DPDP Sections6 mins

DPDP Act Section 37 Explained: Enterprise Blocking Powers

An executive guide for enterprise CFOs on Section 37 of the DPDP Act, detailing how repeated compliance failures can lead to the Central Government blocking public access to your digital platforms in India.

Written byVipul Abhishek· Former Advocate, Supreme Court of India · ComplyDP Co-Founder

Last updated:

Section 37 Explained: Enterprise Blocking Powers

Section 37 of the Digital Personal Data Protection Act, 2023 equips the Central Government with severe powers to block public access to a Data Fiduciary's digital platforms. This is not an initial penalty but a terminal escalation. If the Data Protection Board imposes monetary penalties on your enterprise in two or more instances and determines that blocking your service is in the general public interest, the Board can advise the Central Government to restrict access to the computer resources enabling your operations within the territory of India.

Statutory Text and Regulatory Mechanism

The statutory mechanism is anchored in Section 37(1) of the DPDP Act. The Central Government may act upon a written reference from the Board that intimates the imposition of monetary penalty by the Board on a Data Fiduciary in two or more instances. Furthermore, Section 37(1)(b) specifies the Board must advise the blocking of access by the public to any information generated, transmitted, received, stored or hosted in any computer resource that enables the Data Fiduciary to carry on any activity relating to offering of goods or services to Data Principals within the territory of India. Crucially, the Act mandates that the Data Fiduciary receives an opportunity of being heard before the government, on being satisfied that it is necessary or expedient to do so in the interests of the general public, issues the final blocking order.

Applicability and Territorial Scope

This provision binds all Data Fiduciaries whose operations fall under Section 3 of the Act. This includes enterprises processing digital personal data within India, as well as foreign entities processing data outside India if connected to offering of goods or services to Data Principals in India. For a CFO, this means global operations targeting India carry local blocking risk. Furthermore, it is crucial to recognize what is out of scope to avoid unnecessary compliance overhead. Section 3(c) explicitly exempts personal data processed by an individual for any personal or domestic purpose. Additionally, it does not apply to personal data that is made publicly available either by the Data Principal themselves or by any other person who is under an obligation under any law to make such data publicly available. Understanding these strict applicability parameters ensures you are only safeguarding the data that actually carries Section 37 enforcement risk. The operational reality of these powers takes effect once the transition period concludes, leaving exactly 279 days until the DPDP hard compliance deadline of 13 May 2027.

The CFO Perspective on Total Cost of Ownership

For financial leadership, Section 37 transforms data privacy from a contingent liability into an existential business continuity threat. A platform block halts revenue generation instantly and devastates EBITDA margins for the Indian market. While some executives object to adding another recurring SaaS line item, the ROI is simple: preventing a total market blackout. Unlike a predictable monetary fine that can be provisioned for or partially mitigated through cyber insurance premiums, a government-enforced blackout cuts off the fundamental ability to transact. Vendor consolidation is critical here to lower the overall TCO. Relying on fragmented, manual compliance tracking increases the risk of compounding errors that trigger the two-strike rule under this section. When the Central Government provides the mandated opportunity of being heard, your legal team will need immediate access to immutable logs and forensic evidence of your compliance posture, which fragmented manual systems simply cannot provide during a crisis.

Managing the 72 Hour Breach Window

Operational failures often compound into repeated penalties. The DPDP Rules, 2025 mandate intimation of a personal data breach to affected Data Principals without delay, accompanied by a detailed report to the Data Protection Board within 72 hours. If your enterprise relies on manual incident response and misses this 72 hour window on two separate occasions, you risk incurring the two distinct monetary penalties required to trigger a Section 37 reference. Automating breach response workflows is non-negotiable to protect your platform availability.

Step by Step Compliance Remediation

1. Centralise Grievance Operations. The CFO must fund a unified grievance platform managed by the Data Protection Officer to intercept issues before they escalate to the Board. Section 13 explicitly dictates that both Data Fiduciaries and Consent Managers must provide these readily available means of grievance redressal, and respond within a prescribed period. The primary evidence artifact required is a time-stamped grievance log proving resolution within the precise timelines prescribed by the DPDP Rules, 2025.

2. Deploy Automated Breach and Consent Tracking. Since consent is the primary basis for processing, except where Section 7 legitimate uses apply, your compliance software must maintain unassailable consent logs. The evidence artifact here is an immutable registry of valid itemised notices and granular consent receipts.

3. Legal and Finance Incident Playbook. Establish a formal escalation path so that the CFO and General Counsel are notified the moment the Data Protection Board initiates an inquiry. The evidence artifact is a formally adopted enterprise privacy governance charter that triggers immediate internal reviews to prevent a second, compounding penalty.

Financial Penalties and Escalation Risks

While the Schedule to the Act sets a ceiling of up to 250 crore rupees for failures to take reasonable security safeguards, Section 37 is the ultimate aggravating outcome. Getting it wrong means the Central Government executes a block on your domain, app, or digital infrastructure. The Data Protection Board weighs the nature, gravity, and duration of non-compliance before making this reference. A systemic failure to consolidate your compliance posture accelerates the likelihood of a block, guaranteeing elevated audit fees and legal defense costs well before the block is even executed.

Interaction with Grievance Redressal

Section 37 connects directly to Section 3, applying blocking powers precisely to those computer resources used to offer goods or services to Data Principals in India. It also intersects heavily with Section 13, which mandates readily available means of grievance redressal. Under Section 13(3), a Data Principal must exhaust their opportunity for redressing their grievance with your company or Consent Manager before approaching the Board. Your internal grievance engine is therefore the primary financial firewall preventing the Board from logging the multiple offenses required to trigger a Section 37 escalation.

Take Immediate Action

Stop viewing privacy as a legal abstraction and start managing it as a core enterprise risk. Check whether your current vendor consolidation and compliance posture can prevent the compounding errors that trigger a Section 37 platform block. Visit freescan.complydp.com to run a comprehensive, section-level gap check on your DPDP readiness before the hard deadline.

Sources

Frequently asked questions

What triggers a platform block under Section 37 of the DPDP Act?

The Central Government can block public access to your digital platforms if the Data Protection Board has imposed monetary penalties on your enterprise in two or more instances. The Board must also advise the government that blocking your services is necessary in the interests of the general public, and the enterprise must be given an opportunity of being heard.

Will cyber insurance cover the financial impact of a Section 37 block?

While cyber insurance policies may cover legal defense costs or regulatory fines up to the 250 crore rupee ceiling for initial breaches, they generally do not cover the lost EBITDA and revenue resulting from a government-mandated platform blackout. This makes proactive compliance tooling highly cost-effective compared to relying solely on insurance.

Does Section 37 apply to foreign entities processing data outside India?

Yes, under Section 3 of the Act, if your foreign enterprise processes digital personal data in connection with offering goods or services to Data Principals within the territory of India, you fall under its scope. Consequently, the Central Government can block access to the computer resources that enable your Indian market activities.

Are there any data processing exemptions under Section 3 that limit the scope of Section 37?

Yes. Section 3(c) explicitly exempts personal data processed by an individual for personal or domestic purposes. It also exempts personal data made publicly available by the Data Principal or by any person legally obligated to do so. Processing that falls under these exemptions does not carry the compliance burden that could lead to monetary penalties or a subsequent Section 37 blocking order.

How can we prevent grievances from escalating to the Data Protection Board?

Under Section 13, Data Principals must exhaust their opportunity for redressal with your enterprise or Consent Manager before approaching the Board. By heavily investing in an automated grievance management system that operates within the timelines of the DPDP Rules, 2025, you resolve complaints quickly and prevent the initial monetary penalties that eventually trigger a Section 37 block.

When do these blocking powers take effect for enterprises?

Enforcement capabilities go live upon the final enforcement deadline. With exactly 279 days remaining until the DPDP hard compliance deadline of 13 May 2027, enterprise financial leadership must consolidate their vendors and provision budget for compliance software immediately.