Sections 34-36 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Three short sections sit between the penalty provision and the power to block. Section 34 says every penalty goes to the Consolidated Fund of India. Section 35 protects the Government, the Board and its people from suits and prosecution for things done in good faith. Section 36 lets the Central Government require the Board, any Data Fiduciary or any intermediary to furnish information it calls for. Section 36 is the one with a direct effect on businesses. For help dealing with information demands, see our legal consultation team.
Section 34: "All sums realised by way of penalties imposed by the Board" are credited to the Consolidated Fund of India. Section 35: no suit, prosecution or other legal proceedings lie against the Central Government, the Board, its Chairperson, any Member, officer or employee for anything done or intended to be done in good faith. Section 36: the Central Government may, for the purposes of the Act, require the Board and any Data Fiduciary or intermediary to furnish such information as it may call for.
At a glance
| Section | Subject | Key content | Who it affects |
|---|---|---|---|
| 34 | Penalty proceeds | Credited to the Consolidated Fund of India | Penalised persons; complainants (no share) |
| 35 | Good faith | No suit, prosecution or other proceedings for acts done or intended in good faith | Government, Board, Chairperson, Members, officers, employees |
| 36 | Information | Government may require the Board, any Data Fiduciary or intermediary to furnish information | Board, fiduciaries, intermediaries |
Section 34: where the money goes
"All sums realised by way of penalties imposed by the Board under this Act, shall be credited to the Consolidated Fund of India."
Consequences:
- No share for the complainant. A Data Principal whose complaint leads to a penalty does not receive it. The Act has no compensation provision in sections 27 to 33.
- No funding for the Board. The Board does not keep the sums. The Act says nothing on how it is funded.
- Only penalties "imposed by the Board". Costs imposed on a complainant under section 28(12) are a different matter; section 34 does not mention costs.
A point worth stating plainly to clients: the Act creates no route in these sections for a Data Principal to claim money from the Fiduciary for harm suffered. Section 43A of the IT Act, 2000, which dealt with compensation for failure to protect data, is omitted by section 44(2)(a) of this Act when that provision comes into force. Check the commencement position and the Rules. See section 44.
Section 35: protection for action taken in good faith
"No suit, prosecution or other legal proceedings shall lie against the Central Government, the Board, its Chairperson and any Member, officer or employee thereof for anything which is done or intended to be done in good faith under the provisions of this Act or the rules made thereunder."
| Element | Text | Note |
|---|---|---|
| Protected | The Central Government, the Board, its Chairperson, any Member, officer or employee | Not intermediaries, Consent Managers or fiduciaries |
| Protected acts | "anything which is done or intended to be done" | Covers acts and intended acts |
| Condition | "in good faith" | Bad faith is outside the protection |
| Under | "the provisions of this Act or the rules made thereunder" | Acts outside the Act are not covered |
| Bar | "No suit, prosecution or other legal proceedings shall lie" | Broad bar on civil and criminal proceedings |
What it does not do: it does not bar an appeal under section 29 against a Board order. The appeal is against the order, not a proceeding against the person who made it. It also does not define good faith. The Act does not say who has the burden of showing bad faith. A person who alleges bad faith would have to plead and prove it.
Section 35 sits alongside section 39 (civil courts have no jurisdiction on matters the Board is empowered to decide) and the public servant status in section 25. Together they make the Board's decisions challengeable only through the statutory appeal. See sections 38 and 39.
Section 36: power to call for information
"The Central Government may, for the purposes of this Act, require the Board and any Data Fiduciary or intermediary to furnish such information as it may call for."
Read it piece by piece.
- Who can call: the Central Government. The section does not say that an officer or agency may, nor that a written form is needed.
- Purpose: "for the purposes of this Act": limited to administering the Act. The Act does not say who judges whether a request is within that purpose.
- Who can be required: the Board, "any Data Fiduciary" and "any intermediary". Data Processors and Consent Managers are not named in this section. The Act defines "intermediary" by reference to the IT Act, 2000 only "for the purposes of" section 37 (section 37(3)); section 36 has no separate definition.
- What: "such information as it may call for". The Act sets no limit on content, form or format and gives no time limit for compliance. The Rules may prescribe detail; this article states none.
Interaction with the Board's powers
Section 28(7) gives the Board civil court powers on matters including production of documents and inspection of data. Section 36 is a different channel: the Government, not the Board, asks, and it does not depend on a pending inquiry. Section 36 also covers the Board itself, so the Government can ask the Board for information. This is a point to keep in mind when judging the Board's independence described in section 28(1).
Consequences of not complying
The Act attaches no specific penalty to failure to furnish information under section 36. The Schedule has no item for it. Item 7 covers breach of "any other provision of this Act or the rules made thereunder", up to fifty crore rupees, and it would be for the Board to decide whether failure to comply with section 36 is a breach and whether it is significant under section 33(1). The text does not spell this out, so treat information requests as binding and respond.
Practical steps for a business
- Name a single point of contact for Government information requests.
- Log every request: date, authority, scope, response and sign-off.
- Check the legal basis in the letter: does it refer to section 36 and to the purposes of the Act?
- Limit responses to what is asked, and keep copies of what was supplied.
- Protect confidential material in the way other laws allow; the Act does not address confidentiality of information supplied.
- Keep a record-ready data inventory so that responses are quick and accurate.
Example
The Central Government writes to a messaging platform, an intermediary, asking for information about how it handles notices for blocking of content. The platform responds within the period the letter sets, through a designated officer, and keeps a copy. The Act sets no period; the letter or Rules would.
What the three sections do not say
- No rule on how the Board is funded.
- No definition of "good faith".
- No time limit, format or penalty specific to section 36 requests.
- No statement on confidentiality of information furnished.
Need help with information requests?
Government requests for information, and the records behind them, are easier to handle when the process exists before the letter arrives. Our legal consultation team can help you set up a response procedure and review each request.
Key takeaways
- Penalties go to the Consolidated Fund of India, not the complainant or the Board.
- No suit, prosecution or other proceedings lie against the Government, the Board or its people for good-faith acts under the Act.
- The Central Government can call for information from the Board, any Data Fiduciary or intermediary for the purposes of the Act.
- No specific penalty is set for ignoring a section 36 request.
Read next
- Section 33 of the DPDP Act, 2023: monetary penalty and factors
- Section 37 of the DPDP Act, 2023: blocking of information
- Section 44 of the DPDP Act, 2023: amendments to the IT Act, RTI Act and TRAI Act
- Penalties under the DPDP Act
Disclaimer: Based on the Digital Personal Data Protection Act, 2023 (official text as enacted, No. 22 of 2023) as on 30 September 2026. The DPDP Rules, 2025 were notified in November 2025 and different provisions commence on different dates; this article does not state rule-level detail. Verify the current position in the Rules and the commencement notifications before acting.
