
DPDPA Section 37: Government Power to Direct Blocking for Repeat Data Protection Offenders
Ensure your business meets DPDP Act compliance requirements. Discover key obligations for data fiduciaries, penalty risks, and steps to protect user privacy.
Written by
Sahil Pugalia
Date
Read time
6 min

Most regulatory fines are treated as a cost of doing business. A line item on a spreadsheet. But DPDPA Section 37 changes the math. It authorizes the Central Government to direct the blocking of public access to information that enables a data fiduciary’s activities in India.
It is not a fine. It is a kill switch.
But it only flips after a very specific, defined trigger. This is a targeted enforcement lever for repeat non-compliance, executed with due process safeguards.

What Section 37 Actually Says
Section 37 empowers the Central Government, or its authorized officer, to order any Central Government agency or any intermediary to block public access to information in a computer resource that enables a data fiduciary to offer goods or services to Data Principals in India.
This power is not a standalone weapon. It activates only when the Data Protection Board sends a written reference that both:
- States the Board has imposed a monetary penalty on the data fiduciary in two or more instances.
- Advises, in the interests of the general public, that blocking is warranted.
Before issuing the order, the Government must:
- Give the data fiduciary an opportunity of being heard.
- Be satisfied that blocking is necessary or expedient in the interests of the general public.
- Record reasons in writing.
Every intermediary that receives such a direction is legally bound to comply. The terms computer resource, information, and intermediary carry the meanings assigned under the Information Technology Act, 2000.
Scope and Applicability
This section is narrow but potent. It targets repeat offenders who have attracted two or more monetary penalties from the Board. It does not apply to mere notices or warnings. The Board must also advise blocking in the public interest. Absent both elements, the Government cannot invoke this section.
The blocking is aimed at information in any computer resource that enables the data fiduciary’s offering of goods or services in India. Given the IT Act definitions, this can cover a broad range of digital artifacts and infrastructure, not just a public website. Intermediaries are duty-bound to comply, which can extend enforcement reach across hosting, network, or other layers where the enabling information resides.
What Can Be Blocked and Who Must Act
The object of blocking is information. The trigger is that the information enables the data fiduciary to carry on any activity related to offering goods or services to Data Principals within India.
Practically, this could include:
- URLs, domains, or app endpoints that enable service functionality.
- Content or data that facilitates the service offering.
- Other technical resources within the meaning of computer resource that make the offering possible.
The direction can be addressed to any Central Government agency or any intermediary. Under the IT Act, an intermediary includes entities that receive, store, or transmit information on behalf of others, or provide related services. In practice, this can capture the infrastructure and distribution points that can implement a block effectively.
Due Process and Safeguards
Section 37 is not an arbitrary guillotine. It builds in procedural safeguards:
- Opportunity of being heard for the data fiduciary before an order is made.
- A satisfaction test tied to public interest, which must be met by the Government.
- Reasons for the decision must be recorded in writing.
These guardrails limit arbitrary action and create a record that can be scrutinized. The Board’s role is also specific. It must first impose monetary penalties in two or more instances and then advise blocking in the public interest. Only then can the Government consider a blocking direction.

What This Section Is Not
- It is not a general policy power. It does not grant the power to issue policy directions to the Data Protection Board or to regulate the Board’s priorities. The text is confined to blocking public access to enabling information in cases of repeat monetary penalties.
- It is not a penalty in itself. It is a consequential enforcement measure that can cut off the data fiduciary’s ability to operate in India.
- It does not define appeal processes. Timelines or standards of review for the blocking decision sit elsewhere in law or would be addressed through judicial review if contested.
Practical Implications for Data Fiduciaries
- Treat the first monetary penalty as a critical inflection point. A second penalty can unlock the pathway to a blocking reference. Immediate and verified remediation after the first penalty is essential.
- Document corrective actions comprehensively. Show that the root cause has been addressed, controls have been implemented, and recurrence risk is contained. Evidence matters if a hearing is triggered.
- Monitor for systemic issues. Repeated lapses in consent management, notice, purpose limitation, or security safeguards are the kind of patterns that draw attention. Tighten governance, training, and vendor oversight to prevent recurrence.
- Prepare for the hearing if a reference is made. Be ready with remediation reports, third-party validations if available, and a plan that assures the issue is not ongoing. The goal is to persuade that blocking is not necessary in the public interest.
- Anticipate operational fallout scenarios. If a blocking direction issues, access to key service interfaces could be cut. Have contingency and wind-down steps planned to avoid consumer harm and preserve evidence.
Practical Implications for Intermediaries
- Establish a clear legal process. You need a mechanism to receive, authenticate, and act on Section 37 directions. These are binding. Delayed or incomplete compliance with DPDP intermediary obligations can create exposure.
- Implement precise blocking. The order targets information that enables the data fiduciary’s offering. Avoid overbroad measures that affect unrelated services or third parties. Maintain logs to demonstrate scope control and timing of actions.
- Coordinate cross-functional response. Legal, security, network operations, and customer support must be aligned to execute orders while managing collateral impact and communications.
- Retain records. Keep the direction, internal approvals, technical changes, and validation artifacts. This supports audit readiness and accountability.
Interpreting “Information that Enables” the Offering
The phrase is functional, not formalistic. If a digital element allows the data fiduciary to operate its goods or services in India, it is within reach. Both front-end access points and back-end functional enablers may qualify. The breadth of the IT Act definitions expands technical coverage, but the purpose constraint keeps the focus on what enables the offering. When in doubt, intermediaries should seek clarity from the issuing authority on exact targets to avoid unintended disruption.
Two Short Scenarios
- Repeat breach penalties followed by blocking advice. A data fiduciary suffers multiple breaches and is penalized twice for failing to implement reasonable security safeguards. The Board advises blocking in public interest due to ongoing risks. After a hearing and recorded reasons, the Government directs intermediaries to block access to key service URLs. Public access is cut until compliance is restored and any further relief is obtained.
- Persistent consent violations. A data fiduciary repeatedly misuses personal data for new purposes without consent and attracts two penalties. The Board advises blocking to prevent ongoing misuse. The Government, satisfied that public interest demands it, orders app distribution and hosting intermediaries to block access to the enabling information that supports the service in India.
Execution Tips That Reduce Risk
- Build a penalty prevention program. Track regulatory issues, root causes, and closure evidence. Ensure Board orders are reflected in policy, code, and vendor contracts.
- Use independent verification. After major fixes, obtain external validation of control effectiveness to reduce the chance of repeat findings. Don’t grade your own homework when a second failure means a shutdown.
- Keep a rapid response playbook. Include legal review, regulator engagement protocols, and technical action steps for potential blocking or partial service take-downs.
Ending up at Section 37 is a sign of repeat failure. Avoid the second penalty. If you get a reference and a hearing, put forward a clear remediation record and a credible plan.
Real execution is hard. Finding the gaps, proving closure, and keeping your organization coordinated under regulatory timelines is where teams slip. Regodit provides a structured way to map obligations, evidence controls, track remediation, and stay audit-ready so you are not navigating these stakes with spreadsheets.
Explore how Regodit can help you translate DPDPA requirements into clear controls, evidence, and workflows. If this area is on your risk map, schedule a call to discuss your current posture and a practical path forward.
Disclaimer: The views and explanations shared in this blog are based on our team's understanding of the relevant compliance frameworks. While every effort has been made to ensure accuracy, readers are encouraged to refer to the original legal provisions and official notifications for authoritative guidance. Please reach out to us at connect@solsphere.ai.
Keep reading
All blogs →DPDPA Rule 23: Government Requests for Information from Data Fiduciaries and Intermediaries
Handling a notice under DPDP Act Rule 23 requires strict confidentiality. Discover how to respond to government data requests and ensure full compliance.
DPDPA Rule 22: Appeals to the Appellate Tribunal
Lost at the Data Protection Board? DPDPA Rule 22 governs the digital-first appeals process. Read our complete guide to filing an appeal with the Tribunal.
DPDPA Rule 21: The Machinery Behind the Data Protection Board of India
Ensure your business meets DPDP Act compliance requirements. Discover key obligations for data fiduciaries, penalty risks, and steps to protect user privacy.
