Advanced Search Options : ❯
Section 30 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Appellate Tribunal orders under digital personal data protection law are executable by the Tribunal as civil-court decrees, with all powers of a civil court available for execution. The Tribunal may transmit an order to the civil court having local jurisdiction, which must execute it as though it were its own decree.
Section 29 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Any person aggrieved by an order or direction of the Board may appeal to the Appellate Tribunal within sixty days, subject to prescribed form, manner, and fee requirements. The Tribunal may condone delay for sufficient cause and, after hearing the parties, confirm, modify, or set aside the challenged order. Appeals should be disposed of expeditiously, with reasons recorded for delay beyond six months. Proceedings should function as far as practicable through a digital office.
Bail in alleged cooperative bank loan fraud was denied due to unrecovered funds, influence, and tampering risks.
Bail in allegations of fraudulent loan transactions requires assessment of the prima facie case, offence gravity and societal impact, public interest, and the risk of interference with justice. Alleged concerted siphoning of co-operative bank funds through loans was treated as seriously affecting depositors and the banking system. Temporary bail intended to enable recovery had not resulted in recovery. Alleged influence of the accused, together with a genuine apprehension of evidence tampering and interference with pending proceedings, weighed against release. Bail was therefore denied.
Section 28 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
The Board operates independently and, as far as practicable, through a digital office. It must determine whether sufficient grounds exist before commencing an inquiry, record reasons when closing proceedings or proceeding with inquiry, and follow the principles of natural justice. The Board has civil-court-like powers for summoning, evidence, document production and inspection, but cannot disrupt day-to-day functioning by preventing premises access or taking custody of essential equipment. Interim orders and final action require an opportunity of hearing, while false or frivolous complaints may attract warnings or costs.
Section 27 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
The Board may direct urgent remedial or mitigation measures for notified personal data breaches, inquire into specified breaches involving Data Fiduciaries, Consent Managers, and intermediaries, and impose applicable penalties. It may issue necessary directions after hearing the affected person and recording written reasons, with mandatory compliance. On a representation by an affected person or a reference from the Central Government, it may modify, suspend, withdraw, or cancel a direction subject to appropriate conditions.
Section 26 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Section 26 gives the Chairperson general superintendence and direction-setting authority over all administrative matters of the Board. The Chairperson may authorise Board officers to scrutinise intimations, complaints, references, and correspondence. Individual Members or groups of Members may be authorised to perform Board functions and conduct proceedings, with proceedings allocated among them by the Chairperson.
Section 25 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Public-servant status attaches to Board personnel when they act, or purport to act, under the Digital Personal Data Protection Act, 2023. For such functions, they are deemed public servants under the Indian Penal Code. The status applies only to conduct connected with the exercise or purported exercise of functions under the Act.
Section 24 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
The Data Protection Board of India may appoint officers and employees necessary for efficient discharge of its functions under the Digital Personal Data Protection Act, 2023. Such appointments require prior approval of the Central Government, and the terms and conditions of appointment and service are to be prescribed.
Section 23 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Validity of Board acts and proceedings is protected against challenges based solely on a vacancy or defect in constitution, a defect in appointment of the Chairperson or another Member, or a procedural irregularity that does not affect case merits. Where the Chairperson cannot perform functions because of absence, illness or another cause, the senior-most Member performs those functions until the Chairperson resumes duties.
Section 22 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Resignation by the Chairperson or any other Member becomes effective on the earliest of governmental permission, expiry of three months after notice, a successor taking office, or expiry of the term. Vacancies caused by resignation, removal, death, or otherwise require fresh appointment under the Act. Former office-holders are restricted from accepting employment for one year without prior governmental approval and must disclose subsequent employment with a Data Fiduciary against whom proceedings were initiated by or before them.
Section 21 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Disqualification from appointment or continuation as Chairperson or Member arises from insolvency, a conviction involving moral turpitude, physical or mental incapacity, prejudicial financial or other interests, or abuse of office prejudicial to public interest. Removal by the Central Government requires that the Chairperson or Member first receive an opportunity to be heard.
Section 20 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Service conditions, including salary and allowances, of the Chairperson and other Members are to be prescribed and cannot be varied to their disadvantage after appointment. Each holds office for a two-year term and is eligible for re-appointment, combining protection against adverse service-condition changes with eligibility for successive appointments.
Section 19 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
The Data Protection Board of India comprises a Chairperson and such additional Members as may be notified by the Central Government, with appointments made through the prescribed manner. Appointees must have ability, integrity and standing, together with special knowledge or practical experience in data governance, administration, social or consumer protection laws, dispute resolution, information and communication technology, the digital economy, law, regulation or techno-regulation. At least one appointee must be a legal expert.
Section 18 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Section 18 establishes the Data Protection Board of India from a date appointed by Central Government notification. The Board is a body corporate with perpetual succession and a common seal. Subject to the Act, it may acquire, hold and dispose of movable or immovable property, contract, and sue or be sued. Its headquarters shall be at a place notified by the Central Government.
Section 17 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Section 17 disapplies specified data-protection obligations for processing necessary to enforce legal claims, perform judicial or regulatory functions, support law enforcement, fulfil certain foreign contracts, implement approved corporate transactions, or assess a loan defaulter's financial position. Full exemptions may apply to notified State instrumentalities on specified public-interest grounds and to qualifying research, archiving or statistical processing. The Central Government may also grant targeted exemptions to notified Data Fiduciaries, including recognised startups, and may temporarily disapply any provision to specified Data Fiduciaries or classes.
Section 16 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Cross-border processing of personal data may be restricted through notification for transfers by a Data Fiduciary to specified countries or territories outside India. The provision preserves the operation of Indian laws imposing higher protection standards or stricter restrictions on transfers of personal data outside India, whether concerning particular personal data, Data Fiduciaries, or classes thereof.
Section 15 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Section 15 requires Data Principals to exercise personal-data rights in compliance with applicable laws. They must not impersonate another person, suppress material information when furnishing personal data for State-issued identity or address documentation, or lodge false or frivolous grievances or complaints. Information furnished while exercising correction or erasure rights must be verifiably authentic.
Section 14 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Right to nominate enables a Data Principal to designate another individual, in the manner prescribed by law, to exercise the Data Principal's rights upon death or incapacity. The nominee acts in accordance with the applicable statutory framework and governing rules. Incapacity means inability to exercise Data Principal rights because of unsoundness of mind or infirmity of body.
Section 13 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Section 13 grants a Data Principal the right to readily available grievance redressal against acts or omissions of a Data Fiduciary or Consent Manager concerning personal-data obligations or the exercise of rights. Data Fiduciaries and Consent Managers must respond within the prescribed period. The Data Principal must exhaust the available grievance-redressal process before approaching the Board.
Section 12 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
A Data Principal may seek correction, completion, updating and erasure of personal data for which consent to processing was previously given, subject to applicable legal requirements and procedures. A Data Fiduciary must correct inaccurate or misleading data, complete incomplete data, and update data upon request. Personal data must be erased following a prescribed request unless retention is necessary for the specified purpose or compliance with applicable law.