India's data-protection appeals will be heard by a telecom tribunal. Rule 22 of the Digital Personal Data Protection Rules, 2025, in force from 13 November 2025, designates the Telecom Disputes Settlement and Appellate Tribunal ('TDSAT') as the appellate forum from orders of the Data Protection Board of India — 60 days to appeal, extendable by 60, filed digitally with fees paid over UPI. TDSAT has held the equivalent cyber jurisdiction since 26 May 2017.
TL;DR for founders
When the Data Protection Board finally starts issuing orders, your appeal does not go to a High Court. It goes to TDSAT in New Delhi — the same tribunal that hears telecom licence-fee and broadcasting-interconnect disputes, and which has quietly been India's cyber appellate tribunal since 2017. Two numbers matter: 60 days to appeal a Board order (extendable once by 60), and 45 days to appeal an Adjudicating Officer's order under the IT Act. Miss either and you are arguing condonation, not merits.
How a telecom tribunal ended up owning cyber law
TDSAT was constituted under Section 14 of the Telecom Regulatory Authority of India Act, 1997 ('TRAI Act') to adjudicate disputes between a licensor and licensee, between service providers, and between a service provider and a group of consumers, and to hear appeals from TRAI's directions, decisions and orders. Section 14A gives it original-petition jurisdiction over the same dispute classes.
The cyber jurisdiction arrived by default rather than design. The Information Technology Act, 2000 originally created a Cyber Regulations Appellate Tribunal under Section 48, renamed the Cyber Appellate Tribunal ('CyAT') by the IT (Amendment) Act, 2008 with effect from 27 October 2009. From June 2011 CyAT was dormant — no Chairperson was appointed after the acting Chairperson superannuated, and the tribunal simply stopped functioning for six years.
Section 169 of the Finance Act, 2017 fixed it by substitution: Section 48 of the IT Act was rewritten to designate TDSAT as the "Appellate Tribunal" for IT Act purposes, Sections 49 to 56 (the CyAT-specific provisions on composition, service conditions and procedure) were omitted, and every CyAT function, pending appeal and record transferred to TDSAT with effect from 26 May 2017. The Tribunals Reforms Act, 2021 now governs the service conditions of the Chairperson and Members.
What TDSAT actually hears
The docket runs across distinct classes, each with its own limitation period and onward route. Practitioners researching precedent must filter by class, because getting the class wrong means getting the limitation wrong.
| Class | Source | Limitation |
|---|---|---|
| TRAI Act disputes (§14(a)) — licensor/licensee, inter-provider, consumer groups | TRAI Act 1997 | Not statutorily fixed; laches |
| Appeals from TRAI decisions (§14(b)) | TRAI Act 1997 | 30 days |
| Appeals from Adjudicating Officer orders | IT Act 2000, §48 r/w §57 | 45 days from receipt |
| Appeals from Controller of Certifying Authorities | IT Act 2000, §57 | 45 days |
| Appeals from Airports Economic Regulatory Authority | AERA Act 2008 | Per that Act |
| Appeals from the Data Protection Board | DPDP Act 2023 §29 r/w Rule 22 DPDP Rules 2025 | 60 days, +60 |
Note what is not on that list. Blocking directions under Section 69A of the IT Act and content-takedown disputes under the IT Rules, 2021 go to the High Courts on the writ side, not to TDSAT. The Tribunal's intermediary role is residual: it hears appeals where an intermediary has itself been penalised for a data-handling contravention under Sections 43, 43A or 72A.
The IT Act appeal in practice
Section 46(1A) of the IT Act caps the Adjudicating Officer's jurisdiction at ₹5 crore, with claims above that going to the competent court. That cap has a structural consequence people miss: the largest data-breach compensation claims never enter the Adjudicating Officer track at all, so they never reach TDSAT under Section 48.
Within the track, Section 57(3) fixes 45 days from the date of receipt of the order — not the date of the order — with a proviso permitting condonation for sufficient cause. Section 57(2) bars any appeal from a consent order. On the merits, Section 57(4) allows TDSAT to confirm, modify or set aside, which makes the review a full reappraisal on fact and law rather than the limited supervisory review a writ court would apply. Section 58 supplies civil-court powers — summoning, discovery, evidence on affidavit, commissions, review, dismissal for default, setting aside ex parte orders — while Section 57(5) frees the Tribunal from the Code of Civil Procedure, 1908 and binds it to natural justice instead. Section 57(6) asks the Tribunal to endeavour to dispose of an appeal within six months; that is directory, and the real-world docket runs far longer.
💡 Modelling your DPDP appellate strategy before the Board exists? The Veritect Legal AI platform holds TDSAT's cyber and telecom order set alongside Rule 22 of the DPDP Rules 2025 and Sections 46, 48, 57, 58 and 62 of the IT Act — so you can see which precedent actually transfers to a Data Protection Board appeal and which is telecom-specific. Explore Veritect Legal AI →
Three doctrinal strands worth knowing
Bank liability for customer fraud. TDSAT inherited the Umashankar v. ICICI Bank line from CyAT and re-applied it in IDBI Bank v. Sudhir S. Dhupia (Cyber Appeal No. 7 of 2013, decided 10 January 2019), holding a bank liable under Sections 43 and 43A where its own systems or processes contributed to a phishing or unauthorised-transfer loss. The defences that Section 43 protects only individuals, or that third-party criminality breaks the chain, were rejected. The burden sits on the bank to prove it met reasonable security practices — in current practice, evidenced against the RBI Cyber Security Framework of 2016 and the Master Direction on Digital Payment Security Controls.
The regulator/adjudicator boundary. TDSAT has repeatedly drawn a line between TRAI's regulatory functions under Section 11 of the TRAI Act — tariffs, interconnect, quality of service — and adjudication of disputes between service providers, which vests in the Tribunal.
Procedural attack on regulatory departures. In Reliance Jio Infocomm Ltd. v. Union of India (Telecom Petition No. 1 of 2023, order dated 30 May 2025), TDSAT applied the Fifth Proviso to Section 11(1) of the TRAI Act: where the Department of Telecommunications disagrees with a TRAI recommendation it must refer it back, and where TRAI reiterates, DoT must give due weightage before deciding. A demand issued without that process is vulnerable irrespective of its substantive merits. The same procedural-first instinct is the one to carry into DPDP appeals.
What changes when the Board starts working
The Data Protection Board of India was not constituted as at 26 July 2026 — Rule 17 shortlisting was in its seventh week after the 5 June 2026 application close, with composition fixed at a Chairperson plus four Members by G.S.R. 845(E). So there is no Class 6 precedent yet, and every DPDP appellate strategy currently being written is an extrapolation from the IT Act and TRAI Act docket.
Three features of Rule 22 will shape that docket. Filing is digital, with fees payable over UPI or another RBI-authorised system — TDSAT's first mandatory-digital docket. The fee is pegged to the TRAI Act appeal fee, with a Chairperson's discretion to reduce or waive. And the onward route is narrower than the IT Act's: under Section 29(4) of the DPDP Act the Supreme Court hears a DPDP appeal on questions of law only, whereas Section 62 of the IT Act permits a High Court appeal on fact and law. A factual finding by the Board, once affirmed by TDSAT, is effectively final.
Founder checklist
- Diarise both clocks now — 45 days from receipt for an Adjudicating Officer order, 60 days (plus a single 60-day extension) for a Data Protection Board order. Both run from receipt.
- Fight the facts at first instance. The DPDP onward appeal is on questions of law only, so a factual record lost before the Board and TDSAT is not recoverable in the Supreme Court.
- Do not route takedown or blocking grievances to TDSAT. Those are writ matters before a High Court; filing in the wrong forum burns the limitation period.
- Prepare the security-evidence file in advance — contemporaneous logs and framework-compliance records are what shifted liability in the Umashankar–IDBI line, and the same evidence answers a Section 8(5) DPDP inquiry.
- Budget for duration. Section 57(6)'s six-month target is directory; plan commercial outcomes on a multi-year horizon.
Frequently Asked Questions
Q1: Can we go straight to the High Court instead of TDSAT?
Not against an Adjudicating Officer's order — the statutory appeal under Section 48 of the IT Act lies to TDSAT, and a writ petition that bypasses an available statutory remedy invites dismissal on alternative-remedy grounds. Writ jurisdiction remains available where a genuine constitutional or jurisdictional question is raised, and High Courts have exercised supervision over TDSAT proceedings on that footing.
Q2: Does a CERT-In non-compliance produce a TDSAT appeal?
No. Enforcement of the CERT-In Directions of 28 April 2022 is prosecutorial. Non-compliance with a direction under Section 70B(6) of the IT Act is tried as an offence under Section 70B(7), on a complaint by a CERT-In-authorised officer under Section 70B(8) — a criminal court, not an Adjudicating Officer, and therefore no TDSAT route. Where the same incident also involves a Section 43A contravention, the Adjudicating Officer and TDSAT track runs in parallel with the prosecution.
Q3: Is TDSAT's jurisdiction affected by the Telecommunications Act, 2023?
No — it is preserved. The 2023 Act, commenced in stages from 26 June 2024, continues the Appellate Tribunal constituted under Section 14 of the TRAI Act as the appellate forum for orders under the new Act, including orders under rules such as the Telecommunications (Telecom Cyber Security) Rules, 2024.
Q4: What happens to Section 43A appeals after the DPDP Act fully commences?
Section 44(2)(a) of the DPDP Act, 2023 omits Section 43A of the IT Act on the Phase 3 commencement date of 13 May 2027. Adjudicating Officer proceedings instituted before that date continue under the savings in Section 6 of the General Clauses Act, 1897, and TDSAT continues to hear appeals from them. New data-protection claims arising after that date lie before the Data Protection Board instead.
Q5: Are TDSAT orders enforceable?
Yes. Orders are executable as a decree of a civil court, and the Tribunal can transmit an order to a civil court having local jurisdiction for execution. In cyber appeals TDSAT can also direct interest on compensation.
Q6: Where is TDSAT located and can we appear remotely?
The principal seat is at Chanakyapuri, New Delhi; additional benches may be notified under Section 14H of the TRAI Act. For DPDP appeals, Rule 22 contemplates digital filing and service, with hearings conducted digitally where the Chairperson so directs.
Beyond this brief Preview
Veritect Legal AI holds the full appellate chain: Sections 14, 14A and 18 of the TRAI Act, 1997; Sections 43, 43A, 46, 48, 57, 58, 62, 70B and 79 of the IT Act, 2000 with their amendment footnotes; Section 169 of the Finance Act, 2017; Sections 28, 29 and 44 of the DPDP Act, 2023 with Rule 22 of the DPDP Rules, 2025; the Tribunals Reforms Act, 2021; and TDSAT's cyber and telecom order set from 2020 onward.
Practitioner-level content available on Veritect Legal AI:
- Forum-selection matrix: Adjudicating Officer vs Data Protection Board vs writ court vs civil court by claim type and quantum
- Limitation calendar across all six TDSAT docket classes, keyed to date of receipt
- Security-evidence file template for defending a Section 43A or Section 8(5) proceeding
- DPDP appellate strategy note on the questions-of-law-only ceiling under Section 29(4)
- Digest of TDSAT's cyber and data orders with the doctrinal strand each one establishes
Primary Sources
- Telecom Disputes Settlement and Appellate Tribunal: https://tdsat.gov.in/
- TDSAT — Procedure for Filing Petition / Appeal (2022): https://tdsat.gov.in/admin/news/uploads/TDSAT%20Procedure2022.pdf
- TDSAT — Telecom Petition No. 1 of 2023, order dated 30 May 2025: https://tdsat.gov.in/order_files/final/2025/May/070110000082023_1555.pdf
- Information Technology Act, 2000 — India Code: https://www.indiacode.nic.in/handle/123456789/1999
- Telecom Regulatory Authority of India Act, 1997 — India Code: https://www.indiacode.nic.in/handle/123456789/1965
- Finance Act, 2017 (Section 169) — India Code: https://www.indiacode.nic.in/handle/123456789/2141
- Digital Personal Data Protection Act, 2023 — India Code: https://www.indiacode.nic.in/handle/123456789/20168
- MeitY — Digital Personal Data Protection Rules, 2025: https://www.meity.gov.in/documents/act-and-policies/digital-personal-data-protection-rules-2025-gDOxUjMtQWa
- Tribunals Reforms Act, 2021 — India Code: https://www.indiacode.nic.in/handle/123456789/17246
- Supreme Court of India — judgment portal: https://www.sci.gov.in/