/The Act · Chapter IX · Miscellaneous
Section 35: Protection of action taken in good faith
DPDP Act, 2023 (No. 22 of 2023). In force since 13 November 2025.
- Provision
- Section 35 of The Digital Personal Data Protection Act, 2023
- Status
- In force since 13 November 2025 (phase 1) G.S.R. 843(E)
- Rules made under it
- None identified
- Source
- Ministry of Law and Justice (Legislative Department) · 11 August 2023 · Official PDF
No suit, prosecution or other legal proceedings shall lie against the Central Government, the Board, its Chairperson and any Member, officer or employee thereof for anything which is done or intended to be done in good faith under the provisions of this Act or the rules made thereunder.
Section 35 provides legal immunity to the government and the regulatory body responsible for enforcing the law. Specifically, it protects the Central Government and the Data Protection Board of India (referred to as the Board). This protection extends to the Chairperson, Members, officers, and employees of the Board.\n\nThe provision states that no lawsuit, criminal prosecution, or other legal proceeding can be filed against these entities and individuals for their actions. However, this protection is not absolute. It only applies if the action was taken, or intended to be taken, in good faith while carrying out duties under the Act or its associated rules.\n\nThis means that as long as the government or the Board's staff act honestly and with the intention of following the law, they cannot be sued for those actions. This allows regulators to perform their duties without the threat of legal retaliation.
Key points
- No lawsuit or prosecution can be filed against the Central Government or the Board for actions taken under this law.
- This legal immunity extends to the Chairperson, Members, officers, and employees of the Board.
- The protection only applies to actions that are done, or intended to be done, in good faith under the Act or its rules.
Common misreadings
- People might think this gives the Board absolute immunity, but the text specifies that actions must be done or intended to be done in good faith to be protected.
- People might think this protects Data Fiduciaries, but it only protects the Central Government, the Board, and their personnel.
Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.
/MYND · DPDP practice
Putting this into practice?
MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.