CHAPTER VII - APPEAL AND ALTERNATE DISPUTE RESOLUTION

Section 32 - Voluntary undertaking

Official text

(1)The Board may accept a voluntary undertaking in respect of any matter related to observance of the provisions of this Act from any person at any stage of a proceeding under section 28.

(2)The voluntary undertaking referred to in sub-section (1) may include an undertaking to take such action within such time as may be determined by the Board, or refrain from taking such action, and or publicising such undertaking.

(3)The Board may, after accepting the voluntary undertaking and with the consent of the person who gave the voluntary undertaking vary the terms included in the voluntary undertaking.

(4)The acceptance of the voluntary undertaking by the Board shall constitute a bar on proceedings under the provisions of this Act as regards the contents of the voluntary undertaking, except in cases covered by sub-section (5).

(5)Where a person fails to adhere to any term of the voluntary undertaking accepted by the Board, such breach shall be deemed to be breach of the provisions of this Act and the Board may, after giving such person an opportunity of being heard, proceed in accordance with the provisions of section 33.

Commentary

Section 32 establishes a regulatory settlement mechanism through which the Data Protection Board of India may accept a binding compliance undertaking from a person involved in a proceeding under Section 28. It allows identified compliance failures to be corrected through specific, time-bound commitments without requiring the Board to complete proceedings on the matters covered by the undertaking.

The mechanism balances regulatory efficiency with enforceability. Once the Board accepts an undertaking, proceedings concerning its contents are barred. In return, the person must comply with every accepted term. Failure to do so is deemed to be a breach of the DPDPA and may result in penalty proceedings under Section 33.

Commencement position: Section 32 is scheduled to come into force on13 May 2027, eighteen months after publication of the commencement notification dated 13 November 2025. As of 17 August 2026, it is enacted but not yet operational.

1.1 Nature of the mechanism

A voluntary undertaking is a formal commitment concerning observance of the DPDPA. It may require a person to:

  • correct an existing compliance failure;

  • take remedial or preventive action;

  • complete specified measures within a period determined by the Board;

  • stop or refrain from specified processing;

  • publicise the undertaking; or

  • implement a combination of corrective, preventive and transparency measures.

It is not the same as:

  • an informal assurance given during correspondence;

  • an internal remediation plan;

  • a private settlement with a Data Principal;

  • mediation under Section 31;

  • a contractual promise by a processor;

  • an admission of liability in every case; or

  • an automatic waiver of penalties.

The proposal acquires its statutory effect only when the Board accepts it.

Although described as voluntary, the undertaking becomes binding once accepted. The person is free to decide whether to offer or consent to the undertaking, but is not free to disregard its terms afterward.

1.2 When a voluntary undertaking may be accepted

The Board may accept an undertaking at any stage of a proceeding under Section 28. This allows the mechanism to be used after a proceeding has begun but before it has necessarily reached a final determination.

An undertaking could therefore be proposed:

  • after a complaint or other matter has entered Board proceedings;

  • after the person files its initial response;

  • after preliminary facts reveal a compliance deficiency;

  • during the Board’s examination of the matter;

  • after immediate remedial action has begun; or

  • before the Board reaches a final conclusion.

Section 32 is not framed as a general advance-clearance mechanism. A company cannot ordinarily approach the Board outside a Section 28 proceeding and ask it to approve all future processing through a voluntary undertaking.

The Board retains discretion over acceptance. A person may offer an undertaking, but cannot insist that the Board accept it. The Board may consider whether:

  • the proposed action addresses the complete compliance problem;

  • continuing harm has been stopped;

  • the timetable is realistic;

  • affected Data Principals receive meaningful protection;

  • the commitments are measurable;

  • compliance can be independently verified;

  • the issue is isolated or systemic;

  • similar failures have occurred previously; and

  • accepting the undertaking would ensure effective observance of the Act.

Seriousness does not necessarily make an undertaking unavailable, but a vague promise will be particularly inadequate where the matter involves a large breach, repeated non-compliance, children’s data, deliberate misuse or continuing harm.

1.3 Persons who may give an undertaking

Section 32 permits the Board to accept an undertaking from any person, not only a Data Fiduciary.

Depending on the nature of the proceeding, the person may be:

  • a Data Fiduciary;

  • a Significant Data Fiduciary;

  • a Consent Manager;

  • a State body;

  • an individual;

  • a company, firm or association; or

  • another person properly involved in the proceeding.

A Data Processor may need to perform substantial remedial work. However, an undertaking should not be used to distort the underlying statutory roles.

Example

For example, if a payroll processor exposed employee records, the employer remains accountable as the Data Fiduciary for processing undertaken on its behalf. The undertaking may require the processor to support remediation, but it should not improperly transfer the employer’s Section 8 accountability to the processor.

2. Section 32 permits the undertaking to include publicising it.

Publication may be appropriate where it is necessary to:

  • inform affected Data Principals;

  • explain corrective action;

  • correct misleading public information;

  • provide transparency;

  • enable individuals to seek correction or erasure;

  • demonstrate Board-supervised remediation; or

  • deter recurrence.

The undertaking should specify:

  • whether the full text or a summary will be published;

  • the publication channel;

  • duration;

  • language;

  • whether direct individual communication is also required; and

  • treatment of confidential or security-sensitive information.

Publication should not disclose:

  • additional personal data;

  • exploitable security details;

  • passwords or authentication mechanisms;

  • unremediated vulnerabilities;

  • confidential information of third parties; or

  • the identity of employees who are not properly part of the public matter.

Publicising an undertaking does not replace a mandatory breach notification or other communication required under the Act.

2.1 Variation of an accepted undertaking

The Board may vary an accepted undertaking, but only with the consent of the person who gave it.

Neither side can change it unilaterally:

  • the person cannot extend a deadline or reduce the scope without Board acceptance;

  • the Board cannot rewrite the accepted terms under Section 32(3) without the person’s consent.

2.2 Effect of acceptance: bar on proceedings

Once the Board accepts the undertaking, further DPDPA proceedings are barred as regards the contents of the undertaking, provided the undertaking is complied with.

This gives the person regulatory certainty, but only within the undertaking’s defined scope.

The bar does not necessarily cover:

  • matters omitted from the undertaking;

  • newly discovered processing;

  • separate breaches;

  • future violations;

  • other affected Data Principals’ distinct complaints;

  • obligations under other laws; or

  • conduct occurring after acceptance.

The scope of the undertaking must therefore be drafted carefully.

Example

An undertaking addresses:

  • retention of inactive user accounts;

  • deletion of those accounts; and

  • correction of the retention system.

It does not necessarily bar proceedings concerning a separate failure to notify a personal data breach unless that matter is clearly included.

Likewise, an undertaking covering one marketing campaign does not protect unrelated profiling activities.

2.3 No automatic finding of innocence or liability

Acceptance does not necessarily mean that:

  • the Board has found no violation;

  • the person has formally admitted every alleged breach;

  • all processing was lawful;

  • every affected Data Principal has been compensated; or

  • unrelated matters are closed.

The undertaking resolves the covered regulatory matters through accepted commitments rather than through a completed adjudication.

Where admission or non-admission is important, the accepted terms should address it expressly. The undertaking’s legal consequences come from Section 32, not simply from whether the person admits liability.

2.4 Breach of an undertaking

Failure to comply with any accepted term is deemed to be a breach of the DPDPA.

Before proceeding under Section 33, the Board must give the person an opportunity to be heard. The person may therefore explain matters such as:

  • whether the required action was completed;

  • whether the disputed term applied;

  • whether the evidence demonstrates compliance;

  • whether an impossibility arose;

  • whether a valid variation had been agreed; or

  • whether the alleged non-compliance resulted from another cause.

However, the hearing is not an opportunity to treat accepted obligations as optional.

A breach may include:

  • missing a deadline;

  • completing only part of the required action;

  • failing to cause processor deletion;

  • restarting prohibited processing;

  • submitting misleading completion evidence;

  • failing to publish the undertaking where required;

  • failing to deliver an audit report;

  • failing to implement promised controls; or

  • continuing the same conduct under a different internal label.

The Board may then proceed under Section 33. The deemed breach concerns non-adherence to the undertaking itself, even if the person seeks to reopen arguments about the original underlying matter.

2.5 Relationship with mediation under Section 31

A voluntary undertaking is different from mediation.

Mediation under Section 31Voluntary undertaking under Section 32
Seeks agreement between partiesCreates commitments accepted by the Board
Uses a mediatorDoes not require a mediator
Focuses primarily on resolving a complaintFocuses on observance of the Act
May end without settlementBecomes binding once accepted
Requires mutual agreement on settlementOffered by a person and accepted by the Board
May address individual reliefMay address individual and systemic remediation
Failure to settle is not a breachFailure to comply is deemed a breach of the Act

A mediated settlement may be accompanied by a voluntary undertaking where wider compliance measures are necessary.

Example

A Data Principal and an employer mediate a dispute concerning an inaccurate disciplinary record. They agree that the record will be corrected and the employee’s appraisal reconsidered.

The Board may separately accept an undertaking requiring the employer to:

  • review similar records across the workforce;

  • revise investigation procedures;

  • correct processor databases;

  • train HR personnel; and

  • submit an independent compliance report.

The settlement resolves the individual dispute. The undertaking addresses the systemic compliance issue.

2.6 Detailed case studies

2.7 Case study 1: Recruitment data retained indefinitely

A company retains unsuccessful applicants’ CVs, interview recordings, background reports and AI scores indefinitely. Its recruitment vendor also uses the information to improve a cross-client matching product.

A Board proceeding begins after an applicant complains.

A meaningful undertaking may require the company to:

  • stop indefinite retention;

  • identify completed recruitment exercises;

  • delete records without a continuing lawful purpose;

  • impose a defined retention schedule;

  • cause its recruitment processors to delete copies;

  • separately address the vendor’s independent use;

  • prevent further AI training;

  • revise applicant notices;

  • establish a correction and erasure channel;

  • audit prior deletions; and

  • submit evidence to the Board.

A promise to “review retention practices” would be insufficient because it does not require an outcome.

2.8 Case study 2: Processor security failure

A cloud-hosted payroll system exposes employee salary, PAN and bank details because administrator accounts lacked multifactor authentication.

The employer proposes an undertaking to:

  • complete all required breach notifications;

  • reset affected credentials immediately;

  • implement multifactor authentication;

  • review privileged access;

  • encrypt specified exports;

  • retain and review security logs;

  • revise the processor contract;

  • test incident-response procedures;

  • conduct independent security testing; and

  • report completion to the Board.

Acceptance may bar further proceedings concerning the matters covered, but it would not automatically prevent proceedings if the employer conceals another affected system or later fails to follow the undertaking.

2.9 Case study 3: Marketing after withdrawal

A retailer continues marketing to thousands of customers after withdrawal because each marketing channel maintains a separate suppression list.

The undertaking may require:

  • immediate suspension of the affected campaigns;

  • reconciliation of withdrawal records;

  • centralised suppression;

  • processor correction;

  • direct communication to affected persons;

  • testing across email, SMS and advertising platforms;

  • periodic assurance; and

  • prohibition on reactivation without a valid ground.

This is more effective than resolving only the complaints of the first few customers who approached the Board.

2.10 Case study 4: Inaccurate AI risk scores

A lender uses an AI system that incorrectly classifies customers as high-risk because it relies on outdated employment and income information.

An undertaking may require the lender to:

  • stop using the affected model for adverse decisions;

  • identify persons assessed during the affected period;

  • correct the source data;

  • reassess affected applications;

  • notify relevant applicants;

  • review the model and thresholds;

  • implement human review;

  • establish a challenge process;

  • test data quality and model performance; and

  • submit an independent report.

The undertaking should address decisions already made as well as future model governance.

2.11 Practical design of an undertaking

A well-structured undertaking should ordinarily identify:

  1. the person giving it;

  2. the proceeding and matters covered;

  3. the relevant processing activities;

  4. affected Data Principal categories;

  5. immediate protective action;

  6. permanent corrective measures;

  7. conduct that must stop;

  8. deadlines and milestones;

  9. processors and subprocessors involved;

  10. legally required retention exceptions;

  11. evidence of completion;

  12. independent verification, where appropriate;

  13. reporting to the Board;

  14. publication requirements;

  15. the matters barred from further proceedings;

  16. monitoring arrangements;

  17. permitted variation; and

  18. consequences of non-compliance.

The commitments should be measurable. Expressions such as “reasonable efforts,” “as soon as practicable” or “appropriate improvement” should be supported by objective milestones where possible.

2.12 Concluding interpretation

Section 32 enables the Board to resolve DPDPA compliance matters through binding corrective commitments rather than requiring every issue to proceed to final adjudication.

Its effectiveness depends on three features:

  1. specificity: the undertaking must identify exactly what will be done or stopped;

  2. verification: the Board must be able to determine whether the commitments were fulfilled; and

  3. consequence: breach of an accepted term is itself deemed to be a breach of the Act.

The person giving the undertaking receives a significant benefit: proceedings are barred concerning the matters covered by the accepted terms. In return, the person must perform those terms fully and within the required time.

The central principle is:

Key point

A voluntary undertaking is voluntary when offered, binding when accepted, protective only within its defined scope, and independently enforceable if breached.

Reproduced from official sources for reference. Not legal advice. In case of any discrepancy, the text published in the Gazette of India prevails.