
DPDPA Section 35: Protection for Actions Taken in Good Faith
Navigate DPDP Act compliance with our comprehensive guide. Discover essential steps for data fiduciaries to protect user privacy and avoid hefty penalties.
Written by
Himanshu Jotwani
Date
Read time
5 min

When a regulator hands down a massive penalty, the first instinct of a cornered executive is often to look for someone to sue. DPDPA Section 35 exists to make sure that “someone” isn’t the regulator.
The Act grants legal protection to government authorities and the Data Protection Board when they act in good faith under the law or its rules. This is not just a legal footnote. It dictates how enforcement happens, where accountability sits, and why your legal strategy needs to target the finding, not the official.
What Section 35 Says
No suit, prosecution, or other legal proceeding can be brought against the Central Government, the Data Protection Board, its Chairperson and Members, or any of their officers or employees for anything done, or intended to be done, in good faith under the Act or the rules.
In plain terms: if an official or the Board acts honestly, within their legal powers, and for a lawful purpose under the DPDPA, they are protected from personal legal action. You cannot sue the auditor just because you dislike the audit.

Who Is Covered
The shield attaches to the role, not the individual in a personal capacity. Section 35 covers:
- The Central Government
- The Data Protection Board
- The Board’s Chairperson and Members
- Officers and employees of the government or the Board acting under the Act or the rules
It applies strictly to acts done,or intended to be done,under the DPDPA framework.
What “Good Faith” Means
Good faith is not a vague feeling. It means honest intention, lawful purpose, and action within the scope of authority. It excludes corrupt motives, deliberate wrongdoing, or actions taken with the knowledge that they exceed legal powers.
Typical good-faith actions include:
- Investigations into suspected non-compliance
- Enforcement steps, including imposing penalties
- Issuing directions, conducting compliance checks, and audits
If these are carried out according to the law and without malice, personal liability does not attach to the officials involved. DPDPA good faith protection ensures the machinery of compliance keeps moving.
What Is Outside the Shield
The immunity is a shield, not a blank check. It does not protect:
- Actions driven by corrupt motives or malice
- Intentional violations of law
- Clear excess of legal authority
If an official acts with bad faith or knowingly disregards the law, Section 35 drops. Accountability is preserved for egregious misconduct.
Why This Provision Exists
Enforcement requires judgment calls that will inevitably be contested. Without statutory immunity, officials would face personal lawsuits for every difficult decision. That threat would paralyze the regulatory body.
Section 35 ensures officials can perform their duties without fear of personal litigation when they act lawfully. At the same time, it balances effective enforcement with continued accountability for bad-faith conduct.
What Changes in Practice for Organizations
- Target the decision, not the person. If you disagree with an audit finding, direction, or penalty, focus on the legal and procedural grounds. Section 35 blocks suits against individual officials for actions taken in good faith.
- Expect firmness in enforcement. Regulators who aren’t afraid of personal liability move decisively. Expect the Board and its officers to proceed with investigations, directions, and penalties without hesitation.
- Make your case on record. Maintain strong documentation for compliance decisions, incident response, and remediation. Your best defense is the evidence you can show within the formal process, not adversarial tactics against regulators.
- Prepare for audits and directions. Build internal processes for timely responses, fact gathering, and escalation. Rely on procedure and clarity, not posturing.

Practical Guidance for Teams Interacting With the Board
- Engage promptly and professionally. Aggressive posturing cannot pierce the good-faith shield. Clear, factual submissions can.
- Ask for clarification where needed. If directions or requests seem broad or unclear, seek specific guidance in writing. This narrows the scope and keeps actions aligned with the rules.
- Document your side thoroughly. Preserve logs, policies, assessments, decisions, and correspondence. If you need to challenge an outcome, the paper trail is your only weapon.
- Train your response team. Incident response, legal, and compliance teams should know the touchpoints, timelines, and evidentiary needs before the regulator knocks.
Illustrative Scenarios
- Penalty after a breach. A Board officer imposes a significant penalty for negligent handling that led to a major breach. If the company tries to sue the officer personally, Section 35 protects the officer, provided the decision followed due process, was lawful, and lacked malice.
- Compliance audit and corrective directions. An inspector audits a processor and issues directions to fix gaps. If the processor attempts a personal claim for costs, Section 35 shields the inspector when the actions were within their official capacity and in good faith.
- Advisory guidance on controls. An officer provides compliance guidance that is costly to implement. If the fiduciary sues the officer personally, Section 35 protects the officer when the advice is honest, lawful, and within the scope of the Act and rules.
Boundaries and Interpretation Notes
- Scope ties to the Act and rules. The protection applies only to actions done or intended to be done under the DPDPA or its rules. Step outside that scope, and the shield vanishes.
- Personal liability versus institutional decisions. Section 35 protects the official, it does not validate an incorrect decision. If a ruling is wrong on law or procedure, the right approach is to challenge the decision itself through the mechanisms available under the Act.
- Good faith is a factual test. Intent, lawfulness, and authority matter. Proper documentation and adherence to procedure are often decisive indicators of good faith.
What This Means for Compliance Programs
- Design for scrutiny. Write policies and procedures that your teams can actually follow under audit. Keep them simple, specific, and aligned with the Act and rules.
- Build an evidence trail. Maintain records of risk assessments, vendor diligence, training, incident handling, and decision rationales.
- Calibrate risk responses. When you receive directions or face investigations, move fast, assign owners, and track every step. Show your work.
- Keep tone measured. The law protects good-faith officials. Your best strategy is a disciplined process that demonstrates your own good faith and legal compliance.
Closing
Section 35 protects the enforcement function while preserving accountability for bad faith. For operators, the takeaway is clear: expect firm, process-driven actions from the Board and its officers. Prepare to meet that with clean records, timely responses, and precise arguments on the law and facts. That is how you resolve issues efficiently and keep operations on track.
Real execution is about consistency. Policies, logs, and decisions must line up each time you are tested. At Regodit, we built our platform to give teams a structured way to capture evidence, track obligations, and manage responses,so that when the Board asks questions, your answers stand up under scrutiny.
Disclaimer: The views and explanations shared in this blog are based on our team's understanding of the relevant compliance frameworks. While every effort has been made to ensure accuracy, readers are encouraged to refer to the original legal provisions and official notifications for authoritative guidance. Please reach out to us at connect@solsphere.ai.
Keep reading
All blogs →DPDPA Rule 23: Government Requests for Information from Data Fiduciaries and Intermediaries
Handling a notice under DPDP Act Rule 23 requires strict confidentiality. Discover how to respond to government data requests and ensure full compliance.
DPDPA Rule 22: Appeals to the Appellate Tribunal
Lost at the Data Protection Board? DPDPA Rule 22 governs the digital-first appeals process. Read our complete guide to filing an appeal with the Tribunal.
DPDPA Rule 21: The Machinery Behind the Data Protection Board of India
Ensure your business meets DPDP Act compliance requirements. Discover key obligations for data fiduciaries, penalty risks, and steps to protect user privacy.
