News Analysis4 mins

Identity Fraud in Visa Verification Flags Section 15 DPDP Duties: A CFO's Guide to EdTech Risk

The arrest of a businessman with five passports highlights the intersection of identity fraud and Section 15 Duties of Data Principals under the DPDP Act. For EdTech CFOs, failed identity verification risks massive contingent liability and invalidates verifiable parental consent under the Rules, 2025.

Written byVipul Abhishek· Former Advocate, Supreme Court of India · ComplyDP Co-Founder

Last updated:

What happened

As reported by Hyderabad Mail, Gachibowli police arrested a 55-year-old real estate businessman, Lakshmikanth Reddy Mothukpalli, for acquiring at least five Indian passports using different identities and birth dates since 1997. The fraud was uncovered by US consulate staff during a routine verification of a non-immigrant visa application dated December 8, 2025.

Historical visa records revealed the scale of the identity manipulation. The accused previously applied for an H-1B visa from Quebec in 1997 under the name Middannola Laxmikanth, and again in 1999 from Delhi as Medha Prasoon Kumar Reddy. Consulate data cross-referencing flagged these discrepancies, leading to the police action.

Does the DPDP Act apply here?

The territorial scope of the Digital Personal Data Protection Act, 2023 covers digital personal data processed within India, and processing outside India connected to offering goods or services to Data Principals in India. While sovereign entities handling state identifiers possess specific exemptions, enterprise fiduciaries interacting with user-provided identity data are fully subject to the Act.

This incident directly implicates Section 15 of the Act, which outlines the Duties of Data Principals. Section 15 strictly prohibits individuals from impersonating another person or suppressing material information when providing personal data for state-issued documents. Violations of these duties can attract penalties for the individual, though the operational burden of verifying this data falls heavily on the processing entity.

Legal implications under DPDP

Under Section 4 of the DPDP Act, consent is the primary basis for processing, except where Section 7 legitimate uses apply. When users supply fraudulent identities, any consent obtained is fundamentally flawed. Fiduciaries must maintain reasonable data accuracy, especially when using personal data to make decisions about the Data Principal or when sharing it with third parties.

The DPDP Rules, 2025, notified in November 2025, introduce stringent mechanics for verifiable parental consent under Rule 10 workflows. For platforms relying on identity documents to age-gate users, accepting a falsified identity document nullifies the consent mechanism. Cross-border transfers of such verification data remain generally permitted unless the Central Government restricts transfer to notified countries or territories, but the underlying accuracy requirement persists regardless of where the data flows.

Could this happen to you

For a CFO in the EdTech sector, identity fraud represents a massive contingent liability. If a child uses a manipulated state ID or parent profile to bypass age-gating, the platform might inadvertently apply behavioral tracking or targeted recommendation algorithms to a minor. This strictly violates the Act and exposes the enterprise to penalty ceilings of up to 250 crore rupees.

The financial fallout extends beyond direct penalties to severe EBITDA impact and spiking cyber insurance premium costs. An auditor reviewing your compliance posture will demand evidence that your identity verification stack actually detects anomalies rather than just collecting flawed documents. Relying on disjointed systems increases audit fees and risk, making vendor consolidation around unified data governance a financial imperative.

What companies should do in the next 30 days

1. Model the contingent liability. The CFO and Finance team should quantify the financial exposure of identity-driven consent failures and provision appropriately for compliance upgrades versus potential penalty ceilings.

2. Deploy robust Rule 10 workflows. The Chief Product Officer must integrate verifiable parental consent mechanisms that cross-reference identity data accurately without degrading the user onboarding experience.

3. Revamp breach protocols to meet the Rules, 2025. Ensure the security team can issue intimation to affected Data Principals without delay and submit a detailed report to the Data Protection Board within 72 hours if a data integrity breach occurs.

4. Consolidate verification vendors. Assess total cost of ownership by moving from fragmented KYC tools to a centralized platform that ties identity verification directly to verifiable consent logs.

What to watch

Exactly 270 days remain until the 13 May 2027 hard deadline. Enterprise leaders should monitor how the Data Protection Board penalizes Data Principals under Section 15 versus holding fiduciaries accountable for accepting fraudulent data. The interplay between state enforcement on identity fraud and digital data compliance will define the upcoming audit landscape. To understand your specific exposure and consolidate your compliance strategy, assess your infrastructure today at freescan.complydp.com.

Sources

Frequently asked questions

Does the DPDP Act apply to user-provided identity documents?

Yes. The Act covers digital personal data processed within India, and processing outside India connected to offering goods or services to Data Principals in India. Any digital identity document processed by an enterprise fiduciary falls firmly under this scope.

How does identity fraud impact EdTech compliance under the DPDP Rules, 2025?

The Rules, 2025 mandate strict Rule 10 workflows for verifiable parental consent. If a minor uses a fake adult identity to bypass age-gating, the platform risks engaging in illegal behavioral tracking, rendering its entire consent mechanism invalid.

What are the financial risks of failing to detect identity fraud?

Beyond penalty ceilings of up to 250 crore rupees per instance, CFOs face a direct negative EBITDA impact through spiking cyber insurance premiums and increased audit fees. Strategic vendor consolidation helps mitigate this contingent liability.

What is the DPDP Act timeline for compliance?

Exactly 270 days remain until the 13 May 2027 hard deadline. Companies must finalize their consent architectures, deploy robust breach notification protocols, and execute vendor consolidation efforts well before this date.

How quickly must we report a data integrity breach under the new Rules?

The DPDP Rules, 2025 require organizations to issue an intimation to affected Data Principals without delay and submit a detailed incident report to the Data Protection Board within 72 hours of identifying the breach.