All templates
Board & Governance
Voluntary Undertaking Draft Template (for Board submissions)
A draft voluntary undertaking template for submission to the Data Protection Board of India in connection with a matter under inquiry.
Template
VOLUNTARY UNDERTAKING
To,
The Data Protection Board of India
[Address as notified]
Re: Voluntary Undertaking by [Organization Name] in connection with [brief description of matter / inquiry reference number, if any]
1. INTRODUCTION
[Organization Name] ("the Data Fiduciary"), having its registered office at [Address], respectfully submits this voluntary undertaking to the Data Protection Board of India ("the Board") in connection with [describe the matter - e.g. "the incident intimated to the Board on DD-MM-YYYY under reference BR-2026-001" or "the inquiry initiated by the Board on DD-MM-YYYY"].
2. BACKGROUND
[Provide a concise, factual narrative of the matter giving rise to this undertaking, including relevant dates, the nature of the issue identified, and any prior correspondence with the Board.]
3. ACKNOWLEDGEMENT
[Organization Name] acknowledges the following in relation to this matter:
(a) [State factual acknowledgment - e.g. "that the security safeguards in place at the time did not meet the standard required under Section 8(5) of the Digital Personal Data Protection Act, 2023"]
(b) [Further acknowledgment, if applicable]
This undertaking is offered without prejudice to any position [Organization Name] may otherwise be entitled to take, and is submitted in a spirit of cooperation with the Board's oversight function.
4. UNDERTAKINGS OFFERED
[Organization Name] hereby voluntarily undertakes to the Board as follows:
(a) Remedial Action: To implement [describe specific remedial measure, e.g. "mandatory multi-factor authentication for all administrative access"] by [DD-MM-YYYY].
(b) Process Strengthening: To [describe, e.g. "conduct an independent security review of the affected system and submit findings to the Board"] by [DD-MM-YYYY].
(c) Compensatory / User-Facing Measure (if applicable): To [describe, e.g. "notify all affected Data Principals of the additional safeguards implemented"] by [DD-MM-YYYY].
(d) Reporting: To submit a written compliance status report to the Board confirming completion of the above undertakings by [DD-MM-YYYY], and to permit the Board to verify such compliance in a manner it deems fit.
(e) Ongoing Compliance: To review its processing activities described herein against the requirements of the Digital Personal Data Protection Act, 2023 and the Rules made thereunder on an ongoing basis, and to promptly intimate the Board of any recurrence of a substantially similar issue.
5. REQUEST
[Organization Name] respectfully requests that the Board accept this voluntary undertaking in relation to the matter referenced above, in lieu of / in the course of [further proceedings / the pending inquiry], in accordance with the Board's power to accept such undertakings.
6. AUTHORIZATION
This undertaking is submitted by [Authorized Signatory Name], [Designation], duly authorized by [Organization Name] to make this submission on its behalf.
For [Organization Name]:
[Authorized Signatory Name]
[Designation]
Date: [DD-MM-YYYY]
Internal Note (remove before submission): This draft should be reviewed by external counsel before filing. Ensure all factual statements in Sections 2 and 3 are verified against the Data Breach Log, DPIA records, and Compliance Evidence Index before submission, as this document may be treated as a formal representation to the Board.This template is a starting point, not legal advice. Have it reviewed by qualified counsel before use, and adapt bracketed placeholders to your organization's facts.