Chapter IX · Miscellaneous
Section 37: Government Power to Direct Blocking of Access
Section 37 is the Act's most extraordinary power: after the Board has penalised a Data Fiduciary two or more times and advises it, the Central Government can, after a hearing, order the blocking of public access to that service.
- Chapter
- Chapter IX · Miscellaneous
- Status
- Enacted · phased commencement
- Full compliance
- 13 May 2027
- Applies to
- DF penalised 2+ times
- Official citation
- DPDP Act, 2023, s.37
- Reading time
- 7 min
- Updated
- August 2026
At a glance
Section 37 lets the Central Government, or an officer it authorises, order the blocking of public access to a Data Fiduciary's service, but only through a narrow, last-resort route. It can act only upon a written reference from the Data Protection Board that both (a) intimates the Board has penalised that Data Fiduciary in two or more instances, and (b) advises, in the interests of the general public, blocking access to the information or computer resource enabling that Data Fiduciary to offer goods or services to Data Principals in India [37(1)]. Even then, the Government must give the Data Fiduciary an opportunity of being heard, be satisfied blocking is necessary or expedient in the public interest, and record reasons in writing, before directing any Central Government agency or intermediary to block access. Every intermediary that receives such a direction is bound to comply [37(2)], and an intermediary's failure to comply with 37(2) can itself be referred back to the Board under Section 27(1)(e). The terms computer resource, information and intermediary carry their Information Technology Act 2000 meanings [37(3)]. Section 37 takes effect on 13 May 2027.
Key takeaways
- Section 37 is a last-resort blocking power: the Central Government can order public access to a Data Fiduciary's service to be blocked.
- It is gated by the Board: the Government can act only on a written Board reference that both intimates two or more penalties and advises blocking in the public interest [37(1)].
- Even then there are safeguards: an opportunity of being heard, a public-interest necessity test, and reasons recorded in writing, before any order.
- The order can direct a Central Government agency or any intermediary to block access, and every intermediary must comply [37(2)].
- An intermediary that fails to comply with a 37(2) direction can be referred back to the Board under Section 27(1)(e).
- Key terms (computer resource, information, intermediary) borrow their meaning from the IT Act 2000 [37(3)], the same framework as Section 69A blocking.
Who should read this
Read this if you are a Data Fiduciary that could accumulate repeat penalties, or an intermediary that hosts or carries such a service: it is the clause that can take a service offline, and it explains the narrow path to get there.
In plain language
Section 37 is the heaviest stick in the Act. In the worst case, it lets the Central Government order that public access to a service be blocked, the digital equivalent of pulling a business offline.
It is deliberately hard to reach. The Government cannot use it on its own initiative: it needs a written reference from the Board that says two things, that the Data Fiduciary has been penalised two or more times, and that blocking is advisable in the public interest. Then the Data Fiduciary must be heard, and the Government must record its reasons.
Once an order issues, it can be directed at a government agency or at an intermediary (such as a hosting or access provider), and that intermediary is bound to comply. If it does not, that failure can itself go back to the Board under Section 27(1)(e).
The text of the law
Section 37: Government Power to Direct Blocking of Access
37(1) The Central Government, or an officer it authorises, may act only upon a written reference from the Board that (a) intimates the imposition of a penalty on a Data Fiduciary in two or more instances, and (b) advises, in the public interest, blocking public access to the information or computer resource enabling that Data Fiduciary to offer goods or services to Data Principals in India. After giving the Data Fiduciary an opportunity of being heard, on being satisfied it is necessary or expedient in the public interest, and for reasons recorded in writing, the Government may by order direct any Central Government agency or any intermediary to block, or cause to be blocked, public access to that information.
37(2) Every intermediary that receives a direction under sub-section (1) is bound to comply with it.
37(3) The expressions computer resource, information and intermediary have the meanings assigned to them in the Information Technology Act, 2000.
Wording summarised from the enacted Act. Always confirm against the official Gazette text for authoritative language.
What this means for you
- Treat repeat penalties as an existential risk, not just a cost: two or more penalties is the trigger that opens the door to a blocking reference, so the priority is never reaching a second one.
- If you are an intermediary, build a process to receive, validate and action a blocking direction quickly, because non-compliance is itself referable to the Board under Section 27(1)(e).
- Use the opportunity to be heard: this is a real procedural safeguard, so a Data Fiduciary facing a reference should be ready to make a substantive public-interest case, with evidence, at that stage.
- Do not conflate this with IT Act Section 69A blocking: Section 37 is a DPDP-specific, penalty-triggered power, though it borrows the IT Act 2000 definitions [37(3)].
- Keep your remediation and appeal options live throughout: addressing the underlying breaches and using the Section 29 appeal route is how you avoid the escalation that leads here. Not sure how exposed you are? Take the readiness assessment or find a specialist.
Frequently asked questions
Can the Government block our service on its own?
How many penalties trigger this?
Do we get a chance to respond before blocking?
Who actually carries out the blocking?
Is this the same as Section 69A of the IT Act?
Sources
- Digital Personal Data Protection Act, 2023Ministry of Electronics and IT (MeitY)
- DPDP Rules, 2025Notified 13–14 November 2025
This is an educational explanation, not legal advice. dpdpactindia.in is an independent resource and is not affiliated with the Government of India.