Section 37 permits the Central Government to block public access to the digital service or information through which a repeatedly non-compliant Data Fiduciary offers goods or services to Data Principals in India. It is an exceptional enforcement measure intended for cases where monetary penalties have already been imposed in two or more instances and the Board considers blocking necessary in the general public interest.

The provision does not make blocking automatic after two penalties. The process requires:

  • a written reference from the Data Protection Board;

  • confirmation that monetary penalties were imposed on the Data Fiduciary in two or more instances;

  • the Board’s advice that blocking is required in the general public interest;

  • an opportunity for the Data Fiduciary to be heard;

  • the Central Government’s independent satisfaction that blocking is necessary or expedient in the general public interest; and

  • a reasoned written order.

The Board recommends blocking, but the final decision belongs to the Central Government or an officer specially authorised by it. The Government must consider the Data Fiduciary’s response and record why blocking is justified. Prior penalties alone are insufficient if the Data Fiduciary has corrected the underlying failures and no continuing public risk remains.

The order may require a Central Government agency or an intermediary to block public access to information generated, transmitted, received, stored or hosted in a computer resource that enables the Data Fiduciary to offer goods or services in India. Depending on the service architecture, this may affect a website, mobile application, online marketplace, digital platform, customer portal or another public-facing digital service.

An intermediary receiving a valid blocking direction is legally required to comply. Section 37 adopts the meanings of “computer resource,” “information” and “intermediary” from the Information Technology Act, 2000.

The measure should be proportionate to the identified public risk. Where the compliance failure concerns only a particular feature or service, a targeted restriction may be more appropriate than blocking the Data Fiduciary’s entire digital presence. The Government should also consider the effect on existing users who may need to:

  • withdraw funds;

  • download records;

  • obtain refunds;

  • access purchased services;

  • exercise DPDPA rights; or

  • close their accounts.

Illustration

A digital platform is penalised on separate occasions for continuing to profile users after consent withdrawal. Despite the penalties, it continues the same practice through another advertising system. The Board may recommend blocking if it concludes that the continuing processing creates a public-interest concern and monetary penalties have not secured compliance.

The Government must still hear the platform and consider whether the problem can be addressed through a narrower restriction. If the unlawful profiling occurs only through one advertising interface, blocking that interface may be more proportionate than disabling unrelated account-access functions.

Conversely, where two historical penalties were imposed but the Data Fiduciary has replaced the affected systems, corrected its practices and demonstrated sustained compliance, the numerical threshold does not by itself require blocking.

The final DPDP Rules, 2025 do not prescribe a separate detailed procedure for Section 37. The principal safeguards are therefore contained in the section itself: repeated penalty instances, a written Board reference, public-interest advice, a hearing, independent governmental satisfaction and recorded reasons.

Commencement position: Section 37 is scheduled to come into force on13 May 2027. As of 18 August 2026, it is enacted but not yet operational.