have an advocate settle the draft. **Is a legal notice the same as a court summons?** No. A legal notice is a private demand letter sent by or for the opposite party; no court has seen it, and receiving it carries no direct penalty. A summons is issued by a court after a case has actually been filed, and ignoring a summons has direct consequences — an ex parte decree in a civil suit, or coercive process in a criminal case. **Does replying to a legal notice mean I accept the claim?** No. A reply can deny every allegation and still be a complete reply. Careful replies admit only what is genuinely undisputed, deny the rest with reasons, and reserve all rights. Settlement figures belong in a separate communication marked 'without prejudice', which is protected from later use as evidence under Section 21 of the Bharatiya Sakshya Adhiniyam 2023 (formerly Section 23 of the Indian Evidence Act). **What if I refused to accept the registered post containing the notice?** Refusal usually counts as service. Under Section 27 of the General Clauses Act 1897, a properly addressed, pre-paid registered letter is deemed served, and in C.C. Alavi Haji v. Palapetty Muhammed (2007) the Supreme Court held that a Section 138 notice returned 'refused' or 'unclaimed' is deemed served. Refusing delivery only means you lose the chance to reply while the clock runs anyway. --- ## IT Act offences, explained simply: Sections 65 to 67 and what they mean URL: https://advaslam.com/writing/it-act-offences-explained/ Author: Adv. K J Muhammed Aslam, Advocate (Bar Council of Kerala, K/001823/2026) Published 16 August 2026 Practice area: Cyber crime & IT Act matters Plain-language guide to IT Act offences in India: Sections 65 to 67B explained with punishments, bailability, compounding and how they pair with the BNS. The Information Technology Act, 2000 punishes cyber offences through Sections 65 to 67B — covering source-code tampering, hacking, identity theft, online impersonation, privacy-violating images and obscene content — and most of these offences carry a maximum of three years' imprisonment, making them cognizable but bailable under Section 77B. The Act also runs a separate civil track: Sections 43 and 43A give victims monetary compensation without any criminal trial. Section 66A, once the most invoked provision, no longer exists — the Supreme Court struck it down in 2015. This article walks through each section in plain language, with the exact punishments and how the sections combine with the Bharatiya Nyaya Sanhita in real FIRs. ## Is the IT Act civil or criminal? What is the difference between Section 43 and Section 66? Both. The [IT Act, 2000](https://indiacode.gov.in/handle/123456789/496511) has two parallel tracks, and understanding the split explains most of its architecture. **The civil track** is Chapter IX. Section 43 lists ten kinds of harm to a computer — unauthorised access, downloading data, introducing a virus, causing damage, denying access, and so on — and makes the wrongdoer liable to pay compensation to the victim. No police, no jail: the remedy is money. Claims up to five crore rupees go to the Adjudicating Officer appointed under Section 46 (an officer not below the rank of a Director to the Government of India or an equivalent officer of a State Government); larger claims go to the competent civil court. Section 43A makes a company that negligently fails to protect "sensitive personal data" liable to compensate the person harmed. It remains in force today, but it is scheduled to be omitted when Section 44(2) of the Digital Personal Data Protection Act, 2023 takes effect on 14 May 2027 — the date the DPDP regime's core obligations become enforceable. Businesses tracking that transition can see the [DPDP compliance timeline](https://advaslam.com/writing/dpdp-act-deadline-businesses/). **The criminal track** is Chapter XI. Section 66 converts the civil wrongs of Section 43 into crimes — but only where the act was done *dishonestly* or *fraudulently*, terms borrowed from the Indian Penal Code and now defined in Sections 2(7) and 2(9) of the [Bharatiya Nyaya Sanhita, 2023](https://indiacode.gov.in/handle/123456789/496548). The same hack can therefore produce both a compensation claim under Section 43 and a prosecution under Section 66. Section 77 of the Act says one does not bar the other. ## What does each offence section of the IT Act actually cover? Here is each provision of Chapter XI in the order it appears, with the punishment fixed by the statute. Section numbers and amounts below are taken from the [consolidated text of the Act](https://indiacode.gov.in/handle/123456789/496511). ### Section 65 — Tampering with computer source documents Knowingly concealing, destroying or altering computer source code that the law requires to be kept or maintained. It is a narrow offence — the source code must be one required by law to be maintained, which is why it appears mostly in cases involving licensed software, telecom equipment or government systems. Punishment: up to three years' imprisonment, or fine up to two lakh rupees, or both. ### Section 66 — Computer-related offences The general hacking provision. Any Section 43 act — unauthorised access, data theft, virus insertion, damage, denial of service, account manipulation — done dishonestly or fraudulently. Punishment: up to three years, or fine up to five lakh rupees, or both. ### Section 66B — Dishonestly receiving stolen computer resource Receiving or retaining a stolen computer resource or communication device, knowing or having reason to believe it is stolen. It reaches the buyer of a stolen phone or laptop, and investigators sometimes add it against those holding devices or SIM cards traced to a fraud. Punishment: up to three years, or fine up to one lakh rupees, or both. ### Section 66C — Identity theft Fraudulently or dishonestly using another person's electronic signature, password or "any other unique identification feature". In practice this is the OTP-and-credentials section: phished banking passwords, misused OTPs, SIM-swap frauds, cloned biometrics. Punishment: up to three years' imprisonment *and* fine up to one lakh rupees. ### Section 66D — Cheating by personation using a computer resource Cheating by pretending to be someone else through any communication device or computer resource. This is the workhorse of Indian cyber-fraud FIRs: phishing sites, fake customer-care numbers, fake matrimonial and social-media profiles, "digital arrest" calls impersonating police or customs, fraudulent investment platforms. Punishment: up to three years *and* fine up to one lakh rupees. Victims of payment frauds under this section should act within hours — the steps are set out in [how to complain about UPI fraud and recover money](https://advaslam.com/writing/upi-fraud-complaint-recovery/). ### Section 66E — Violation of privacy Intentionally capturing, publishing or transmitting an image of a person's private area without consent, in circumstances where privacy is reasonably expected. It covers hidden-camera images and non-consensual sharing of intimate images. Punishment: up to three years, or fine up to two lakh rupees, or both. It is almost always paired with voyeurism under Section 77 of the BNS (formerly Section 354C IPC). ### Section 66F — Cyber terrorism The gravest offence in the Act: unauthorised access or denial-of-service attacks intended to threaten the unity, integrity, security or sovereignty of India or to strike terror, or accessing data restricted for reasons of State security. Punishment: imprisonment which may extend to imprisonment for life. It is rarely and cautiously invoked; ordinary hacking does not meet its threshold. ### Sections 67, 67A and 67B — The obscenity cluster - **Section 67** punishes publishing or transmitting obscene material in electronic form: first conviction up to three years and fine up to five lakh rupees; a repeat conviction up to five years and fine up to ten lakh rupees. - **Section 67A** covers material containing a sexually explicit act: five years and ten lakh rupees on first conviction, seven years and ten lakh rupees on repeat. - **Section 67B** covers material depicting children in sexually explicit acts — creating, browsing, downloading, exchanging or facilitating it: five years and ten lakh rupees on first conviction, seven years on repeat. It operates alongside Sections 13 to 15 of the POCSO Act, 2012. These three sections, usually with extortion under Section 308 of the BNS (formerly Sections 383–384 IPC), form the charge structure in sextortion cases. Sections 67 to 67B carry a public-good exception for scientific, literary, artistic or heritage material. ### Sections 72 and 72A — Breach of confidentiality Both provisions were decriminalised by the Jan Vishwas (Amendment of Provisions) Act, 2023, with effect from 30 November 2023: they no longer carry imprisonment and now impose monetary penalties. Section 72 covers officials who obtained access to records using powers under the IT Act and then disclose them without consent: penalty up to five lakh rupees. Section 72A is broader and more practical: any person — including an intermediary or service provider — who obtained personal information under a lawful contract and discloses it without consent, intending or knowing it will cause wrongful loss or gain, is liable to a penalty up to twenty-five lakh rupees. ## Is Section 66A still in force? Can an FIR be registered under it? No. The Supreme Court struck down Section 66A in its entirety in [Shreya Singhal v. Union of India](https://indiankanoon.org/doc/110813550/), (2015) 5 SCC 1, by judgment dated 24 March 2015, holding that its vague terms — "grossly offensive", "annoyance", "inconvenience" — violated Article 19(1)(a) and were not saved by Article 19(2). A struck-down provision is void; no FIR, charge sheet or conviction can rest on it. Because police stations kept invoking it anyway, the Supreme Court in People's Union for Civil Liberties v. Union of India (order dated 12 October 2022) directed all states and police forces to stop registering 66A cases and to delete the section from pending prosecutions. If an FIR today cites Section 66A, that is a ground to seek deletion of the charge, and if the FIR rests on 66A alone, to seek quashing — the route is explained in [filing a writ petition before the High Court of Kerala](https://advaslam.com/writing/writ-petition-high-court-kerala/). Note what Shreya Singhal did *not* do: it upheld the website-blocking power under Section 69A and read down intermediary liability under Section 79. Only 66A fell. ## Which IT Act offences are cognizable and which are bailable? Section 77B of the Act sets the rule: offences punishable with imprisonment of three years and above are **cognizable** (police can register an FIR and arrest without a warrant), and offences punishable with three years are **bailable** (bail is a right, granted at the police station or by the Magistrate). The practical result — most IT Act offences are both. | Section | What it punishes | Maximum punishment | Bailable? | |---|---|---|---| | 65 | Tampering with source code | 3 years or ₹2 lakh or both | Yes | | 66 | Hacking, data theft (s.43 acts done dishonestly) | 3 years or ₹5 lakh or both | Yes | | 66B | Receiving stolen computer resource/device | 3 years or ₹1 lakh or both | Yes | | 66C | Identity theft (passwords, OTPs, signatures) | 3 years and ₹1 lakh | Yes | | 66D | Cheating by personation online | 3 years and ₹1 lakh | Yes | | 66E | Privacy-violating images | 3 years or ₹2 lakh or both | Yes | | 66F | Cyber terrorism | Up to life imprisonment | No | | 67 | Obscene electronic material | 3 years + ₹5 lakh (first conviction) | Yes (first conviction) | | 67A | Sexually explicit material | 5 years + ₹10 lakh (first conviction) | No | | 67B | Child sexual abuse material | 5 years + ₹10 lakh (first conviction) | No | | 72 | Breach of confidentiality by officials | Penalty up to ₹5 lakh (no imprisonment since 2023) | Not applicable | | 72A | Disclosure of personal data in breach of contract | Penalty up to ₹25 lakh (no imprisonment since 2023) | Not applicable | Two further procedural rules matter. Under Section 78, only a police officer of the rank of Inspector or above may investigate an IT Act offence — in Kerala that typically means the Cyber Police Station of the district or an Inspector at the local station. And under Section 75, the Act applies to offences committed outside India, by any person of any nationality, if the computer or network involved is located in India. ## Can IT Act offences be compounded or settled? Yes, within limits. Section 77A allows a competent court to compound any IT Act offence *except* those punishable with life imprisonment or with a term exceeding three years. Three further bars apply: no compounding where a previous conviction exposes the accused to enhanced punishment, where the offence affects the socio-economic conditions of the country, or where it was committed against a child below 18 or against a woman. So a first-time Section 66 or 66C case between business rivals may realistically end in compounding, while Sections 66F, 67A and 67B never can, and a 66E case against a woman victim cannot either. The accused applies in the trial court under Section 77A(2), which adopts the plea-bargaining procedure of Sections 265B and 265C CrPC — provisions now carried into Sections 289 to 300 of the BNSS. ## How do IT Act sections pair with BNS offences in a real FIR? Cyber-crime FIRs almost never cite the IT Act alone. Since 1 July 2024, offences are charged under the Bharatiya Nyaya Sanhita, 2023 rather than the IPC, and the pairings run to a pattern: | Situation | IT Act section | BNS section (old IPC) | |---|---|---| | Online payment fraud, phishing | 66C, 66D | 318(4) — cheating (420 IPC); 319(2) — cheating by personation (419 IPC) | | Sextortion, threats to leak images | 67, 67A, 66E | 308 — extortion (383–384 IPC); 351 — criminal intimidation (503/506 IPC) | | Fake profiles, morphed images | 66D, 67 | 356 — defamation (499/500 IPC); 336 — forgery (463/465 IPC) | | Hidden camera, image capture | 66E | 77 — voyeurism (354C IPC) | | Persistent online harassment of a woman | 66E, 67 | 78 — stalking (354D IPC); 79 — insulting the modesty of a woman (509 IPC) | The BNS sections matter for the accused because they can change the bail picture: cheating under Section 318(4) BNS carries up to seven years, so an FIR pairing 66D with 318(4) is effectively non-bailable even though 66D alone is bailable. They matter for victims because property traced under them can be seized and accounts frozen under Section 106 of the BNSS (formerly Section 102 CrPC) — the mechanism behind most frozen-account notices, explained in [what to do when a cyber cell freezes your bank account](https://advaslam.com/writing/bank-account-frozen-cyber-cell-kerala/). ## How is electronic evidence proved in an IT Act case? Every screenshot, server log, CDR and CCTV clip in these cases is an electronic record, and its admissibility is governed by Section 63 of the [Bharatiya Sakshya Adhiniyam, 2023](https://indiacode.gov.in/handle/123456789/496549), which replaced Section 65B of the Indian Evidence Act on 1 July 2024. Section 63(4) requires a certificate identifying the record, describing how it was produced, and confirming the device was working properly. The BSA tightened the old rule: the certificate must now be signed both by the person in charge of the device or activity *and* by an expert, in the form prescribed in the Schedule to the Adhiniyam, with a hash report of the record enclosed. The Supreme Court held in Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal, (2020) 7 SCC 1, that the certificate is mandatory unless the original device itself is produced — reasoning that continues to govern Section 63. On who may sign Part B, the Supreme Court in *Pune Bar Association v. Union of India*, W.P.(C) No. 599 of 2026 (order dated 22 May 2026), read Sections 39(1) and 39(2) of the Adhiniyam together and observed that a person shown, on unimpeachable material, to have special skill and expertise in computer science and cyber forensics may sign Part B as an expert — not only an Examiner of Electronic Evidence notified under Section 79A of the IT Act — though the Court kept that question of law open. In practice, a prosecution or complaint that skips the certificate risks its core evidence being ruled inadmissible at trial. ## What should a complainant or an accused do first? For a victim, speed beats paperwork: 1. For financial fraud, call the national helpline **1930** immediately — within the first few hours banks can freeze the fraudster's receiving accounts. 2. File a complaint on the [National Cyber Crime Reporting Portal](https://cybercrime.gov.in/) with transaction IDs, screenshots and numbers used. 3. Follow up with a written FIR at the local or Cyber Police Station. Under Section 173 of the BNSS (formerly Section 154 CrPC), the FIR can be given at any station regardless of where the offence occurred, and even by electronic communication. 4. Preserve original devices and records — they will be needed for the Section 63 BSA certificate. For a person accused or named in a notice: do not delete accounts, chats or data — that can become a separate offence and destroys exculpatory material too. Check which sections the FIR actually cites, since bailability turns on them, and verify no struck-down provision like 66A appears. Respond to police notices in writing and take legal advice promptly; an advocate can assess whether the case is one for bail, compounding under Section 77A, or quashing. An overview of how these cases progress is at [cyber crime practice](https://advaslam.com/practice/cyber-crime/). ## Primary sources - [Information Technology Act, 2000 — India Code](https://indiacode.gov.in/handle/123456789/496511) - [IT Act, 2000 — consolidated text with amendments (PDF)](https://indiacode.gov.in/server/api/core/bitstreams/770a7d02-48f2-4274-bab9-10d0f48ee264/content) - [Shreya Singhal v. Union of India, (2015) 5 SCC 1 — Indian Kanoon](https://indiankanoon.org/doc/110813550/) - [Bharatiya Nyaya Sanhita, 2023 — India Code](https://indiacode.gov.in/handle/123456789/496548) - [Bharatiya Sakshya Adhiniyam, 2023 — India Code](https://indiacode.gov.in/handle/123456789/496549) - [National Cyber Crime Reporting Portal — cybercrime.gov.in](https://cybercrime.gov.in/) ### Frequently asked questions **Is Section 66A of the IT Act still valid?** No. Section 66A was struck down as unconstitutional by the Supreme Court in Shreya Singhal v. Union of India, (2015) 5 SCC 1, on 24 March 2015. Any FIR or charge sheet invoking Section 66A after that date is invalid, and in October 2022 the Supreme Court directed all states to close pending 66A prosecutions. If you see 66A in an FIR, point this out to the police or the court immediately. **What is the punishment under Section 66C of the IT Act?** Section 66C punishes identity theft — fraudulently or dishonestly using another person's password, electronic signature or any other unique identification feature, which in practice covers OTPs, banking credentials and biometric identifiers. The punishment is imprisonment up to three years and a fine up to one lakh rupees. The offence is cognizable and bailable under Section 77B. **What is the difference between Section 66C and Section 66D of the IT Act?** Section 66C targets the misuse of someone's credentials — passwords, OTPs, electronic signatures or other unique identifiers. Section 66D targets cheating by pretending to be someone else through a computer or phone — fake profiles, phishing calls, impersonating officials or companies. Most online frauds involve both: the fraudster impersonates (66D) to extract credentials, then uses them (66C). Police commonly invoke both sections together with cheating under Section 318(4) of the BNS. **Are IT Act offences bailable?** Most are. Under Section 77B, offences punishable with three years' imprisonment — Sections 65, 66, 66B, 66C, 66D, 66E and 67 (first conviction) — are bailable, though cognizable, so police can register an FIR and arrest without a warrant. Sections 67A and 67B (five years or more) and Section 66F (cyber terrorism, up to life) are non-bailable. **Can an IT Act case be settled or compounded out of court?** Partly. Section 77A lets a court compound IT Act offences except those punishable with life imprisonment or a term exceeding three years. Compounding is barred where the accused faces enhanced punishment due to a previous conviction, where the offence affects the socio-economic conditions of the country, or where it was committed against a woman or a child below 18. So a first-time Section 66 or 66C case may be compounded, but Sections 67A, 67B and 66F cannot. **Who investigates IT Act offences?** Under Section 78 of the IT Act, only a police officer of the rank of Inspector or above may investigate an IT Act offence. In Kerala, complaints typically go to the local police station, the district Cyber Police Station, or online through the National Cyber Crime Reporting Portal (cybercrime.gov.in) and the 1930 helpline for financial frauds. --- ## UPI Fraud: From Complaint to Recovery, Step by Step URL: https://advaslam.com/writing/upi-fraud-complaint-recovery/ Author: Adv. K J Muhammed Aslam, Advocate (Bar Council of Kerala, K/001823/2026) Published 16 August 2026 Practice area: Cyber crime & IT Act matters A step-by-step guide to filing a UPI fraud complaint in India: the 1930 helpline, cybercrime.gov.in, RBI liability rules, FIR, ombudsman and court remedies. If money has just left your account through a UPI fraud, call the national cyber fraud helpline **1930** or file a complaint at [cybercrime.gov.in](https://cybercrime.gov.in) immediately — this is the only mechanism that can freeze the money while it is still inside the banking system. Then notify your bank in writing the same day, because the RBI's limited-liability rules for unauthorised transactions run on a three-working-day clock. Everything after that — the FIR, the ombudsman, the court application for refund — builds on those first two steps. This article walks through every remedy, in the order it should be used. ## What should I do in the first hour after a UPI fraud? Fraud proceeds rarely sit still. They are pushed through a chain of mule accounts and wallets within hours, then withdrawn as cash or converted at an ATM. Practitioners and police call the reporting window the "golden hour" for a reason: a freeze only works on money that is still inside the system. Do these five things, in this order: 1. **Call 1930.** The helpline runs 24×7. The operator records the transaction details and pushes the complaint into the Citizen Financial Cyber Frauds Reporting and Management System (CFCFRMS), which alerts the receiving bank or wallet. 2. **File on the National Cyber Crime Reporting Portal (NCRP)** at [cybercrime.gov.in](https://cybercrime.gov.in) under the financial fraud category. Save the acknowledgment number — every later step, including the court application, will refer to it. 3. **Write to your bank the same day.** Email the fraud/dispute address and your home branch, describing the transaction and asking the bank to attempt recall and to note the date of your notification. This starts the RBI liability clock in your favour. 4. **Preserve the evidence.** Keep the 12-digit UPI transaction reference number, screenshots of the payment and chat, the fraudster's UPI ID and phone number, and any SMS alerts. Do not delete the conversation. 5. **Ignore "refund officers".** A common second-round scam is a call claiming to process your refund and asking for an OTP or a small "verification" payment. No bank, police unit or NPCI official asks for an OTP to return money. ## How does the 1930 freeze-the-chain mechanism actually work? The CFCFRMS, operated by the [Indian Cyber Crime Coordination Centre (I4C)](https://i4c.mha.gov.in/ncrp.aspx) under the Ministry of Home Affairs, connects banks, wallets and payment intermediaries to one backend. When your complaint is registered, it travels along the money trail: the first beneficiary bank checks whether the amount is still in the account and, if so, places a hold or lien on it. If the money has already hopped to a second or third account, the alert follows it, and each bank in the chain marks a hold on whatever landed with it. The frozen amount does not come back to you automatically. It stays on hold — typically under [Section 106 BNSS](https://indiacode.gov.in/handle/123456789/496550) (formerly Section 102 CrPC), the police power to seize property connected with an offence — until the investigation progresses and a court orders its release. What the golden-hour report achieves is preservation: it stops the money leaving the system, so that there is something left for a court to return. The complaint is simultaneously escalated to the State police. In Kerala, financial fraud complaints from NCRP are routed to the district cyber police stations, and larger cases may be taken up by specialised units. ## Will the bank refund me? The RBI limited-liability rules For **unauthorised** transactions — debits you never approved — the RBI circular [Customer Protection – Limiting Liability of Customers in Unauthorised Electronic Banking Transactions](https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=11040) (RBI/2017-18/15, DBR.No.Leg.BC.78/09.07.005/2017-18, dated 6 July 2017) gives you enforceable rights against your own bank: - **Zero liability** if the fraud arose from the bank's own contributory fraud, negligence or deficiency — regardless of when you report. Zero liability also applies to a third-party breach (neither you nor the bank at fault) if you notify the bank **within three working days** of learning of the transaction. - **Limited liability** if you notify a third-party breach within **four to seven working days**: your loss is capped at ₹5,000 for basic savings (BSBD) accounts, **₹10,000 for most savings accounts and prepaid instruments**, and ₹25,000 for current accounts and higher-end products — or the transaction value, whichever is lower. - **Beyond seven working days**, your liability is decided by the bank's board-approved policy, which the bank must publish. - Where the loss is due to **your own negligence** — such as sharing a PIN or OTP — you bear the loss until you report; losses after your report fall on the bank. - The bank must give **shadow credit** of the disputed amount within **10 working days** of your notification and resolve the complaint within **90 days**. The burden of proving that you are liable lies on the bank, not on you. A parallel circular of [4 January 2019](https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=11446) (DPSS.CO.PD.No.1417/02.14.006/2018-19) extends the same framework to wallets and prepaid instruments issued by non-banks. The critical distinction: if a scammer tricked you into approving a payment with your own UPI PIN, the transaction is **authorised**, and this framework does not apply. Your remedies then are the CFCFRMS freeze, the criminal case and a court application over the frozen money — which is why the golden-hour report matters most in exactly these cases. ## How do I raise a dispute in the UPI app itself? NPCI, which operates UPI under authorisation from the RBI under the Payment and Settlement Systems Act, 2007, runs an in-app [dispute redressal mechanism](https://www.npci.org.in/what-we-do/upi/dispute-redressal-mechanism) (the Unified Dispute and Issue Resolution framework, UDIR). Open the transaction in your UPI app, select "raise dispute" or "report an issue", and the complaint flows to the banks involved through automated channels; unresolved disputes escalate to NPCI. NPCI's toll-free helpline is 1800-120-1740. This route is most effective for failed or duplicated transactions and transfers to a wrong UPI ID. For fraud, treat it as a complement to — never a substitute for — the 1930/NCRP report and the written bank complaint. ## Do I need an FIR, and which offences apply? Yes, for anything beyond a trivial amount. The NCRP complaint triggers the freeze; the FIR drives the investigation, the chargesheet and, ultimately, the court's power to return frozen money. Under [Section 173 BNSS](https://indiacode.gov.in/handle/123456789/496550) (formerly Section 154 CrPC), an FIR in a cognizable offence can now be registered at **any police station irrespective of where the offence occurred** — the "Zero FIR" is statutory — and information can even be given by electronic communication, to be signed within three days. Kerala has cyber police stations attached to each police district. The offences that typically apply to a UPI fraud: | Provision | Offence | Punishment | |---|---|---| | [Section 318(4) BNS](https://indiacode.gov.in/handle/123456789/496548) (formerly Section 420 IPC) | Cheating and dishonestly inducing delivery of property | Up to 7 years and fine | | [Section 319(2) BNS](https://indiacode.gov.in/handle/123456789/496548) (formerly Section 419 IPC) | Cheating by personation | Up to 5 years, or fine, or both | | [Section 66C, IT Act 2000](https://indiacode.gov.in/handle/123456789/496511) | Identity theft — fraudulent use of another's password or unique identification | Up to 3 years and fine up to ₹1 lakh | | [Section 66D, IT Act 2000](https://indiacode.gov.in/handle/123456789/496511) | Cheating by personation using a computer resource | Up to 3 years and fine up to ₹1 lakh | A fuller treatment of the IT Act offences is in [IT Act offences explained](https://advaslam.com/writing/it-act-offences-explained/). ## What if the bank stalls or rejects the claim? The RBI Ombudsman If the bank rejects your unauthorised-transaction claim, misses the 90-day deadline, or simply does not respond, the [Reserve Bank – Integrated Ombudsman Scheme, 2021](https://rbidocs.rbi.org.in/rdocs/Content/PDFs/RBIOS2021_121121.pdf) (RB-IOS) is the escalation route. The sequence matters: 1. **First complain in writing to the bank** and keep proof of the date. 2. **Wait 30 days.** If the bank rejects the complaint, gives an unsatisfactory reply, or stays silent for 30 days, the ombudsman complaint becomes maintainable. 3. **File online at [cms.rbi.org.in](https://cms.rbi.org.in)** — free of cost, no lawyer required — within one year of the bank's reply (or within one year and 30 days of your complaint if the bank never replied). The Ombudsman can award the actual loss caused by the deficiency in service up to **₹20 lakh**, plus up to **₹1 lakh** for loss of time, expenses and mental anguish. In UPI fraud matters, the ombudsman route works best where the dispute is really with the bank — a genuinely unauthorised debit, a missed shadow-credit deadline, a failure to act on your golden-hour report. ## What can courts do — and how do I get frozen money released? Once CFCFRMS or the police freeze money in a beneficiary account, the path back to the victim runs through the jurisdictional criminal court: 1. **Application for release of property.** Under Sections 497 to 505 BNSS (formerly Sections 451 to 459 CrPC), the magistrate dealing with the case can order interim custody or release of seized property — including a specific frozen amount traceable to your transaction. The application is supported by the NCRP acknowledgment, the FIR, your bank statement and the beneficiary bank's confirmation of the hold. 2. **Attachment and restitution.** Section 107 BNSS is a new provision with no CrPC equivalent: on a police application, the court can attach property identified as proceeds of crime and, after a show-cause process, order its **distribution to the persons affected — through the District Magistrate, within 60 days**. It is an emerging but promising restitution route in multi-victim UPI frauds. 3. **Consumer commission.** Where the loss flows from the bank's deficiency in service — for example, ignoring your timely report — a complaint lies before the District Consumer Commission (pecuniary jurisdiction up to ₹50 lakh) under the Consumer Protection Act, 2019. See the [civil and consumer practice overview](https://advaslam.com/practice/civil-consumer/). 4. **Civil suit** against identified beneficiaries for recovery of money, realistic only where the fraudster or account holder is traceable and has assets. In practice, the single most common bottleneck is not the law but the paper trail: victims who kept their NCRP acknowledgment, wrote to the bank on day one and obtained the FIR find the release application straightforward; those who only called 1930 and stopped there do not. ## Which remedy does what? The full map | Remedy | Where | Realistic timeline | What it can achieve | |---|---|---|---| | 1930 / NCRP complaint | Phone / [cybercrime.gov.in](https://cybercrime.gov.in) | Hours (freeze), weeks (police action) | Freezes money still in the banking chain; starts the police process | | Bank complaint (RBI framework) | Your bank, in writing | 10 working days shadow credit; 90 days resolution | Full refund of unauthorised transactions if reported in time | | UPI app dispute (UDIR) | In-app / NPCI 1800-120-1740 | Days | Reversal of failed, duplicated or wrong-recipient transactions | | FIR | Any police station (Zero FIR) / cyber police station | Months | Investigation, arrest, chargesheet; foundation for court release of funds | | RBI Ombudsman (RB-IOS 2021) | [cms.rbi.org.in](https://cms.rbi.org.in) | Months | Award up to ₹20 lakh + ₹1 lakh against the bank for deficiency | | Magistrate application (ss.497–505 BNSS) | Jurisdictional criminal court | Months | Release of frozen, traceable amounts back to the victim | | Consumer commission / civil suit | District Commission / civil court | 1–3 years | Compensation from the bank; recovery from identified beneficiaries | ## What are the realistic chances of recovery? Honest expectations, by scenario: - **Reported within hours, money still in the chain.** The best case. Holds are commonly secured on part or all of the amount; the fight then shifts to the magistrate application for release, which takes months but has a defined path. - **Unauthorised transaction, reported within three working days.** Strong position even if the fraudster is never caught, because the refund right under the RBI circular runs against your own bank, with the burden of proof on the bank. - **Authorised-but-induced payment, reported late.** The hardest case. Money withdrawn as cash or converted through layered mule accounts is usually beyond the freeze mechanism; recovery then depends on the criminal case, Section 107 BNSS attachment, or a civil claim against traceable beneficiaries. No remedy guarantees recovery, and anyone who promises otherwise should be treated with suspicion. Speed of reporting is the one variable fully in the victim's control, and it dominates every other factor. ## What if I unknowingly received fraud money? The other side of the freeze mechanism: if a fraudster routed tainted money through your account — a marketplace sale, a "work-from-home" payout, a stranger's "wrong transfer" you returned — your account may be frozen or lien-marked in a cyber case registered far from Kerala. That does not make you an accused, but it does require a considered response: identifying the freezing authority, replying to notices with your own paper trail, and moving the jurisdictional court or the High Court where the freeze is disproportionate. That situation has its own detailed guide: [bank account frozen by a cyber cell — what to do](https://advaslam.com/writing/bank-account-frozen-cyber-cell-kerala/), and the broader practice context is at [cyber crime practice](https://advaslam.com/practice/cyber-crime/). ## Primary sources - [RBI circular dated 6 July 2017 — Customer Protection: Limiting Liability of Customers in Unauthorised Electronic Banking Transactions](https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=11040) - [RBI circular dated 4 January 2019 — Limiting Liability of Customers in Unauthorised Electronic Payment Transactions in Prepaid Payment Instruments](https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=11446) - [Reserve Bank – Integrated Ombudsman Scheme, 2021](https://rbidocs.rbi.org.in/rdocs/Content/PDFs/RBIOS2021_121121.pdf) and the [RBI Complaint Management System](https://cms.rbi.org.in) - [National Cyber Crime Reporting Portal](https://cybercrime.gov.in) and the [Indian Cyber Crime Coordination Centre (I4C)](https://i4c.mha.gov.in/ncrp.aspx) - [NPCI — UPI Dispute Redressal Mechanism](https://www.npci.org.in/what-we-do/upi/dispute-redressal-mechanism) - [Bharatiya Nyaya Sanhita, 2023](https://indiacode.gov.in/handle/123456789/496548) - [Bharatiya Nagarik Suraksha Sanhita, 2023](https://indiacode.gov.in/handle/123456789/496550) - [Information Technology Act, 2000](https://indiacode.gov.in/handle/123456789/496511) ### Frequently asked questions **Can I recover money lost in a UPI fraud?** Yes, but the odds depend almost entirely on speed. If you report through the 1930 helpline or cybercrime.gov.in while the money is still moving between accounts, banks can freeze it in the chain and a court can later order its return. Once the fraudster withdraws the money as cash, recovery becomes far harder and shifts to criminal prosecution and civil remedies. **What is the time limit to report UPI fraud in India?** There is no statutory deadline, but the first few hours decide whether the money can be frozen inside the banking chain. Separately, the RBI's zero-liability protection for unauthorised transactions requires you to notify your bank within three working days of learning of the transaction. Reporting within four to seven working days caps your liability at ₹10,000 for most savings accounts; beyond seven days, the bank's board-approved policy applies. **Is calling 1930 the same as filing an FIR?** No. The 1930 call registers a complaint on the Citizen Financial Cyber Frauds Reporting and Management System, which triggers the freeze mechanism but is not an FIR. An FIR under Section 173 BNSS (formerly Section 154 CrPC) is registered separately by the police, and you will usually need one for a full investigation and for the court to release frozen money back to you. **Does RBI zero liability apply if I transferred the money to the scammer myself?** No. The RBI circular of 6 July 2017 protects unauthorised transactions — debits you never approved. If a scammer deceived you into authorising a UPI payment with your own PIN, the transaction is treated as authorised, and your remedies are the 1930/NCRP freeze, the criminal case and a court application for refund, not the liability framework. **How long does the bank have to resolve a UPI fraud complaint?** For unauthorised electronic transactions, the RBI circular requires the bank to give shadow credit of the disputed amount within 10 working days of notification and to resolve the complaint within 90 days. If the bank rejects the claim or does not reply within 30 days, you can escalate to the RBI Ombudsman free of cost at cms.rbi.org.in. **What happens to my money if it gets frozen in the fraudster's account?** It stays on hold under Section 106 BNSS (formerly Section 102 CrPC) until a court deals with it. The victim can apply to the jurisdictional magistrate for release of the identified amount under Sections 497 to 505 BNSS (formerly Sections 451 to 459 CrPC), supported by the NCRP acknowledgment, the FIR and the bank trail. Magistrates can order refund of traceable amounts to victims on such applications. --- ## Writ petitions before the High Court of Kerala: when Article 226 is the right remedy URL: https://advaslam.com/writing/writ-petition-high-court-kerala/ Author: Adv. K J Muhammed Aslam, Advocate (Bar Council of Kerala, K/001823/2026) Published 16 August 2026 Practice area: High Court writs & procedure How a writ petition under Article 226 works before the High Court of Kerala: the five writs, when a writ is maintainable, filing at Kochi, and timelines. A writ petition under Article 226 of the Constitution is the direct remedy before the High Court of Kerala when a government body, statutory authority, or official acts illegally, refuses to act, or acts without hearing you. It is filed at Ernakulam, numbered as a Writ Petition (Civil) — WP(C) — and heard first at an admission stage where interim protection can be granted within days. It is the right remedy where the dispute is against a public authority on questions of legality; it is usually the wrong remedy where a statutory appeal exists, where the facts are seriously disputed, or where the opposite party is purely private. ## What is Article 226, and what power does it give the High Court of Kerala? [Article 226](https://legislative.gov.in/constitution-of-india/) is part of the High Court's original constitutional jurisdiction — the case starts in the High Court itself, rather than coming up on appeal. Clause (1) empowers every High Court to issue "directions, orders or writs" to any person or authority, including any Government, within its territory. Two features make it wide. It protects fundamental rights **and** operates "for any other purpose" — meaning ordinary legal rights, statutory duties, and procedural fairness. And it reaches "any person or authority", not just the State in the narrow sense. The jurisdiction is discretionary. Unlike Article 32 before the Supreme Court, no one has a guaranteed right to an Article 226 remedy; the court weighs alternative remedies, delay, and conduct before granting relief. That discretion drives most of the practical rules below. Article 226 is distinct from Article 227, the High Court's supervisory power over subordinate courts and tribunals. Following [Radhey Shyam v. Chhabi Nath, (2015) 5 SCC 423](https://indiankanoon.org/search/?formInput=radhey%20shyam%20chhabi%20nath%202015), challenges to orders of civil courts go under Article 227, not as writs of certiorari under Article 226. ## Which of the five writs fits my problem? Article 226 names five writs. In drafting practice at Ernakulam, petitions usually pray for a specific writ "or any other appropriate writ, order or direction", so nothing is lost by choosing imperfectly. Still, knowing which writ fits sharpens the petition. | Writ | What it does | Everyday Kerala example | |---|---|---| | **Certiorari** | Quashes an order already passed by an authority or tribunal that acted without jurisdiction, in violation of natural justice, or with an error of law on the face of the record | A Municipal Secretary cancels a building permit without issuing a show-cause notice or hearing the permit holder | | **Mandamus** | Commands a public authority to perform a duty it is refusing or neglecting to perform | A bank account frozen at a cyber cell's instance under [Section 106 BNSS (formerly Section 102 CrPC)](https://indiankanoon.org/search/?formInput=section%20106%20bharatiya%20nagarik%20suraksha%20sanhita%20seizure) stays frozen for months with no order served and no response to representations | | **Prohibition** | Stops a court or tribunal from continuing proceedings it has no jurisdiction to conduct — issued before the decision, unlike certiorari | A rent control court proceeds with an eviction petition over a building exempt from the Kerala Buildings (Lease and Rent Control) Act | | **Quo warranto** | Questions the legal authority of a person holding a public office | A statutory appointment made without the qualifications the governing statute or regulations prescribe | | **Habeas corpus** | Requires a detained person to be produced before the court and the detention justified | A preventive detention order under the Kerala Anti-Social Activities (Prevention) Act, 2007 challenged by the detenu's family | Mandamus has one drafting precondition worth knowing: the petitioner should ordinarily show a demand and a refusal (or continued inaction). A written representation to the authority, annexed as an exhibit, is standard groundwork before filing. In frozen-account matters this pairs naturally with the banking and police-procedure steps covered in [what to do when a cyber cell freezes your bank account](https://advaslam.com/writing/bank-account-frozen-cyber-cell-kerala/). Habeas corpus petitions in the Kerala High Court go before a Division Bench and are treated with urgency — listing within days, and production or records called for quickly. ## When is a writ petition NOT the right remedy? Three doctrines account for most writ dismissals at the admission stage. **1. The alternative remedy rule.** If the statute that produced the grievance gives an appeal or revision, the High Court will usually send the petitioner there first. GST assessments, revenue recovery demands, and consumer disputes are routine examples — each has its own appellate ladder. The rule is one of discretion, not jurisdiction, and [Whirlpool Corporation v. Registrar of Trade Marks, (1998) 8 SCC 1](https://indiankanoon.org/search/?formInput=whirlpool%20corporation%20registrar%20of%20trade%20marks%201998) settles the exceptions: a writ lies despite an alternative remedy where there is a violation of natural justice, where the authority acted wholly without jurisdiction, where the vires of the statute itself is under challenge, or where a fundamental right is infringed. A petition invoking an exception should plead it specifically, not as boilerplate. **2. Disputed questions of fact.** Writ proceedings run on affidavits; there is no oral evidence or cross-examination. Where the case turns on which of two factual versions is true — who signed what, what was orally agreed, whether goods were delivered — the writ court will decline and leave the parties to a civil suit. Matters that may instead belong in a suit or consumer forum are discussed under [civil and consumer disputes](https://advaslam.com/practice/civil-consumer/). **3. Private parties.** Article 226 does not resolve private disputes. A quarrel with a neighbour, employer, or business partner is not writ territory, and pure contractual disputes with even a government body are generally excluded unless a public law element exists. The exception is the public-function doctrine: in [Andi Mukta Sadguru Trust v. V.R. Rudani, (1989) 2 SCC 691](https://indiankanoon.org/search/?formInput=andi%20mukta%20sadguru%20v.r.%20rudani), the Supreme Court held that mandamus can issue against a private body discharging a public duty — there, an aided private college. Private universities, aided schools, and electricity licensees are recurring Kerala examples. ## Can I file in the Kerala High Court against an authority outside Kerala? Yes, where the cause of action arises wholly or partly in Kerala. Article 226(2) says the power may be exercised by any High Court within whose territory the cause of action arises, "notwithstanding that the seat of such Government or authority... is not within those territories." In practice, I see this most often in cyber-freeze matters: a police station in another state instructs a bank to freeze an account, and the account holder — who banks and lives in Kochi or Kozhikode — feels the freeze in Kerala. Because the account is maintained and the consequence operates within the state, part of the cause of action arises here, and the Kerala High Court can be moved even though the freezing authority sits elsewhere. The same logic covers central authorities headquartered in Delhi or Mumbai whose orders take effect against a person in Kerala. The converse caution: if no part of the cause of action touches Kerala — the order was passed elsewhere, against property elsewhere, affecting activities elsewhere — residence in Kerala alone will not confer jurisdiction. ## How is a writ petition filed and heard at Ernakulam? The Kerala High Court sits at Ernakulam, and writ practice follows the Kerala High Court Rules, 1971 together with the [Electronic Filing Rules for Courts (Kerala), 2021](https://prosecution.kerala.gov.in/images/pdf/GO_Rt_1350-2021-Home_revised.pdf). The sequence, step by step: 1. **Drafting.** The petition sets out the parties, a chronological statement of facts, numbered legal grounds, and the prayers. Documents are marked as Exhibits P1, P2 and so on, each affirmed in a supporting affidavit sworn before an advocate authorised to attest or a notary. The prayer clause should include the specific writ sought, any consequential direction, an interim relief prayer (typically stay of the impugned order), and costs. 2. **E-filing.** Petitions are filed electronically through the Kerala High Court's [e-filing system](https://ecourt.keralacourts.in/), with pleadings uploaded as signed PDFs. The court fee on a writ petition is a fixed, nominal amount under the Kerala Court Fees and Suits Valuation Act, 1959; habeas corpus petitions are exempt. 3. **Scrutiny and numbering.** The Registry scrutinises the filing and either numbers it — WP(C) No. ___ of 2026 — or returns a defect list (common defects: missing pagination, unattested exhibits, court-fee shortfall). Defects must be cured within the time allowed, or the petition is treated as not pursued. 4. **Admission hearing.** The petition is listed before the Single Judge holding the relevant roster. The judge may dismiss it at the threshold, admit it and order notice to the respondents, or dispose of it immediately with directions. Urgent matters can be moved for early listing. 5. **Interim orders.** Interim stay is commonly sought at admission. Article 226(3) builds in a safeguard: if an interim order is passed without hearing the affected party, that party may apply to vacate it, and the court must decide the vacate application within two weeks — failing which the interim order stands automatically vacated. Serving an advance copy on the Government Pleader before moving for interim relief against the State is standard practice. 6. **Counter-affidavits.** Respondents file counter-affidavits, typically within four to eight weeks; the petitioner may file a reply affidavit. Pleadings then close. 7. **Final hearing and judgment.** The matter is heard on the affidavits and documents. The court may allow the petition (issuing the writ), dismiss it, or dispose of it with directions. 8. **Appeal.** A Single Judge's judgment can be challenged in a writ appeal before a Division Bench under Section 5 of the [Kerala High Court Act, 1958](https://indiankanoon.org/search/?formInput=kerala%20high%20court%20act%201958%20section%205), within 30 days (Article 117, Limitation Act, 1963). A further challenge lies to the Supreme Court by Special Leave Petition under Article 136 — ordinarily within 90 days, and within 60 days where a certificate of fitness was refused or a death sentence is involved. Drafting quality matters more in writ practice than almost anywhere else: the court decides on the affidavits, so a fact omitted from the petition effectively does not exist. Suppression of a material fact — such as a pending appeal on the same subject — is itself a ground for dismissal with costs. The mechanics of affidavit-backed pleading are part of the broader work described under [High Court litigation](https://advaslam.com/practice/high-court-litigation/). ## How long does a writ petition realistically take? Timelines vary sharply by the nature of the relief sought. Broad ranges from current practice at Ernakulam: | Matter type | Interim stage | Final disposal | |---|---|---| | Habeas corpus | Listing within days | Days to a few weeks | | Direction to decide a pending application (mandamus for inaction) | Often unnecessary | Frequently disposed at admission, within weeks | | Bank account freeze / seizure challenges | Interim directions possible at admission | Weeks to a few months | | Service matters (appointments, promotions, disciplinary orders) | Stay possible at admission | 6–18 months | | Licence and permit refusals | Stay or status quo at admission | 6–18 months | | Challenges to Government Orders, schemes, or policy decisions | Contested interim stage | 1–3 years | Two points temper these numbers. First, effective relief often arrives at the interim stage — a stay of a demolition, a direction to de-freeze salary credits, protection of an appointment — long before final judgment. Second, connected batches (many petitions on one GO) move at the pace of the batch, not the individual case. ## What does "disposed with directions" mean? It is the workhorse outcome of writ practice. The court does not declare either side right; it directs the authority to do its job within a fixed time — most commonly, to consider the petitioner's application or representation and pass a reasoned order within four to eight weeks, after hearing the petitioner. This is not a defeat. It converts open-ended inaction into a time-bound obligation enforceable by contempt proceedings if disobeyed. And because the authority must now pass a **reasoned** order after a hearing, any fresh adverse order arrives with reasons that can be tested — in a second writ petition if the defect is legal, or in the statutory appeal if one exists. ## What does delay cost? The doctrine of laches No limitation statute applies to Article 226, but delay is far from free. Under the doctrine of laches, the court may refuse relief solely because the petitioner slept on the grievance — especially where third-party rights have since crystallised, as in appointments or tenders. Working rules from practice: service and licensing matters should be filed within roughly three to six months of the impugned order; challenges where others have acted on the decision, faster still. A continuing wrong — an ongoing illegal freeze, non-payment of a pension each month, continuing detention — resets the clock, and habeas corpus is never barred by delay. Where delay exists, the petition itself should explain it candidly; an unexplained gap of years is usually fatal at the admission stage. The practical takeaway: an aggrieved person should send the demand-and-refusal representation early, preserve the acknowledgments, and take legal advice promptly rather than waiting for the authority to relent. ## Primary sources - [Constitution of India — Articles 226 and 227](https://legislative.gov.in/constitution-of-india/) (Legislative Department, Government of India) - [Whirlpool Corporation v. Registrar of Trade Marks, (1998) 8 SCC 1](https://indiankanoon.org/search/?formInput=whirlpool%20corporation%20registrar%20of%20trade%20marks%201998) — exceptions to the alternative remedy rule - [Andi Mukta Sadguru Trust v. V.R. Rudani, (1989) 2 SCC 691](https://indiankanoon.org/search/?formInput=andi%20mukta%20sadguru%20v.r.%20rudani) — mandamus against private bodies performing public functions - [Radhey Shyam v. Chhabi Nath, (2015) 5 SCC 423](https://indiankanoon.org/search/?formInput=radhey%20shyam%20chhabi%20nath%202015) — civil court orders challengeable under Article 227, not 226 - [Kerala High Court — official website](https://highcourt.kerala.gov.in/) - [Kerala High Court e-filing and case services](https://ecourt.keralacourts.in/) - [Electronic Filing Rules for Courts (Kerala), 2021](https://prosecution.kerala.gov.in/images/pdf/GO_Rt_1350-2021-Home_revised.pdf) - [Kerala High Court Act, 1958 — Section 5 (writ appeals)](https://indiankanoon.org/search/?formInput=kerala%20high%20court%20act%201958%20section%205) ### Frequently asked questions **Is there a time limit for filing a writ petition under Article 226?** No statute fixes a limitation period for Article 226 petitions, and the Limitation Act, 1963 does not apply to them. But the High Court applies the doctrine of laches: unexplained delay can defeat the petition by itself. In practice, service and licensing matters should be filed within about three to six months of the impugned order, and any longer delay should be explained in the petition. **How long does a writ petition take in the Kerala High Court?** It depends on what the petition asks for. A petition seeking only a direction to an authority to decide a pending application is often disposed of at the admission stage itself, within weeks. A contested challenge to a government order typically takes one to three years to final hearing, though interim protection can come within days of filing. Habeas corpus petitions are treated as urgent and move in days. **Can I file a writ petition against a private company or bank?** Generally no — Article 226 runs against the State, statutory authorities, and bodies performing public functions, not private parties in private disputes. The exception is where a private body discharges a public duty: the Supreme Court in Andi Mukta v. V.R. Rudani (1989) held that mandamus can issue against such a body. Banks are routinely made respondents where they act on directions of a public authority, such as a police freeze on an account. **Can the Kerala High Court hear a writ petition against an authority located outside Kerala?** Yes, if the cause of action arose wholly or partly within Kerala. Article 226(2) allows the High Court to issue writs to a government or authority seated outside its territory when part of the cause of action arises inside it. A common example is a bank account held in Kerala frozen at the instance of a cyber cell in another state — the freeze operates in Kerala, so the Kerala High Court can be moved. **What does it mean when a writ petition is 'disposed with directions'?** The court has not decided who is right on the merits; it has instead directed the authority to act — usually to consider the petitioner's application or representation and pass a reasoned order within a fixed time, often four to eight weeks. This is the most common outcome in inaction cases. If the authority then passes an adverse order, that fresh order can be challenged separately. **What happens if a writ petition is dismissed by a Single Judge?** A writ appeal lies to a Division Bench of the same High Court under Section 5 of the Kerala High Court Act, 1958. The limitation for an intra-court appeal is 30 days under Article 117 of the Limitation Act, 1963. Beyond that, a Special Leave Petition to the Supreme Court under Article 136 is possible — ordinarily within 90 days of the judgment, and within 60 days where the High Court refused a certificate of fitness or, in a criminal case, a death sentence is involved. --- # Procedure guides ## Bail & Anticipatory Bail in Kerala — BNSS Procedure URL: https://advaslam.com/guides/bail-anticipatory-bail-kerala-guide-bnss/ Author: Adv. K J Muhammed Aslam, Advocate (Bar Council of Kerala, K/001823/2026) Published 22 September 2026 Practice area: Criminal law: bail, quash & appeals Explains the BNSS 478–483 bail chain in Kerala — anticipatory bail, regular bail, CrPC transition and paperbook discipline. Information only. Bail in Kerala now runs under the Bharatiya Nagarik Suraksha Sanhita, 2023 (BNSS), in force from 1 July 2024. Section 478 covers bailable offences, Section 480 non-bailable offences before the Magistrate, Section 482 anticipatory bail on apprehension of arrest, and Section 483 the special bail powers of the Sessions Court and High Court. The offence classification and custody stage decide which provision and forum apply. ## What does each BNSS bail provision cover? **Short answer:** Section 478 governs bail for bailable offences; Section 479 caps detention for undertrial prisoners; Section 480 governs bail for non-bailable offences; Section 482 governs anticipatory bail on apprehension of arrest; and Section 483 confers special bail powers on the High Court and Court of Session. The offence classification and custody stage decide the provision. The old CrPC equivalents were Sections 436, 436A, 437, 438, and 439 respectively, and many orders still cite both for clarity during transition. Bail remains a judicial discretion guided by statute, gravity, antecedents, cooperation, and conditions — not a fixed formula. Each application must invoke the correct section with custody facts. ## When should regular bail under Sections 480 or 483 be sought? **Short answer:** Regular bail is sought after arrest or remand, before the Magistrate under Section 480 or before the Sessions Court or High Court under Section 483. The plea states custody dates, allegations, investigation stage, grounds such as parity or prolonged custody, and conditions offered including cooperation and non-tampering. First applications ordinarily go to the court with jurisdiction over the case, with High Court filings explaining prior applications and changed circumstances where applicable. Custody length, charge-sheet status, recovery, and antecedents materially shape the hearing. Suppression of antecedents or breach of earlier conditions damages credibility. ## When does anticipatory bail under Section 482 lie? **Short answer:** Anticipatory bail under Section 482 lies where there is reasonable apprehension of arrest in a non-bailable offence. The applicant shows the basis of apprehension, willingness to cooperate, roots in the jurisdiction, and conditions offered, while the prosecution is heard on custodial-interrogation need, gravity, and antecedents. Kerala courts examine notice procedure, the FIR or complaint stage, the need for recovery, and prior conduct. Interim protection, if granted, is conditional and time-sensitive. Filing without disclosing parallel proceedings, prior rejections, or related crimes risks adverse orders. Anticipatory relief does not decide guilt; it regulates pre-arrest custody. ## What conditions and cancellations should applicants understand? **Short answer:** Bail conditions typically include cooperation with investigation, non-tampering with witnesses or evidence, availability for trial, passport or travel directions, and sureties. Breach, fresh offending, absconding, or suppression can lead to cancellation and custody, with the prosecution moving the court for revocation. Conditions should be realistic and complied with from day one — attendance dates diarised, surety documents ready, and travel permissions sought in advance. Modification is sought by reasoned application, not by unilateral non-compliance. Every condition binds until varied by the court. ## What paperbook does the registry and court expect? **Short answer:** The paperbook states custody and case details in a table, annexes the FIR or complaint, remand or arrest memo, prior orders, ID and address proof, and surety materials where applicable. The affidavit verifies facts, and the vakalatnama authorises counsel; prosecutor-notice procedure of the forum is followed. Chronology matters: date of offence, FIR, arrest/remand, custody days, charge-sheet status, and prior bail history. Selective annexures and unexplained gaps invite adjournments. Remote drafting requires the client to confirm every date and enclosure in writing before filing. ## How do custody length, parity, and Section 479 operate? **Short answer:** Custody length, investigation progress, and parity with co-accused on similar roles shape bail discretion, while Section 479 addresses undertrial detention limits with statutory exceptions for grave and multiple-charge cases. The application should tabulate custody days, charge-sheet status, and the co-accused position with orders. Parity is not arithmetic equality — roles, recoveries, and antecedents distinguish cases. Section 479 relief is on bond with conditions, not an acquittal, and its exceptions for serious offences must be addressed honestly. A clean custody table with dates does more work than pages of assertion. ## What sureties, verification, and compliance follow a bail order? **Short answer:** Bail orders specify sureties, amounts, verification, and reporting or surrender mechanics; compliance means producing valid ID, address proof, and solvent sureties promptly, verifying them where directed, and diarising every attendance and condition. Remote clients should courier originals or present them as the court directs. Common post-order pitfalls include sureties with deficient documents, missed reporting dates, and travel without permission. Each invites cancellation proceedings. Keep a compliance file — order copy, surety IDs, attendance endorsements — and seek modification by reasoned application before any unavoidable default. ## BNSS bail provisions at a glance | BNSS | Subject | Old CrPC | Forum | |---|---|---|---| | 478 | Bail in bailable offences | 436 | Police / Magistrate | | 479 | Maximum detention for undertrials | 436A | Court (release on bond) | | 480 | Bail in non-bailable cases | 437 | Magistrate | | 482 | Anticipatory bail | 438 | Sessions / High Court | | 483 | Special powers of HC / Sessions | 439 | High Court / Sessions | | 187(3) | Default bail on charge-sheet delay (60/90 days) | 167(2) | Magistrate — before final report | ## How should remote clients prepare for bail hearings from outside Kerala? **Short answer:** Remote clients prepare by confirming the crime number, custody dates, and prior orders in writing, executing the vakalatnama and affidavit as directed, and keeping ID, address proof, and surety documents ready for the hearing date. Instructions, drafts, and endorsements move over video, email, and phone with version control. Practical discipline includes a single contact person, no parallel factual versions across forums, disclosure of other cases or stations involved, and travel readiness where surrender or verification is ordered. Courts test consistency across filings more than eloquence at the bar; a clean, confirmed paperbook prepared remotely outperforms a last-minute physical appearance with gaps. Where sureties are local to Kerala and the applicant is elsewhere, surety verification mechanics and timelines should be settled with counsel before the hearing rather than improvised after the order. ## Primary sources - [Bharatiya Nagarik Suraksha Sanhita, 2023](https://indiacode.gov.in/handle/123456789/496550), ss.187(3), 478–480, 482–483 (India Code). - [Bharatiya Nyaya Sanhita, 2023](https://indiacode.gov.in/handle/123456789/496548) (offence classification); Kerala court and registry practice. - Transition references: CrPC ss.436/436A/437/438/439 (repealed, cited for mapping). ### Frequently asked questions **Is bail automatic in bailable offences?** Bail is a matter of right subject to conditions and sureties, but procedure, identification, and conditions still apply under Section 478. **Does filing in the High Court first help?** Ordinarily the hierarchy is followed and prior applications disclosed. Direct High Court filings explain why the lower forum was not approached. **What is the effect of Section 479?** It addresses undertrial detention limits with statutory exceptions for grave offences; release is on bond with conditions, not an acquittal. **Can bail conditions be modified?** Yes, by reasoned application showing changed circumstances. Breach before modification risks cancellation. **Does anticipatory bail stop investigation?** No. It protects against arrest on conditions; cooperation with investigation continues. **How long does a bail hearing take in Kerala?** Timelines vary by forum, roster, prosecution response time, and custody urgency; no timeline can be promised. --- ## Bank Account Frozen by Kerala Cyber Cell — Response Guide URL: https://advaslam.com/guides/bank-account-frozen-kerala-cyber-cell-guide/ Author: Adv. K J Muhammed Aslam, Advocate (Bar Council of Kerala, K/001823/2026) Published 22 September 2026 Practice area: Cyber crime & IT Act matters Explains what to do when Kerala cyber police freeze a bank account — BNSS 106/94/497, S.105 AV rules, NCRP trail and release steps. Information only. When a Kerala bank account is frozen after a UPI or bank transfer, the freeze usually follows a police requisition linked to a cyber complaint on the National Cybercrime Reporting Portal (NCRP). Identify the requisitioning authority, crime or NCRP number and lien amount; preserve lawful-source proof for the disputed entry; and send written representations to the branch and cyber cell seeking partial release of the non-lien balance. ## Why was my account frozen without my bank explaining? **Short answer:** Banks usually act on a police requisition to preserve a disputed credit entry, and frontline staff may only see a lien marker without the underlying complaint details. The freeze is generally entry-linked — a specific suspect credit — but the bank may restrict operations until the requisitioning authority clarifies the amount and scope. The first task is therefore identification: which authority issued the requisition, under what crime or NCRP acknowledgement number, and for what amount. Without that, representations go in circles. Written requests to the branch and to the cyber cell or police station, with account and transaction details, move identification forward. ## What law governs debit-freeze, seizure, and release? **Short answer:** Police powers to require production of records, to seize or preserve property linked to an offence, and courts' powers to order interim custody or release now sit in BNSS Sections 106, 94, and 497 (BNSS 106 = CrPC 102 seizure; BNSS 94 = CrPC 91 production; BNSS 497 = CrPC 451 custody; BNSS 105 is new — AV-recording with no CrPC equivalent). Banks preserve the entry; release of the lien or the balance follows police or court directions on the record. No private party can order a freeze; only the process of law does. The account holder's remedy is representation with lawful-source proof, followed by graded escalation — supervisory police outreach, the NCRP trail, and court applications where statute provides. Civil suits against the bank alone rarely resolve a requisition-based freeze. ## What should I do in the first 72 hours? **Short answer:** Record the freeze date, lien amount, and the specific credit entry; download statements; preserve invoices, salary credits, or sale proof for that entry; file or update an NCRP complaint on cybercrime.gov.in (or helpline 1930); and send written representations to the branch and the requisitioning authority seeking the requisition copy and partial release of the non-lien balance. Do not split, layer, or rapidly move funds to evade the lien — that complicates the lawful-source showing. Keep all communication in writing, retain postal and email proof, and maintain one consistent factual version across bank, police, and portal filings. ## How do NCRP, 1930, and the bank follow-up fit together? **Short answer:** The NCRP acknowledgement and 1930 call create the traceable complaint record; the bank's fraud or lien desk maps that record to the lien; and the concerned cyber cell or police station decides on continuation or release. Each leg needs the same transaction identifiers — UTRs, dates, amounts, and counterparty details. Follow up on all three legs in parallel with the same document set, noting acknowledgement numbers and officer details. Where the complainant and the account holder are different persons in different states, coordination passes through the respective police stations, which explains the time taken. ## When do courts get involved, and what paperbook is needed? **Short answer:** Courts get involved where representation does not resolve the freeze — typically through applications for interim custody or release of seized property, with notice to the prosecution and the bank. The paperbook needs KYC, statements, the disputed-entry explanation, NCRP and representation proofs, and the requisition details once known. The prayer is usually calibrated: release of the non-lien balance first, then the disputed entry on conditions such as bond or undertaking. Outcomes depend on investigation stage, complaint status, and the strength of the source proof; no release can be promised. ## What documents prove lawful source for the disputed entry? **Short answer:** Lawful-source proof matches the entry's nature: salary credits need payslips and employer confirmation; trade receipts need invoices, delivery proof, and GST records where applicable; P2P or crypto-adjacent receipts need platform ledgers, KYC of counterparties, and bank trails. One entry, one document chain, with amounts and dates aligned. General six-month statements alone rarely suffice — the authority wants the specific credit explained, not the account's overall character. Highlight the entry in the statement, number the enclosures, and keep the explanation identical across bank, police, and court filings. Inconsistencies across filings are treated as adverse material. ## How should escalation be sequenced if representation stalls? **Short answer:** Escalation runs in writing: branch to nodal or fraud desk, requisitioning station to supervisory officers, NCRP status follow-up with acknowledgement numbers, and then a calibrated court application for release of the non-lien balance or the disputed sum on bond. Each step encloses the prior correspondence to show diligence. Parallel complaints to unrelated forums without the requisition details waste time. The sequence that works is identification first, partial-release request second, and court remedy third — with every letter dated, acknowledged, and filed. Timelines depend on inter-state coordination and investigation stage and cannot be promised. ## Freeze-response sequence | Step | Action | Proof preserved | |---|---|---| | 1 | Note freeze date, lien amount, entry | Screenshots, statements | | 2 | Assemble source proof for the entry | Invoices, salary, sale deed | | 3 | NCRP filing / 1930 call | Acknowledgement number | | 4 | Written branch representation | Email + postal receipts | | 5 | Written cyber-cell representation | Requisition-copy request | | 6 | Calibrated court application (if needed) | Full paperbook with index | ## How do P2P, merchant, and salary-credit freezes differ in handling? **Short answer:** P2P and merchant-credit freezes need trade ledgers, platform KYC, and counterparty trails; salary-credit freezes need employer confirmation and payslips; marketplace settlements need order-level reconciliation. The authority's question is always the same — whose money was this entry and for what lawful transaction — but the proving document changes with the credit type. Mixed-use accounts need entry-wise segregation: highlight the disputed credit, explain adjacent credits briefly, and avoid burying the target entry in bulk statements. Where the account received funds from an unknown upstream source via a customer's own transfer, state that chain honestly with the customer's details rather than disowning the entry. Investigators distinguish candid intermediaries with records from evasive holders without them, and the representation's tone and completeness shape that assessment from the first reading. ## Primary sources - [BNSS](https://indiacode.gov.in/handle/123456789/496550) ss.106/94/497 (India Code) + s.105 (new, AV-recording); CrPC ss.102/91/451 (transition mapping). - NCRP: [cybercrime.gov.in](https://cybercrime.gov.in/); helpline 1930; [CERT-In Directions 28.04.2022](https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf) (reporting context). - [RBI directions](https://www.rbi.org.in/Scripts/BS_ViewMasterDirections.aspx) on fraud reporting and customer protection (information context). ### Frequently asked questions **Will the whole balance stay frozen?** Often only the disputed entry is lien-marked, but operations may be restricted until clarified. Seek written confirmation of the lien amount and partial release. **How long does unfreeze take?** It depends on inter-state police coordination, investigation stage, and document completeness. No timeline can be promised. **Should I close the account?** No. Closing or rapidly moving funds during a requisition complicates the record. Represent in writing instead. **Can the bank alone unfreeze?** Where the freeze rests on a police requisition, the bank needs the authority's direction or a court order. Coordinate both. **What if I am a victim too (P2P/merchant)?** State that clearly with trade, KYC, and ledger proof. Victim-chain cases need especially clean documentation. --- ## Consumer Complaints in Kerala — Limits, Appeals, Paperbook URL: https://advaslam.com/guides/consumer-complaint-kerala-district-state-limits/ Author: Adv. K J Muhammed Aslam, Advocate (Bar Council of Kerala, K/001823/2026) Published 22 September 2026 Practice area: Civil, property & consumer matters Explains consumer complaints in Kerala — ₹50 lakh and ₹2 crore commission limits, the two-year rule, 45/30/30 appeal chain and paperbook. Information only. A consumer complaint in Kerala goes to the commission fixed by the consideration paid, not the compensation claimed: the District Commission up to ₹50 lakh, the State Commission above ₹50 lakh up to ₹2 crore, and the National Commission above ₹2 crore. It must be filed within two years of the cause of action, and appeals follow a 45/30/30-day chain. ## Which commission should the complaint go to? **Short answer:** Pecuniary jurisdiction turns on the consideration paid: District Commissions handle complaints where it is up to ₹50 lakh, State Commissions above ₹50 lakh up to ₹2 crore, and the National Commission above ₹2 crore, under the Consumer Protection (Jurisdiction of the District Commission, the State Commission and the National Commission) Rules, 2021, notified on 30 December 2021. Territorial nexus follows residence, transaction, or opposite-party location under the 2019 Act. Filing in the wrong commission wastes months on return and refiling. Quantify the consideration paid carefully — under the 2019 Act it, not the compensation claimed, fixes the forum (Section 34(1)) — annex bills proving consideration, and plead the nexus — branch, delivery address, or service location — expressly. E-filing through e-Daakhil supplements, not replaces, registry scrutiny. ## What is the two-year rule and how is delay condoned? **Short answer:** Consumer complaints must be filed within two years of the cause of action, with condonation available on sufficient cause shown with dates and proof. Each day's delay needs explanation; generic office-delay pleas without a date table are routinely rejected. Cause of action here means the deficiency date plus any rejection or failed-redress date. Prior legal notices, grievance tickets, and repair visits extend the narrative but do not automatically extend limitation — plead them with documents and seek condonation separately where needed. ## What paperbook gets a consumer complaint admitted? **Short answer:** The paperbook needs the complaint with verification and affidavit, bills and warranty or contract proof, the deficiency chronology with photos or job cards, prior notices with postal proof, the relief table (refund, compensation, costs), and ID and authorisation. E-Daakhil uploads mirror the physical set. Relief must be specific: refund amount, interest from which date, compensation heads, and costs. Open-ended "as the Commission deems fit" prayers without figures delay valuation and jurisdiction checks. Opposite parties must be correctly arrayed — dealer, manufacturer, and service centre where each played a role. ## How do hearings, evidence, and orders proceed? **Short answer:** After admission and notice, the opposite party files a version, evidence proceeds by affidavit with cross-examination where allowed, and arguments close with a reasoned order on deficiency, liability, and quantum. Interim directions are limited and fact-sensitive. Medical, housing, and vehicle matters often need expert or technical records — prescriptions, commissioning reports, or job cards. The "job card omits the complaint" pleading point in vehicle cases illustrates why contemporaneous records outweigh later assertions. ## What are the 45/30/30-day appeal limits? **Short answer:** Appeals from District to State ordinarily carry a 45-day limit, State to National a 30-day limit, and National to Supreme Court a 30-day limit, each with deposit or pre-deposit conditions and condonation on sufficient cause. Missing the window without a date-wise explanation risks dismissal at the threshold. Appeal paperbooks need the impugned order, the full complaint record, the deposit proof, and the delay application with affidavit where applicable. Execution of the original order follows statutory procedure and registry practice; stay pending appeal needs an express order, not an assumption. ## How do e-commerce, travel, and housing complaints differ in proof? **Short answer:** E-commerce complaints hinge on order snapshots, payment proof, delivery records, and platform-seller correspondence; travel complaints hinge on tickets, itineraries, and cancellation terms; housing complaints hinge on agreements, payment schedules, possession letters, and occupancy or completion proof. Each category fails without its native documents. Plead the platform-seller distinction in e-commerce, the refund-and-rebooking ledger in travel, and the delay-with-possession timeline in housing. Generic deficiency narratives without category-native annexures invite dismissal or nominal awards. Screenshots need dates and order IDs, not selective crops. ## How are compensation, interest, and costs quantified? **Short answer:** Compensation follows proved heads — refund with interest from a stated date, documented consequential loss, and litigation costs — each with bills or records, rather than a single inflated global figure. Interest runs from the pleaded date of deficiency or payment, and costs follow the Commission's assessment of conduct and proof. Structure the relief table as line items: principal, interest computation, loss with voucher, and costs, totalling to the amount claimed. Exaggerated claims without vouchers undermine credibility on liability itself; modest, vouchered claims with clean limitation succeed more reliably. ## Forum and timeline snapshot | Item | Rule (verify current notification) | Practice note | |---|---|---| | District Commission | Up to Rs.50 lakh (Consumer Protection (Jurisdiction of District/State/National Commission) Rules, 2021) | Plead consideration + nexus | | State Commission | Above Rs.50 lakh up to Rs.2 crore (2021 Jurisdiction Rules); hears District appeals (45 days) | Deposit + record needed | | National Commission | Above Rs.2 crore (2021 Jurisdiction Rules); hears State appeals (30 days) | Strict paperbook | | Supreme Court | Appeals from National (30 days) | Leave and record discipline | | Limitation | 2 years from cause of action (S.69 CPA 2019) | Date table for condonation | ## What registry, verification, and e-Daakhil discipline avoids defects? **Short answer:** Registry defects most often involve mismatched valuations, unsigned verifications, illegible annexures, missing ID or authorisation, and unindexed exhibits. E-Daakhil uploads should mirror a paginated physical set with a signed verification, affidavit, and consecutively numbered exhibits, each legible and complete rather than selectively cropped. Before filing, cross-check the consideration paid against the pecuniary slab, verify names and addresses of every opposite party, confirm the two-year computation with the cause-of-action date, and test every PDF for readability. Defect cures consume the very limitation and listing time the complaint seeks to save; a registry-clean first filing with a complete index typically reaches admission faster than a hurried filing followed by three cure memos. Remote complainants should confirm product serial numbers, invoice figures, and service dates against originals in writing before the draft is finalised. ## Primary sources - [Consumer Protection Act 2019](https://indiacode.gov.in/handle/123456789/496115); Consumer Protection (Jurisdiction of the District Commission, the State Commission and the National Commission) Rules, 2021 (e-Gazette notification dated 30.12.2021; [PIB release, 30.12.2021](https://www.pib.gov.in/PressReleasePage.aspx?PRID=1786342)) – verify the current notification before filing. - E-Daakhil procedure; Kerala District/State Commission practice. ### Frequently asked questions **Is a legal notice mandatory before filing?** Not statutorily mandatory, but prior notice with proof strengthens deficiency and quantum and is expected in practice. **Can both dealer and manufacturer be parties?** Yes, where each has a role in sale, warranty, or service. Array all material parties with their addresses. **Are e-commerce complaints maintainable locally?** Territorial nexus through delivery, residence, or transaction footprint is pleaded; platform, seller, and logistics roles are distinguished. **What compensation is realistic?** Compensation follows proved loss with bills and records; inflated, unvouched claims without bills and records fail. Quantify heads separately. **Does e-Daakhil filing complete the process?** No. Registry scrutiny, defect cure, admission, and service complete filing; track each stage. **Can interest be claimed from the notice date?** Interest is pleaded from a stated date with computation; the Commission awards it on proved loss and conduct, not automatically. **What if the opposite party does not appear?** The Commission may proceed ex parte on the complaint record; a complete paperbook with postal and service proof therefore decides one-sided matters. --- ## Digital-Arrest Calls & Online Harassment — Kerala Response Note URL: https://advaslam.com/guides/digital-arrest-online-harassment-response-note/ Author: Adv. K J Muhammed Aslam, Advocate (Bar Council of Kerala, K/001823/2026) Published 22 September 2026 Practice area: Cyber crime & IT Act matters Explains why "digital arrest" calls are fraud, how to report them and where online harassment complaints go under the IT Rules and BNS. Information only. A "digital arrest" call is fraud: Indian law has no such procedure, and no agency arrests or interrogates over video call while demanding secrecy or money. Disconnect without paying, preserve the numbers, UPI IDs and chats, report on cybercrime.gov.in or helpline 1930, notify the bank's fraud desk in writing, and file a police complaint. Online harassment runs on platform-grievance and police tracks in parallel. ## Is a "digital arrest" call real? **Short answer:** No. Indian law contains no procedure called digital arrest, and no agency arrests or interrogates over video call while demanding secrecy or money transfer. Every such call is impersonation and extortion, punishable under provisions including Section 66D of the IT Act and Sections 318, 308, and 351 of the BNS. Disconnect and report. Genuine summons or notices arrive in writing through verifiable channels with document references, not through threats on WhatsApp or Skype demanding gift cards, crypto, or immediate transfer. Any caller who forbids contacting family or police, or who stages a fake "courtroom" on video, confirms the fraud. ## What should I do in the first hour after the call or message? **Short answer:** Disconnect without paying, preserve the numbers, UPI IDs, and chat or call records with screenshots, note amounts and UTRs if money moved, warn family against secrecy instructions, and report on cybercrime.gov.in or helpline 1930. Then inform the bank's fraud desk in writing and file a police complaint with the preserved evidence. Speed matters for fund trails, but accuracy matters more: one consistent written version across portal, bank, and police filings. Do not delete chats, reinstall apps to "clean" the phone, or confront the caller. Preserve device logs for later Section 63 BSA certification if proceedings follow. ## How is sextortion and image-based blackmail handled? **Short answer:** Sextortion and intimate-image blackmail are addressed under IT Act Sections 66E, 67, and 67A with BNS provisions on extortion, criminal intimidation, and related offences. The response is preservation of chats and payment demands, no further payment or imagery, confidential reporting on NCRP, and takedown requests to the platform's grievance mechanism. Victims often fear exposure more than loss; that fear is what the offender monetises. Reporting channels accept confidential complaints, and platforms operating in India must maintain grievance redressal under the IT Rules. Evidence discipline — original files, URLs, timestamps — decides later remedies more than any negotiation with the offender. ## What about loan-app harassment and abusive recovery? **Short answer:** Abusive recovery — contact-list shaming, morphed images, threats, or persistent calls — may attract IT Act and BNS provisions alongside RBI digital-lending and recovery norms. Preserve call logs, messages, and app permissions, complain to the lender's grievance redressal and the RBI Sachet portal, and report criminal threats to NCRP and police. Borrowing status does not licence harassment. The response separates the civil repayment question from the criminal harassment question: legitimate dues are addressed through documented channels, while threats and defamation are reported as offences with evidence. ## How do takedown, evidence, and platform grievance fit together? **Short answer:** Takedown runs through the platform's grievance officer under the IT Rules 2021 (as amended in 2026 for synthetically generated information), with NCRP and police complaints in parallel for investigation. Evidence runs through Section 63 BSA certification of chats, images, logs, and call records for later proceedings. File the platform complaint with exact URLs, timestamps, and ID proof; retain acknowledgement numbers; and keep originals with hash or device details where possible. Re-uploads need fresh complaints with new URLs. No takedown timeline for every category can be promised; procedure and follow-up decide outcomes. ## How should families and workplaces respond to contact-list threats? **Short answer:** Where offenders threaten to message family, employers, or contacts, warn those circles briefly that a fraud attempt is underway, ask them to block and preserve any messages, and avoid paying for silence. A short factual warning deprives the offender of surprise, which is the primary leverage in contact-list extortion. Do not share additional images, IDs, or money to "verify" bona fides during the panic. Preserve the threat messages with timestamps, note which contacts were approached, and include that list in the NCRP and police filings. Counselling support for minors and distressed victims should precede any detailed statement-taking. ## What longer-term protection reduces repeat targeting? **Short answer:** Longer-term protection includes tightening app permissions, enabling two-factor authentication, reviewing privacy settings on social and professional profiles, separating payment identities from public contact details, and practising verification callbacks for any authority claim through independently sourced numbers. Victim details circulate on offender lists, so a quiet period of heightened hygiene follows every incident. Periodically check bank statements and credit or CIBIL alerts for misuse of leaked KYC, and retain the complaint acknowledgement numbers for future linkage. Awareness within the household — especially for elderly members and students — prevents the second attempt that often follows the first within weeks. ## First-hour checklist | Priority | Action | Why | |---|---|---| | 1 | Disconnect, do not pay | Payment funds further extortion | | 2 | Screenshot numbers, IDs, chats | Evidence for portal + police | | 3 | Note UTRs if money moved | Bank trail for lien/recall | | 4 | Report NCRP / 1930 | Traceable complaint record | | 5 | Written bank fraud-desk notice | Preservation request | | 6 | Platform grievance with URLs | Takedown track | ## What should witnesses, screenshots, and device preservation cover? **Short answer:** Witnesses cover who saw the call or messages and when; screenshots cover numbers, profiles, demands, and payment details with visible timestamps; device preservation covers original chats, call logs, and app data without deletion or factory reset. Together they form the evidentiary spine if investigation or trial follows. Ask witnesses for a short dated note while memory is fresh, capture full-screen screenshots rather than cropped fragments, and back up the device before any repair or OS update. Where Section 63 BSA certification is later needed, the custodian's statement links each exhibit to its source device or account; after-the-fact reconstructions without originals carry little weight. One organised evidence folder with an index outperforms scattered forwards across family WhatsApp groups. ## Primary sources - [IT Act](https://indiacode.gov.in/handle/123456789/496511) ss.66C/66D/66E/67/67A/79; [IT Rules 2021](https://indiacode.gov.in/handle/123456789/510233) as [amended 10.02.2026](https://egazette.gov.in/WriteReadData/2026/269993.pdf) (SGI labelling, takedown). - [BNS](https://indiacode.gov.in/handle/123456789/496548) ss.318/308/351/356/77; Shreya Singhal v. UoI (2015) 5 SCC 1 (s.66A invalid). - NCRP [cybercrime.gov.in](https://cybercrime.gov.in/); helpline 1930; [RBI digital-lending and recovery norms](https://www.rbi.org.in/Scripts/BS_ViewMasterDirections.aspx). ### Frequently asked questions **The caller showed my Aadhaar and a fake warrant. Is it real?** No. Data display plus a video "court" is a known impersonation pattern. Verify only through written, independently sourced official channels. **Should I pay a small amount to make them stop?** No. Payment marks the victim as compliant and typically escalates demands. Preserve and report. **Can I report without family knowing?** NCRP and police complaints can be filed by the victim directly; confidentiality concerns can be stated in the complaint. Minor victims should involve a trusted adult or counsellor. **The platform rejected my takedown. What next?** Re-file with precise URLs and rule references, escalate within the grievance appellate framework, and pursue the police-investigation track in parallel. **Is Section 66A still relevant?** No. Section 66A was struck down in Shreya Singhal (2015). Online-abuse remedies now rest on current IT Act, BNS, and IT Rules provisions. --- ## DPDP Readiness Checklist for Kerala Small Businesses URL: https://advaslam.com/guides/dpdp-readiness-checklist-small-business/ Author: Adv. K J Muhammed Aslam, Advocate (Bar Council of Kerala, K/001823/2026) Published 22 September 2026 Practice area: Data protection & DPDP compliance Explains ten practical DPDP readiness controls for small businesses — data mapping, notices, consent, breach response and vendor terms. Information only. A small business that decides why customer or employee data is collected is a Data Fiduciary under the DPDP Act, 2023. With the DPDP Rules notified on 13 November 2025 and commencement phased into 2027, readiness means ten controls: a data map, notice and consent, purpose limitation, access control, retention, a breach playbook, vendor terms, a cross-border record, a rights tracker and a children's-data flow. ## What is the DPDP Act's core bargain for a small business? **Short answer:** Collect only what is needed, on clear consent with notice, use it only for the stated purpose, keep it accurate and secure, retain it only as long as required, and honour grievance and deletion requests. The Data Fiduciary bears the accountability; processors and vendors act only on documented instructions. Small businesses are fiduciaries whenever they decide purposes — billing, marketing, HR, support logs. Even a contact form plus WhatsApp marketing creates fiduciary duties. Mapping what data exists, where it sits, and why it is kept is therefore step zero; everything else follows the map. ## How should consent and notice be fixed first? **Short answer:** Consent must be free, specific, informed, unconditional, and withdrawable, preceded by a notice stating what is collected, why, and how to withdraw or complain. Pre-ticked boxes, bundled consents, and dark patterns do not qualify, and consent managers become available under the phased Rules. Practical fix: rewrite each collection point — forms, checkout, app permissions — with purpose-specific checkboxes, a linked notice in plain language, and a logged timestamp. Store the consent artefact; it is the first document the Board or a complainant will ask for. ## What security, breach, and retention controls are expected? **Short answer:** Reasonable security safeguards, breach notification to affected principals and the Data Protection Board within the Rule 7 timelines, and deletion on purpose-fulfilment or withdrawal are the operational core, sitting alongside the CERT-In 6-hour incident-reporting clock where it applies. Retention schedules and access controls evidence the control. Small-team implementation means MFA on admin accounts, least-privilege access, encrypted backups, a one-page breach playbook with owner and phone numbers, and a retention table (data → purpose → period → deletion method). Logs of access and deletion close the loop; undocumented controls are treated as absent. ## How should vendors, processors, and cross-border storage be handled? **Short answer:** Vendors processing data on the business's behalf need written DPDP-aligned instructions covering purpose, categories, security, sub-processors, breach notice, audit, and exit deletion, with cross-border transfers assessed under Section 16 and Rule 15. The fiduciary remains answerable for vendor failures. Inventory every sub-processor — payment gateway, CRM, email, analytics, cloud region — record hosting locations, and add the DPA schedule to renewals. Where children's data or high-volume sensitive data is involved, reassess necessity first; avoidance beats paperwork. ## What rights and grievance workflow must work? **Short answer:** Data principals hold rights to access, correction, erasure, nomination, and grievance redressal, and the fiduciary must publish grievance means and resolve complaints within prescribed timelines before Board escalation. A working email, tracker, and template replies constitute the minimum viable workflow. Assign one owner, acknowledge promptly, verify identity proportionately, act or reason refusal in writing, and log the outcome. Children's data and verifiable parental consent need a separate documented flow under Section 9 and Rules 10/12 where applicable. ## How should HR and employee data be brought into scope? **Short answer:** HR data — resumes, salary, attendance, health-adjacent records, and exit files — needs the same map, purpose, access, and retention discipline as customer data, with narrower access and clearer deletion on exit. Offer letters and HR policies should state purposes, retention, and grievance means in plain language. Practical steps include segregating HR folders from shared drives, limiting payroll access, documenting background-verification consent, and fixing an exit checklist that revokes access and schedules deletion. Employee grievances about data misuse follow the same tracker as customer requests, with identity verification proportionate to sensitivity. ## What marketing, cookies, and analytics hygiene is required? **Short answer:** Marketing lists, cookies, pixels, and analytics need purpose-specific consent, opt-out paths, and vendor records — purchased databases and silent tracking contradict the consent bargain. Each campaign should trace to a consent source, each cookie to a disclosed purpose, and each analytics vendor to the sub-processor register. Fixes include consent-mode banners with reject-as-easy-as-accept, UTM-to-consent linkage for lead forms, suppression lists honoured across tools, and periodic purging of stale contacts. Children's or student audiences trigger the higher Section 9 parental-consent flow; where age cannot be assured, avoid targeting that segment. ## Readiness checklist (10 controls) | # | Control | Evidence of compliance | |---|---|---| | 1 | Data map (what/where/why) | Inventory sheet | | 2 | Notice + consent artefacts | Logged consent records | | 3 | Purpose limitation | Collection-point audit | | 4 | Access control + MFA | Access matrix, MFA log | | 5 | Retention + deletion schedule | Retention table, deletion certs | | 6 | Breach playbook (DPDP + CERT-In clocks) | One-page playbook, drill date | | 7 | Vendor DPAs + sub-processor list | Signed schedules | | 8 | Cross-border record (s.16/R.15) | Hosting-region register | | 9 | Rights + grievance tracker | Ticket log, templates | | 10 | Children's-data flow (if any) | Parental-consent SOP | ## How should incidents be drilled and documented before the Board acts? **Short answer:** Incident readiness means a named owner, a contact sheet, a containment checklist, and a practice drill, so that breach assessment, principal notification, Board notification, and CERT-In reporting each trigger on time with logged decisions. Undrilled teams discover missing passwords, access, and vendor contacts during the incident itself. Run a tabletop exercise: simulate a leaked spreadsheet or compromised inbox, walk through containment, assessment, and notification decisions, and record lessons with assigned fixes. File the drill date, attendees, and action items alongside the breach playbook; that file evidences reasonable safeguards and accountability far better than a policy nobody has opened. Re-drill when vendors, systems, or team members change, and keep the contact sheet current. ## Primary sources - [DPDP Act 2023](https://indiacode.gov.in/handle/123456789/496508); DPDP Rules 2025, [G.S.R. 846(E) 13.11.2025](https://egazette.gov.in/WriteReadData/2025/267650.pdf) ([MeitY](https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf)/Gazette); commencement [G.S.R. 843(E) 13.11.2025](https://egazette.gov.in/WriteReadData/2025/267647.pdf). - [CERT-In Directions 28.04.2022](https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf) + FAQs 18.05.2022; DPDP ss.9/10/16; Rules 7/10/12/13/15. ### Frequently asked questions **Does DPDP apply to offline registers?** Yes, where personal data is digitised or processed digitally. The map should include registers later entered into systems. **What is the CERT-In vs DPDP clock confusion?** CERT-In Directions impose a 6-hour incident report for covered entities; DPDP Rule 7 imposes Board and principal notification on its own timeline. Assess both; neither excuses the other. **Do small businesses need a Data Protection Officer?** Only Significant Data Fiduciaries carry the DPO/DPIA/audit load under Section 10. Small businesses need the ten controls above, scaled sensibly. **What penalties apply?** Graded penalties under the Act's schedule apply after commencement of the penalty provisions. Preparation now reduces exposure later. **Where do we start this month?** Data map, consent-notice rewrite, MFA plus backups, and the breach playbook — in that order. --- ## Online IPR Takedown — Kerala Information Note URL: https://advaslam.com/guides/ipr-online-takedown-kerala-information/ Author: Adv. K J Muhammed Aslam, Advocate (Bar Council of Kerala, K/001823/2026) Published 22 September 2026 Practice area: Business, banking & IPR Explains online IPR takedown for Kerala brands — trademark and copyright tracks, BSA-63 evidence preservation and patent referral. Information only. Online IPR takedown for Kerala brands depends on the right involved: trademark and brand-impersonation matters use cease-and-desist, platform grievance and INDRP domain action; copyright matters use ownership-backed platform takedown; and patent questions go on referral to a registered patent agent, not takedown. Every track needs exact URLs, dated captures and Section 63 BSA-compatible evidence. Section 66A of the IT Act is no longer law. ## Which track fits which infringement? **Short answer:** Trademark and brand-impersonation matters run on passing-off and infringement with intermediary takedown and domain-dispute tracks; copyright matters run on ownership plus platform takedown; patent disputes do not resolve by takedown and need attorney-led prosecution or enforcement referral. Classification first, procedure second. The common error is filing every grievance everywhere. A phishing domain needs the registrar plus INDRP plus intermediary record; a copied Instagram creative needs copyright takedown with ownership proof; a software-patent question needs a patent-agent opinion, not a platform complaint. Match the right to the forum. ## How does trademark-splits and domain (INDRP) action work? **Short answer:** Online trademark enforcement combines a cease-and-desist with evidence, a platform grievance under Rule 3(2) with exact URLs (Rule 3(1)(d) applies to takedowns on court/government order), and domain action through INDRP arbitration for .in names (or UDRP for gTLDs) on confusing similarity, no legitimate interest, and bad faith. NCRP and police complaints run in parallel where phishing or fraud exists. The TM-split means: registered-mark claims cite numbers and classes; unregistered claims plead passing-off with goodwill proof; and both preserve screenshots, WHOIS, and payment trails. Domain relief is transfer or cancellation on the arbitral record — plead all three INDRP elements with documents. ## How does copyright takedown for creators and startups work? **Short answer:** Copyright takedown identifies the work, ownership chain, the infringing URLs, and the good-faith statement required by the platform's form, with registration or creation proof and assignment records where freelancers or agencies created the work. Counter-notice and repeat-infringer tracks follow platform procedure. Ownership decides outcomes: freelancer-built code or creatives vest per Sections 17–19 of the Copyright Act and the written assignment, not per payment alone. Attach the assignment, the registration or deposit record, and side-by-side comparisons; vague "they copied my idea" complaints without expression-level proof fail. ## Why do patent matters go on referral, not takedown? **Short answer:** Patent questions — including software and AI under Section 3(k) and the CRI Guidelines of 29 July 2025 — turn on novelty, inventive step, and technical effect assessed by the Patent Office, not by platforms. Online complaints cannot determine infringement; referral to a registered patent agent for search, drafting, or enforcement opinion is the route. Founders should separate the patent question from the brand and copyright questions in the same dispute: pursue takedown for the copy, INDRP for the domain, and a patent-agent referral for the underlying technology. Mixing them delays all three. ## What evidence and grievance discipline wins takedowns? **Short answer:** Complete complaints give exact URLs (not "their website"), dated screenshots with visible marks, rights documents, a short infringement table mapping right to URL, and ID with authorisation. They file with the platform grievance officer first, retain acknowledgement numbers, and escalate on re-uploads with fresh URLs. Section 63 BSA certification preserves chats, logs, and page captures for later proceedings. A short table — work or mark, registration, URL, date captured, infringing element — outperforms pages of narrative. Note on Section 66A: it was struck down in Shreya Singhal (2015); current remedies rest on IP statutes with IT Act and BNS support. ## How should Startups sequence NDA, registration, and disclosure? **Short answer:** Startups should sequence protection as NDA before disclosure, registration where the asset qualifies, and controlled publication only after filing or documented trade-secret controls. Pitch decks, freelancer engagements, and marketplace listings are the three disclosure points where rights are most often lost without signatures. Practical order: template NDA executed before sharing decks or code, freelancer assignment with IP clauses before work begins, trademark filing before brand launch, and patent-agent screening before publishing technical details. Each step is dated and filed; the sequence itself becomes evidence of diligence in later disputes. ## What criminal and intermediary escalation supports IP fraud? **Short answer:** Where infringement shades into fraud — phishing checkouts, fake franchise collections, counterfeit sales with deception — NCRP and police complaints under IT Act and BNS provisions run alongside the IP track, with UTRs, URLs, and parcel records preserved. The intermediary grievance record and the INDRP or platform outcome become exhibits in the criminal file. Sequence the tracks without contradiction: one factual version across C&D, platform, domain, and police filings, with the same rights table and URL list. Overstating criminality in a purely civil copy dispute damages credibility; reserving criminal escalation for genuine fraud preserves it. ## Track selector | Dispute | Primary track | Parallel track | |---|---|---| | Fake site / phishing domain (.in) | INDRP + intermediary grievance | NCRP/police if fraud | | Copied photos, video, listings | Copyright takedown + C&D | Repeat-infringer escalation | | App clone (brand + code) | TM grievance + copyright takedown | DPA/vendor review | | Software/AI patentability | Patent-agent referral (s.3k/CRI 2025) | Trade-secret/NDA controls | | Review abuse / impersonation | Platform grievance + record | Defamation remedies (no 66A) | ## How should evidence be preserved for later court or arbitral proceedings? **Short answer:** Preservation means dated captures with URLs and hashes where possible, WHOIS and registrar records, purchase or transaction trails for counterfeits, and a Section 63 BSA-compatible custodian linkage for electronic records. Takedown alone rarely ends determined infringers; the preserved record decides the second round. Maintain an infringement ledger: right asserted, registration details, URL, capture date, infringing element, platform acknowledgement, and outcome, with re-uploads as fresh rows. Notarised or hash-verified captures outweigh bare printouts where proceedings follow, and consistent ledger discipline across C&D, platform, domain, and police tracks prevents contradictions. Retain originals; platforms may purge complaint attachments after closure, leaving the ledger as the only complete record. ## Primary sources - [Trade Marks Act 1999](https://indiacode.gov.in/handle/123456789/495962) (s.29 etc.); [Copyright Act 1957](https://indiacode.gov.in/handle/123456789/496733) (ss.2(o), 14, 16–19, 51, 63B); [Patents Act](https://indiacode.gov.in/handle/123456789/495964) s.3(k); [CRI Guidelines 29.07.2025 (CGPDTM)](https://ipindia.gov.in/frontend/pdf/patents/guidelines/GUIDELINES%20FOR%20EXAMINATION%20OF%20COMPUTER%20RELATED%20INVENTIONS%20(CRIs)%20-%202025.pdf). - [IT Act](https://indiacode.gov.in/handle/123456789/496511) ss.66C/66D/79; [IT Rules 2021](https://indiacode.gov.in/handle/123456789/510233) as [amended 10.02.2026](https://egazette.gov.in/WriteReadData/2026/269993.pdf); [INDRP Policy (NIXI)](https://www.registry.in/domaindisputeresolution); Shreya Singhal v. UoI (2015) 5 SCC 1. ### Frequently asked questions **How fast is takedown?** Timelines vary by platform, category, and completeness; sensitive categories under the 2026 SGI amendments move faster. No timeline can be promised. **Do I need registration to complain?** Registration strengthens but does not always bar complaints; passing-off and ownership-chain proof carry unregistered claims with evidence. **What is INDRP cost and time?** INDRP arbitration follows NIXI procedure with fees and reasoned awards; timelines vary by caseload. Verify the current schedule before filing. **Can I get damages online?** Damages and accounts follow court or arbitral proceedings; takedown itself does not award compensation. **Is Section 66A usable against abuse?** No. It was struck down in 2015. Current online-abuse remedies use IP statutes, IT Act provisions, BNS, and IT Rules. --- ## SARFAESI, DRT and the Kerala Writ Route URL: https://advaslam.com/guides/sarfaesi-drt-writ-route-information/ Author: Adv. K J Muhammed Aslam, Advocate (Bar Council of Kerala, K/001823/2026) Published 22 September 2026 Practice area: Business, banking & IPR Explains the SARFAESI 13-series sequence, 13(8) redemption, 45/30-day DRT clocks and when writ petitions before the High Court lie. Information only. A borrower facing SARFAESI measures should track the Section 13 sequence and its clocks: a documented 13(3A) representation after the 60-day 13(2) demand, a Section 17 application to the DRT within 45 days of 13(4) measures, and a DRAT appeal under Section 18 within 30 days with pre-deposit. Section 13(8) allows redemption before sale publication, and High Court writs lie only on recognised exceptions. ## What is the Section 13 sequence borrowers must track? **Short answer:** Section 13(2) issues the 60-day demand; Section 13(3A) obliges the creditor to consider the borrower's representation and communicate reasons; Section 13(4) measures follow on non-compliance; Section 14 provides Magistrate assistance where needed; and Rules 8–9 govern possession notice, valuation, and auction procedure. Each stage has its own proof and notice requirements. Borrowers should diarise the 13(2) date immediately, file a documented 13(3A) representation within the window, and preserve sanction letters, statements, and payment proof. Gaps — unapplied payments, wrong NPA dates, limit errors — belong in the 13(3A) reply first, because later forums ask what was raised and when. ## What is the DRT remedy and what are the 45/30-day clocks? **Short answer:** Section 17 applications before the DRT challenge 13(4) and subsequent measures within 45 days, while appeals to the DRAT under Section 18 carry a 30-day clock with pre-deposit conditions. Limitation, valuation, and auction-regularity grounds are tested on the record with the full loan paperbook. The DRT paperbook needs the sanction and security documents, 13(2)/13(3A)/13(4) correspondence, possession and valuation notices, auction records, and payment proof. Stay or status-quo prayers need urgency reasons and balance-of-convenience pleadings; suppression of payments or parallel proceedings damages interim relief. ## When will the High Court entertain a SARFAESI writ? **Short answer:** High Courts ordinarily relegate SARFAESI disputes to the DRT remedy and entertain writs only on recognised exceptions — jurisdiction without authority, natural-justice breach, fundamental-rights violation, or vires issues. Delay, disputed facts, and auction challenges without DRT history face rigorous maintainability scrutiny. The petition must plead the DRT position honestly — filed, pending, decided, or why the exception applies — and enclose the 13-series record. Interim relief depends on prima facie jurisdictional ground, balance, and full disclosure. No stay can be promised; auction calendars continue unless expressly stayed. ## What should guarantors and auction purchasers know? **Short answer:** Guarantors are tested on guarantee scope, invocation, and notice, with independent 13-series correspondence where applicable. Auction purchasers are tested on title flow — sale certificate, registration, and delivery — and on compliance with Rules 8–9 procedure that conditions a clean title. Guarantors should preserve invocation letters and payment records separately from the principal borrower file. Purchasers should verify encumbrance, tenancy, and DRT-litigation pendency before bidding; post-auction challenges turn on the procedural record, not on assumptions. ## How do OTS, restructuring, and settlement fit in? **Short answer:** One-time settlement, restructuring, and negotiated payoffs run alongside — not instead of — the statutory clocks. Proposals in writing with payment capacity proof preserve credibility; oral assurances do not stop measures. Accepted terms need a dated settlement letter with schedule, default consequences, and closure documentation. Parallel-track discipline matters: pursue settlement while protecting limitation before the DRT. Letting the 45-day clock expire during "settlement talks" without a filed application forfeits the statutory remedy. ## How are valuation and auction challenges structured? **Short answer:** Valuation and auction challenges test reserve-price fixation, valuer reports, possession and sale notices with service proof, publication compliance, and inter-se bidding conduct under Rules 8–9. The application exhibits each notice with dates, the valuation record, and the auction proceedings, identifying the precise procedural breach. Successful challenges plead prejudice with specifics — undervaluation with comparable evidence, non-service with address proof, publication defects with copies — rather than general unfairness. Purchaser equities and third-party rights developed after a confirmed sale narrow relief to compensation or upset-price directions in many cases. ## What does Section 13(8) redemption allow before auction? **Short answer:** Section 13(8) lets the borrower redeem the secured asset by tendering the full dues with costs, charges, and expenses before the sale notice is published. Part-payments do not stop the sale; only complete tender within the window does. The redemption working needs the creditor's dues statement with appropriation details. Redemption runs on the creditor's written dues figure — demand it with the 13(3A) reply and reconcile every payment against statements. Where the creditor disputes the tender amount, the Section 17 application carries the redemption plea with payment proof; auction confirmation to a bona fide purchaser narrows later relief substantially. ## What NPA-date, payment-application, and limitation defences arise? **Short answer:** NPA classification dates, correct application of payments to principal versus charges, and limitation for enforcement are tested against statements, RBI prudential norms, and the loan record. Borrowers should reconcile every payment to statements and demand the NPA-date working with the 13(2) reply. These defences belong in the 13(3A) representation first with payment proof, then in the Section 17 application with a reconciliation table. Raising them for the first time at auction stage without prior correspondence weakens interim relief; the record rewards early, documented disputes. ## Clocks and stages | Stage | Provision | Clock / test | |---|---|---| | Demand | s.13(2) | 60 days to comply | | Representation | s.13(3A) | Creditor to consider + respond | | Redemption | s.13(8) | Before sale-publication — full dues + costs/expenses | | Measures challenge | s.17 to DRT | 45 days from 13(4)/measures | | DRAT appeal | s.18 | 30 days + pre-deposit | | Possession/auction | Rules 8–9 | Notice, valuation, publication | | Writ | Art.226 | Exception grounds only | ## What settlement correspondence protects limitation while talks continue? **Short answer:** Settlement correspondence protects limitation by putting every proposal, counter-offer, and payment in dated writing, expressly reserving statutory remedies, and filing the Section 17 application within the 45-day clock regardless of assurances. Oral promises to hold measures in abeyance have no procedural value unless confirmed in an official letter. Structure each letter as proposal with amounts and dates, capacity proof, and a request for written confirmation with a response deadline, copying the file for the DRT record. Where part-payments are made during talks, obtain receipts with appropriation details rather than general acknowledgements. If the creditor's settlement letter issues, verify schedule, default consequences, closure scope, and title-document return before signing; an imprecise OTS letter generates the next dispute it was meant to close. ## Primary sources - [SARFAESI Act](https://indiacode.gov.in/handle/123456789/496260) ss.13/14/17/18; [Security Interest (Enforcement) Rules 2002](https://indiacode.gov.in/handle/123456789/509770), Rules 8–9. - [Recovery of Debts and Bankruptcy Act, 1993](https://indiacode.gov.in/handle/123456789/496321) (formerly the RDDBFI Act; DRT/DRAT); [Constitution](https://www.legislative.gov.in/constitution-of-india) Art.226 (exception doctrine via case law). ### Frequently asked questions **Can a writ stop an auction next week?** Only on a made-out exception ground with full record and urgency; courts do not stay auctions on bare hardship. Protect the DRT clock simultaneously. **Does a 13(3A) reply automatically stop measures?** No. It obliges consideration and a reasoned response; further challenge follows the Section 17 route. **What deposit applies in DRAT appeals?** Pre-deposit conditions under Section 18 apply as per statute and tribunal orders; budget before filing. **Can symbolic possession be challenged?** Yes, through Section 17 on the applicable grounds with the possession-record annexed. **Do guarantors get separate notices?** Guarantee invocation and applicable 13-series correspondence are addressed to guarantors; preserve each separately. **Can possession be restored after auction confirmation?** Post-confirmation relief narrows substantially once third-party rights crystallise; challenge valuation and procedure promptly within the 45-day clock instead. **Does an OTS proposal stay measures?** No, unless confirmed in an official written communication. Keep the DRT clock protected during talks. --- ## Section 138 Cheque Bounce — Kerala Procedure URL: https://advaslam.com/guides/section-138-cheque-bounce-kerala-procedure/ Author: Adv. K J Muhammed Aslam, Advocate (Bar Council of Kerala, K/001823/2026) Published 22 September 2026 Practice area: Business, banking & IPR Explains the Section 138 cheque bounce chain — 30-day/15-day/one-month notices, cognizance under S.210, 143A: up to 20%; S.148: minimum 20%. Information only. A Section 138 cheque-bounce case in Kerala runs on a strict chain: a written demand within 30 days of dishonour information, 15 days from receipt for the drawer to pay, and a complaint before the Magistrate within one month after those 15 days expire. Missing any link destroys the cause of action. Sections 143A (interim compensation up to 20%) and 148 (appeal deposit, minimum 20%) overlay the trial. ## What is the 30-day/15-day/one-month chain and why does it decide everything? **Short answer:** The cheque must be presented within its validity, a written demand must be issued within 30 days of dishonour information, the drawer gets 15 days from receipt to pay, and the complaint must follow within one month after those 15 days expire (Section 142(1)(b), with condonation under its proviso where applicable). Missing any link destroys the cause of action. Kerala filings fail most often on proof of the middle links — dispatch and receipt dates of the demand notice. Registered post with acknowledgement, preserved postal receipts, and a correctly described cheque table (number, date, amount, memo reason) are therefore as important as the merits. Separate offences need separate notice-and-complaint discipline. ## What must the Section 138 notice and complaint contain? **Short answer:** The notice states cheque details, presentation and return dates with memo reasons, the amount demanded, and the 15-day payment warning, sent within 30 days of dishonour information. The complaint states the full chain with dates, the accused's role, territorial nexus, and limitation compliance, with proof of authority where the complaint is filed through a representative (Section 142 allows only the payee or holder in due course to complain). The paperbook annexes the cheque copy, return memo, bank advice, notice with postal proof and acknowledgement, reply if any, and the authorisation or board resolution. Complaints by firms, companies, or holders need careful array; a wrong complainant is a curable-but-costly defect. ## What happens after filing: cognizance, summons, and trial? **Short answer:** The court examines the complaint and sworn statement or affidavit, takes cognizance (BNSS S.210) if the chain is prima facie made out, and issues summons or warrant. Plea, evidence by affidavit, cross-examination, BNSS Section 351 examination (ex-CrPC 313), and arguments follow in the summary-trial-informed procedure of Sections 143–147. Compounding under Section 147 is available and frequently ends cases at any stage, including appeal, on court-accepted terms. Most Kerala dockets push settlement alongside trial; payment schedules with default clauses, recorded by the court, prevent second-round litigation. ## What are Sections 143A and 148 (the 20% directions)? **Short answer:** Section 143A empowers the trial court to direct interim compensation up to 20% of the cheque amount during trial on statutory considerations, while Section 148 empowers the appellate court, in the drawer's appeal against conviction, to order a deposit of a minimum of 20% of the fine/compensation. Both are discretionary, reasoned, and fact-sensitive. These are information, not leverage threats: courts weigh conduct, delay, and prima facie material. Directions to pay or deposit carry timelines and consequences for default stated in the order. Appellate strategy must budget for the deposit possibility rather than discovering it after filing. ## What defences and settlement points actually matter? **Short answer:** Material defences include limitation breaks, absence of legally enforceable debt, material alteration, non-service of demand, wrong array, and stop-payment explained by full facts — each needing documents, not bare pleas. Security-cheque and blank-cheque contentions turn on the enforceable-debt evidence and the surrounding transaction record. Settlement drafting should fix the total, schedule, mode, default consequence, withdrawal of complaint or appeal, and return of documents. Vague "settle for less" orders without dates invite execution disputes; precise memos recorded by the court close files cleanly. ## How are company, firm, and authorised-representative complaints structured? **Short answer:** Entity complaints plead incorporation or firm registration, the authorised person's authority with board resolution or authorisation letter, the signatory's role in the transaction, and vicarious liability with specific averments on responsibility. The complaint array names the company or firm with the responsible officers on dated allegations. Kerala registries scrutinise authorisation closely — undated resolutions, post-facto authorisations, and mismatched signatories draw defects. Attach the incorporation or registration proof, the current authorisation, and the transaction documents linking the accused officers to the cheque and the underlying debt. ## What territorial, limitation, and condonation points arise in Kerala? **Short answer:** Territorial nexus under Section 142(2) follows presentment and collection-branch linkages, pleaded with bank details, while limitation follows the 30-day/15-day/one-month chain with Section 142 condonation on sufficient cause shown date-wise. Complaints should state both nexus and chain with calendar dates, not approximations. Common cures include amending the nexus pleading with branch proof before cognizance objections harden, and filing a separate delay affidavit with postal and receipt records rather than burying the explanation in the complaint. Remote complainants should confirm every date against originals before the draft is finalised. ## Procedure at a glance | Stage | Deadline / test | Proof needed | |---|---|---| | Presentment | Within cheque validity | Bank memo, advice | | Demand notice | Within 30 days of dishonour info | Notice + postal + AD | | Payment window | 15 days from receipt | Receipt date | | Complaint | Within one month after 15-day expiry | Chain pleaded, s.142 complied | | Interim (143A) | During trial, up to 20% | Court's reasoned order | | Appeal deposit (148) | In appeal against conviction, minimum 20% if ordered | Appellate order terms | ## How do compounding, mediation, and settlement memos close cases cleanly? **Short answer:** Compounding under Section 147 with a court-recorded memo fixing the total, schedule, mode, default consequence, and complaint-or-appeal withdrawal closes cases cleanly at trial or appellate stages. Mediation or Lok Adalat settlements need the same precision, with payment acknowledgements and document-return clauses recorded by the forum. Insist on calendar dates rather than "within a reasonable time," specify the consequence of a missed instalment including revival of proceedings, and record who withdraws what by when. Where security documents or original cheques are to be returned, list them by number. Remote parties should verify identity and authority for settlement signatories before the memo is recorded, since a settlement by an unauthorised person invites reopening applications that erase the savings the compromise was meant to secure. ## Primary sources - [Negotiable Instruments Act](https://indiacode.gov.in/handle/123456789/496318) ss.138–148, 142 (India Code). - Doctrines: limitation chain, compounding (s.147), summary procedure (ss.143–146). ### Frequently asked questions **Can one notice cover multiple cheques?** Practice varies; separate particulars per cheque with a compliant demand for each is the safe course. Legal advice on the specific set is needed. **Does a reply to the notice help the accused?** A prompt, documented reply with payment or dispute proof shapes later discretion; silence is not itself guilt but forfeits an early record. **Is imprisonment automatic on conviction?** Sentence follows trial findings and statutory sentencing; appeals with Section 148 deposit directions are common. No outcome can be promised. **Can the case settle after conviction?** Compounding under Section 147 is available at appellate stages on court-accepted terms. **Which court has jurisdiction?** Territorial rules under Section 142(2) turn on presentment and collection branches; plead the nexus expressly. --- ## Service & Labour Orders in Kerala — KAT, CAT & Writ Route URL: https://advaslam.com/guides/service-labour-orders-kat-cat-writ-route/ Author: Adv. K J Muhammed Aslam, Advocate (Bar Council of Kerala, K/001823/2026) Published 22 September 2026 Practice area: Service & labour matters Explains service and labour disputes in Kerala — KAT, CAT, labour courts and tribunals, tribunal-origin writs and the High Court route. Information only. The forum for a Kerala service or labour dispute depends on the employer and the rule source: Kerala State government service matters ordinarily go to the Kerala Administrative Tribunal (KAT); central government, railway and covered public-sector matters to the Central Administrative Tribunal (CAT) Ernakulam Bench; and workman disputes to labour courts and industrial tribunals. The High Court's writ jurisdiction supervises all of them. ## Which forum governs which employee? **Short answer:** Kerala State government and allied service matters ordinarily go to the KAT; central government, railways, and covered public-sector service matters go to the CAT's Ernakulam Bench; workman disputes under labour statutes go to labour courts and industrial tribunals; and writ jurisdiction supervises all of them on jurisdictional and rights grounds. Classification turns on the employer, the applicable service rules, and whether the claimant is a workman or a service holder. Appointment orders, rule books, and disciplinary regulations decide forum more reliably than designations. Plead the employer and rule source expressly at filing. ## What reliefs do KAT and CAT grant, and on what grounds? **Short answer:** Tribunals test appointments, seniority, promotion, transfer, suspension, disciplinary penalties, pay fixation, and retirement benefits against the applicable rules, Articles 14 and 16, and natural justice. Illegality, irrationality, and procedural impropriety remain the organising grounds, with the rule and the impugned order on record. Grounds commonly raised include rule-violation, non-application of reservation or seniority norms, enquiry without charges or hearing, and orders by incompetent authority. Bare hardship without rule breach rarely sustains relief. Chronology with GO numbers, orders, and representations decides admission. ## What paperbook do tribunals expect? **Short answer:** Tribunals expect the application with verification and affidavit, the appointment and rule position, the impugned order, prior representations and appeals with receipts, seniority or gradation lists where relevant, and the vakalatnama. Interlocutory relief needs a separate stay petition with urgency reasons. Exhaustion of departmental appeal or review where the rules mandate it should be pleaded honestly; skipping it invites rejection. Where limitation applies, a date-wise delay explanation with proof accompanies the application. ## When does a writ against a tribunal or service order lie? **Short answer:** Writs lie against tribunal orders and original service orders on jurisdictional error, patent illegality, natural-justice violation, or fundamental-rights breach — not as a routine second appeal on facts. The High Court examines the record for legality while declining to reweigh evidence or substitute its view on punishment proportionality except within settled limits. SARFAESI-style alternative-remedy discipline applies by analogy: where the tribunal remedy is efficacious, writs are entertained only on the recognised exceptions. The petition should state the tribunal history, enclose its order, and plead the exception ground expressly. ## How should disciplinary and termination matters be handled? **Short answer:** Disciplinary matters turn on charge memo, reply opportunity, enquiry minutes, report, second-show-cause where applicable, and the final order — each with dates and service proof. Termination simpliciter versus punitive termination, probation confirmation status, and the applicable rule decide the challenge's shape. Show-cause replies should traverse charges paragraph-wise with documents and seek hearing; post-order challenges attack competence, procedure, and proportionality on the record. Parallel criminal proceedings are disclosed; suppression damages credibility across forums. ## How do seniority, promotion, and pay-fixation disputes turn? **Short answer:** Seniority and promotion disputes turn on gradation lists, rule-based quotas, reservation rosters, and DPC minutes, while pay-fixation disputes turn on pay rules, option exercises, and anomaly orders — each requiring the applicable GO or rule with dates. The application should exhibit the list or fixation order with the rival position identified. Relief typically seeks quashing of the impugned list or order with a direction to redraw or refix per rules, not a declaration of the applicant as senior by assertion. Impleading affected parties where seniority reordering is sought avoids dismissal for non-joinder; omitting them is a common procedural failure. ## What interim relief and execution discipline applies? **Short answer:** Interim relief — stay of transfer, promotion, reversion, or recovery — needs urgency, prima facie rule breach, balance of convenience, and disclosure of departmental appeals pending. Tribunals grant narrow, time-bound interim orders; writ courts supervising them apply the same discipline with the tribunal record enclosed. Post-order execution follows tribunal and contempt procedure with compliance correspondence on record. Where recoveries from salary are ordered to be withheld, the order's conditions govern deductions; unilateral departmental recovery against an operating stay invites contempt scrutiny. ## Forum map | Employee / dispute | First forum | Supervision | |---|---|---| | Kerala State service | KAT | High Court (Arts. 226/227) | | Central service / Railways / covered PSU | CAT Ernakulam Bench | High Court | | Workman (ID Act etc.) | Labour court / Industrial tribunal | High Court | | Private employment (contract) | Civil court / arbitration per contract | Appeal as per statute | ## How should remote service holders manage records and representation? **Short answer:** Remote service holders manage matters by maintaining a chronological service file — appointment order, probation and confirmation letters, gradation lists, transfer and posting orders, representations with receipts, and the impugned order — with GO and rule numbers noted against each event. Drafts, affidavits, and exhibits move over email with version control before filing. Designate one correspondent, confirm every date and number against originals in writing, and disclose departmental appeals pending or decided so the tribunal record is complete. Where colleagues are similarly placed, coordinate without clubbing incompatible claims; seniority reordering needs affected parties impleaded, and mass petitions without individual cause pleadings invite separation orders. Posting outside Kerala does not change forum — the employer and rule source decide it — but it raises the premium on a complete, confirmed paperbook reaching counsel before limitation or posting deadlines expire. ## Primary sources - [Administrative Tribunals Act 1985](https://indiacode.gov.in/handle/123456789/496165); KAT/[CAT](https://cgat.gov.in/) procedure; service rules and GOs (Kerala/Centre). - [Constitution](https://www.legislative.gov.in/constitution-of-india) Arts. 14/16/226/227; the labour codes in force from 21 November 2025 ([Code on Wages 2019](https://indiacode.gov.in/handle/123456789/496699); [Industrial Relations Code 2020](https://indiacode.gov.in/handle/123456789/496702); [Code on Social Security 2020](https://indiacode.gov.in/handle/123456789/496700); [OSH Code 2020](https://indiacode.gov.in/handle/123456789/496701)) and their transitional provisions — verify current position on filing. ### Frequently asked questions **Can I go straight to the High Court in a service matter?** Where a tribunal has jurisdiction, approach it first; writs lie on the recognised exceptions with the tribunal position pleaded. **What if both transfer and disciplinary issues exist?** Plead each with its rule and order separately; omnibus allegations without rule linkage weaken both. **Is there limitation before tribunals?** Yes, under the respective tribunal statutes with condonation on sufficient cause. Date tables are essential. **Can punishment be substituted by the court?** Courts test legality and proportionality bounds; substitution is exceptional and reasoned, never assumed. **Do labour and service remedies overlap?** Classification as workman versus service holder decides the track; plead the employment and rule position first. **Can a transfer order be stayed?** Interim stay needs urgency with a prima facie rule breach and balance of convenience; hardship alone rarely sustains it, and joining without protest alters the equities. **What if the department ignores a tribunal order?** Compliance correspondence followed by execution or contempt procedure enforces the order; keep every representation and receipt on record. --- ## Writ Petitions before the Kerala High Court — Types & Grounds URL: https://advaslam.com/guides/writ-petitions-kerala-high-court-types-grounds/ Author: Adv. K J Muhammed Aslam, Advocate (Bar Council of Kerala, K/001823/2026) Published 22 September 2026 Practice area: High Court writs & procedure Explains the five writ types before the Kerala High Court — mandamus, certiorari, prohibition, quo warranto and habeas corpus. Information only. A writ petition before the Kerala High Court lies under Article 226 against the State, its instrumentalities or authorities discharging public functions, while Article 227 gives supervisory jurisdiction over subordinate courts and tribunals. The five writs are habeas corpus, mandamus, certiorari, prohibition and quo warranto. There is no fixed limitation, but delay, disputed facts or an efficacious alternative remedy can lead the court to decline. ## What are the five types of writs and when is each used? **Short answer:** Habeas corpus tests unlawful detention; mandamus compels a public authority to perform a legal duty; certiorari quashes orders passed without jurisdiction or in violation of natural justice; prohibition restrains a forum from exceeding jurisdiction; and quo warranto tests the legality of a public-office appointment. The facts determine the writ, not the label chosen. Beyond the label, Kerala practice requires the petitioner to show which respondent is a State or instrumentality, what legal duty or jurisdictional error is involved, and why the writ is the appropriate remedy. Prayers routinely combine a principal writ with ancillary directions such as interim stay, status quo, or record production. Mislabelled petitions are not always fatal, but a mismatched prayer weakens interim relief. ## Who can file a writ petition and against whom? **Short answer:** Any person whose fundamental or legal right is affected may approach the High Court under Article 226, subject to maintainability rules. The respondent must generally be the State, its instrumentality, or an authority discharging public functions; purely private disputes without a public-law element are ordinarily not entertained. In Kerala, writs commonly run against the State government, statutory boards, universities, local authorities, banks acting under statute (in limited contexts), and tribunals. Where the dispute is purely contractual or involves disputed facts requiring evidence, the court may relegate parties to civil suit or tribunal remedies. Standing, delay, and alternative remedy are examined at admission. ## What are the main grounds for mandamus, certiorari, and prohibition? **Short answer:** Mandamus requires a legal duty plus demand and refusal; certiorari requires jurisdictional error, patent illegality, or natural-justice violation on the record; prohibition requires a pending proceeding without jurisdiction. Illegality, irrationality, and procedural impropriety remain the organising grounds across all three. Common Kerala illustrations include non-consideration of statutory representations, adverse orders without hearing, orders by an incompetent authority, reliance on non-existent material, and palpable non-application of mind. Grounds must be pleaded with dates and annexed orders — bare allegations of unfairness do not sustain admission. ## What documents and pleadings does the Kerala registry expect? **Short answer:** The registry expects a memo of parties, verification and affidavit, chronology with dates, consecutively numbered exhibits with an index, the impugned order, prior representations with receipts, and vakalatnama. Defects on numbering, legibility, or authorisation delay admission. Exhibits should be complete, not selective extracts, and pleadings should state the alternative-remedy position honestly. Where an interim order is sought, a separate interim-relief petition with urgency reasons accompanies the writ. E-filing practice and defect-cure procedure of the Kerala High Court apply in addition to paper-book requirements. ## When will the High Court decline a writ and relegate parties elsewhere? **Short answer:** The court may decline where an efficacious alternative remedy exists, disputed questions of fact need trial, there is unexplained delay and laches, or third-party rights have crystallised. SARFAESI/DRT matters, service disputes with tribunal jurisdiction, and consumer disputes are typical relegation contexts absent exceptional grounds. Exceptions include enforcement of fundamental rights, orders without jurisdiction, violations of natural justice, and vires challenges. The petition should anticipate the alternative-remedy objection and plead the exception expressly, with supporting dates and orders, rather than omitting the issue. ## How do interim relief, pleadings, and disposal typically proceed? **Short answer:** At admission the court considers maintainability, prima facie case, balance of convenience, and urgency, and may issue notice, grant interim protection, or dismiss in limine. Counter-affidavits, replies, and additional documents follow, with many writs disposed at the admission stage after hearing. Interim orders are time-bound and condition-sensitive; suppression of material facts risks vacation. Final hearing addresses the jurisdictional or rights question on the record. Timelines vary with roster, pendency, and whether the matter turns on law or on contested facts. ## What limitation, delay, and laches discipline applies to writs? **Short answer:** Writs have no fixed limitation, but delay and laches defeat discretionary relief where rights have crystallised or the petitioner slept on known grievances. The petition should state the date of knowledge, each representation with receipts, and reasons for every gap, so the court can test promptness on the record. Kerala admission courts routinely ask why the petitioner waited — transfer orders challenged after joining, tenders challenged after award, admissions challenged after classes began. A forthright delay explanation with documents outperforms silence. Where delay is unavoidable, interim relief narrows to preserving the remaining remedy rather than unwinding completed actions. ## How should prayers, interim relief, and affidavits be drafted? **Short answer:** Prayers should seek the correct writ with specific directions — quash the order dated X, direct consideration of the representation dated Y within a stated time — supported by a verified affidavit, chronology, and complete exhibits. Interim prayers state urgency, balance of convenience, and the prejudice if refused. Overbroad prayers ("quash all proceedings forever") invite rejection; precise, record-linked prayers invite consideration. Affidavits must verify personal knowledge versus record belief separately, disclose prior petitions and orders, and avoid argumentative annexures. Clean paperbooks get earlier hearings. ## Writ types at a glance | Writ | Core question | Typical Kerala use | Key pleading point | |---|---|---|---| | Habeas corpus | Is detention lawful? | Custody/production matters | Who holds the person, under what authority | | Mandamus | Has a legal duty been refused? | Representations, approvals, disbursal | Duty + demand + refusal with dates | | Certiorari | Is the order vitiated on record? | Quasi-judicial orders | Jurisdictional error / natural-justice breach | | Prohibition | Should a forum be restrained? | Proceedings without jurisdiction | Pending proceeding + lack of jurisdiction | | Quo warranto | Is public office lawfully held? | Appointments to public posts | Office + disqualification or rule breach | ## Primary sources - [Constitution of India](https://www.legislative.gov.in/constitution-of-india), Articles 226–227 (Legislative Department). - [Kerala High Court](https://highcourt.kerala.gov.in/) Rules; Kerala HC e-filing practice. - Key doctrines: jurisdictional error, natural justice, alternative remedy, delay and laches (case law via IndianKanoon / SCC). ### Frequently asked questions **Can a writ be filed directly without approaching the authority first?** Ordinarily the petitioner should first make a representation and allow reasonable time, because mandamus requires demand and refusal. Exceptions exist for jurisdictional or fundamental-rights violations. **Is there a limitation period for writs?** No fixed limitation, but unexplained delay defeats discretionary relief. File promptly and explain any gap with dates. **Can disputed facts be decided in a writ?** Generally no. Where evidence and cross-examination are needed, civil or tribunal remedies are appropriate. **What is the difference between Articles 226 and 227?** Article 226 is original writ jurisdiction against State action; Article 227 is supervisory jurisdiction over subordinate courts and tribunals. Pleadings specify the provision invoked. **Does a writ guarantee interim stay?** No. Interim relief depends on prima facie case, balance, urgency, and full disclosure. No outcome can be promised. ---