TDSAT as India's Cyber and Data Appellate Tribunal: DPDP Appeals Route

Regulatory Explainer Platforms & Intermediaries 28 Jul 2026 Status: in-force
TL;DR

The Telecom Disputes Settlement and Appellate Tribunal (TDSAT), constituted under Section 14 of the TRAI Act, 1997, became the appellate tribunal for the Information Technology Act, 2000 on 26 May 2017 when Section 169 of the Finance Act, 2017 substituted Section 48 of the IT Act and absorbed the dormant Cyber Appellate Tribunal. From 13 November 2025, Rule 22 of the DPDP Rules, 2025 designates TDSAT as the appellate forum from Data Protection Board of India orders, with a 60-day limitation extendable by 60 days, mandatory digital filing and UPI-based fees. Appeals from IT Act matters go to the High Court under Section 62 on fact and law; DPDP appeals go to the Supreme Court on questions of law only.

Veritect
Veritect Legal Intelligence
Legal Intelligence Agent
7 min read
Continue with Veritect

Search 5M+ Indian judgments that interpret this instrument.

Try Veritect free Book a demo

India's data-protection appeals will be heard by a telecom tribunal. Rule 22 of the Digital Personal Data Protection Rules, 2025, in force from 13 November 2025, designates the Telecom Disputes Settlement and Appellate Tribunal ('TDSAT') as the appellate forum from orders of the Data Protection Board of India — 60 days to appeal, extendable by 60, filed digitally with fees paid over UPI. TDSAT has held the equivalent cyber jurisdiction since 26 May 2017.

TL;DR for founders

When the Data Protection Board finally starts issuing orders, your appeal does not go to a High Court. It goes to TDSAT in New Delhi — the same tribunal that hears telecom licence-fee and broadcasting-interconnect disputes, and which has quietly been India's cyber appellate tribunal since 2017. Two numbers matter: 60 days to appeal a Board order (extendable once by 60), and 45 days to appeal an Adjudicating Officer's order under the IT Act. Miss either and you are arguing condonation, not merits.

How a telecom tribunal ended up owning cyber law

TDSAT was constituted under Section 14 of the Telecom Regulatory Authority of India Act, 1997 ('TRAI Act') to adjudicate disputes between a licensor and licensee, between service providers, and between a service provider and a group of consumers, and to hear appeals from TRAI's directions, decisions and orders. Section 14A gives it original-petition jurisdiction over the same dispute classes.

The cyber jurisdiction arrived by default rather than design. The Information Technology Act, 2000 originally created a Cyber Regulations Appellate Tribunal under Section 48, renamed the Cyber Appellate Tribunal ('CyAT') by the IT (Amendment) Act, 2008 with effect from 27 October 2009. From June 2011 CyAT was dormant — no Chairperson was appointed after the acting Chairperson superannuated, and the tribunal simply stopped functioning for six years.

Section 169 of the Finance Act, 2017 fixed it by substitution: Section 48 of the IT Act was rewritten to designate TDSAT as the "Appellate Tribunal" for IT Act purposes, Sections 49 to 56 (the CyAT-specific provisions on composition, service conditions and procedure) were omitted, and every CyAT function, pending appeal and record transferred to TDSAT with effect from 26 May 2017. The Tribunals Reforms Act, 2021 now governs the service conditions of the Chairperson and Members.

What TDSAT actually hears

The docket runs across distinct classes, each with its own limitation period and onward route. Practitioners researching precedent must filter by class, because getting the class wrong means getting the limitation wrong.

Class Source Limitation
TRAI Act disputes (§14(a)) — licensor/licensee, inter-provider, consumer groups TRAI Act 1997 Not statutorily fixed; laches
Appeals from TRAI decisions (§14(b)) TRAI Act 1997 30 days
Appeals from Adjudicating Officer orders IT Act 2000, §48 r/w §57 45 days from receipt
Appeals from Controller of Certifying Authorities IT Act 2000, §57 45 days
Appeals from Airports Economic Regulatory Authority AERA Act 2008 Per that Act
Appeals from the Data Protection Board DPDP Act 2023 §29 r/w Rule 22 DPDP Rules 2025 60 days, +60

Note what is not on that list. Blocking directions under Section 69A of the IT Act and content-takedown disputes under the IT Rules, 2021 go to the High Courts on the writ side, not to TDSAT. The Tribunal's intermediary role is residual: it hears appeals where an intermediary has itself been penalised for a data-handling contravention under Sections 43, 43A or 72A.

The IT Act appeal in practice

Section 46(1A) of the IT Act caps the Adjudicating Officer's jurisdiction at ₹5 crore, with claims above that going to the competent court. That cap has a structural consequence people miss: the largest data-breach compensation claims never enter the Adjudicating Officer track at all, so they never reach TDSAT under Section 48.

Within the track, Section 57(3) fixes 45 days from the date of receipt of the order — not the date of the order — with a proviso permitting condonation for sufficient cause. Section 57(2) bars any appeal from a consent order. On the merits, Section 57(4) allows TDSAT to confirm, modify or set aside, which makes the review a full reappraisal on fact and law rather than the limited supervisory review a writ court would apply. Section 58 supplies civil-court powers — summoning, discovery, evidence on affidavit, commissions, review, dismissal for default, setting aside ex parte orders — while Section 57(5) frees the Tribunal from the Code of Civil Procedure, 1908 and binds it to natural justice instead. Section 57(6) asks the Tribunal to endeavour to dispose of an appeal within six months; that is directory, and the real-world docket runs far longer.

💡 Modelling your DPDP appellate strategy before the Board exists? The Veritect Legal AI platform holds TDSAT's cyber and telecom order set alongside Rule 22 of the DPDP Rules 2025 and Sections 46, 48, 57, 58 and 62 of the IT Act — so you can see which precedent actually transfers to a Data Protection Board appeal and which is telecom-specific. Explore Veritect Legal AI →

Three doctrinal strands worth knowing

Bank liability for customer fraud. TDSAT inherited the Umashankar v. ICICI Bank line from CyAT and re-applied it in IDBI Bank v. Sudhir S. Dhupia (Cyber Appeal No. 7 of 2013, decided 10 January 2019), holding a bank liable under Sections 43 and 43A where its own systems or processes contributed to a phishing or unauthorised-transfer loss. The defences that Section 43 protects only individuals, or that third-party criminality breaks the chain, were rejected. The burden sits on the bank to prove it met reasonable security practices — in current practice, evidenced against the RBI Cyber Security Framework of 2016 and the Master Direction on Digital Payment Security Controls.

The regulator/adjudicator boundary. TDSAT has repeatedly drawn a line between TRAI's regulatory functions under Section 11 of the TRAI Act — tariffs, interconnect, quality of service — and adjudication of disputes between service providers, which vests in the Tribunal.

Procedural attack on regulatory departures. In Reliance Jio Infocomm Ltd. v. Union of India (Telecom Petition No. 1 of 2023, order dated 30 May 2025), TDSAT applied the Fifth Proviso to Section 11(1) of the TRAI Act: where the Department of Telecommunications disagrees with a TRAI recommendation it must refer it back, and where TRAI reiterates, DoT must give due weightage before deciding. A demand issued without that process is vulnerable irrespective of its substantive merits. The same procedural-first instinct is the one to carry into DPDP appeals.

What changes when the Board starts working

The Data Protection Board of India was not constituted as at 26 July 2026 — Rule 17 shortlisting was in its seventh week after the 5 June 2026 application close, with composition fixed at a Chairperson plus four Members by G.S.R. 845(E). So there is no Class 6 precedent yet, and every DPDP appellate strategy currently being written is an extrapolation from the IT Act and TRAI Act docket.

Three features of Rule 22 will shape that docket. Filing is digital, with fees payable over UPI or another RBI-authorised system — TDSAT's first mandatory-digital docket. The fee is pegged to the TRAI Act appeal fee, with a Chairperson's discretion to reduce or waive. And the onward route is narrower than the IT Act's: under Section 29(4) of the DPDP Act the Supreme Court hears a DPDP appeal on questions of law only, whereas Section 62 of the IT Act permits a High Court appeal on fact and law. A factual finding by the Board, once affirmed by TDSAT, is effectively final.

Founder checklist

  • Diarise both clocks now — 45 days from receipt for an Adjudicating Officer order, 60 days (plus a single 60-day extension) for a Data Protection Board order. Both run from receipt.
  • Fight the facts at first instance. The DPDP onward appeal is on questions of law only, so a factual record lost before the Board and TDSAT is not recoverable in the Supreme Court.
  • Do not route takedown or blocking grievances to TDSAT. Those are writ matters before a High Court; filing in the wrong forum burns the limitation period.
  • Prepare the security-evidence file in advance — contemporaneous logs and framework-compliance records are what shifted liability in the Umashankar–IDBI line, and the same evidence answers a Section 8(5) DPDP inquiry.
  • Budget for duration. Section 57(6)'s six-month target is directory; plan commercial outcomes on a multi-year horizon.

Frequently Asked Questions

Q1: Can we go straight to the High Court instead of TDSAT?

Not against an Adjudicating Officer's order — the statutory appeal under Section 48 of the IT Act lies to TDSAT, and a writ petition that bypasses an available statutory remedy invites dismissal on alternative-remedy grounds. Writ jurisdiction remains available where a genuine constitutional or jurisdictional question is raised, and High Courts have exercised supervision over TDSAT proceedings on that footing.

Q2: Does a CERT-In non-compliance produce a TDSAT appeal?

No. Enforcement of the CERT-In Directions of 28 April 2022 is prosecutorial. Non-compliance with a direction under Section 70B(6) of the IT Act is tried as an offence under Section 70B(7), on a complaint by a CERT-In-authorised officer under Section 70B(8) — a criminal court, not an Adjudicating Officer, and therefore no TDSAT route. Where the same incident also involves a Section 43A contravention, the Adjudicating Officer and TDSAT track runs in parallel with the prosecution.

Q3: Is TDSAT's jurisdiction affected by the Telecommunications Act, 2023?

No — it is preserved. The 2023 Act, commenced in stages from 26 June 2024, continues the Appellate Tribunal constituted under Section 14 of the TRAI Act as the appellate forum for orders under the new Act, including orders under rules such as the Telecommunications (Telecom Cyber Security) Rules, 2024.

Q4: What happens to Section 43A appeals after the DPDP Act fully commences?

Section 44(2)(a) of the DPDP Act, 2023 omits Section 43A of the IT Act on the Phase 3 commencement date of 13 May 2027. Adjudicating Officer proceedings instituted before that date continue under the savings in Section 6 of the General Clauses Act, 1897, and TDSAT continues to hear appeals from them. New data-protection claims arising after that date lie before the Data Protection Board instead.

Q5: Are TDSAT orders enforceable?

Yes. Orders are executable as a decree of a civil court, and the Tribunal can transmit an order to a civil court having local jurisdiction for execution. In cyber appeals TDSAT can also direct interest on compensation.

Q6: Where is TDSAT located and can we appear remotely?

The principal seat is at Chanakyapuri, New Delhi; additional benches may be notified under Section 14H of the TRAI Act. For DPDP appeals, Rule 22 contemplates digital filing and service, with hearings conducted digitally where the Chairperson so directs.


Beyond this brief Preview

Veritect Legal AI holds the full appellate chain: Sections 14, 14A and 18 of the TRAI Act, 1997; Sections 43, 43A, 46, 48, 57, 58, 62, 70B and 79 of the IT Act, 2000 with their amendment footnotes; Section 169 of the Finance Act, 2017; Sections 28, 29 and 44 of the DPDP Act, 2023 with Rule 22 of the DPDP Rules, 2025; the Tribunals Reforms Act, 2021; and TDSAT's cyber and telecom order set from 2020 onward.

Practitioner-level content available on Veritect Legal AI:

  • Forum-selection matrix: Adjudicating Officer vs Data Protection Board vs writ court vs civil court by claim type and quantum
  • Limitation calendar across all six TDSAT docket classes, keyed to date of receipt
  • Security-evidence file template for defending a Section 43A or Section 8(5) proceeding
  • DPDP appellate strategy note on the questions-of-law-only ceiling under Section 29(4)
  • Digest of TDSAT's cyber and data orders with the doctrinal strand each one establishes

Access Veritect Legal AI →


Primary Sources

Primary source

Title: Telecom Disputes Settlement and Appellate Tribunal — cyber and data appellate jurisdiction under Section 48 IT Act 2000 and Rule 22 DPDP Rules 2025
Issuer: Telecom Disputes Settlement and Appellate Tribunal
Effective: 2017-05-26

Frequently asked

Which tribunal hears appeals from Data Protection Board of India orders?

The Telecom Disputes Settlement and Appellate Tribunal. Section 29 of the Digital Personal Data Protection Act, 2023 nominated 'the Appellate Tribunal' without naming it; Rule 22 of the Digital Personal Data Protection Rules, 2025, in force from 13 November 2025, designates TDSAT expressly. The limitation is 60 days from receipt of the Board's order, extendable once by a further 60 days. Filing is digital and the fee matches the fee for an appeal under the Telecom Regulatory Authority of India Act, 1997, unless reduced or waived by the Chairperson.

Why does a telecom tribunal hear cyber and data cases at all?

Because the dedicated cyber tribunal collapsed. The Information Technology Act, 2000 originally created a Cyber Regulations Appellate Tribunal under Section 48, renamed the Cyber Appellate Tribunal by the IT (Amendment) Act, 2008 with effect from 27 October 2009. It went dormant from June 2011 when no Chairperson was appointed after the acting Chairperson superannuated. Section 169 of the Finance Act, 2017 then substituted Section 48 of the IT Act to designate TDSAT as the Appellate Tribunal, omitted Sections 49 to 56, and transferred all Cyber Appellate Tribunal functions and pending appeals to TDSAT with effect from 26 May 2017.

What is the deadline for appealing an Adjudicating Officer's order under the IT Act?

Forty-five days. Section 57(3) of the Information Technology Act, 2000 requires the appeal to be filed within forty-five days from the date on which a copy of the Adjudicating Officer's order is received by the person aggrieved — the clock runs from receipt, not from the date of the order. The proviso allows TDSAT to entertain a late appeal on sufficient cause. No appeal lies from an order made with the consent of the parties under Section 57(2).

How much can an Adjudicating Officer award, and what happens above that?

Up to Rs 5 crore. Section 46(1A) of the Information Technology Act, 2000, inserted by the IT (Amendment) Act, 2008, gives the Adjudicating Officer jurisdiction where the claim for damage does not exceed rupees five crore, with the proviso vesting jurisdiction over claims above that figure in the competent court. So a large data-breach compensation claim does not start before an Adjudicating Officer at all, and therefore never reaches TDSAT by the Section 48 route.

Where does an appeal go after TDSAT?

It depends on the source statute, and the three routes differ materially. From an IT Act appeal, Section 62 of the IT Act allows an appeal to the High Court within sixty days of communication, on any question of fact or law, with a further sixty days available on sufficient cause. From a TRAI Act appeal, Section 18 of the TRAI Act sends the matter directly to the Supreme Court on the grounds specified in Section 100 of the Code of Civil Procedure, 1908, bypassing the High Court. From a DPDP appeal, Section 29(4) of the DPDP Act, 2023 read with Rule 22 allows an appeal to the Supreme Court on questions of law only.

Does TDSAT hear challenges to content blocking or intermediary takedown orders?

No. Blocking directions under Section 69A of the Information Technology Act, 2000 and content-takedown disputes under the IT Rules, 2021 proceed through the writ jurisdiction of the High Courts, not through TDSAT. The Tribunal's role in the intermediary ecosystem is residual — it hears appeals from Adjudicating Officer orders where an intermediary has been penalised for its own data-handling contravention under Sections 43, 43A or 72A, not from blocking or takedown directions.

What standard of review does TDSAT apply on appeal?

A full reappraisal on fact and law, not the limited supervisory review a writ court applies. Section 57(4) of the IT Act empowers the Tribunal to pass such orders as it thinks fit, confirming, modifying or setting aside the order appealed against. Section 58 vests it with civil-court powers over summoning witnesses, discovery and production of documents, evidence on affidavit, commissions, review of its own decisions and setting aside ex parte orders. Section 57(5) provides that the Tribunal is not bound by the Code of Civil Procedure, 1908 but is guided by the principles of natural justice.

Is there any DPDP precedent from TDSAT yet?

No. The Data Protection Board of India had not been constituted as at 26 July 2026 — the Search-cum-Selection Committee under Rule 17 of the DPDP Rules, 2025 was in its seventh week of shortlisting following the 5 June 2026 application close, and Section 19(1) composition was fixed at a Chairperson plus four Members by G.S.R. 845(E). No Board order exists, so no appeal has been filed. The available precedent set is TDSAT's IT Act and TRAI Act docket, which is what practitioners are currently using to model DPDP appellate strategy.

Tags

tdsat platforms-intermediaries dpdp-act-2023 appellate-tribunal section-46-adjudicating-officer data-protection-board it-act-2000 trai-act-1997
About Veritect

AI research & drafting, purpose-built for Indian litigation.

Veritect indexes 5 million+ judgments from the Supreme Court of India and all 25 High Courts, 1,000+ Central and State bare acts, and 50,000+ statutory sections — including the new BNS, BNSS, and BSA codes.

Built for Indian courts. Trusted by litigation practices from solo chambers to full-service firms.

Try Veritect free