Contents
- DPA drafting — s.8(2) valid-contract clauses Kerala vendors will sign
- Tiering — processor, sub-processor or second fiduciary
- Cross-border transfer — s.16 blacklist model and what to write in the DPA
- Breach indemnity — who pays when the processor leaks
- Reasonable safeguards checklist — s.8(5) without inventing mandates
- ISO 27001 mapping — using audit language without overclaiming
- Ransomware — when encryption of your own data is a personal data breach
- 72-hour + without-delay notices — Board and each affected principal
- Breach playbook — contain, assess, notify, submit, document, mitigate
- Late notice — delay condonation and mitigation story
- Victim push — breach victim's complaint to the Board
- Grievance mechanism + officer — s.8(10)/s.13 front door that must work
- Grievance SLA — counting the response window without guessing
- Consent Manager grievance — when the dashboard itself fails
- Law-enforcement sharing shield — s.11(2) replies without tipping off
- Accuracy duty — s.8(3) where data decides loans, jobs or admissions
- Publish the contact — s.8(9) DPO or answerable person on the website
- Processor erasure cascade — stopping the copies after stop
DPA drafting — s.8(2) valid-contract clauses Kerala vendors will sign
Business shares customer data with IT, payroll, delivery or marketing vendors on invoices and WhatsApp instructions.
What it involvess.8(2) (processor only under valid contract) + s.8(1) (fiduciary stays liable) + s.8(5)–(7) flow-downs.
Relevant lawss.8(1)–(2), 8(5)–(7); Rules r.6(1)(f) (contract must provide for reasonable security safeguards); s.33 quantum (mitigation, s.33(2)(e)).
ForumCommercial drafting; Board tests the contract on breach/complaint; civil court for indemnity recovery.
Procedure & stageRole clause → instructions-only processing → safeguards + access limits → breach-notify-without-delay + assist → stop/erase cascade → audit + sub-processor control → term + return/delete.
RemedyEnforceable DPA; mitigation credit before Board; inter-party recovery by suit/arbitration.
High Court connectionKerala-seated suits/arbitrations enforce indemnity; Board liability itself is not transferable by contract (s.8(1)).
Documents normally requiredVendor data-flow, existing invoices/MSAs, sub-processor list, access matrix.
Limitations.8 and r.6 commence May 2027 (18 months after the 13 Nov 2025 commencement notification); sign before sharing, not after.
One-page NDA enough?
No. s.8(2) requires a valid contract, and Rules r.6(1)(f) requires it to provide for reasonable security safeguards. An NDA rarely covers instructions-only limits, breach assistance, erasure cascade or audit.
Tiering — processor, sub-processor or second fiduciary
Payment gateway, analytics firm and delivery partner are all labelled "vendors" though one decides purposes itself.
What it involvess.2(i) vs 2(k): who determines purpose+means (fiduciary) vs who acts on behalf under instructions (processor).
Relevant lawss.2(i)/(k), 8(1)–(3); s.11 sharing trail where fiduciary-to-fiduciary.
ForumClassification memo; Board on dispute.
Procedure & stagePurpose-control test per vendor → processor track (DPA) or fiduciary track (own notice/consent + sharing disclosure under s.11(1)(b)) → map sub-processors.
RemedyCorrect track per vendor; s.11 disclosure fixed where second fiduciary exists.
High Court connectionMisclassification surfaces in Kerala consumer/civil suits (who is answerable to the customer) and Board inquiries in parallel.
Documents normally requiredContracts, product specs (who decides what), sharing logs.
Limitations.8 commences May 2027 (18 months after the 13 Nov 2025 commencement notification).
Gateway says it is only a processor — accept that?
Test control, not labels. If it decides fraud-scoring purposes or reuses data, it may be a fiduciary for that slice.
Cross-border transfer — s.16 blacklist model and what to write in the DPA
Kerala startup stores backups or uses support tooling abroad and assumes transfers are banned — or assumes they are free forever.
What it involvess.16(1): Government may by notification restrict transfer to notified countries/territories; s.16(2): higher-protection sectoral laws still apply.
Relevant laws.16; sectoral transfer restrictions continue (s.38); Rules r.15 (transfer abroad subject to requirements the Central Government may specify by general or special order on making data available to a foreign State or its entities); r.13(4) (Significant Data Fiduciaries: specified data not to leave India).
ForumNotification watch; Board on breach; sectoral regulator (RBI/health/finance) for sectoral bars.
Procedure & stageData-map destinations → check s.16(1) notifications and r.15 orders in force → apply sectoral bars (e.g., payment/health) → DPA transfer + safeguard + return clauses → re-check quarterly.
RemedyTransfer discipline + evidence file; direction/penalty only on notified-breach or sectoral breach.
High Court connectionSectoral-transfer disputes with regulators may reach Kerala HC on Art.226; DPDP merits go Board → TDSAT.
Documents normally requiredHosting/support location list, DPA transfer clause, sectoral applicability note.
LimitationCheck the s.16(1) notifications in force before each transfer; s.16 and r.15 commence May 2027 (18 months after the 13 Nov 2025 commencement notification).
US/EU server — automatically illegal?
On Act text, no, unless restricted by a s.16(1) notification or barred by a sectoral law under s.16(2). Check the notifications in force at the time.
Breach indemnity — who pays when the processor leaks
Fiduciary pays Board penalty + victim suits while the at-fault vendor points to a capped invoice.
What it involvess.8(1) (Board penalty stays on fiduciary) vs contract indemnity for civil loss, notice costs and claims.
Relevant lawss.8(1), 8(5)–(6), 33–34 (penalty to Consolidated Fund of India, not recoverable as "compensation"); Indian Contract Act, 1872 for indemnity enforcement.
ForumBoard (penalty, non-transferable) + civil court/arbitration in Kerala per contract (indemnity/damages).
Procedure & stageUncapped breach-notify/assist duties → indemnity for third-party claims + notice/forensics costs → insurance alignment → preservation of recourse evidence.
RemedyContract recovery of civil loss; Board penalty itself is not indemnifiable as a "pass-through fine" — plead it as loss only where contract law permits.
High Court connectionKerala civil courts/arbitral tribunals decide indemnity; writ does not recover money.
Documents normally requiredDPA/MSA, breach forensics, cost invoices, victim-claim papers.
LimitationContract limitation/notice clauses; Board inquiry runs separately.
Can we make the vendor pay the Rs.250 cr penalty?
The Board levies it on the person in breach; whether contract law lets you recover it inter se is a separate civil question. Draft and take advice — do not promise.
Reasonable safeguards checklist — s.8(5) without inventing mandates
Business wants a tick-box "s.8(5)-mandated" list (encryption, 2FA, etc.) to show the Board.
What it involvess.8(5): protect data in possession/control, including via processors, by reasonable safeguards to prevent breach. The Act states the standard; Rules r.6 prescribes minimum safeguards (encryption/obfuscation/masking/virtual tokens, access control, logs, backups, one-year log retention, processor contract terms), not an open product list. Schedule Sl.1: up to Rs.250 cr (to Consolidated Fund of India).
Relevant lawss.8(4)–(5); Rules r.6(1)(a)–(g) minimum safeguards, r.14(3) (grievance response period not exceeding 90 days); s.33(2) quantum factors (nature/gravity, data type, repetition, gain/loss avoided, mitigation timeliness, proportionality, impact).
ForumInternal controls; Board on breach.
Procedure & stageAccess-minimisation → credential + patch discipline → logging/monitoring → backup/restore test → vendor oversight → incident drill → evidence file. Describe as the Rules r.6 minimums plus good practice toward s.8(5), not as a blanket product mandate.
RemedyMitigation credit (s.33(2)(e)); penalty/direction on failure.
High Court connectionTechnical adequacy is a Board fact-finding issue; Kerala HC writ tests only process legality.
Documents normally requiredAccess matrix, patch/log samples, backup-test proof, vendor oversight notes, drill record.
LimitationContinuous; s.8 and r.6 commence May 2027 (18 months after the 13 Nov 2025 commencement notification).
Does the Act require encryption?
The Act requires reasonable safeguards (s.8(5)); Rules r.6(1)(a) lists encryption, obfuscation, masking or virtual tokens as examples of the minimum data-security measures, alongside access control, logging, backups and processor contract terms.
ISO 27001 mapping — using audit language without overclaiming
Management wants "ISO = DPDP compliant" slide for customers.
What it involvesMapping ISO 27001 controls to s.8(4)–(5) and SDF audit/DPIA vocabulary (s.10) as evidence, not equivalence.
Relevant lawss.8(4)–(5), 10(2)(b)–(c); Board decides breach on Act facts.
ForumInternal assurance; Board as evidence.
Procedure & stageControl-to-obligation map → gap closure → auditor note framed as support for s.8(5)/s.10, not as statutory certification.
RemedyStronger mitigation story (s.33(2)); no immunity from inquiry.
High Court connectionNone directly; procurement disputes over "certified" claims go to Kerala civil fora on contract/misrepresentation law.
Documents normally requiredSoA, audit reports, mapping sheet, closure evidence.
LimitationAudit cycle; s.8 commences May 2027 (18 months after the 13 Nov 2025 commencement notification).
ISO certificate stops Board penalty?
No. It evidences effort; the Board tests Act compliance on facts.
Ransomware — when encryption of your own data is a personal data breach
server encrypted, "no exfiltration proved," so team treats it as an IT outage, not a breach.
What it involvess.2(u): unauthorised processing OR accidental disclosure/acquisition/sharing/use/alteration/destruction/loss of access compromising confidentiality/integrity/availability. Loss of access alone can qualify.
Relevant lawss.2(u), 8(5)–(6); Schedule Sl.1–Sl.2.
ForumBoard (intimation + inquiry); criminal complaint for extortion/hacking under applicable criminal + IT Act provisions separately.
Procedure & stageTreat as presumed breach until forensics rules out compromise → contain + preserve logs → assess confidentiality/integrity/availability impact → notify track (r.7) → criminal complaint in parallel.
RemedyCompliant intimation + mitigation record; penalty contained vs silence-aggravated.
High Court connectionRansom/extortion crimes go to Kerala police/courts; DPDP intimation runs to the Board in parallel.
Documents normally requiredForensic timeline, affected-data scope, ransom artefacts, notices sent.
LimitationPrincipals and Board: without delay (r.7(1), 7(2)(a)); detailed Board report within 72 hours of becoming aware, or a longer period the Board allows on written request (r.7(2)(b)).
No leak proved — can we stay silent?
Loss of access compromising availability can itself be a breach under s.2(u). Silence risks the separate Rs.200 cr notice track. Get an urgent review.
72-hour + without-delay notices — Board and each affected principal
Team notifies the Board in a week and users "later," or vice versa.
What it involvess.8(6): on breach, intimate Board AND each affected Data Principal in prescribed form/manner; Rules r.7: each affected principal and the Board without delay; detailed Board report within 72 hours of becoming aware (extendable by the Board on written request). Schedule Sl.2: up to Rs.200 cr for notice failure.
Relevant lawss.8(6), 27(1)(a) (Board may direct urgent remedial/mitigation steps + inquire + penalise); s.33.
ForumBoard (digital office, s.28(1)).
Procedure & stageHour-0 contain + scope → plain-language principal notice (what, impact, what-to-do, contact) → Board intimation without delay → detailed 72-hour Board submission → supplements as forensics mature.
RemedyNotice compliance closes the Sl.2 track; underlying Sl.1 safeguard breach still examined separately.
High Court connectionUrgent interim Board directions (s.28(10)) challenged only on jurisdictional/procedural grounds via TDSAT/writ; comply first, contest on record.
Documents normally requiredBreach scope note, both notices + delivery proof, 72-hour submission, remediation log.
LimitationWithout delay (principals and Board) + detailed Board report within 72 hours of becoming aware, unless the Board allows longer on a written request (r.7(2)(b)).
Can we wait for full forensics before telling users?
No. Notify without delay on what is known, then supplement. Delay aggravates quantum (s.33(2)).
Breach playbook — contain, assess, notify, submit, document, mitigate
No on-call list, no log preservation, contradictory customer messages after an incident.
What it involvesOperationalising ss.8(5)–(6), 27–28, 33(2)(e) (timely effective mitigation counts).
Relevant lawss.8(5)–(6), 27(1)(a), 28(7)/(10), 33(2)(e).
ForumInternal; Board on intimation.
Procedure & stage1) Contain + preserve. 2) Assess (data, heads, severity). 3) Notify (r.7). 4) Submit. 5) Document. 6) Mitigate + harden. 7) Post-incident review.
RemedyPlaybook evidence = mitigation credit; absence = aggravation.
High Court connectionKerala police cyber complaint for the crime; Board intimation for DPDP — run both, do not mix them.
Documents normally requiredCall tree, log-retention proof, notice templates (EN+ML), submission file, review note.
LimitationSame r.7 spine: without delay + 72-hour detailed Board report.
Wipe and reinstall fast to look efficient?
No. Preserve logs first; destruction of evidence hurts both the criminal case and Board mitigation.
Late notice — delay condonation and mitigation story
Breach discovered late or notified late; business fears the Rs.200 cr track is automatic.
What it involvesNo "condonation" section in the Act; delay is weighed in quantum (s.33(2): nature/gravity/duration, data type, repetition, gain/avoidance, mitigation timeliness/effectiveness, proportionality, impact) and via voluntary undertaking (s.32)/mediation (s.31).
Relevant lawss.31–33; s.28(6) natural justice.
ForumBoard inquiry; TDSAT appeal (60 days).
Procedure & stageFrank delay affidavit (when known, why late) → complete notices now → show effective mitigation + cooperation → consider s.32 undertaking → appeal on quantum if needed.
RemedyReduced quantum / undertaking-closure if accepted; breach of undertaking revives s.33 (s.32(5)).
High Court connectionQuantum appeals go to TDSAT; Kerala HC writ only for hearing-fairness or jurisdictional error.
Documents normally requiredDetection timeline, reason-for-delay proof, notices, mitigation invoices/logs.
LimitationTDSAT 60 days from Board order receipt.
Apology letter enough?
No. Show timeline + notices + fixes + cooperation. Paper remorse without remediation carries little weight under s.33(2).
Victim push — breach victim's complaint to the Board
Leaked customer in Kerala gets spam/fraud after a breach and wants the business punished and paid.
What it involvess.27(1)(b) Data Principal complaint (breach / fiduciary-obligation breach / rights denial) after s.13 grievance exhaust; penalty to Consolidated Fund of India only.
Relevant lawss.13(3), 27(1)(b), 28, 33–34.
ForumFiduciary grievance → Board (digital) → TDSAT.
Procedure & stageGrievance to fiduciary with leak evidence → wait out its published response period (max 90 days, DPDP Rules r.14(3)) → Board complaint with exhaust proof + loss trail → Board screens (s.28(3)–(5)) → inquiry → penalty/direction if significant breach.
RemedyBoard direction/penalty (Consolidated Fund of India). Money loss needs a separate civil suit (fraud/contract/damages) in the competent Kerala court — say so upfront.
High Court connectionKerala cause of action supports Kerala filings for the civil-suit leg; Board complaint itself is digital regardless of Board seat.
Documents normally requiredGrievance + delivery proof, breach notice received, spam/fraud trail, loss proof, ID.
LimitationFiduciary's grievance reply within the published period, max 90 days (DPDP Rules r.14(3)); Board complaint route (s.27) in force from May 2027 (G.S.R. 843(E)); TDSAT 60 days from receipt of Board order (s.29(2)).
Will the Board give me compensation?
No. Board penalties go to the Consolidated Fund of India. Compensation needs a civil suit.
Grievance mechanism + officer — s.8(10)/s.13 front door that must work
No published contact, generic inbox, no tracking — then a Board complaint alleges denial of rights.
What it involvess.8(10) (effective grievance mechanism) + s.8(9) (publish DPO/authorised contact) + s.13(1)–(2) (readily-available means; respond within prescribed period).
Relevant lawss.8(9)–(10), 13; s.27(1)(b) intake after exhaust.
ForumInternal; Board on escalation.
Procedure & stagePublish officer + channels (EN+ML) → ticket + acknowledge → decide in-window → reasoned reply → escalate-to-Board note with exhaust proof.
RemedyDefensible closure; mechanism absence itself is a breach finding.
High Court connectionKerala complainants use the published Kerala-facing contact to anchor cause of action; writ only for process error.
Documents normally requiredPublished contact capture, ticket log, replies, escalation notes.
LimitationPublish a response period not exceeding 90 days and meet it (DPDP Rules r.14(3); in force May 2027).
Outsource grievance to a call centre?
You may, but the fiduciary owns effectiveness (s.8(1)). Train, script DPDP replies, and audit.
Grievance SLA — counting the response window without guessing
Team cites "90 days" or "30 days" from blogs as if in the Act.
What it involvess.13(2): respond within *such period as may be prescribed.* The Act itself states no days; DPDP Rules r.14(3) requires each fiduciary/Consent Manager to publish its response period, not exceeding 90 days.
Relevant laws.13(2); DPDP Rules, 2025 r.14(3); s.13(3) exhaust rule.
ForumInternal SLA + Board screening.
Procedure & stagePublish a realistic response period (max 90 days, r.14(3)) → acknowledge quickly and decide well within it → back it with technical/organisational measures (r.14(3)) → cite the Act/Rules in replies, never blogs.
RemedyTimely-reply proof defeats "denial of rights" complaints.
High Court connectionNone beyond standard grievance → Board → TDSAT chain.
Documents normally requiredSLA note, ticket timestamps, Rules-text tracker.
LimitationYour published period, capped at 90 days by r.14(3) (in force May 2027). The 90 days is a ceiling in the Rules, not a figure in the Act.
No reply in X days — can we go to the Board?
File the grievance properly, keep delivery proof, wait out the fiduciary's published response period (max 90 days, DPDP Rules r.14(3)), then escalate with that proof.
Consent Manager grievance — when the dashboard itself fails
Withdrawal via Manager does not propagate; principal blames both Manager and business.
What it involvess.13(1) (Manager must offer grievance means) + s.27(1)(c)–(d) (Board inquires into Manager breaches and registration-condition breaches).
Relevant lawss.6(7)–(9), 13(1), 27(1)(c)–(d); DPDP Rules r.4 + First Schedule (Consent Manager registration and obligations).
ForumManager grievance + fiduciary grievance in parallel → Board.
Procedure & stageComplain to both with receipt IDs → preserve propagation logs → Board complaint with both exhaust proofs.
RemedyDirection/penalty on Manager and/or fiduciary (Consolidated Fund of India); civil suit for loss.
High Court connectionSame digital Board → TDSAT (60 days) chain; writ only for process error.
Documents normally requiredManager receipts, propagation logs, both grievances + proofs.
LimitationManager and fiduciary each reply within their published period, max 90 days (r.14(3)); TDSAT 60 days.
Manager fixed it — is the fiduciary off the hook?
No. Each answers for its own obligations (s.8(1) for fiduciaries; registration duties for Managers).
Law-enforcement sharing shield — s.11(2) replies without tipping off
DSAR asks "who did you share my data with" where one recipient was police/cyber-cell on written request.
What it involvess.11(2): no duty to disclose sharing with another fiduciary authorised by law where sharing was on its written request for offence/cyber-incident prevention-detection-investigation or prosecution/punishment.
Relevant laws.11(2); s.17(1)(c) (crime-prevention processing); BNSS/cyber-incident instruments for the underlying request validity.
ForumFiduciary reply; Board on DSAR complaint.
Procedure & stageVerify written request + legal authorisation → withhold that recipient narrowly with s.11(2) citation → disclose the rest.
RemedyLawful limited-withholding; over-withholding becomes a fresh grievance.
High Court connectionValidity of the underlying police requisition tested in criminal/writ courts; DPDP reply tested before Board.
Documents normally requiredWritten requisition, authorisation citation, redaction note.
LimitationNo separate day-count for access requests in the Act or Rules; answer promptly — an unanswered request can be taken up as a grievance (s.13(1)), answerable within the published period (max 90 days, r.14(3)).
Verbal police request — enough to withhold?
On s.11(2) text, the request must be in writing from an authorised fiduciary. Insist on paper.
Accuracy duty — s.8(3) where data decides loans, jobs or admissions
Stale score, old address or duplicate record feeds an automated rejection.
What it involvess.8(3): where data is likely to be used for a decision affecting the principal OR disclosed to another fiduciary, ensure completeness/accuracy/consistency.
Relevant laws.8(3); ss.11–12 (access/correction correct the input); s.33 quantum (data type, gravity).
ForumDesign + grievance → Board.
Procedure & stageFlag decision-feeding fields → source-verify + refresh cadence → correction SLA → pre-decision accuracy check → log.
RemedyProcess fix + correction; penalty/direction on systemic failure (Consolidated Fund of India); wrongful-decision loss by civil suit.
High Court connectionLoan/job/admission merits stay in sectoral/civil fora; DPDP accuracy is the parallel Board track.
Documents normally requiredDecision-field list, verification cadence, correction logs.
LimitationContinuous.
Customer gave wrong data — still our fault?
s.8(1) keeps the fiduciary answerable for observance, but s.15(b)/(c)/(e) (impersonation/suppression/authenticity) is your evidence. Verify inputs and record it.
Publish the contact — s.8(9) DPO or answerable person on the website
Notice names no one; DSARs bounce.
What it involvess.8(9): publish, in prescribed manner, business contact of DPO (if applicable) or person able to answer processing questions. SDF DPO is s.10(2)(a) (India-based, reports to Board/governing body, grievance point).
Relevant lawss.8(9), 10(2)(a); DPDP Rules r.9 (publish prominently on website/app; repeat in every reply to a rights request).
ForumWebsite compliance; Board on grievance-escalation.
Procedure & stagePublish name/role/channel on site/app + notice + signage → quote it in every rights-request reply (r.9) → monitor → log queries.
RemedyCloses "no channel" complaints at screening.
High Court connectionPublished Kerala-facing contact anchors Art.226(2) cause of action if writ later needed.
Documents normally requiredWebsite capture, notice copy, inbox monitoring proof.
Limitationr.9 in force May 2027; publish ahead of that.
Small business — must we appoint a DPO?
s.10 DPO is for notified Significant Data Fiduciaries. Others publish an answerable person's contact under s.8(9).
Processor erasure cascade — stopping the copies after stop
Fiduciary deletes but marketing vendor, backup and analytics copies live on.
What it involvess.8(7)(b): cause processors to erase data made available for processing; paired with s.6(6) post-withdrawal cease and s.12(3) erasure.
Relevant lawss.6(6), 8(7)(b), 12(3).
ForumContract enforcement + Board on complaint.
Procedure & stageErasure instruction with scope + deadline → processor confirmations incl. sub-processors + backup-cycle note → file.
RemedyClosed erasure loop; open copies become fresh breach/notice exposure.
High Court connectionIndemnity for lingering-copy loss by Kerala civil suit; Board track for the DPDP breach itself.
Documents normally requiredErasure instructions, confirmations, backup-deletion cycle proof.
LimitationReasonable time (s.6(6)); keep processing logs and associated data at least 1 year from processing, then erase (DPDP Rules r.8(3)).
Vendor says backups cannot be deleted?
Get a technical deletion-cycle commitment (crypto-erasure/suppression + overwrite schedule) with dates — "cannot" without a plan fails s.8(7)(b).