AMLEGALS — Strategic Lawyering

Transparency

Corrections Log

A public record of every substantive correction made to legal and regulatory content on this website. Each entry identifies the error, the correction applied, and the statutory basis.

Maintained under the AMLEGALS Editorial Policy

Statutory Reference

Pages Affected

  • Homepage hero banner
  • Board governance insight article
  • Board liability editorial
  • DPDPA Studio keywords
  • DPO Toolkit whitepaper
  • India deep-dive Section 36 entry
  • GEO answer section
  • llms.txt, llms-full.txt
  • DPDPA board governance static resource

Error Identified

Multiple pages attributed “personal liability of directors” to Section 36 of the DPDPA. Section 36 is titled “Power of Central Government to Call for Information” and contains no personal liability provision. The DPDPA does not impose personal liability on directors or officers — penalties under Section 33 read with The Schedule are imposed on the Data Fiduciary entity.

Correction Applied

All references corrected. Section 36 entries now accurately describe the Central Government's power to call for information. Board governance content rewritten to reflect that DPDPA penalties attach to the entity under Section 33, not to individual directors. The “officer in default” concept (present in the Companies Act) does not exist in the DPDPA.

Statutory Basis

Section 33, Section 36 of the Digital Personal Data Protection Act, 2023; The Schedule to the DPDPA.

Factual Accuracy

Pages Affected

  • SaaS data portability privacy guide

Error Identified

Guide discussed “data portability rights under DPDPA” including preparation for “portability requests.” The DPDPA does not confer a right to data portability. Section 11 provides the right to access information about processing; Section 12 provides the right to correction and erasure. There is no equivalent of GDPR Article 20.

Correction Applied

Guide rewritten as “Data Access and Correction Rights for SaaS Products Under DPDPA.” All portability references removed. Content now covers Section 11 (access) and Section 12 (correction/erasure) obligations.

Statutory Basis

Sections 11 and 12 of the DPDPA 2023. Cf. GDPR Article 20 (data portability) — no analogous provision in DPDPA.

Statutory Reference

Pages Affected

  • DPO practice insights — penalty architecture sections

Error Identified

Three references cited “Section 34: Directions by the Board — non-compliance up to ₹250 Crore” as a penalty provision. Section 34 of the DPDPA is titled “Consolidated Fund of India” and concerns the crediting of penalty amounts. It is not a penalty-imposing provision.

Correction Applied

References corrected. Penalty architecture now accurately attributes penalties to Section 33 read with The Schedule. Section 34 is no longer cited as a source of penalty exposure.

Statutory Basis

Sections 33 and 34 of the DPDPA 2023; The Schedule to the DPDPA.

Factual Accuracy

Pages Affected

  • DPO practice insights — penalty architecture

Error Identified

Claimed “the Board may enhance penalty up to twice the Schedule amount” reaching ₹500 Crore. The DPDPA contains no doubling provision. Section 33(2) lists factors the Board considers when determining penalty quantum, but does not permit exceeding Schedule maximums.

Correction Applied

Doubling claim removed. Content now describes Section 33(2) factors (nature, duration, type of personal data, repetition, mitigating actions) that influence penalty determination within Schedule limits.

Statutory Basis

Section 33(2) of the DPDPA 2023; The Schedule (maximum ₹250 Crore for a single contravention).

Characterisation

Pages Affected

  • GEO answer section — extraterritorial scope description

Error Identified

Described DPDPA's extraterritorial reach as covering entities “offering goods or services to, or profiling individuals within India.” Section 3 of the DPDPA applies to processing outside India only in connection with offering goods or services. It does not include a profiling trigger (unlike GDPR Article 3(2)(b)).

Correction Applied

Profiling reference removed. Extraterritorial scope now accurately reflects Section 3: “offering goods or services to Data Principals in India.”

Statutory Basis

Section 3 of the DPDPA 2023. Cf. GDPR Article 3(2)(b).

Characterisation

Pages Affected

  • India Did Not Copy GDPR analysis
  • DPDPA Practice page

Error Identified

Used “Indian citizens” instead of “Data Principals in India.” The DPDPA applies based on territorial presence, not citizenship. Additionally, cross-border transfer framework was described as a “whitelist” rather than the actual negative-list architecture.

Correction Applied

Terminology corrected to “Data Principals in India” throughout. Cross-border framework described as “negative-list framework under Section 16 and Rule 15.”

Statutory Basis

Section 2(j) (definition of Data Principal), Section 3 (territorial scope), Section 16 and Rule 15 (cross-border transfer framework) of the DPDPA 2023 and DPDP Rules 2025.

Typographical

Pages Affected

  • Privacy guides canonical URLs
  • Root layout canonical

Error Identified

Several privacy guide pages used a development-environment canonical URL (amlegalsdpdpa.abacusai.app) instead of the production domain. Root layout set a homepage canonical that cascaded to all pages without explicit canonicals, causing incorrect self-referencing.

Correction Applied

All canonical URLs corrected to amlegalsdpdpa.com. Root-level canonical removed so pages without explicit canonicals do not inherit an incorrect homepage canonical.

Statutory Basis

Technical SEO correction — canonical URL best practices.

Characterisation

Pages Affected

  • Insight article: India Data Transfer Mechanisms (restricted-jurisdiction notification)
  • Global industry DPDPA data
  • Startup hub data

Error Identified

Content described the Section 16(1) restricted-jurisdiction notification as having already been issued by the Central Government. As of August 2026, no such notification has been published in the Official Gazette.

Correction Applied

All references reframed as conditional/anticipatory language ("when issued", "may be issued"). Explicit disclosure added: no restricted-jurisdiction notification published as of August 2026.

Statutory Basis

Section 16(1), Digital Personal Data Protection Act 2023 — power to notify restricted jurisdictions by Gazette notification. No such notification located in MeitY official material.

Typographical

Pages Affected

  • All pages (title metadata)
  • Homepage JSON-LD
  • Sitemap lastModified

Error Identified

Title template produced a doubled suffix (‘| AMLEGALS | AMLEGALS DPDPA’) on ~220 pages. Root layout injected 11 JSON-LD blocks on every page (23 total on homepage). All 357 sitemap URLs shared one lastModified date.

Correction Applied

Title suffix deduplicated (single ‘| AMLEGALS’). Layout JSON-LD reduced to 2 global schemas (Organization + WebSite); person/office/breadcrumb schemas moved to homepage only. Sitemap lastModified dates differentiated by content-creation period (March–August 2026).

Statutory Basis

Google Webmaster Guidelines — canonical metadata, structured-data accuracy, sitemap freshness signals.

Found an error? Write to [email protected] with the page URL, the specific text, and the statutory basis for your concern.

This log is maintained under the AMLEGALS Editorial Policy.