---
title: "Significant data fiduciaries, the Board and TDSAT"
description: "Significant data fiduciaries, the Board, TDSAT, e-sign and domains: 18 matters, each with the law, forum, procedure, documents and limitation. SDF…"
url: "https://advaslam.com/practice/data-protection/matters/sdf-board-tdsat-esign-domain/"
image: "https://advaslam.com/og.png"
---

DPDP compliance

# Significant data fiduciaries, the Board, TDSAT, e-sign and domains

18 matters from the DPDP compliance index. Each entry sets out the problem, the law, the forum, the procedure, the documents usually needed and the limitation clock. General information only — verify the current position on your facts before acting.

**Contents**

1.  SDF readiness — will the Government notify us as Significant
2.  DPO appointment — India-based, Board-facing, grievance-owning
3.  DPIA drafting — description, risk, management for SDF processing
4.  Independent data audit — auditor who evaluates SDF compliance
5.  Gap-audit, ROPA, consent vault and training — the four-file SDF starter
6.  Board complaint drafting — s.27(1)(b) after grievance exhaust
7.  Voluntary undertaking — s.32 corporate-probation strategy
8.  How the Board starts — breach intimation, reference, court direction, suo-motu screen
9.  Mitigation for quantum — s.33(2) seven-factor story
10.  TDSAT appeal — 60 days, sufficient cause, 6-month endeavour
11.  Mediation — s.31 Board-directed settlement track
12.  E-sign harmonisation — consent records that survive evidence scrutiny
13.  INDRP + WHOIS — phishing domain using your brand to harvest data
14.  Phishing + blocking — s.37 DPDP vs s.69A IT Act takedown routes
15.  Intermediary clock — reports, acknowledgement and GAC/69A overlay
16.  E-commerce seller + platform — who owns the customer-data breach
17.  Dark patterns vs DPDP consent — when UI itself voids consent
18.  Section 37 blocking deep-dive — the 2-penalty gate most blogs skip

## SDF readiness — will the Government notify us as Significant

Large hospital chain, NBFC, edtech or platform with volume/sensitive data does not know if SDF duties will hit.

What it involvess.10(1) factors: volume/sensitivity, rights-risk, sovereignty/integrity impact, electoral-democracy risk, State security, public order. s.10 commences May 2027 (G.S.R. 843(E)); SDF status arises only on notification.

Relevant laws.10(1); DPDP Rules r.13 (annual DPIA + audit with report to Board, algorithmic due diligence, localisation of Government-specified data).

ForumNotification watch; Board applies SDF duties only if notified.

Procedure & stageSelf-score on six factors → build SDF-ready posture (DPO/DPIA/audit) without claiming SDF status → diary MeitY notifications + May 2027.

RemedyReady posture; duties trigger only on notification.

High Court connectionSDF notification vires, if cause of action in Kerala, testable under Art.226; merits of SDF compliance go Board → TDSAT.

Documents normally requiredVolume/sensitivity note, risk note, readiness tracker.

Limitations.10 in force May 2027; SDF duties attach only on notification.

**Big database = automatically SDF?**

No. SDF status needs Central Government notification under s.10(1). Bigness is a factor, not the notification.

## DPO appointment — India-based, Board-facing, grievance-owning

Company names a foreign privacy lead or a junior inbox-manager as DPO.

What it involvess.10(2)(a): DPO represents the SDF under the Act; based in India; responsible to Board of Directors/similar governing body; point of contact for grievance redressal.

Relevant laws.10(2)(a); ss.8(9)–(10) contact/mechanism; s.33 Schedule Sl.4 (up to Rs.150 cr for s.10 breach, Consolidated Fund of India).

ForumBoard on SDF-breach inquiry.

Procedure & stageIndia-based appointment → Board-reporting line in writing → publish contact (s.8(9)) → own grievance SLA → keep independence from business targets.

RemedyCompliant appointment + mitigation record.

High Court connectionDPO-breach findings go Board → TDSAT (60 days); service/employment terms of the DPO herself go to Kerala labour/civil fora per contract.

Documents normally requiredAppointment letter, reporting-line proof, published contact, grievance ownership note.

LimitationOn SDF notification (s.10 in force May 2027).

**Can the IT head double as DPO?**

Only with a real s.10(2)(a) mandate, India base, governing-body reporting and grievance ownership — plus conflict management. Form over substance fails.

## DPIA drafting — description, risk, management for SDF processing

New lending, health or edtech rollout launches with no written risk review.

What it involvess.10(2)(c)(i): periodic DPIA = description of principals' rights + processing purpose, assessment/management of rights-risk, other prescribed matters.

Relevant laws.10(2)(c)(i); DPDP Rules r.13(1)–(2) (DPIA + audit once every 12 months; report of significant observations to the Board); s.33(2) quantum uses mitigation.

ForumInternal SDF record; Board calls for it on inquiry.

Procedure & stageScope → rights/purpose description → risk assess → controls + residual risk → owner + review date → file. Non-SDFs may adopt a lite DPIA as good practice (say so).

RemedyEvidence of organised compliance; absence aggravates SDF breach.

High Court connectionDPIA adequacy is Board fact-finding; writ only for process error.

Documents normally requiredDPIA, control closure evidence, review cadence.

LimitationOnce in every 12 months from SDF notification (r.13(1)); in force May 2027.

**Small business needs a DPIA?**

The Act mandates DPIA only for SDFs. Others may do a proportionate review voluntarily — do not present it as statutory compulsion.

## Independent data audit — auditor who evaluates SDF compliance

Internal team "audits itself" and calls it s.10 compliance.

What it involvess.10(2)(b): appoint independent data auditor to evaluate compliance; plus s.10(2)(c)(ii) periodic audit.

Relevant laws.10(2)(b)–(c); DPDP Rules r.13(1)–(2) (audit once every 12 months; report of significant observations to the Board).

ForumBoard on inquiry calls for reports.

Procedure & stageIndependent appointment → scope (ss.4–10 + Rules) → report → management closure → re-audit cadence.

RemedyAudit trail + mitigation credit; self-audit alone weakens the story.

High Court connectionAuditor appointment disputes are contract matters in Kerala fora; audit findings feed Board inquiries.

Documents normally requiredEngagement letter (independence), report, closure evidence.

LimitationOnce in every 12 months from SDF notification (r.13(1)).

**Statutory auditor can do it?**

Only if independent and competent on data-compliance scope with a proper mandate. Independence + scope matter more than title.

## Gap-audit, ROPA, consent vault and training — the four-file SDF starter

Management wants one "DPDP certificate" instead of working papers.

What it involvesReadiness assessment → Record of Processing Activities → consent/notice vault (s.6(10)) → staff training. No "certificate" exists under the Act.

Relevant lawss.4–10 (mapped per flow); s.6(10) proof; s.8(4) organisational measures; DPDP Rules r.6 minimum safeguards (encryption/obfuscation/masking/virtual tokens, access control, logs + monitoring, backups, 1-year log retention, processor contract terms) and r.14(3) grievance period (max 90 days); First Schedule Part B item 4(c) — 7-year record retention binds Consent Managers, not every fiduciary.

ForumInternal; Board-ready on inquiry.

Procedure & stageQuestionnaire → Red/Amber/Green findings → ROPA (purpose, data, base, sharing, retention, vendor) → vault → role-wise training + drill.

RemedyRoadmap (now / before May 2027 / ongoing); mitigation evidence.

High Court connectionWorking papers anchor Kerala grievance/Board replies; writ does not assess their adequacy on merits.

Documents normally requiredQuestionnaire, ROPA, vault exports, training attendance + material.

LimitationMay 2027 full posture (Rules r.3, 5–16 in force 18 months from 13.11.2025).

**Template pack = compliant?**

No. Templates are a start; populated, versioned, Kerala-specific working papers are the compliance.

## Board complaint drafting — s.27(1)(b) after grievance exhaust

Principal files a narrative grievance with no exhaust proof, no breach pinning, no relief shaped to Board powers.

What it involvess.27(1)(b): Board inquires on principal complaint (breach / fiduciary-obligation breach / rights denial), Government reference, or court direction. s.13(3) exhaust-first applies.

Relevant lawss.13(3), 27(1)(b), 28 (screening, natural justice, civil-court powers, interim orders, costs for false complaints).

ForumBoard as digital office (s.28(1)).

Procedure & stageGrievance + wait out the published response period (max 90 days, r.14(3)) → complaint with parties, facts, sections breached, exhaust proof, evidence, relief (direction/penalty/inquiry) → track digitally.

RemedyInquiry → interim order (s.28(10)) / direction (s.27(2)) / penalty if significant breach (s.33, Consolidated Fund of India) / closure with reasons (s.28(4)/(11)). Compensation needs civil suit.

High Court connectionKerala complainants file digitally; Kerala HC writ only for Board-process illegality. Keep Kerala-addressed exhaust proof.

Documents normally requiredGrievance + delivery/wait proof, breach/rights evidence, ID, relief note.

LimitationComplaint route (s.27) from May 2027; grievance period max 90 days (r.14(3)); Board inquiry to finish within 6 months, extendable by up to 3 months at a time (r.19(9)); TDSAT 60 days on Board order.

**Board will get my money back?**

No. It can direct and penalise (penalty to Consolidated Fund of India). Money needs a civil suit.

## Voluntary undertaking — s.32 corporate-probation strategy

Fiduciary wants to fix quickly and close proceedings without a contested penalty order.

What it involvess.32: undertaking at any stage of s.28 proceedings (do/stop by date, publicise); Board may vary with consent; acceptance bars proceedings on those contents — unless breached, when breach = Act breach → s.33 (s.32(5)).

Relevant laws.32; ss.28, 33.

ForumBoard during inquiry.

Procedure & stagePropose specific, dated, verifiable actions + publication → seek acceptance → comply + file proof → if terms need change, seek s.32(3) variation (do not self-vary).

RemedyClosure on those contents if honoured; full penalty machinery on breach.

High Court connectionUndertaking acceptance/breach findings go to TDSAT (60 days); writ only for hearing-fairness issues.

Documents normally requiredDraft undertaking, compliance timeline, publication + closure proof.

LimitationBoard-fixed dates inside the undertaking — diary strictly.

**Undertaking = admission of guilt for civil suits?**

It is a Board-recorded commitment with publication. Take advice on civil-suit spillover before wording it.

## How the Board starts — breach intimation, reference, court direction, suo-motu screen

Business assumes the Board only acts on victim complaints and ignores intimation/reference routes.

What it involvess.27(1)(a)–(e): (a) s.8(6) breach intimations (urgent remedial/mitigation + inquiry + penalty); (b) principal complaints/references/court directions; (c) Manager complaints; (d) Manager-registration breach; (e) s.37(2) intermediary reference. s.28 screening: sufficient grounds? If not, close with reasons (s.28(4)); if yes, reasoned inquiry (s.28(5)) on natural justice (s.28(6)).

Relevant lawss.27–28; s.37(2).

ForumBoard (digital).

Procedure & stageIntake → s.28(3) screen → close or inquire (civil-court powers s.28(7); no disruptive seizure s.28(8); police/Govt assistance s.28(9); interim orders s.28(10)) → close or s.33.

RemedyDirection/penalty or reasoned closure; costs/warning for false complaints (s.28(12)).

High Court connectionKerala HC directions to the Board (in writs) arrive via s.27(1)(b); challenges to Board screening go TDSAT/writ on legality only.

Documents normally requiredIntimation/complaint/reference + annexures, reply with section-wise rebuttal + mitigation file.

LimitationBoard-directed timelines in notices; TDSAT 60 days after order.

**Board officers can seize servers?**

s.28(8) bars preventing premises access or seizing equipment/items that would hurt day-to-day functioning. Cooperate and record.

## Mitigation for quantum — s.33(2) seven-factor story

Notice/consent/safeguard lapse admitted; business wants the number contained.

What it involvess.33(1) (penalty only if breach significant, after hearing, per Schedule) + s.33(2)(a)–(g): nature/gravity/duration; data type; repetition; gain/avoidance; mitigation timeliness/effectiveness; proportionality/deterrence; impact on person.

Relevant laws.33 + Schedule (250/200/200/150 cr, Rs.10k, undertaking-linked, 50 cr residuary).

ForumBoard inquiry; TDSAT on quantum.

Procedure & stageAdmit-or-contest clearly → file mitigation bundle (timeline, notices, fixes, spend, cooperation, no repetition, proportionality note) → argue per factor → consider s.32/s.31 → appeal quantum if needed.

RemedyLower/withdrawn penalty or undertaking-closure; penalty if imposed goes to Consolidated Fund of India.

High Court connectionQuantum appeals to TDSAT (60 days); writ only for perverse/non-speaking orders or hearing denial.

Documents normally requiredBreach timeline, notice/delivery proof, fix invoices, cooperation record, financial-impact note (audited where claimed).

LimitationTDSAT 60 days from receipt.

**First offence = no penalty?**

No. First-time status helps under repetition/proportionality but the Act has no first-offence immunity. Show full mitigation.

## TDSAT appeal — 60 days, sufficient cause, 6-month endeavour

Board order/direction received; business or complainant misses the appeal mechanics.

What it involvess.29(1)–(2): any person aggrieved appeals to Appellate Tribunal (TDSAT) within 60 days of receipt, filed digitally with the same fee as a TRAI Act appeal unless reduced/waived by the TDSAT Chairperson (DPDP Rules r.22); s.29(3) delay condonation on sufficient cause; s.29(4)–(7) hearing + confirm/modify/set-aside + 6-month endeavour (reasons if longer); s.29(9) further appeal to Supreme Court via TRAI Act s.18; s.30 execution as civil decree.

Relevant lawss.29–30; TRAI Act ss.14A/16/18 procedure overlay (as applied).

ForumTDSAT (functions digitally as far as practicable, s.29(10)); then Supreme Court on law.

Procedure & stageCompute 60 days from receipt → file with fee + condonation affidavit if late → seek stay/modification on merits → within TDSAT, push for 6-month disposal.

RemedyConfirm/modify/set-aside; TDSAT order executable as decree (s.30), transmittable to local civil court.

High Court connectionKerala HC writ remains for Board-process illegality or Art.21 issues, but the statutory appeal is TDSAT; choose forum deliberately and watch limitation on both tracks.

Documents normally requiredBoard order + receipt proof, appeal memo, fee, stay application, condonation affidavit if late.

Limitation60 days (s.29(2)); extension only on sufficient cause (s.29(3)). TDSAT-to-SC per TRAI Act s.18 timelines.

**File writ instead of TDSAT to save time?**

The Act bars civil courts (s.39) and channels appeals to TDSAT. Writs test legality/fairness, not merits. Get forum advice fast — limitation runs.

## Mediation — s.31 Board-directed settlement track

Complaint capable of practical fix (correction, deletion, process change) heads for a full penalty contest.

What it involvess.31: if Board thinks complaint resolvable by mediation, it directs parties to attempt it via mutually-agreed mediator or under any law in force.

Relevant laws.31; general mediation law continues (s.38).

ForumBoard → mediator.

Procedure & stageSignal willingness early → agree mediator → settle scope (fix + timeline, no penalty admission beyond facts) → report back to Board.

RemedyPractical closure; penalty track paused to the extent resolved. Victim money still needs civil settlement/deed if claimed.

High Court connectionKerala mediation centres/courts may host the sitting per agreement; Board records outcome.

Documents normally requiredSettlement draft, compliance proof, consent terms.

LimitationBoard-directed mediation window — diary strictly.

**Mediation = no penalty ever?**

No. It resolves what it resolves; significant-breach penalty remains Board's call under s.33.

## E-sign harmonisation — consent records that survive evidence scrutiny

Clickwrap consent challenged as "no signature, no proof."

What it involvesDPDP ss.5–6 + s.6(10) proof read with IT Act ss.3/3A (electronic/digital signatures), s.10A (e-contract validity), BSA 2023 s.63 conditions for electronic records (dual certificates; BSA in force 01.07.2024).

Relevant lawDPDP ss.5, 6(10); IT Act ss.3, 3A, 10A; BSA 2023 s.63 certificate practice (dual certificates; BSA in force 01.07.2024).

ForumBoard (DPDP proof) + civil/criminal courts (record admissibility).

Procedure & stageBind notice version + identity + affirmative action + timestamp (hash/log) → retain BSA 2023 s.63-ready dual-certificate path → produce vault + certificate on inquiry/trial.

RemedyAdmissible, weight-carrying consent proof.

High Court connectionKerala courts test BSA 2023 s.63 compliance strictly (dual certificates; BSA in force 01.07.2024); build the certificate chain at collection, not after dispute.

Documents normally requiredVault schema, hash/log samples, BSA 2023 s.63 dual-certificate draft, signer/identity method note.

LimitationContinuous; produce within Board/court-directed time.

**OTP click = signature?**

It evidences assent if tied to identity + notice version + purpose. Loose clicks without that binding fail s.6(10).

## INDRP + WHOIS — phishing domain using your brand to harvest data

Lookalike.in domain collects Kerala customer data in your brand's name.

What it involves.IN Registry INDRP (bad-faith registration/use) + registrar/WHOIS disclosure path + DPDP ss.8(5)–(6) if your customers' data is harvested (your notice/breach duties unaffected by the fraud).

Relevant lawINDRP Policy (.IN) + IT Act intermediary/takedown overlay; DPDP ss.8(5)–(6) for your own breach duties; Trade Marks Act, 1999 for brand rights where registered.

ForumINDRP arbitrator (NIXI) for transfer/cancellation; registrar for takedown/suspension; Board only for your DPDP duties; criminal complaint for fraud.

Procedure & stagePreserve phishing capture + victim trail → registrar abuse report → INDRP filing (confusing similarity + your rights + no legitimate interest + bad faith) → parallel police complaint → warn customers without admitting DPDP breach you did not cause.

RemedyDomain transfer/cancellation/suspension; fraud prosecution; DPDP mitigation record for your own notice to affected users if needed.

High Court connectionINDRP arbitration runs under the Arbitration and Conciliation Act, 1996, seated at Delhi; Delhi courts have exclusive jurisdiction over it (INDRP Policy). Brand suits lie in Kerala civil courts per jurisdiction.

Documents normally requiredWHOIS history, phishing captures, trademark proof, victim complaints, registrar correspondence.

LimitationFile fast — phishing domains move quickly.

**WHOIS is redacted — how to find the holder?**

Through registrar abuse/LEA disclosure channels and INDRP pleadings. Do not publish unverified attributions.

## Phishing + blocking — s.37 DPDP vs s.69A IT Act takedown routes

Team cites "DPDP blocking" for every abusive site.

What it involvesDPDP s.37: only after Board has imposed penalty 2+ times + public-interest advice, Central Government after hearing may order blocking of information enabling that fiduciary's India offering (via agency/intermediary; intermediary bound, s.37(2)). IT Act s.69A: separate Government blocking for sovereignty/security/public order etc. with its own procedure.

Relevant lawDPDP s.37; IT Act s.69A + Blocking Rules, 2009; IT Act s.79 + Intermediary Rules for platform reports.

ForumCentral Government (blocking); intermediary compliance; Board reference underlying s.37.

Procedure & stageFor s.37: show 2+ penalties + hearing + public-interest order (rare, slow). For live phishing: platform report + police complaint + s.69A/executive route via competent authority — faster practical track.

RemedyAccess-blocking; DPDP penalty track unaffected.

High Court connectionBlocking orders tested in constitutional courts (Shreya Singhal / Art.19(2) proportionality backdrop); Kerala cause of action → Kerala HC Art.226 where maintainable.

Documents normally requiredPenalty orders (for s.37), phishing evidence, platform/police reports.

LimitationPlatform/police track immediately; s.37 is post-penalty and slow.

**One Board penalty = site blocked?**

No. s.37 needs 2+ penalties + advice + hearing + public-interest satisfaction. Do not promise blocking.

## Intermediary clock — reports, acknowledgement and GAC/69A overlay

Marketplace/social platform ignores a Kerala user's data-misuse report; user mixes DPDP grievance with platform grievance.

What it involvesIT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 as amended by G.S.R. 120(E) dt 10.02.2026 (in force 20.02.2026): grievance acknowledged in 24 hrs, resolved in 7 days (r.3(2)(a)(i)); removal requests on most r.3(1)(b) content resolved in 36 hrs (proviso); 3-hr removal on court order/authorised Government intimation (r.3(1)(d)); 2-hr action on intimate-image/impersonation complaints (r.3(2)(b)); appeal to Grievance Appellate Committee within 30 days of the Grievance Officer's communication (r.3A(3)); DPDP ss.8/13/27 run separately against the fiduciary.

Relevant lawIT Act s.79 + Intermediary Rules, 2021 (as amended to 10.02.2026); DPDP ss.13, 27 for the fiduciary track.

ForumPlatform grievance officer → GAC (for intermediary track); fiduciary grievance → Board (for DPDP track). Run both, do not conflate.

Procedure & stageFile platform report (receipt ID) → escalate to GAC in-window → parallel s.13 grievance to the fiduciary → Board on DPDP failure.

RemedyContent/action on platform track; DPDP direction/penalty on fiduciary track (Consolidated Fund of India).

High Court connectionGAC/platform orders and blocking directions tested in writ courts on legality; DPDP merits go TDSAT.

Documents normally requiredPlatform receipts, content URLs/captures, fiduciary grievance proof.

LimitationPlatform: acknowledge 24 hrs / resolve 7 days (r.3(2)(a)(i)); GAC appeal within 30 days (r.3A(3)); TDSAT 60 days for DPDP appeal.

**Platform removed the post — DPDP complaint over?**

Not necessarily. Removal fixes the post; unlawful processing/breach history still answers under DPDP.

## E-commerce seller + platform — who owns the customer-data breach

Seller's buyer list leaks via platform API or seller's own download; each blames the other.

What it involvesRole test (Data Fiduciary vs Data Processor, s.2(i)/(k)) + s.8(1) non-delegable duty + s.8(2) contracts + Consumer Protection (E-Commerce) Rules, 2020 duties alongside.

Relevant lawDPDP ss.2(i)/(k), 8; Consumer Protection Act, 2019 + E-commerce Rules, 2020 (platform/seller duties); IT Act intermediary overlay where applicable.

ForumBoard (DPDP) + consumer commissions (service deficiency) + civil court (damages/indemnity).

Procedure & stageClassify per flow (platform-as-fiduciary vs processor) → DPA/API terms → breach-notice ownership → consumer-case defence on facts.

RemedyBoard direction/penalty (Consolidated Fund of India); consumer relief (refund/compensation) in commissions; inter-party recovery by suit.

High Court connectionKerala consumer commissions/civil courts handle buyer claims locally; Board/TDSAT handle DPDP.

Documents normally requiredPlatform-seller agreement, API scope, breach forensics, buyer notices.

LimitationConsumer complaint within 2 years of cause of action (CPA s.69); breach intimation to the Board without delay + detailed report within 72 hrs (DPDP Rules r.7(2)); grievance reply within the published period, max 90 days (DPDP Rules r.14(3)); TDSAT 60 days on Board orders.

**Platform terms say seller owns all data risk — enough?**

Not for the Board (s.8(1)). It governs inter-party recovery only.

## Dark patterns vs DPDP consent — when UI itself voids consent

Nagging, false urgency, basket-sneaking or disguised ads manufacture "consent."

What it involvesDPDP s.6(1) (free/specific/informed/unconditional/unambiguous + affirmative action) read with CCPA Guidelines for Prevention and Regulation of Dark Patterns, 2023 (specified patterns) under the CPA, 2019.

Relevant lawDPDP s.6; CPA, 2019 + CCPA Dark Pattern Guidelines, 2023; E-commerce Rules, 2020.

ForumBoard (consent validity) + consumer commissions/CCPA (dark-pattern practice).

Procedure & stagePattern audit (nagging, pre-tick, trick wording, guilt-shaming) → rebuild affirmative, symmetrical choices → keep withdrawal as easy as consent (s.6(4)).

RemedyValid-consent posture; dark-pattern direction/penalty on consumer track; DPDP penalty on consent-failure track (Consolidated Fund of India).

High Court connectionConsumer orders appealed in Kerala consumer appellate fora; DPDP validity goes Board → TDSAT.

Documents normally requiredScreen recordings, copy deck, consent/withdrawal symmetry proof.

LimitationMay 2027 DPDP posture; dark-pattern enforcement is live now — fix immediately.

**Small pop-up trick — really a legal issue?**

Yes, on both tracks: it undermines s.6 "free/unambiguous" consent and matches listed dark patterns. Fix the UI, not just the text.

## Section 37 blocking deep-dive — the 2-penalty gate most blogs skip

Advice promises "we will get the app blocked" after one leak.

What it involvess.37(1): Board reference in writing intimating 2+ penalty instances + public-interest blocking advice → Central Government/officer, after hearing the fiduciary, if satisfied necessary/expedient in public interest with recorded reasons, orders agency/intermediary to block information enabling that fiduciary's India offering. s.37(2): intermediary bound. Definitions via IT Act (s.37(3)).

Relevant laws.37; IT Act meanings (computer resource/information/intermediary).

ForumCentral Government on Board reference; intermediary executes.

Procedure & stageTwo penalties → reference → hearing → reasoned public-interest order → intermediary blocking. One penalty is insufficient on text.

RemedyAccess-blocking in India; penalties themselves already to Consolidated Fund of India.

High Court connections.37 orders are reasoned State action testable under Art.226 (proportionality, hearing) with Kerala cause of action where applicable.

Documents normally requiredBoth penalty orders, reference, hearing record, blocking order.

LimitationNo DPDP day-count; blocking-rule procedure timelines apply to execution.

**Victim can seek blocking directly?**

No. s.37 runs only on Board reference after 2+ penalties. Victims use platform report + police + civil suit in the meantime.

More in this area

## Data protection & DPDP compliance: other matters

-   [Applicability, data fiduciaries, notices and consent](https://advaslam.com/practice/data-protection/matters/applicability-fiduciary-notices-consent/)
-   [Rights, children, employees, CCTV and retention](https://advaslam.com/practice/data-protection/matters/rights-children-employee-cctv-retention/)
-   [Vendors, security, breach and grievances](https://advaslam.com/practice/data-protection/matters/vendor-security-breach-grievance/)
-   Significant data fiduciaries, the Board, TDSAT, e-sign and domains
-   [AI governance and compliance](https://advaslam.com/practice/data-protection/matters/ai-governance/)

[Every matter in this area, on one page →](https://advaslam.com/practice/data-protection/matters/)
[Data protection & DPDP compliance: the practice area →](https://advaslam.com/practice/data-protection/)

Procedure guides

-   [DPDP Readiness Checklist for Small Business](https://advaslam.com/guides/dpdp-readiness-checklist-small-business/)

Contact

[WhatsApp](https://wa.me/919497240215?text=Hello%2C%20I%20found%20advaslam.com%20and%20would%20like%20to%20discuss%20a%20matter.) [contact@advaslam.com](mailto:contact@advaslam.com) [+91 94972 40215](tel:+919497240215)

3rd Floor, Lalan Towers (KGL Builders), Vanchi Square, High Court Junction, Ernakulam, Kerala 682031 · Monday – Saturday, 10:00 – 18:30 (by appointment)

```json
{"@context":"https://schema.org","@graph":[{"@type":"WebSite","@id":"https://advaslam.com/#website","url":"https://advaslam.com","name":"Adv. K J Muhammed Aslam","alternateName":"advaslam.com","publisher":{"@id":"https://advaslam.com/#person"},"inLanguage":"en-IN"},{"@type":"Person","@id":"https://advaslam.com/#person","name":"K J Muhammed Aslam","alternateName":["Adv. K J Muhammed Aslam","Advocate K J Muhammed Aslam","Muhammed Aslam K J","Adv. Aslam"],"honorificPrefix":"Adv.","jobTitle":"Advocate","description":"Advocate enrolled with the Bar Council of Kerala, practising from High Court Junction, Ernakulam: cyber and technology law, data protection (DPDP), business, banking and IPR, and litigation before the High Court of Kerala and the courts at Ernakulam.","url":"https://advaslam.com/profile/","image":"https://advaslam.com/og.png","telephone":"+919497240215","email":"contact@advaslam.com","address":{"@type":"PostalAddress","streetAddress":"3rd Floor, Lalan Towers (KGL Builders), Vanchi Square, High Court Junction","addressLocality":"Ernakulam","addressRegion":"Kerala","postalCode":"682031","addressCountry":"IN"},"alumniOf":{"@type":"CollegeOrUniversity","name":"Bharata Mata School of Legal Studies"},"memberOf":[{"@type":"Organization","name":"Bar Council of Kerala","url":"https://barcouncilkerala.org/lawyer-registry-list"},{"@type":"Organization","name":"Kerala High Court Advocates' Association","url":"https://khcaa.com/"}],"identifier":[{"@type":"PropertyValue","propertyID":"Bar Council of Kerala Enrolment No.","value":"K/001823/2026"},{"@type":"PropertyValue","propertyID":"KHCAA Membership No.","value":"OAJ 358"}],"knowsAbout":["Information Technology Act 2000","Cyber crime law","Technology law and technology contracts","Digital Personal Data Protection Act 2023","DPDP compliance","Data protection and privacy law","Business and commercial law","Contract drafting and negotiation","Banking and finance law","Negotiable Instruments Act cheque dishonour","SARFAESI Act","Intellectual property law","Copyright and trademark law","Patent infringement","GST and income-tax law","Blockchain and cryptocurrency technology","Web3 wallets and NFTs","Drone regulation and DigitalSky framework","Writ petitions under Article 226","Criminal law","Civil and consumer litigation","Family and succession law","Service and labour law","Legal drafting","Mediation and dispute resolution"],"knowsLanguage":["en","ml"],"workLocation":{"@id":"https://advaslam.com/#practice"},"hasCredential":[{"@type":"EducationalOccupationalCredential","credentialCategory":"Enrolment as an advocate","identifier":"K/001823/2026","recognizedBy":{"@type":"Organization","name":"Bar Council of Kerala"},"description":"Enrolled as an advocate with the Bar Council of Kerala (K/001823/2026), 2026"},{"@type":"EducationalOccupationalCredential","credentialCategory":"degree","educationalLevel":"Bachelor","recognizedBy":{"@type":"CollegeOrUniversity","name":"Bharata Mata School of Legal Studies"},"description":"BBA LLB (Hons.), Bharata Mata School of Legal Studies (2025)"},{"@type":"EducationalOccupationalCredential","credentialCategory":"Remote Pilot Certificate","recognizedBy":{"@type":"Organization","name":"Directorate General of Civil Aviation, India"},"description":"DGCA Remote Pilot Certificate, issued 2022"}],"subjectOf":[{"@type":"CreativeWork","name":"Govind Babu v. State of Kerala (Crl.M.C. No. 5640 of 2026, 2026:KER:69496)","url":"https://indiankanoon.org/doc/151180872/","datePublished":"2026-09-10","publisher":{"@type":"Organization","name":"High Court of Kerala"}},{"@type":"CreativeWork","name":"Viji Sagar v. State of Kerala (Crl.M.C. No. 1603 of 2026, 2026:KER:20803)","url":"https://indiankanoon.org/doc/193042273/","datePublished":"2026-03-09","publisher":{"@type":"Organization","name":"High Court of Kerala"}},{"@type":"CreativeWork","name":"Anjana v. Manoharan A.P. (C.R.P. No. 442 of 2025, 2026:KER:10054)","url":"https://indiankanoon.org/doc/68585852/","datePublished":"2026-02-05","publisher":{"@type":"Organization","name":"High Court of Kerala"}}],"sameAs":["https://www.linkedin.com/in/azlubro","https://portal.khcaa.com/advocate?id=10480","https://lexosys.com"]},{"@type":"LegalService","@id":"https://advaslam.com/#practice","name":"Adv. K J Muhammed Aslam — Advocate, Ernakulam","url":"https://advaslam.com","image":"https://advaslam.com/og.png","telephone":"+919497240215","email":"contact@advaslam.com","address":{"@type":"PostalAddress","streetAddress":"3rd Floor, Lalan Towers (KGL Builders), Vanchi Square, High Court Junction","addressLocality":"Ernakulam","addressRegion":"Kerala","postalCode":"682031","addressCountry":"IN"},"geo":{"@type":"GeoCoordinates","latitude":9.9889,"longitude":76.2748},"hasMap":"https://www.google.com/maps/search/?api=1&query=Lalan+Towers+High+Court+Junction+Ernakulam","areaServed":[{"@type":"City","name":"Ernakulam"},{"@type":"City","name":"Kochi"},{"@type":"State","name":"Kerala"},{"@type":"Country","name":"India"}],"openingHoursSpecification":{"@type":"OpeningHoursSpecification","dayOfWeek":["Monday","Tuesday","Wednesday","Thursday","Friday","Saturday"],"opens":"10:00","closes":"18:30"},"founder":{"@id":"https://advaslam.com/#person"},"knowsAbout":["Cyber crime and IT Act matters","Data protection and DPDP Act compliance","Business, banking, intellectual property and tax","Legal drafting","Criminal law: bail, quash and appeals","Writ petitions before the High Court of Kerala","Civil, property and consumer matters","Family and succession matters","Service and labour matters"]},{"@type":"CollectionPage","name":"Significant data fiduciaries, the Board, TDSAT, e-sign and domains","description":"Significant data fiduciaries, the Board, TDSAT, e-sign and domains: 18 matters, each with the law, forum, procedure, documents and limitation. SDF…","url":"https://advaslam.com/practice/data-protection/matters/sdf-board-tdsat-esign-domain/","inLanguage":"en-IN","dateModified":"2026-09-28T00:00:00.000Z","isPartOf":{"@id":"https://advaslam.com/#website"},"author":{"@id":"https://advaslam.com/#person"},"mainEntity":{"@type":"ItemList","numberOfItems":18,"itemListElement":[{"@type":"ListItem","position":1,"name":"SDF readiness — will the Government notify us as Significant","url":"https://advaslam.com/practice/data-protection/matters/sdf-board-tdsat-esign-domain/#sdf-readiness-will-the-government-notify-us-as-significant"},{"@type":"ListItem","position":2,"name":"DPO appointment — India-based, Board-facing, grievance-owning","url":"https://advaslam.com/practice/data-protection/matters/sdf-board-tdsat-esign-domain/#dpo-appointment-india-based-board-facing-grievance-owning"},{"@type":"ListItem","position":3,"name":"DPIA drafting — description, risk, management for SDF processing","url":"https://advaslam.com/practice/data-protection/matters/sdf-board-tdsat-esign-domain/#dpia-drafting-description-risk-management-for-sdf-processing"},{"@type":"ListItem","position":4,"name":"Independent data audit — auditor who evaluates SDF compliance","url":"https://advaslam.com/practice/data-protection/matters/sdf-board-tdsat-esign-domain/#independent-data-audit-auditor-who-evaluates-sdf-compliance"},{"@type":"ListItem","position":5,"name":"Gap-audit, ROPA, consent vault and training — the four-file SDF starter","url":"https://advaslam.com/practice/data-protection/matters/sdf-board-tdsat-esign-domain/#gap-audit-ropa-consent-vault-and-training-the-four-file-sdf-starter"},{"@type":"ListItem","position":6,"name":"Board complaint drafting — s.27(1)(b) after grievance exhaust","url":"https://advaslam.com/practice/data-protection/matters/sdf-board-tdsat-esign-domain/#board-complaint-drafting-s271b-after-grievance-exhaust"},{"@type":"ListItem","position":7,"name":"Voluntary undertaking — s.32 corporate-probation strategy","url":"https://advaslam.com/practice/data-protection/matters/sdf-board-tdsat-esign-domain/#voluntary-undertaking-s32-corporate-probation-strategy"},{"@type":"ListItem","position":8,"name":"How the Board starts — breach intimation, reference, court direction, suo-motu screen","url":"https://advaslam.com/practice/data-protection/matters/sdf-board-tdsat-esign-domain/#how-the-board-starts-breach-intimation-reference-court-direction-suo-motu-screen"},{"@type":"ListItem","position":9,"name":"Mitigation for quantum — s.33(2) seven-factor story","url":"https://advaslam.com/practice/data-protection/matters/sdf-board-tdsat-esign-domain/#mitigation-for-quantum-s332-seven-factor-story"},{"@type":"ListItem","position":10,"name":"TDSAT appeal — 60 days, sufficient cause, 6-month endeavour","url":"https://advaslam.com/practice/data-protection/matters/sdf-board-tdsat-esign-domain/#tdsat-appeal-60-days-sufficient-cause-6-month-endeavour"},{"@type":"ListItem","position":11,"name":"Mediation — s.31 Board-directed settlement track","url":"https://advaslam.com/practice/data-protection/matters/sdf-board-tdsat-esign-domain/#mediation-s31-board-directed-settlement-track"},{"@type":"ListItem","position":12,"name":"E-sign harmonisation — consent records that survive evidence scrutiny","url":"https://advaslam.com/practice/data-protection/matters/sdf-board-tdsat-esign-domain/#e-sign-harmonisation-consent-records-that-survive-evidence-scrutiny"},{"@type":"ListItem","position":13,"name":"INDRP + WHOIS — phishing domain using your brand to harvest data","url":"https://advaslam.com/practice/data-protection/matters/sdf-board-tdsat-esign-domain/#indrp-whois-phishing-domain-using-your-brand-to-harvest-data"},{"@type":"ListItem","position":14,"name":"Phishing + blocking — s.37 DPDP vs s.69A IT Act takedown routes","url":"https://advaslam.com/practice/data-protection/matters/sdf-board-tdsat-esign-domain/#phishing-blocking-s37-dpdp-vs-s69a-it-act-takedown-routes"},{"@type":"ListItem","position":15,"name":"Intermediary clock — reports, acknowledgement and GAC/69A overlay","url":"https://advaslam.com/practice/data-protection/matters/sdf-board-tdsat-esign-domain/#intermediary-clock-reports-acknowledgement-and-gac69a-overlay"},{"@type":"ListItem","position":16,"name":"E-commerce seller + platform — who owns the customer-data breach","url":"https://advaslam.com/practice/data-protection/matters/sdf-board-tdsat-esign-domain/#e-commerce-seller-platform-who-owns-the-customer-data-breach"},{"@type":"ListItem","position":17,"name":"Dark patterns vs DPDP consent — when UI itself voids consent","url":"https://advaslam.com/practice/data-protection/matters/sdf-board-tdsat-esign-domain/#dark-patterns-vs-dpdp-consent-when-ui-itself-voids-consent"},{"@type":"ListItem","position":18,"name":"Section 37 blocking deep-dive — the 2-penalty gate most blogs skip","url":"https://advaslam.com/practice/data-protection/matters/sdf-board-tdsat-esign-domain/#section-37-blocking-deep-dive-the-2-penalty-gate-most-blogs-skip"}]}},{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://advaslam.com/"},{"@type":"ListItem","position":2,"name":"Practice","item":"https://advaslam.com/practice/"},{"@type":"ListItem","position":3,"name":"Data protection & DPDP compliance","item":"https://advaslam.com/practice/data-protection/"},{"@type":"ListItem","position":4,"name":"Matters","item":"https://advaslam.com/practice/data-protection/matters/"},{"@type":"ListItem","position":5,"name":"Significant data fiduciaries, the Board, TDSAT, e-sign and domains","item":"https://advaslam.com/practice/data-protection/matters/sdf-board-tdsat-esign-domain/"}]},{"@type":"FAQPage","@id":"https://advaslam.com/practice/data-protection/matters/sdf-board-tdsat-esign-domain/#faq","isPartOf":{"@id":"https://advaslam.com/#website"},"mainEntity":[{"@type":"Question","name":"Big database = automatically SDF?","acceptedAnswer":{"@type":"Answer","text":"No. SDF status needs Central Government notification under s.10(1). Bigness is a factor, not the notification."}},{"@type":"Question","name":"Can the IT head double as DPO?","acceptedAnswer":{"@type":"Answer","text":"Only with a real s.10(2)(a) mandate, India base, governing-body reporting and grievance ownership — plus conflict management. Form over substance fails."}},{"@type":"Question","name":"Small business needs a DPIA?","acceptedAnswer":{"@type":"Answer","text":"The Act mandates DPIA only for SDFs. Others may do a proportionate review voluntarily — do not present it as statutory compulsion."}},{"@type":"Question","name":"Statutory auditor can do it?","acceptedAnswer":{"@type":"Answer","text":"Only if independent and competent on data-compliance scope with a proper mandate. Independence + scope matter more than title."}},{"@type":"Question","name":"Template pack = compliant?","acceptedAnswer":{"@type":"Answer","text":"No. Templates are a start; populated, versioned, Kerala-specific working papers are the compliance."}},{"@type":"Question","name":"Board will get my money back?","acceptedAnswer":{"@type":"Answer","text":"No. It can direct and penalise (penalty to Consolidated Fund of India). Money needs a civil suit."}},{"@type":"Question","name":"Undertaking = admission of guilt for civil suits?","acceptedAnswer":{"@type":"Answer","text":"It is a Board-recorded commitment with publication. Take advice on civil-suit spillover before wording it."}},{"@type":"Question","name":"Board officers can seize servers?","acceptedAnswer":{"@type":"Answer","text":"s.28(8) bars preventing premises access or seizing equipment/items that would hurt day-to-day functioning. Cooperate and record."}},{"@type":"Question","name":"First offence = no penalty?","acceptedAnswer":{"@type":"Answer","text":"No. First-time status helps under repetition/proportionality but the Act has no first-offence immunity. Show full mitigation."}},{"@type":"Question","name":"File writ instead of TDSAT to save time?","acceptedAnswer":{"@type":"Answer","text":"The Act bars civil courts (s.39) and channels appeals to TDSAT. Writs test legality/fairness, not merits. Get forum advice fast — limitation runs."}},{"@type":"Question","name":"Mediation = no penalty ever?","acceptedAnswer":{"@type":"Answer","text":"No. It resolves what it resolves; significant-breach penalty remains Board's call under s.33."}},{"@type":"Question","name":"OTP click = signature?","acceptedAnswer":{"@type":"Answer","text":"It evidences assent if tied to identity + notice version + purpose. Loose clicks without that binding fail s.6(10)."}},{"@type":"Question","name":"WHOIS is redacted — how to find the holder?","acceptedAnswer":{"@type":"Answer","text":"Through registrar abuse/LEA disclosure channels and INDRP pleadings. Do not publish unverified attributions."}},{"@type":"Question","name":"One Board penalty = site blocked?","acceptedAnswer":{"@type":"Answer","text":"No. s.37 needs 2+ penalties + advice + hearing + public-interest satisfaction. Do not promise blocking."}},{"@type":"Question","name":"Platform removed the post — DPDP complaint over?","acceptedAnswer":{"@type":"Answer","text":"Not necessarily. Removal fixes the post; unlawful processing/breach history still answers under DPDP."}},{"@type":"Question","name":"Platform terms say seller owns all data risk — enough?","acceptedAnswer":{"@type":"Answer","text":"Not for the Board (s.8(1)). It governs inter-party recovery only."}},{"@type":"Question","name":"Small pop-up trick — really a legal issue?","acceptedAnswer":{"@type":"Answer","text":"Yes, on both tracks: it undermines s.6 \"free/unambiguous\" consent and matches listed dark patterns. Fix the UI, not just the text."}},{"@type":"Question","name":"Victim can seek blocking directly?","acceptedAnswer":{"@type":"Answer","text":"No. s.37 runs only on Board reference after 2+ penalties. Victims use platform report + police + civil suit in the meantime."}}]}]}
```
