DPDPA Section 32: Voluntary Undertakings and How They Work

DPDPA Section 32: Voluntary Undertakings and How They Work

Ensure your business meets DPDP Act compliance requirements. Discover key obligations for data fiduciaries, penalty risks, and steps to protect user privacy.

Himanshu Jotwani

Written by

Himanshu Jotwani

Date

Read time

6 min

A voluntary undertaking sounds like a polite corporate apology. You admit a gap, promise to fix it, and everyone moves on. Under DPDPA Section 32, it is anything but.

Section 32 creates a formal path for resolving compliance issues through a voluntary undertaking given to the Data Protection Board. It is a settlement tool available during a proceeding under section 28. If accepted, it halts further action by the Board on those specific issues.

But this is not a soft option.

The moment you fail to comply with the undertaking, that failure is treated as a breach of the Act itself. The Board can then move under section 33 after giving you a hearing. You are trading litigation risk for a strict, unforgiving performance obligation.

What DPDPA Section 32 Permits

The Board may accept a DPDP voluntary undertaking from any person on any matter related to observance of the Act.

This can happen at any stage of a proceeding under section 28. The undertaking can include commitments to take specific actions within a time set by the Board, to refrain from certain actions, and to publicise the undertaking itself.

The Board and the person who gave the undertaking can later agree to vary its terms.

The provision is broad. It can apply to data fiduciaries and any other person involved in the matter before the Board.

When It Applies

Availability is tied strictly to an active proceeding under section 28.

You cannot use Section 32 as a general pre-emptive safe harbor outside that context. Once a section 28 proceeding is on, you can propose an undertaking at any stage.

In practice, this means internal detection of issues should trigger two parallel tracks. First, immediate containment and remediation. Second, a readiness plan for an undertaking if a section 28 proceeding begins or is likely.

Illustration showing two parallel tracks for internal detection of issues under DPDPA Section 32.

What Can Be Included in an Undertaking

The text allows commitments to act, to refrain, and to publicise. The interpretation of this in operations is straightforward:

  • Corrective actions. Fix a non-compliant consent flow, implement stronger access controls, or revise retention schedules.
  • Preventive controls. Introduce regular audits, strengthen vendor oversight, or improve breach detection.
  • Structural changes. Update policies, train staff, or assign clear ownership.
  • Cease or pause. Halt a processing activity until it meets the Act’s standards.
  • Publicity. Agree to communicate the undertaking, which can support transparency and deterrence.

The Board determines timelines. Build realistic but disciplined schedules, and be prepared to show a credible plan and the resources to execute it.

Effect of Acceptance

Acceptance has a strong legal effect. It creates a bar on further proceedings under the Act regarding the contents of the accepted undertaking.

In plain terms: once the Board accepts the undertaking, it will not continue to prosecute the same issues covered by it.

As long as you perform exactly as promised.

The bar is not global. It attaches only to the contents of the undertaking. Any issues outside its scope remain live. Also, if you default on any term, that breach is treated as a breach of the Act, and section 33 consequences can follow after a hearing.

Variation and Publicity

The Board can vary the terms after acceptance, but only with the consent of the person who gave the undertaking.

Treat variation as a controlled change process. If your implementation hits constraints, engage early and seek a documented variation. Do not unilaterally deviate.

Publicity is part of the menu. If the undertaking includes a commitment to publicise, plan the messaging. Keep it factual, avoid minimising the issue, and align internal and external communications.

Consequences of Breach

Failure to meet any term of the accepted undertaking is deemed a breach of the Act. The Board may then proceed under section 33 after giving you an opportunity to be heard.

The operational takeaway is simple: treat the undertaking like a binding order.

Missed milestones, partial implementation, or quiet scope changes will cost you more than if you had not used this route at all. Build contingency buffers, assign single-threaded owners, and document evidence of completion.

Practical Use by Compliance and Operations Teams

  • Assess fit early. If a section 28 proceeding is in play or anticipated, evaluate whether an undertaking can resolve the issues faster and with more certainty than a contested path.
  • Draft with precision. Define scope, controls, deliverables, timelines, and verification methods. Avoid vague promises. Specify how completion will be demonstrated.
  • Align with the Board’s expectations. The Board sets timeframes and can require publicity. Be prepared to justify your plan with risk assessments, technical details, and resourcing.
  • Establish monitoring and reporting. While not explicitly required by the text, you should implement periodic internal reviews and prepare clear progress updates. This supports accountability and helps avoid slippage.
  • Maintain evidence. Keep implementation records, training logs, configuration changes, vendor notices, and test results. If questioned, you need to show not just intent, but outcomes.
  • Plan for variation. If circumstances shift, seek timely consented variation. Document the rationale and new timelines.
  • Keep other obligations intact. An undertaking does not replace statutory duties. Continue to meet breach notification, data principal rights, and other control requirements.

Boundaries and Interpretation Points

  • Not a blanket amnesty. The bar applies only to the contents of the accepted undertaking. Problems outside that scope remain subject to proceedings.
  • Not a substitute for compliance. You still need to meet all obligations under the Act. Use an undertaking to close gaps, not to avoid baseline controls.
  • Timing matters. It is available only in the context of a section 28 proceeding. Pre-emptive corrective action is still wise but does not by itself trigger Section 32.
  • Reduction of penalties is not guaranteed. While voluntary correction can show good faith, the statute does not promise reduced penalties. Your best leverage is precise scope, credible delivery, and full performance.
  • Breach escalates quickly. Any failure counts as a breach of the Act, exposing you to section 33 paths. Manage it like a critical regulatory commitment.
Illustration showing a checklist of appropriate commitments for DPDPA Section 32 compliance.

Examples of Appropriate Commitments

  • Security remediation: Encrypt sensitive datasets at rest within 60 days, roll out multi-factor authentication to all privileged accounts within 30 days, and complete independent verification within 90 days.
  • Consent remediation: Redesign consent flows to meet the Act’s consent requirements, retrain frontline teams, and deploy an auditable consent registry within a fixed timeline.
  • Data minimisation and retention: Remove unnecessary data fields from a processing activity and implement an automated deletion schedule with logs reviewed monthly.
  • Awareness and governance: Conduct mandatory training across specific roles and establish clear accountability by designating responsible owners.

What Changes in Practice

For leaders, Section 32 is a structured route to resolve live cases with certainty. It trades litigation risk for a performance obligation. The bar on proceedings for the agreed scope is valuable, but only if you execute flawlessly.

For engineers and operators, expect clear deadlines and defined outcomes. The plan must be realistic, resourced, and testable. Treat it like a high-stakes project with executive visibility, formal change control, and tracked milestones.

For counsel and compliance teams, the heavy lift is in scoping, drafting, negotiating timelines, and setting verification criteria that the Board will find credible. Ensure the undertaking aligns with your broader compliance roadmap so fixes are durable, not tactical patches.

The mechanism rewards disciplined execution. If your organization can reliably deliver, an undertaking can close the file faster and cleaner than a drawn-out fight.

If delivery is shaky, do not sign what you cannot complete.

At Regodit, we know that an undertaking is only as good as the evidence proving you met it. We help teams operationalize commitments like these. We turn abstract legal obligations into clear tasks, timelines, owners, and verifiable evidence, so you can prove performance without scrambling.

If Section 32 is on your table, Regodit can help you structure the plan, track obligations, and maintain the exact evidence the Board expects.

Disclaimer: The views and explanations shared in this blog are based on our team's understanding of the relevant compliance frameworks. While every effort has been made to ensure accuracy, readers are encouraged to refer to the original legal provisions and official notifications for authoritative guidance. Please reach out to us at connect@solsphere.ai.

Keep reading

All blogs →