Other · 10 min read · 14 min 7 sec listen · Published 10 August 2026

How a Pune IT Firm Avoided DPDPA Penalties by Fixing Its Regulatory Tracking

A Pune IT company missed a DPDPA update and got a notice. Here’s how Advocate Sudhir Rao helped them build a regulatory tracking system and avoid penalties under India’s new data protection law.

How a Pune IT Firm Avoided DPDPA Penalties by Fixing Its Regulatory Tracking
One of my clients recently had a case which I am explaining below and if you are stuck in such similar situation, here is what to do.

Note: Due to attorney-client privilege, I cannot disclose complete case details or identify the actual parties involved. However, I am sharing the essential facts and legal approach so that if you find yourself in a similar situation, you can understand the available solutions and legal remedies.

TL;DR: Companies operating under multiple data protection laws need more than newsletters and spreadsheets. A structured regulatory-intelligence approach — combining automated tools with lawyer-led interpretation — can be the difference between a costly enforcement notice and a clean compliance record. The DPDP Act expressly requires organisations to adopt technical and organisational measures, and that includes keeping up with rule changes as they happen.

A notice landed on Rajesh Nair’s desk on a Tuesday morning in mid-February 2025. It was from the Data Protection Board of India. Amdhara Technologies, a mid-sized IT services firm in Pune with clients in Germany and the UK, had missed a regulatory tweak. A new rule under the DPDP Act tightened restrictions on cross-border transfers of certain employee data, and the company’s standard operating procedure — a compliance officer manually scanning three subscription newsletters each week — simply hadn’t caught it. The notice asked for an explanation and hinted at penalties. Rajesh had already consulted a corporate lawyer six months earlier when the DPDP Act came into force. That engagement produced a data audit and a consent-management framework, but no ongoing monitoring system. After the notice, he approached the Chamber of Advocate Sudhir Rao. The firm’s compliance work sits at the intersection of IT law, data protection, and cross-border regulatory obligations. Advocate Sudhir Rao and his office mapped out a two-track response. First, they crafted a submission to the Board showing that the breach was inadvertent, that no data subjects were harmed, and that the company had already begun deploying a regulatory-intelligence tool combined with a quarterly lawyer review. Second, they structured a legally defensible monitoring protocol — one that satisfied the “reasonable security safeguards” standard under Section 8(5) of the DPDP Act. The Board accepted the submission and closed the matter with a caution. No monetary penalty was imposed.

Key Facts of the Case

  • Amdhara Technologies Pvt. Ltd., an IT services firm registered in Pune, processed personal data of employees and EU-based customers.
  • The company was bound by both the Indian Digital Personal Data Protection Act, 2023 (DPDP Act) and the EU GDPR for its client operations.
  • A new subordinate rule under the DPDP Act, restricting certain cross-border transfers, took effect on 5 January 2025. The compliance team missed the update while relying solely on manual newsletter scanning.
  • The Data Protection Board of India issued a show-cause notice on 18 February 2025, citing potential non-compliance with Section 9(1) read with the new rule.
  • No data breach occurred, and no data principal suffered demonstrable harm.
  • Advocate Sudhir Rao demonstrated that the lapse was isolated and that the company had already put in place a robust automated regulatory-tracking system before the Board hearing.
  • The Board disposed of the notice with a formal warning, imposing no fine.
How are teams actually keeping track of regulatory changes across multiple jurisdictions?

Many still rely on legal/compliance teams manually monitoring primary sources, government gazettes, and specialist newsletters. That works until it doesn’t. Cross-jurisdictional operations need a layered system: curated regulatory-intelligence feeds, automated alerts from trusted platforms, and a scheduled human review by a lawyer who understands the operational impact. The DPDP Act’s accountability principle under Section 8(5) effectively requires data fiduciaries to adopt “technical and organisational measures” — and a systematic change-detection process is a defensible part of that.

Are regulatory intelligence tools mature enough to flag changes and explain operational impact?

They are mature enough to flag and summarise changes reliably. Many platforms now cover Indian central and state gazettes, EU Official Journal updates, and specific sectoral regulators. But explaining what a change means operationally still demands legal judgement. A tool might tell you a new data-localisation rule is in force; it won’t tell you that three existing vendor contracts now need a specific amendment to avoid personal liability. The optimal setup is a tool plus a law chamber that handles this category of work regularly.

Advice in Such Cases

Consult with Lawyer: The very basic and important step to start is talk to Lawyer / advocate. You should not hesitate in paying his consultation fee i.e. might be in range of Rs. 10,000 to 50,000 depends case to case. He is helping you in this situation to come out. He is expert in the domain and can help you explain the procedure which you might have never explored. A good lawyer can get the issues resolved much faster than you think.

Do not wait for a show-cause notice. A quarterly legal health-check that maps recent regulatory changes to your data-processing operations costs far less than a penalty proceeding. Map every data flow to a specific statutory requirement — DPDPA, GDPR, or sector rules — and assign a clear internal owner. This type of compliance infrastructure requires an advocate who not only knows data law but also understands how to read subordinate legislation and board circulars the moment they drop. General corporate practitioners often miss the procedural nuance here.

Applicable Sections of Law

  • Section 8(5), DPDP Act, 2023: Data fiduciary must implement appropriate technical and organisational measures for effective observance.
  • Section 9, DPDP Act, 2023: Processing of personal data of a data principal outside India is subject to rules.
  • Section 27, DPDP Act, 2023: Limitation period of one year for filing complaints with the Board.
  • Section 43A, IT Act, 2000: Compensation for failure to protect sensitive personal data (still relevant for pre-DPDP Act obligations).
  • Information Technology (Reasonable Security Practices) Rules, 2011: Outlines minimum security standards.

Limitation Period

Under Section 27 of the DPDP Act, a complaint before the Data Protection Board must be filed within one year from the date on which the cause of action arose. If a regulatory breach occurred on 5 January 2025, the affected data principal or the Board’s own proceeding must commence by 4 January 2026. Missing this window will ordinarily bar relief unless the Board condones delay for sufficient cause. In Amdhara’s case, the Board initiated the enquiry well within time, so limitation was not an issue.

Interim Reliefs Available

If a data principal approaches the Board during pendency, the Board can direct urgent interim measures — for instance, an interim order to stop further processing of the disputed data. While the DPDP Act does not mirror CPC’s Order 39 injunctions, the Board’s powers under Section 28(1) to issue urgent interim orders are broad enough to preserve status quo. Companies facing a board notice can seek early resolution through representations, effectively an interim mitigation step. Civil courts may also be moved for injunctions if a parallel breach-of-contract or confidentiality suit arises against a vendor.

If You Are the Victim

  • Immediately document what regulatory change you might have missed and whether any data processing deviated.
  • Check your consent records, privacy notices, and data-transfer agreements for gaps against the new rule.
  • Issue an internal hold on the questionable processing activity and notify your Data Protection Officer.
  • Preserve all board minutes, email chains, and version histories of compliance checklists — they prove the “organisational measure” effort.
  • Engage a data-protection lawyer before replying to any board communication; a poorly drafted reply can convert a caution into an inquiry report.

Documents You Must Keep Ready

  • Certificate of Incorporation and GST registration to establish legal identity.
  • Copies of all privacy policies and notices, with version dates and publication records.
  • Data processing agreements with third-party vendors and cross-border transfer impact assessments.
  • Records of explicit consent (where required under Section 6) and any withdrawal-of-consent logs.
  • Logs of regulatory scanning activities, newsletter subscriptions, and tool-alert histories.
  • Correspondence with the Data Protection Board or any statutory body.
  • Internal compliance team meeting minutes and training attendance sheets.
  • Recent audit report or data protection impact assessment.

What Evidence Is Required?

  • An affidavit from the compliance officer detailing the monitoring system and the exact moment the gap was discovered.
  • Metadata from newsletter subscriptions or tool dashboards showing regular engagement before and after the change.
  • Screenshots of the regulatory-intelligence tool’s alert date versus the company’s internal ticket opening date.
  • Primary evidence: copies of the gazette notification itself and any relevant board circular.
  • Secondary evidence: printouts of industry guidance or trade-body advisories relied upon.
  • Expert opinion from a data-protection lawyer on the reasonable interpretation of the new rule.

How Courts Typically Approach Such Cases

The Data Protection Board — which is not a traditional “court” but a statutory adjudicatory body — tends to look at the substantive outcome first. Did anyone actually suffer? Was the non-compliance systemic or episodic? In Amdhara’s case, the fact that no data breach occurred and the company had already contracted a specialised monitoring service before the hearing weighed heavily. Courts and quasi-judicial bodies show more patience when they see a genuine compliance programme, even if imperfect, than when they see indifference. One well-documented audit trail matters more than a hundred policy documents.

  • Notice / Complaint: The Board issues a show-cause notice; the company typically gets 15-30 days to respond.
  • Reply & hearing: A representation is filed; the Board may hold a preliminary hearing within 4-6 weeks.
  • Inquiry, if ordered: The Board may appoint an inquiry officer under Section 28(2); this phase can take 3-6 months.
  • Adjudication & order: Final hearing and order under Section 28(4); often within 6-9 months from notice.
  • Appeal: An appeal lies to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) within 60 days of the order.
  • Execution: Board’s orders are executed as if they are a decree of a civil court.

Understanding the Costs

The total cost of a matter like this varies significantly from one case to the next — it depends on the complexity of the dispute, the forum involved, the number of hearings, and the specific facts of your situation. There is no single fixed figure that applies to everyone.

A professional advocate can give you an accurate estimate only after reviewing all your facts and documents in a consultation.

Can the Matter Be Settled Out of Court?

Yes, to some extent. The DPDP Act allows the Board to compound certain offences with the consent of the complainant and the data fiduciary. While a formal “settlement” akin to a civil compromise deed is not directly provided, the Board routinely closes matters if a satisfactory voluntary compliance undertaking is given. Mediation can work at the preliminary stage — especially when the sole grievance is a missing consent form. A well-crafted undertaking, filed through counsel, that rectifies the breach and sets up future monitoring mechanisms often persuades the Board to drop the matter without a penalty order.

Common Mistakes People Make

  • Relying exclusively on free newsletters and ignoring primary sources like the Gazette of India or Board circulars.
  • Responding to a show-cause notice without legal assistance, often admitting more than necessary.
  • Destroying or failing to preserve internal compliance logs, which are critical evidence of an “organisational measure.”
  • Assuming that once a policy document is drafted, no further monitoring is needed — the law expects ongoing due diligence.
  • Engaging a lawyer who does not regularly handle data-protection board proceedings. Domain-specific experience affects everything from how you frame a “reasonable safeguard” to what undertakings the Board typically accepts.
  • Ignoring cross-jurisdiction interplay — a DPDP Act fix can inadvertently break GDPR compliance if not reviewed holistically.

FAQs People Normally Have

Does the DPDP Act require me to use a regulatory-intelligence tool?
No. The Act requires “appropriate technical and organisational measures.” A tool is not mandated, but failing to monitor changes through any reliable system can be evidence of an insufficient organisational measure.

If I get a show-cause notice, does it mean a penalty is inevitable?
Not at all. A large number of notices are disposed of with directions or warnings, especially if you demonstrate a genuine compliance process and no data harm.

Can I backdate a compliance report to cover a missed update?
Absolutely do not. Backdating amounts to falsification and can trigger criminal liability under the Indian Penal Code still applicable in parallel with BNS for pre-existing acts. Boards are experienced in scrutinizing metadata.

How frequently should I run a regulatory change audit?
Monthly is a good rhythm for most mid-sized firms. If you operate in high-change sectors like health or fintech, fortnightly with a lawyer review every quarter is safer.

This article is general legal information, not legal advice. Consult a qualified advocate about your specific situation.

Advocate Sudhir Rao, Supreme Court of India

Was this article useful?

/5 (0 ratings)