Next dueCompany / ROC
14 OCTADT-1 · Auditor appointment (after AGM)in 4 days 30 OCTAOC-4 · Financial statements · FY 2025-26in 20 days 31 OCTMSME-1 · Dues to MSMEs · Apr–Sep 2026in 21 days 21 NOVITR filing · Audit cases · AY 2026-27 · extended from 31 Octin 42 days 29 NOVMGT-7 / 7A · Annual return · FY 2025-26in 50 days 30 JUNDPT-3 · Return of deposits · FY 2026-27in 263 days 11 OCTGSTR-1 · Outward supplies · Sep 2026tomorrow 15 OCTPF & ESI · Contributions · Sep 2026in 5 days
All due dates

Section 8 of the Digital Personal Data Protection Act, 2023: Accuracy and organisational measures

Where personal data is likely to be used to make a decision that affects the Data Principal, or likely to be disclosed to another Data Fiduciary, the fiduciary processing it must...

Published
Updated
Reading time
7 min
Views
7
Questions
6 answered
  • Expert Reviewed
  • Medium Complexity
Topic
Data Protection
Published
September 30, 2026
Last updated
Oct 8, 2026
Reading time
7 min
0:00
Last updated: October 2026Verified against: Government sources

Section 8(3) requires a Data Fiduciary to ensure that personal data is complete, accurate and consistent where it is likely to be used for a decision affecting the Data Principal or disclosed to another Data Fiduciary. Section 8(4) requires appropriate technical and organisational measures to make the Act's observance effective. A short legal consultation can help map where your data feeds decisions.

Sub-sections (3) and (4) at a glance

Sub-sectionTriggerDuty
8(3)(a)Data likely to be used to make a decision that affects the Data PrincipalEnsure completeness, accuracy and consistency
8(3)(b)Data likely to be disclosed to another Data FiduciaryEnsure completeness, accuracy and consistency
8(4)AlwaysImplement appropriate technical and organisational measures to ensure effective observance of the Act and the rules

Section 8(3): accuracy is triggered by use

The duty is not a blanket "keep all data accurate". It is conditional on two situations, each using the words "is likely to be":

  • (a) used to make a decision that affects the Data Principal. Examples are credit approval, hiring or promotion, insurance pricing, service eligibility or account suspension. The Act does not define "a decision that affects" her, so read it by ordinary meaning: an outcome that changes her position.
  • (b) disclosed to another Data Fiduciary. Sharing data with a group company, a credit bureau, a business partner or a marketplace seller engages the duty, even if no decision is made at your end.

The "likely" wording means you cannot wait until the data is actually used. If a record is held for a purpose where decisions are an ordinary outcome, the duty is already on you. "Data Fiduciary processing such personal data" is the bound party, which includes a fiduciary that received the data from another.

Three words deserve a separate look. Completeness means missing fields that change the picture, for example a loan record showing a default but not the later settlement. Accuracy means correct facts. Consistency means the same person's data does not differ across your systems, for example two addresses in CRM and billing with no rule for which prevails. The text gives no test or standard, so the assessment is factual: what you did to keep data fit for the decision.

Interaction with the Data Principal's right to correction

Section 12(2) says that on a Data Principal's request the fiduciary must correct inaccurate or misleading data, complete incomplete data and update it. Section 8(3) works on the fiduciary's own initiative; section 12 works on request. Section 15(e) in turn requires the Data Principal to furnish only verifiably authentic information when exercising the right to correction or erasure. See section 12.

Where section 8(3) may not apply

Section 17(3) lets the Central Government notify certain Data Fiduciaries or classes, including startups, to whom section 5, sub-sections (3) and (7) of section 8 and sections 10 and 11 do not apply. That covers sub-section (3) of section 8, but only where such a notification exists. The other exemptions in section 17(1) switch off Chapter II except sub-sections (1) and (5) of section 8, so sub-section (3) is exempt in those cases. Check the notifications for your category. See section 17(3).

Section 8(4): "technical and organisational measures"

Section 8(4) is general and short. The fiduciary "shall implement appropriate technical and organisational measures to ensure effective observance of the provisions of this Act and the rules made thereunder". The Act gives no list, so the standard is that the measures be appropriate and effective. In practice, this is the accountability layer that sits behind every other obligation:

  • Technical: access controls, logging, encryption, automated retention and deletion, consent records, a way to route a withdrawal to all systems.
  • Organisational: a named owner for compliance, written policies, staff training, a vendor register, an incident playbook, periodic internal review.

It is different from section 8(5), which is specifically about security safeguards to prevent a personal data breach and carries its own higher penalty. Section 8(4) is about making the whole Act work in the organisation. See reasonable security safeguards.

The word "appropriate" scales with the business. A five-person firm and a national platform will not look alike. Section 33(2) does not use "appropriateness" but does require the Board to weigh the nature of the data, the gravity and duration of a breach and mitigation, which in practice is where documented measures help.

Consequence of breach

There is no dedicated Schedule entry for section 8(3) or 8(4). Item 7 of the Schedule covers breach of any other provision of the Act or the rules: penalty may extend to fifty crore rupees. The Board can impose it only after an inquiry, a hearing, and a determination that the breach is significant (section 33(1)). Inaccurate data that leads to a data breach could additionally engage section 8(5), which has its own entry. See penalties.

Practical examples

Example 1: lender and bureau. A lender shares repayment data with another Data Fiduciary. If the lender has not updated a settled account, the data is incomplete and inaccurate at the point of disclosure. Section 8(3)(b) is the relevant duty.

Example 2: hiring tool. An employer uses applicant records to shortlist candidates. The decision affects the applicant, so section 8(3)(a) expects reasonably complete, accurate and consistent records, for example no mix-up between two candidates with the same name.

Example 3: no owner for compliance. A company has a privacy policy on its website but no process to route requests, no training and no vendor list. The gap is one of organisational measures under section 8(4).

Common mistakes

  • Treating accuracy as only a Data Principal's right to ask, not as the fiduciary's own duty.
  • Ignoring disclosure to other fiduciaries because "no decision is made here".
  • Relying on a policy document as the only measure.
  • Confusing section 8(4) with security safeguards in section 8(5).

Need help with data quality and accountability measures?

If you are unsure which of your systems feed decisions or get shared with other businesses, a structured review helps set priorities. Speak to us under our legal consultation service to shape practical measures for your size of business.

Key takeaways

  • The accuracy duty is triggered by likely decisions affecting the Data Principal or likely disclosure to another Data Fiduciary.
  • It covers completeness, accuracy and consistency.
  • Technical and organisational measures must be appropriate and effective.
  • No Schedule entry is specific to these sub-sections; the fifty crore ceiling for other provisions applies.
  • Section 17(3) notifications, if any, can remove sub-section (3) for certain fiduciaries.

Read next

Disclaimer: Based on the Digital Personal Data Protection Act, 2023 (official text as enacted, No. 22 of 2023) as on 30 September 2026. The DPDP Rules, 2025 were notified in November 2025 and different provisions commence on different dates; this article does not state rule-level detail. Verify the current position in the Rules and the commencement notifications before acting.

Quick recapKey facts & short answers

Key Facts About Section 8

  • Applies in: All states across India, under the relevant central law.
  • Mode: Mostly online via the official government portal.
  • Typical timeline: Ranges from a few days to a few weeks depending on the case.
  • Non-compliance: May attract penalties, interest or late fees.
  • Expert help: TaxClue completes the entire process end to end for you.

Does section 8(3) require all personal data to be accurate?

The text applies it to data likely to be used for a decision affecting the Data Principal or likely to be disclosed to another Data Fiduciary.

What counts as a decision that affects the Data Principal?

The Act does not define it. Read it by ordinary meaning as an outcome that changes her position, such as credit, hiring or eligibility.

Good compliance is boring by design; the drama starts only when something has been skipped.

— TaxClue Compliance Desk

Section 8: a key compliance topic in Indian tax and corporate law that businesses and individuals must understand to remain compliant.

Related Services & Guides

Was this article helpful?
About the author
13,350 articles
Vikas Sharma Verified expert Tax & Compliance Expert

Experienced in company registration, GST, trademark, and compliance. Helping Indian businesses stay compliant.

Last reviewed: Live

Disclaimer: This article is for general informational purposes only and does not constitute professional tax, legal or financial advice. Laws, rates and due dates change and can vary by individual case — always verify with the relevant government source (e.g. mca.gov.in, incometax.gov.in) or consult a qualified professional before acting. TaxClue accepts no liability for decisions taken based on this content.

People also ask

Questions, answered

Short, direct answers to the 6 questions readers ask most on this topic.

The text applies it to data likely to be used for a decision affecting the Data Principal or likely to be disclosed to another Data Fiduciary.

The Act does not define it. Read it by ordinary meaning as an outcome that changes her position, such as credit, hiring or eligibility.

Section 8(4) does not list them. They are the systems and internal arrangements that make the Act work in practice, and must be appropriate and effective.

No. Security safeguards to prevent a personal data breach are in section 8(5), with a separate and higher penalty.

Only if the Central Government notifies it, or its class, under section 17(3). Check the notifications.

Item 7 of the Schedule applies: up to fifty crore rupees for breach of any other provision, subject to section 33.