Advanced Search Options : ❯
Section 10 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Significant Data Fiduciaries must appoint an India-based Data Protection Officer accountable to their board or similar governing body and acting as the grievance-redressal contact. They must appoint an independent data auditor to evaluate compliance and conduct periodic Data Protection Impact Assessments, periodic data audits, and prescribed additional measures. Designation may follow an assessment of personal-data volume and sensitivity, risks to Data Principals' rights, and potential effects on sovereignty, electoral democracy, State security, and public order.
Section 9 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Processing of personal data of a child, or of a person with disability who has a lawful guardian, requires verifiable consent from the parent or lawful guardian in the prescribed manner. Processing likely to cause a detrimental effect on a child's well-being is prohibited. Data Fiduciaries must not track or behaviourally monitor children, or direct targeted advertising at them. Prescribed exemptions and age-based exemptions for verifiably safe processing may apply.
Section 8 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Data Fiduciaries remain responsible for compliance in respect of personal-data processing undertaken by them or through Data Processors. Processor engagement for goods or services activities requires a valid contract. Fiduciaries must maintain data accuracy where decisions affecting Data Principals or disclosures are involved, apply technical and organisational safeguards, and notify the Board and affected Data Principals of breaches. They must erase data upon consent withdrawal or when the specified purpose ends, subject to legally required retention, and provide contact information and grievance redressal.
Section 7 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Data Fiduciaries may process personal data for a voluntarily supplied specified purpose unless the Data Principal indicates non-consent, and must cease processing where requested assistance is no longer needed. State entities may process data for prescribed public delivery where prior consent or notified government records exist, subject to applicable standards. Further legitimate uses include statutory functions and disclosures, legal-order compliance, medical emergencies, public-health threats, disasters, public-order breakdowns, and employment-related safeguards against loss or liability.
Section 6 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Consent for personal-data processing must be free, specific, informed, unconditional and unambiguous, based on clear affirmative action, and limited to data necessary for the stated purpose. Consent requests must be clear, accessible in prescribed languages, and provide relevant contact details. Data Principals may withdraw consent as easily as it was given; the Data Fiduciary and its Data Processors must then cease processing within a reasonable time unless processing is legally required or authorised. Where consent is disputed, the Data Fiduciary must prove compliant notice and consent.
Section 5 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
A Data Fiduciary seeking consent must give or precede its request with notice identifying the personal data proposed for processing, the processing purpose, the Data Principal's rights, and the complaint mechanism before the Board. For consent obtained before commencement, equivalent information must be provided as soon as reasonably practicable, while processing may continue until consent is withdrawn. Notices must be accessible in English or an Eighth Schedule language.
Section 4 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Processing of a Data Principal's personal data is permitted only in accordance with the Act, for a lawful purpose, and on the basis of consent or certain legitimate uses. A lawful purpose is one not expressly forbidden by law. These alternative grounds govern the basis for processing within Data Fiduciary obligations. Section 4 is to come into force eighteen months after 13 November 2025.
Section 3 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Section 3 governs processing of digital personal data collected in India in digital form or subsequently digitised, and extends to overseas processing connected with offering goods or services to Data Principals in India. It excludes personal or domestic processing by individuals and personal data publicly made available by the Data Principal or by a person legally required to disclose it. The provision takes effect eighteen months from 13 November 2025.
Section 2 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Digital personal data protection definitions identify the Data Principal, Data Fiduciary, Data Processor, Consent Manager, Significant Data Fiduciary and Data Protection Officer. Processing includes automated operations involving collection, storage, use, sharing, disclosure, restriction, erasure and destruction of digital personal data. Personal data breach covers unauthorised processing and accidental events compromising confidentiality, integrity or availability. The framework also provides for digital proceedings, Board-registered consent management, specified purpose, certain legitimate uses, and broad meanings of person, gain and loss.
Section 1 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Digital Personal Data Protection Act, 2023 establishes a framework for processing digital personal data that recognises individuals' right to protect personal data while permitting processing for lawful purposes. Commencement occurs on dates appointed by Central Government notification, and different provisions may commence on different dates. References to commencement are provision-specific, with commencement indicated with effect from 13 November 2025.
Unregistered investment advisory fees cannot be retained; unclaimed amounts must be deposited for verified investor refunds and protection.
Fees collected for investment advisory services provided without required registration cannot be retained merely because no investor responds to a refund invitation. Such amounts must be deposited with the regulator, which must invite and verify investor claims. Any balance remaining unclaimed after that process must be transferred to the Investor Protection Fund. The absence of refund claims does not legitimise retention of fees earned through unregistered investment advisory activity.
Notification No. Digital Personal Data Protection Act, 2023 (No. 22 of 2023) Dated:- 11-8-2023 Infor...
Digital personal data may be processed only for a lawful purpose based on valid consent or specified legitimate uses. Consent must be free, specific, informed, unconditional and unambiguous, supported by clear notice, and withdrawable with comparable ease. Data Fiduciaries remain responsible for processing undertaken by themselves or their processors, must maintain security safeguards, notify personal data breaches, erase data when no longer needed unless legal retention is required, and provide grievance redressal. Children's data requires verifiable parental or guardian consent, with restrictions on harmful processing, tracking, behavioural monitoring and targeted advertising.
Section 153D Approval Requires Independent Year-Wise Review, Invalidating Mechanical Composite Assessment Approvals and Consequential Assessments
Section 153D prior approval for search assessments requires the approving authority to independently examine draft assessment orders, assessment records and relevant search material for each assessment year. A composite approval issued without evidence of record movement, separate year-wise consideration, reasons or verification indicates a routine and mechanical exercise rather than informed statutory approval. Approval granted in this manner is invalid for want of application of mind, and assessment orders founded on it are vitiated and liable to be quashed.
Search assessment additions require incriminating material linked to the addition, while accounted genuine expenses cannot be treated as unexplained.
In an unabated assessment under Section 153A, additions require incriminating material found during the search and a link between that material and the proposed addition. An unsecured-loan addition lacking that nexus is unsustainable. Alleged unexplained-expense additions are likewise unsustainable where seized entries are reconciled with agreements and books, verification reveals no adverse discrepancy, and the transactions represent genuine accounted business dealings. These principles support deletion of additions founded on recorded expenses or loans unconnected with incriminating search material.
Functional, asset and risk analysis governs reliable transfer-pricing comparables, while overdue foreign-currency receivables require separate interest benchmarking.
Transfer-pricing benchmarking under the Transactional Net Margin Method requires a disclosed, reasoned functional, asset and risk analysis to support comparable-company exclusions and selections across distribution, software-development and technical-support segments. Absent that analysis, comparability determinations require fresh, transparent evaluation with an opportunity to submit evidence. Deferred payment or receivables exceeding the agreed credit period constitute a separate international transaction, because only credit within that period is embedded in the sale price. Foreign-currency delayed receivables require separate interest benchmarking at LIBOR plus a 200-basis-point spread.
Revenue treatment of brand development confirms deductibility where existing business outlays create no separate capital asset
Brand-development outlays incurred in an existing business are revenue expenditure where they support the profit-earning process and create no capital asset; commercial expediency cannot be displaced without evidence of non-business purpose. Additional deduction claims may be considered in appellate proceedings, and accrued redemption premium on transferable zero-coupon debentures is deductible where no identifiable payee gives rise to withholding obligations. Corporate guarantees require a service charge but are not benchmarked as bank guarantees; a 0.2% fee reflected limited benefit. Aircraft treated as aeroplanes qualify for 40% depreciation. Investment shares consistently held as investments and sold through limited delivery-based transactions generate capital gains, supported by consistency of past treatment.
Treaty relief for international shipping freight remains available when a revised return corrects the treaty country code.
Freight income from operating ships in international traffic qualifies for exemption under Article 8 of the India-Singapore tax treaty where eligibility is undisputed. Where such income was offered under section 44B because the return form did not permit a direct treaty-exemption claim, relief under section 90 must be granted. An incorrect treaty-country code in the original return cannot justify denial when a revised return corrected the code to Singapore but was not processed. Relief is to be granted for eligible income after an opportunity of hearing.
Reasonable cause for audit non-compliance prevents penalty where death of the compliance manager and disability caused the default.
Penalty for failure to obtain an audit under Section 44AB cannot be sustained where the assessee proves reasonable cause under Section 273B. Dependence on a person responsible for business and regulatory compliance, that person's death, and the assessee's disability and resulting inability to manage the business showed that the default was neither deliberate nor lacking in bona fides. These circumstances constituted reasonable cause, making the penalty for audit non-compliance unsustainable.
Delayed audit reports may substantially support charitable exemption claims despite late filing before return processing is completed.
Charitable exemption may not be denied in return processing solely because Form No. 10B was filed after the prescribed date where the audit report was available before the intimation. The filing deadline for the audit report is treated as procedural and directory in those circumstances, with timely availability before processing constituting substantial compliance. The condonation route for delayed filing operates as an additional remedy and does not exclude appellate review of an adjustment to the exemption claim. Consequently, refusal to condone delay need not prevent appellate consideration or acceptance of the exemption claim.
Jurisdictional defects in reassessment invalidate revisionary action when statutory approval comes from an incompetent authority.
Jurisdictional objections to reassessment may be raised collaterally in an appeal against revision under section 263 because revision presupposes a legally valid assessment order. A defect in the authority to initiate reassessment cannot be cured by waiver, acquiescence, participation, or failure to challenge the reassessment directly. Where more than three years have elapsed, section 151(ii) requires sanction from the Principal Chief Commissioner or Chief Commissioner; approval by the Principal Commissioner under section 151(i) does not meet that condition. Reassessment without competent sanction is void ab initio and cannot support revisionary jurisdiction under section 263.