Contents
- SDF readiness — will the Government notify us as Significant
- DPO appointment — India-based, Board-facing, grievance-owning
- DPIA drafting — description, risk, management for SDF processing
- Independent data audit — auditor who evaluates SDF compliance
- Gap-audit, ROPA, consent vault and training — the four-file SDF starter
- Board complaint drafting — s.27(1)(b) after grievance exhaust
- Voluntary undertaking — s.32 corporate-probation strategy
- How the Board starts — breach intimation, reference, court direction, suo-motu screen
- Mitigation for quantum — s.33(2) seven-factor story
- TDSAT appeal — 60 days, sufficient cause, 6-month endeavour
- Mediation — s.31 Board-directed settlement track
- E-sign harmonisation — consent records that survive evidence scrutiny
- INDRP + WHOIS — phishing domain using your brand to harvest data
- Phishing + blocking — s.37 DPDP vs s.69A IT Act takedown routes
- Intermediary clock — reports, acknowledgement and GAC/69A overlay
- E-commerce seller + platform — who owns the customer-data breach
- Dark patterns vs DPDP consent — when UI itself voids consent
- Section 37 blocking deep-dive — the 2-penalty gate most blogs skip
SDF readiness — will the Government notify us as Significant
Large hospital chain, NBFC, edtech or platform with volume/sensitive data does not know if SDF duties will hit.
What it involvess.10(1) factors: volume/sensitivity, rights-risk, sovereignty/integrity impact, electoral-democracy risk, State security, public order. s.10 commences May 2027 (G.S.R. 843(E)); SDF status arises only on notification.
Relevant laws.10(1); DPDP Rules r.13 (annual DPIA + audit with report to Board, algorithmic due diligence, localisation of Government-specified data).
ForumNotification watch; Board applies SDF duties only if notified.
Procedure & stageSelf-score on six factors → build SDF-ready posture (DPO/DPIA/audit) without claiming SDF status → diary MeitY notifications + May 2027.
RemedyReady posture; duties trigger only on notification.
High Court connectionSDF notification vires, if cause of action in Kerala, testable under Art.226; merits of SDF compliance go Board → TDSAT.
Documents normally requiredVolume/sensitivity note, risk note, readiness tracker.
Limitations.10 in force May 2027; SDF duties attach only on notification.
Big database = automatically SDF?
No. SDF status needs Central Government notification under s.10(1). Bigness is a factor, not the notification.
DPO appointment — India-based, Board-facing, grievance-owning
Company names a foreign privacy lead or a junior inbox-manager as DPO.
What it involvess.10(2)(a): DPO represents the SDF under the Act; based in India; responsible to Board of Directors/similar governing body; point of contact for grievance redressal.
Relevant laws.10(2)(a); ss.8(9)–(10) contact/mechanism; s.33 Schedule Sl.4 (up to Rs.150 cr for s.10 breach, Consolidated Fund of India).
ForumBoard on SDF-breach inquiry.
Procedure & stageIndia-based appointment → Board-reporting line in writing → publish contact (s.8(9)) → own grievance SLA → keep independence from business targets.
RemedyCompliant appointment + mitigation record.
High Court connectionDPO-breach findings go Board → TDSAT (60 days); service/employment terms of the DPO herself go to Kerala labour/civil fora per contract.
Documents normally requiredAppointment letter, reporting-line proof, published contact, grievance ownership note.
LimitationOn SDF notification (s.10 in force May 2027).
Can the IT head double as DPO?
Only with a real s.10(2)(a) mandate, India base, governing-body reporting and grievance ownership — plus conflict management. Form over substance fails.
DPIA drafting — description, risk, management for SDF processing
New lending, health or edtech rollout launches with no written risk review.
What it involvess.10(2)(c)(i): periodic DPIA = description of principals' rights + processing purpose, assessment/management of rights-risk, other prescribed matters.
Relevant laws.10(2)(c)(i); DPDP Rules r.13(1)–(2) (DPIA + audit once every 12 months; report of significant observations to the Board); s.33(2) quantum uses mitigation.
ForumInternal SDF record; Board calls for it on inquiry.
Procedure & stageScope → rights/purpose description → risk assess → controls + residual risk → owner + review date → file. Non-SDFs may adopt a lite DPIA as good practice (say so).
RemedyEvidence of organised compliance; absence aggravates SDF breach.
High Court connectionDPIA adequacy is Board fact-finding; writ only for process error.
Documents normally requiredDPIA, control closure evidence, review cadence.
LimitationOnce in every 12 months from SDF notification (r.13(1)); in force May 2027.
Small business needs a DPIA?
The Act mandates DPIA only for SDFs. Others may do a proportionate review voluntarily — do not present it as statutory compulsion.
Independent data audit — auditor who evaluates SDF compliance
Internal team "audits itself" and calls it s.10 compliance.
What it involvess.10(2)(b): appoint independent data auditor to evaluate compliance; plus s.10(2)(c)(ii) periodic audit.
Relevant laws.10(2)(b)–(c); DPDP Rules r.13(1)–(2) (audit once every 12 months; report of significant observations to the Board).
ForumBoard on inquiry calls for reports.
Procedure & stageIndependent appointment → scope (ss.4–10 + Rules) → report → management closure → re-audit cadence.
RemedyAudit trail + mitigation credit; self-audit alone weakens the story.
High Court connectionAuditor appointment disputes are contract matters in Kerala fora; audit findings feed Board inquiries.
Documents normally requiredEngagement letter (independence), report, closure evidence.
LimitationOnce in every 12 months from SDF notification (r.13(1)).
Statutory auditor can do it?
Only if independent and competent on data-compliance scope with a proper mandate. Independence + scope matter more than title.
Gap-audit, ROPA, consent vault and training — the four-file SDF starter
Management wants one "DPDP certificate" instead of working papers.
What it involvesReadiness assessment → Record of Processing Activities → consent/notice vault (s.6(10)) → staff training. No "certificate" exists under the Act.
Relevant lawss.4–10 (mapped per flow); s.6(10) proof; s.8(4) organisational measures; DPDP Rules r.6 minimum safeguards (encryption/obfuscation/masking/virtual tokens, access control, logs + monitoring, backups, 1-year log retention, processor contract terms) and r.14(3) grievance period (max 90 days); First Schedule Part B item 4(c) — 7-year record retention binds Consent Managers, not every fiduciary.
ForumInternal; Board-ready on inquiry.
Procedure & stageQuestionnaire → Red/Amber/Green findings → ROPA (purpose, data, base, sharing, retention, vendor) → vault → role-wise training + drill.
RemedyRoadmap (now / before May 2027 / ongoing); mitigation evidence.
High Court connectionWorking papers anchor Kerala grievance/Board replies; writ does not assess their adequacy on merits.
Documents normally requiredQuestionnaire, ROPA, vault exports, training attendance + material.
LimitationMay 2027 full posture (Rules r.3, 5–16 in force 18 months from 13.11.2025).
Template pack = compliant?
No. Templates are a start; populated, versioned, Kerala-specific working papers are the compliance.
Board complaint drafting — s.27(1)(b) after grievance exhaust
Principal files a narrative grievance with no exhaust proof, no breach pinning, no relief shaped to Board powers.
What it involvess.27(1)(b): Board inquires on principal complaint (breach / fiduciary-obligation breach / rights denial), Government reference, or court direction. s.13(3) exhaust-first applies.
Relevant lawss.13(3), 27(1)(b), 28 (screening, natural justice, civil-court powers, interim orders, costs for false complaints).
ForumBoard as digital office (s.28(1)).
Procedure & stageGrievance + wait out the published response period (max 90 days, r.14(3)) → complaint with parties, facts, sections breached, exhaust proof, evidence, relief (direction/penalty/inquiry) → track digitally.
RemedyInquiry → interim order (s.28(10)) / direction (s.27(2)) / penalty if significant breach (s.33, Consolidated Fund of India) / closure with reasons (s.28(4)/(11)). Compensation needs civil suit.
High Court connectionKerala complainants file digitally; Kerala HC writ only for Board-process illegality. Keep Kerala-addressed exhaust proof.
Documents normally requiredGrievance + delivery/wait proof, breach/rights evidence, ID, relief note.
LimitationComplaint route (s.27) from May 2027; grievance period max 90 days (r.14(3)); Board inquiry to finish within 6 months, extendable by up to 3 months at a time (r.19(9)); TDSAT 60 days on Board order.
Board will get my money back?
No. It can direct and penalise (penalty to Consolidated Fund of India). Money needs a civil suit.
Voluntary undertaking — s.32 corporate-probation strategy
Fiduciary wants to fix quickly and close proceedings without a contested penalty order.
What it involvess.32: undertaking at any stage of s.28 proceedings (do/stop by date, publicise); Board may vary with consent; acceptance bars proceedings on those contents — unless breached, when breach = Act breach → s.33 (s.32(5)).
Relevant laws.32; ss.28, 33.
ForumBoard during inquiry.
Procedure & stagePropose specific, dated, verifiable actions + publication → seek acceptance → comply + file proof → if terms need change, seek s.32(3) variation (do not self-vary).
RemedyClosure on those contents if honoured; full penalty machinery on breach.
High Court connectionUndertaking acceptance/breach findings go to TDSAT (60 days); writ only for hearing-fairness issues.
Documents normally requiredDraft undertaking, compliance timeline, publication + closure proof.
LimitationBoard-fixed dates inside the undertaking — diary strictly.
Undertaking = admission of guilt for civil suits?
It is a Board-recorded commitment with publication. Take advice on civil-suit spillover before wording it.
How the Board starts — breach intimation, reference, court direction, suo-motu screen
Business assumes the Board only acts on victim complaints and ignores intimation/reference routes.
What it involvess.27(1)(a)–(e): (a) s.8(6) breach intimations (urgent remedial/mitigation + inquiry + penalty); (b) principal complaints/references/court directions; (c) Manager complaints; (d) Manager-registration breach; (e) s.37(2) intermediary reference. s.28 screening: sufficient grounds? If not, close with reasons (s.28(4)); if yes, reasoned inquiry (s.28(5)) on natural justice (s.28(6)).
Relevant lawss.27–28; s.37(2).
ForumBoard (digital).
Procedure & stageIntake → s.28(3) screen → close or inquire (civil-court powers s.28(7); no disruptive seizure s.28(8); police/Govt assistance s.28(9); interim orders s.28(10)) → close or s.33.
RemedyDirection/penalty or reasoned closure; costs/warning for false complaints (s.28(12)).
High Court connectionKerala HC directions to the Board (in writs) arrive via s.27(1)(b); challenges to Board screening go TDSAT/writ on legality only.
Documents normally requiredIntimation/complaint/reference + annexures, reply with section-wise rebuttal + mitigation file.
LimitationBoard-directed timelines in notices; TDSAT 60 days after order.
Board officers can seize servers?
s.28(8) bars preventing premises access or seizing equipment/items that would hurt day-to-day functioning. Cooperate and record.
Mitigation for quantum — s.33(2) seven-factor story
Notice/consent/safeguard lapse admitted; business wants the number contained.
What it involvess.33(1) (penalty only if breach significant, after hearing, per Schedule) + s.33(2)(a)–(g): nature/gravity/duration; data type; repetition; gain/avoidance; mitigation timeliness/effectiveness; proportionality/deterrence; impact on person.
Relevant laws.33 + Schedule (250/200/200/150 cr, Rs.10k, undertaking-linked, 50 cr residuary).
ForumBoard inquiry; TDSAT on quantum.
Procedure & stageAdmit-or-contest clearly → file mitigation bundle (timeline, notices, fixes, spend, cooperation, no repetition, proportionality note) → argue per factor → consider s.32/s.31 → appeal quantum if needed.
RemedyLower/withdrawn penalty or undertaking-closure; penalty if imposed goes to Consolidated Fund of India.
High Court connectionQuantum appeals to TDSAT (60 days); writ only for perverse/non-speaking orders or hearing denial.
Documents normally requiredBreach timeline, notice/delivery proof, fix invoices, cooperation record, financial-impact note (audited where claimed).
LimitationTDSAT 60 days from receipt.
First offence = no penalty?
No. First-time status helps under repetition/proportionality but the Act has no first-offence immunity. Show full mitigation.
TDSAT appeal — 60 days, sufficient cause, 6-month endeavour
Board order/direction received; business or complainant misses the appeal mechanics.
What it involvess.29(1)–(2): any person aggrieved appeals to Appellate Tribunal (TDSAT) within 60 days of receipt, filed digitally with the same fee as a TRAI Act appeal unless reduced/waived by the TDSAT Chairperson (DPDP Rules r.22); s.29(3) delay condonation on sufficient cause; s.29(4)–(7) hearing + confirm/modify/set-aside + 6-month endeavour (reasons if longer); s.29(9) further appeal to Supreme Court via TRAI Act s.18; s.30 execution as civil decree.
Relevant lawss.29–30; TRAI Act ss.14A/16/18 procedure overlay (as applied).
ForumTDSAT (functions digitally as far as practicable, s.29(10)); then Supreme Court on law.
Procedure & stageCompute 60 days from receipt → file with fee + condonation affidavit if late → seek stay/modification on merits → within TDSAT, push for 6-month disposal.
RemedyConfirm/modify/set-aside; TDSAT order executable as decree (s.30), transmittable to local civil court.
High Court connectionKerala HC writ remains for Board-process illegality or Art.21 issues, but the statutory appeal is TDSAT; choose forum deliberately and watch limitation on both tracks.
Documents normally requiredBoard order + receipt proof, appeal memo, fee, stay application, condonation affidavit if late.
Limitation60 days (s.29(2)); extension only on sufficient cause (s.29(3)). TDSAT-to-SC per TRAI Act s.18 timelines.
File writ instead of TDSAT to save time?
The Act bars civil courts (s.39) and channels appeals to TDSAT. Writs test legality/fairness, not merits. Get forum advice fast — limitation runs.
Mediation — s.31 Board-directed settlement track
Complaint capable of practical fix (correction, deletion, process change) heads for a full penalty contest.
What it involvess.31: if Board thinks complaint resolvable by mediation, it directs parties to attempt it via mutually-agreed mediator or under any law in force.
Relevant laws.31; general mediation law continues (s.38).
ForumBoard → mediator.
Procedure & stageSignal willingness early → agree mediator → settle scope (fix + timeline, no penalty admission beyond facts) → report back to Board.
RemedyPractical closure; penalty track paused to the extent resolved. Victim money still needs civil settlement/deed if claimed.
High Court connectionKerala mediation centres/courts may host the sitting per agreement; Board records outcome.
Documents normally requiredSettlement draft, compliance proof, consent terms.
LimitationBoard-directed mediation window — diary strictly.
Mediation = no penalty ever?
No. It resolves what it resolves; significant-breach penalty remains Board's call under s.33.
E-sign harmonisation — consent records that survive evidence scrutiny
Clickwrap consent challenged as "no signature, no proof."
What it involvesDPDP ss.5–6 + s.6(10) proof read with IT Act ss.3/3A (electronic/digital signatures), s.10A (e-contract validity), BSA 2023 s.63 conditions for electronic records (dual certificates; BSA in force 01.07.2024).
Relevant lawDPDP ss.5, 6(10); IT Act ss.3, 3A, 10A; BSA 2023 s.63 certificate practice (dual certificates; BSA in force 01.07.2024).
ForumBoard (DPDP proof) + civil/criminal courts (record admissibility).
Procedure & stageBind notice version + identity + affirmative action + timestamp (hash/log) → retain BSA 2023 s.63-ready dual-certificate path → produce vault + certificate on inquiry/trial.
RemedyAdmissible, weight-carrying consent proof.
High Court connectionKerala courts test BSA 2023 s.63 compliance strictly (dual certificates; BSA in force 01.07.2024); build the certificate chain at collection, not after dispute.
Documents normally requiredVault schema, hash/log samples, BSA 2023 s.63 dual-certificate draft, signer/identity method note.
LimitationContinuous; produce within Board/court-directed time.
OTP click = signature?
It evidences assent if tied to identity + notice version + purpose. Loose clicks without that binding fail s.6(10).
INDRP + WHOIS — phishing domain using your brand to harvest data
Lookalike.in domain collects Kerala customer data in your brand's name.
What it involves.IN Registry INDRP (bad-faith registration/use) + registrar/WHOIS disclosure path + DPDP ss.8(5)–(6) if your customers' data is harvested (your notice/breach duties unaffected by the fraud).
Relevant lawINDRP Policy (.IN) + IT Act intermediary/takedown overlay; DPDP ss.8(5)–(6) for your own breach duties; Trade Marks Act, 1999 for brand rights where registered.
ForumINDRP arbitrator (NIXI) for transfer/cancellation; registrar for takedown/suspension; Board only for your DPDP duties; criminal complaint for fraud.
Procedure & stagePreserve phishing capture + victim trail → registrar abuse report → INDRP filing (confusing similarity + your rights + no legitimate interest + bad faith) → parallel police complaint → warn customers without admitting DPDP breach you did not cause.
RemedyDomain transfer/cancellation/suspension; fraud prosecution; DPDP mitigation record for your own notice to affected users if needed.
High Court connectionINDRP arbitration runs under the Arbitration and Conciliation Act, 1996, seated at Delhi; Delhi courts have exclusive jurisdiction over it (INDRP Policy). Brand suits lie in Kerala civil courts per jurisdiction.
Documents normally requiredWHOIS history, phishing captures, trademark proof, victim complaints, registrar correspondence.
LimitationFile fast — phishing domains move quickly.
WHOIS is redacted — how to find the holder?
Through registrar abuse/LEA disclosure channels and INDRP pleadings. Do not publish unverified attributions.
Phishing + blocking — s.37 DPDP vs s.69A IT Act takedown routes
Team cites "DPDP blocking" for every abusive site.
What it involvesDPDP s.37: only after Board has imposed penalty 2+ times + public-interest advice, Central Government after hearing may order blocking of information enabling that fiduciary's India offering (via agency/intermediary; intermediary bound, s.37(2)). IT Act s.69A: separate Government blocking for sovereignty/security/public order etc. with its own procedure.
Relevant lawDPDP s.37; IT Act s.69A + Blocking Rules, 2009; IT Act s.79 + Intermediary Rules for platform reports.
ForumCentral Government (blocking); intermediary compliance; Board reference underlying s.37.
Procedure & stageFor s.37: show 2+ penalties + hearing + public-interest order (rare, slow). For live phishing: platform report + police complaint + s.69A/executive route via competent authority — faster practical track.
RemedyAccess-blocking; DPDP penalty track unaffected.
High Court connectionBlocking orders tested in constitutional courts (Shreya Singhal / Art.19(2) proportionality backdrop); Kerala cause of action → Kerala HC Art.226 where maintainable.
Documents normally requiredPenalty orders (for s.37), phishing evidence, platform/police reports.
LimitationPlatform/police track immediately; s.37 is post-penalty and slow.
One Board penalty = site blocked?
No. s.37 needs 2+ penalties + advice + hearing + public-interest satisfaction. Do not promise blocking.
Intermediary clock — reports, acknowledgement and GAC/69A overlay
Marketplace/social platform ignores a Kerala user's data-misuse report; user mixes DPDP grievance with platform grievance.
What it involvesIT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 as amended by G.S.R. 120(E) dt 10.02.2026 (in force 20.02.2026): grievance acknowledged in 24 hrs, resolved in 7 days (r.3(2)(a)(i)); removal requests on most r.3(1)(b) content resolved in 36 hrs (proviso); 3-hr removal on court order/authorised Government intimation (r.3(1)(d)); 2-hr action on intimate-image/impersonation complaints (r.3(2)(b)); appeal to Grievance Appellate Committee within 30 days of the Grievance Officer's communication (r.3A(3)); DPDP ss.8/13/27 run separately against the fiduciary.
Relevant lawIT Act s.79 + Intermediary Rules, 2021 (as amended to 10.02.2026); DPDP ss.13, 27 for the fiduciary track.
ForumPlatform grievance officer → GAC (for intermediary track); fiduciary grievance → Board (for DPDP track). Run both, do not conflate.
Procedure & stageFile platform report (receipt ID) → escalate to GAC in-window → parallel s.13 grievance to the fiduciary → Board on DPDP failure.
RemedyContent/action on platform track; DPDP direction/penalty on fiduciary track (Consolidated Fund of India).
High Court connectionGAC/platform orders and blocking directions tested in writ courts on legality; DPDP merits go TDSAT.
Documents normally requiredPlatform receipts, content URLs/captures, fiduciary grievance proof.
LimitationPlatform: acknowledge 24 hrs / resolve 7 days (r.3(2)(a)(i)); GAC appeal within 30 days (r.3A(3)); TDSAT 60 days for DPDP appeal.
Platform removed the post — DPDP complaint over?
Not necessarily. Removal fixes the post; unlawful processing/breach history still answers under DPDP.
E-commerce seller + platform — who owns the customer-data breach
Seller's buyer list leaks via platform API or seller's own download; each blames the other.
What it involvesRole test (Data Fiduciary vs Data Processor, s.2(i)/(k)) + s.8(1) non-delegable duty + s.8(2) contracts + Consumer Protection (E-Commerce) Rules, 2020 duties alongside.
Relevant lawDPDP ss.2(i)/(k), 8; Consumer Protection Act, 2019 + E-commerce Rules, 2020 (platform/seller duties); IT Act intermediary overlay where applicable.
ForumBoard (DPDP) + consumer commissions (service deficiency) + civil court (damages/indemnity).
Procedure & stageClassify per flow (platform-as-fiduciary vs processor) → DPA/API terms → breach-notice ownership → consumer-case defence on facts.
RemedyBoard direction/penalty (Consolidated Fund of India); consumer relief (refund/compensation) in commissions; inter-party recovery by suit.
High Court connectionKerala consumer commissions/civil courts handle buyer claims locally; Board/TDSAT handle DPDP.
Documents normally requiredPlatform-seller agreement, API scope, breach forensics, buyer notices.
LimitationConsumer complaint within 2 years of cause of action (CPA s.69); breach intimation to the Board without delay + detailed report within 72 hrs (DPDP Rules r.7(2)); grievance reply within the published period, max 90 days (DPDP Rules r.14(3)); TDSAT 60 days on Board orders.
Platform terms say seller owns all data risk — enough?
Not for the Board (s.8(1)). It governs inter-party recovery only.
Dark patterns vs DPDP consent — when UI itself voids consent
Nagging, false urgency, basket-sneaking or disguised ads manufacture "consent."
What it involvesDPDP s.6(1) (free/specific/informed/unconditional/unambiguous + affirmative action) read with CCPA Guidelines for Prevention and Regulation of Dark Patterns, 2023 (specified patterns) under the CPA, 2019.
Relevant lawDPDP s.6; CPA, 2019 + CCPA Dark Pattern Guidelines, 2023; E-commerce Rules, 2020.
ForumBoard (consent validity) + consumer commissions/CCPA (dark-pattern practice).
Procedure & stagePattern audit (nagging, pre-tick, trick wording, guilt-shaming) → rebuild affirmative, symmetrical choices → keep withdrawal as easy as consent (s.6(4)).
RemedyValid-consent posture; dark-pattern direction/penalty on consumer track; DPDP penalty on consent-failure track (Consolidated Fund of India).
High Court connectionConsumer orders appealed in Kerala consumer appellate fora; DPDP validity goes Board → TDSAT.
Documents normally requiredScreen recordings, copy deck, consent/withdrawal symmetry proof.
LimitationMay 2027 DPDP posture; dark-pattern enforcement is live now — fix immediately.
Small pop-up trick — really a legal issue?
Yes, on both tracks: it undermines s.6 "free/unambiguous" consent and matches listed dark patterns. Fix the UI, not just the text.
Section 37 blocking deep-dive — the 2-penalty gate most blogs skip
Advice promises "we will get the app blocked" after one leak.
What it involvess.37(1): Board reference in writing intimating 2+ penalty instances + public-interest blocking advice → Central Government/officer, after hearing the fiduciary, if satisfied necessary/expedient in public interest with recorded reasons, orders agency/intermediary to block information enabling that fiduciary's India offering. s.37(2): intermediary bound. Definitions via IT Act (s.37(3)).
Relevant laws.37; IT Act meanings (computer resource/information/intermediary).
ForumCentral Government on Board reference; intermediary executes.
Procedure & stageTwo penalties → reference → hearing → reasoned public-interest order → intermediary blocking. One penalty is insufficient on text.
RemedyAccess-blocking in India; penalties themselves already to Consolidated Fund of India.
High Court connections.37 orders are reasoned State action testable under Art.226 (proportionality, hearing) with Kerala cause of action where applicable.
Documents normally requiredBoth penalty orders, reference, hearing record, blocking order.
LimitationNo DPDP day-count; blocking-rule procedure timelines apply to execution.
Victim can seek blocking directly?
No. s.37 runs only on Board reference after 2+ penalties. Victims use platform report + police + civil suit in the meantime.