Chapter IX · Miscellaneous
Section 35: Protection of Action Taken in Good Faith
Section 35 is a shield for the regulators: no suit, prosecution or other legal proceeding lies against the Central Government, the Board or its people for anything done, or intended to be done, in good faith under the Act.
- Chapter
- Chapter IX · Miscellaneous
- Status
- In force
- Effective
- 13 November 2025
- Applies to
- Government, Board & staff
- Official citation
- DPDP Act, 2023, s.35
- Reading time
- 3 min
- Updated
- August 2026
At a glance
Section 35 protects the Central Government, the Data Protection Board, and its Chairperson, Members, officers and employees from suits, prosecutions or other legal proceedings for anything done, or intended to be done, in good faith under the Act or the Rules. It is a standard good-faith immunity clause for the regulator and its staff; it does not immunise Data Fiduciaries or protect bad-faith conduct. Unlike much of the Act, Section 35 is already in force, having commenced on 13 November 2025.
Key takeaways
- Section 35 gives the Central Government, the Board and its people immunity from legal proceedings for acts done in good faith under the Act.
- It covers anything done or intended to be done in good faith, including the Chairperson, Members, officers and employees.
- It is a shield for regulators, not for Data Fiduciaries: it does not reduce your obligations or your penalty exposure.
- It protects good faith only: it is not a licence for arbitrary or bad-faith action.
- Unlike most of the Act, Section 35 is already in force (since 13 November 2025).
Who should read this
Read this if you want the full map of the Act: it is a regulator-protection clause, useful to understand who you can and cannot take to court over a DPDP action, but it does not change a Data Fiduciary's duties.
In plain language
Section 35 is a good-faith immunity clause, the kind found in most Indian regulatory statutes. It means the Government, the Board and the people who run it cannot be personally sued or prosecuted for actions they take in good faith while doing their job under the Act.
The important limits: it protects good faith only, and it protects the regulator, not the regulated. It does nothing to shrink a Data Fiduciary's obligations, and it is not a defence you can invoke for your own processing.
The text of the law
Section 35: Protection of Action Taken in Good Faith
35 No suit, prosecution or other legal proceeding shall lie against the Central Government, the Board, its Chairperson and any Member, officer or employee for anything done or intended to be done in good faith under the Act or the Rules.
Wording summarised from the enacted Act. Always confirm against the official Gazette text for authoritative language.
What this means for you
- Understand what it does not do for you: Section 35 protects the regulator, so it never reduces your own compliance duties or penalty exposure.
- Note it is already live: this clause commenced on 13 November 2025, ahead of the main obligations, because the machinery to run the regime needed protection first.
- If you believe a Board action was taken in bad faith, the good-faith shield would not apply, but that is a narrow, fact-heavy argument; your normal route to challenge a Board order is the Section 29 appeal. Not sure where you stand on a Board matter? Take the readiness assessment or find a specialist.
Frequently asked questions
Does Section 35 protect our company?
Can the Board be sued at all?
Is Section 35 in force yet?
Does good faith excuse any Board action?
Sources
- Digital Personal Data Protection Act, 2023Ministry of Electronics and IT (MeitY)
- DPDP Rules, 2025Notified 13–14 November 2025
This is an educational explanation, not legal advice. dpdpactindia.in is an independent resource and is not affiliated with the Government of India.