Advanced Search Options : ❯
Section 14 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Right to nominate enables a Data Principal to designate another individual, in the manner prescribed by law, to exercise the Data Principal's rights upon death or incapacity. The nominee acts in accordance with the applicable statutory framework and governing rules. Incapacity means inability to exercise Data Principal rights because of unsoundness of mind or infirmity of body.
Section 13 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Section 13 grants a Data Principal the right to readily available grievance redressal against acts or omissions of a Data Fiduciary or Consent Manager concerning personal-data obligations or the exercise of rights. Data Fiduciaries and Consent Managers must respond within the prescribed period. The Data Principal must exhaust the available grievance-redressal process before approaching the Board.
Section 12 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
A Data Principal may seek correction, completion, updating and erasure of personal data for which consent to processing was previously given, subject to applicable legal requirements and procedures. A Data Fiduciary must correct inaccurate or misleading data, complete incomplete data, and update data upon request. Personal data must be erased following a prescribed request unless retention is necessary for the specified purpose or compliance with applicable law.
Section 11 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Section 11 enables a Data Principal who has previously consented to processing to request from the relevant Data Fiduciary a summary of personal data and processing activities, identities of recipients and the data shared, and prescribed related information. Disclosure of recipient identities and prescribed related information is excluded for sharing with a legally authorised Data Fiduciary on a written request connected with preventing, detecting or investigating offences or cyber incidents, or prosecuting or punishing offences.
Section 10 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Significant Data Fiduciary status may be notified after considering the scale and sensitivity of personal data processing and related risks to Data Principal rights, national interests, electoral democracy, State security, and public order. Such fiduciaries must appoint an India-based Data Protection Officer and an independent data auditor, conduct periodic Data Protection Impact Assessments and audits, and comply with further prescribed measures.
Section 9 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Data Fiduciaries must obtain verifiable consent from a child's parent or lawful guardian before processing a child's personal data and must not undertake processing likely to harm the child's well-being. Tracking, behavioural monitoring and targeted advertising directed at children are prohibited. Prescribed exemptions may apply to specified Data Fiduciaries, purposes and conditions. Where processing is verifiably safe, an age-based exemption may apply to specified consent and child-protection obligations.
Section 8 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Data Fiduciaries remain responsible for compliant personal-data processing undertaken by them or by Data Processors, who may be engaged only under valid contracts. They must maintain data quality for consequential decisions or disclosures, implement technical and organisational compliance measures, maintain reasonable security safeguards, and notify the Board and affected Data Principals of breaches. Personal data must be erased on consent withdrawal or when its purpose ends, unless legal retention is required, including erasure by Data Processors. They must also publish appropriate contact information and provide effective grievance redressal.
Section 7 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
A Data Fiduciary may process personal data for the specified purpose for which a Data Principal voluntarily supplies it, provided the Data Principal has not indicated non-consent, and must cease processing when requested assistance is no longer required. Processing is also permitted for prescribed State benefits and functions, legally required disclosures, compliance with judgments or orders, medical emergencies, public-health threats, disasters, public-order breakdowns, and employment purposes. Employment-related processing includes protection against loss or liability, prevention of corporate espionage, confidentiality of trade secrets, intellectual property or classified information, and provision of employee-requested services or benefits.
Section 6 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Consent-based personal data processing requires free, specific, informed, unconditional and unambiguous affirmative consent, limited to data necessary for a specified purpose. Consent requests must use clear language, permit access in English or a listed constitutional language, and provide rights-related contact details. Consent may be withdrawn as easily as it is given; the Data Fiduciary and its Data Processors must then cease processing within a reasonable time unless otherwise authorised by law. The Data Fiduciary must prove compliant notice and consent where disputed.
Section 5 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Data Fiduciaries must provide notice before or with a consent request, identifying the personal data proposed for processing, its purpose, the means to exercise statutory rights, and the complaint mechanism. For consent obtained before commencement, notice must be provided as soon as reasonably practicable, and processing may continue until consent is withdrawn. Notices must be accessible in English or an Eighth Schedule language.
Section 4 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Personal data processing is permitted only in accordance with the Act and for a lawful purpose. Processing a Data Principal's personal data may proceed where the Data Principal has given consent or where it falls within certain legitimate uses. A lawful purpose is one not expressly forbidden by law.
Section 3 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Digital Personal Data Protection Act, 2023 applies to processing of digital personal data within India when collected digitally or subsequently digitised, and to certain processing outside India connected with offering goods or services to Data Principals in India. Coverage excludes personal data processed for personal or domestic purposes and data publicly made available by the Data Principal or by a person legally obliged to disclose it.
Section 2 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Processing comprises wholly or partly automated operations on digital personal data, including collection, storage, use, sharing, restriction, erasure and destruction. A personal data breach includes unauthorised processing or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access that compromises confidentiality, integrity or availability. A Data Fiduciary determines the purpose and means of processing, while a Data Processor acts on its behalf. Consent Managers enable Data Principals to give, manage, review and withdraw consent through an accessible, transparent and interoperable platform.
Section 1 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Digital Personal Data Protection Act, 2023 establishes a framework for processing digital personal data that recognises individuals' interest in protecting personal data while permitting processing for lawful purposes. Commencement is not fixed automatically by enactment: provisions take effect on dates appointed by the Central Government through notification in the Official Gazette, with different provisions capable of entering into force on different dates.
Unregistered investment advisory fees cannot be retained; unclaimed amounts must be deposited for verified investor refunds and protection.
Fees collected for investment advisory services provided without required registration cannot be retained merely because no investor responds to a refund invitation. Such amounts must be deposited with the regulator, which must invite and verify investor claims. Any balance remaining unclaimed after that process must be transferred to the Investor Protection Fund. The absence of refund claims does not legitimise retention of fees earned through unregistered investment advisory activity.
Notification No. Digital Personal Data Protection Act, 2023 (No. 22 of 2023) Dated:- 11-8-2023 Infor...
Digital personal data may be processed only for a lawful purpose based on valid consent or specified legitimate uses. Consent must be free, specific, informed, unconditional and unambiguous, supported by clear notice, and withdrawable with comparable ease. Data Fiduciaries remain responsible for processing undertaken by themselves or their processors, must maintain security safeguards, notify personal data breaches, erase data when no longer needed unless legal retention is required, and provide grievance redressal. Children's data requires verifiable parental or guardian consent, with restrictions on harmful processing, tracking, behavioural monitoring and targeted advertising.
Section 153D Approval Requires Independent Year-Wise Review, Invalidating Mechanical Composite Assessment Approvals and Consequential Assessments
Section 153D prior approval for search assessments requires the approving authority to independently examine draft assessment orders, assessment records and relevant search material for each assessment year. A composite approval issued without evidence of record movement, separate year-wise consideration, reasons or verification indicates a routine and mechanical exercise rather than informed statutory approval. Approval granted in this manner is invalid for want of application of mind, and assessment orders founded on it are vitiated and liable to be quashed.
Search assessment additions require incriminating material linked to the addition, while accounted genuine expenses cannot be treated as unexplained.
In an unabated assessment under Section 153A, additions require incriminating material found during the search and a link between that material and the proposed addition. An unsecured-loan addition lacking that nexus is unsustainable. Alleged unexplained-expense additions are likewise unsustainable where seized entries are reconciled with agreements and books, verification reveals no adverse discrepancy, and the transactions represent genuine accounted business dealings. These principles support deletion of additions founded on recorded expenses or loans unconnected with incriminating search material.
Functional, asset and risk analysis governs reliable transfer-pricing comparables, while overdue foreign-currency receivables require separate interest benchmarking.
Transfer-pricing benchmarking under the Transactional Net Margin Method requires a disclosed, reasoned functional, asset and risk analysis to support comparable-company exclusions and selections across distribution, software-development and technical-support segments. Absent that analysis, comparability determinations require fresh, transparent evaluation with an opportunity to submit evidence. Deferred payment or receivables exceeding the agreed credit period constitute a separate international transaction, because only credit within that period is embedded in the sale price. Foreign-currency delayed receivables require separate interest benchmarking at LIBOR plus a 200-basis-point spread.
Revenue treatment of brand development confirms deductibility where existing business outlays create no separate capital asset
Brand-development outlays incurred in an existing business are revenue expenditure where they support the profit-earning process and create no capital asset; commercial expediency cannot be displaced without evidence of non-business purpose. Additional deduction claims may be considered in appellate proceedings, and accrued redemption premium on transferable zero-coupon debentures is deductible where no identifiable payee gives rise to withholding obligations. Corporate guarantees require a service charge but are not benchmarked as bank guarantees; a 0.2% fee reflected limited benefit. Aircraft treated as aeroplanes qualify for 40% depreciation. Investment shares consistently held as investments and sold through limited delivery-based transactions generate capital gains, supported by consistency of past treatment.