AMLEGALS — Strategic Lawyering

Transparency

Corrections Log

A public record of every substantive correction made to legal and regulatory content on this website. Each entry identifies the error, the correction applied, and the statutory basis.

Maintained under the AMLEGALS Editorial Policy

Statutory Reference

Pages Affected

  • Homepage hero banner
  • Board governance insight article
  • Board liability editorial
  • DPDPA Studio keywords
  • DPO Toolkit whitepaper
  • India deep-dive Section 36 entry
  • GEO answer section
  • llms.txt, llms-full.txt
  • DPDPA board governance static resource

Error Identified

Multiple pages attributed “personal liability of directors” to Section 36 of the DPDPA. Section 36 is titled “Power of Central Government to Call for Information” and contains no personal liability provision. The DPDPA does not impose personal liability on directors or officers — penalties under Section 33 read with The Schedule are imposed on the Data Fiduciary entity.

Correction Applied

All references corrected. Section 36 entries now accurately describe the Central Government's power to call for information. Board governance content rewritten to reflect that DPDPA penalties attach to the entity under Section 33, not to individual directors. The “officer in default” concept (present in the Companies Act) does not exist in the DPDPA.

Statutory Basis

Section 33, Section 36 of the Digital Personal Data Protection Act, 2023; The Schedule to the DPDPA.

Factual Accuracy

Pages Affected

  • SaaS data portability privacy guide

Error Identified

Guide discussed “data portability rights under DPDPA” including preparation for “portability requests.” The DPDPA does not confer a right to data portability. Section 11 provides the right to access information about processing; Section 12 provides the right to correction and erasure. There is no equivalent of GDPR Article 20.

Correction Applied

Guide rewritten as “Data Access and Correction Rights for SaaS Products Under DPDPA.” All portability references removed. Content now covers Section 11 (access) and Section 12 (correction/erasure) obligations.

Statutory Basis

Sections 11 and 12 of the DPDPA 2023. Cf. GDPR Article 20 (data portability) — no analogous provision in DPDPA.

Statutory Reference

Pages Affected

  • DPO practice insights — penalty architecture sections

Error Identified

Three references cited “Section 34: Directions by the Board — non-compliance up to ₹250 Crore” as a penalty provision. Section 34 of the DPDPA is titled “Consolidated Fund of India” and concerns the crediting of penalty amounts. It is not a penalty-imposing provision.

Correction Applied

References corrected. Penalty architecture now accurately attributes penalties to Section 33 read with The Schedule. Section 34 is no longer cited as a source of penalty exposure.

Statutory Basis

Sections 33 and 34 of the DPDPA 2023; The Schedule to the DPDPA.

Factual Accuracy

Pages Affected

  • DPO practice insights — penalty architecture

Error Identified

Claimed “the Board may enhance penalty up to twice the Schedule amount” reaching ₹500 Crore. The DPDPA contains no doubling provision. Section 33(2) lists factors the Board considers when determining penalty quantum, but does not permit exceeding Schedule maximums.

Correction Applied

Doubling claim removed. Content now describes Section 33(2) factors (nature, duration, type of personal data, repetition, mitigating actions) that influence penalty determination within Schedule limits.

Statutory Basis

Section 33(2) of the DPDPA 2023; The Schedule (maximum ₹250 Crore for a single contravention).

Characterisation

Pages Affected

  • GEO answer section — extraterritorial scope description

Error Identified

Described DPDPA's extraterritorial reach as covering entities “offering goods or services to, or profiling individuals within India.” Section 3 of the DPDPA applies to processing outside India only in connection with offering goods or services. It does not include a profiling trigger (unlike GDPR Article 3(2)(b)).

Correction Applied

Profiling reference removed. Extraterritorial scope now accurately reflects Section 3: “offering goods or services to Data Principals in India.”

Statutory Basis

Section 3 of the DPDPA 2023. Cf. GDPR Article 3(2)(b).

Characterisation

Pages Affected

  • India Did Not Copy GDPR analysis
  • DPDPA Practice page

Error Identified

Used “Indian citizens” instead of “Data Principals in India.” The DPDPA applies based on territorial presence, not citizenship. Additionally, cross-border transfer framework was described as a “whitelist” rather than the actual negative-list architecture.

Correction Applied

Terminology corrected to “Data Principals in India” throughout. Cross-border framework described as “negative-list framework under Section 16 and Rule 15.”

Statutory Basis

Section 2(j) (definition of Data Principal), Section 3 (territorial scope), Section 16 and Rule 15 (cross-border transfer framework) of the DPDPA 2023 and DPDP Rules 2025.

Typographical

Pages Affected

  • Privacy guides canonical URLs
  • Root layout canonical

Error Identified

Several privacy guide pages used a development-environment canonical URL (amlegalsdpdpa.abacusai.app) instead of the production domain. Root layout set a homepage canonical that cascaded to all pages without explicit canonicals, causing incorrect self-referencing.

Correction Applied

All canonical URLs corrected to amlegalsdpdpa.com. Root-level canonical removed so pages without explicit canonicals do not inherit an incorrect homepage canonical.

Statutory Basis

Technical SEO correction — canonical URL best practices.

Characterisation

Pages Affected

  • Insight article: India Data Transfer Mechanisms (restricted-jurisdiction notification)
  • Global industry DPDPA data
  • Startup hub data

Error Identified

Content described the Section 16(1) restricted-jurisdiction notification as having already been issued by the Central Government. As of August 2026, no such notification has been published in the Official Gazette.

Correction Applied

All references reframed as conditional/anticipatory language ("when issued", "may be issued"). Explicit disclosure added: no restricted-jurisdiction notification published as of August 2026.

Statutory Basis

Section 16(1), Digital Personal Data Protection Act 2023 — power to notify restricted jurisdictions by Gazette notification. No such notification located in MeitY official material.

Typographical

Pages Affected

  • All pages (title metadata)
  • Homepage JSON-LD
  • Sitemap lastModified

Error Identified

Title template produced a doubled suffix (‘| AMLEGALS | AMLEGALS DPDPA’) on ~220 pages. Root layout injected 11 JSON-LD blocks on every page (23 total on homepage). All 357 sitemap URLs shared one lastModified date.

Correction Applied

Title suffix deduplicated (single ‘| AMLEGALS’). Layout JSON-LD reduced to 2 global schemas (Organization + WebSite); person/office/breadcrumb schemas moved to homepage only. Sitemap lastModified dates differentiated by content-creation period (March–August 2026).

Statutory Basis

Google Webmaster Guidelines — canonical metadata, structured-data accuracy, sitemap freshness signals.

Statutory Reference

Pages Affected

  • DPDPA Studio FAQ
  • DPDPA Lawyers India page
  • llms-full.txt

Error Identified

Several pages described the DPDP Act 2023 as having "8 Chapters". The Act is arranged in 9 Chapters containing 44 Sections.

Correction Applied

All references corrected to "9 Chapters". A single ACT_CHAPTERS constant (=9) was added to the internal legal-facts registry so the figure is sourced consistently.

Statutory Basis

The Digital Personal Data Protection Act, 2023 — 9 Chapters, 44 Sections.

Statutory Reference

Pages Affected

  • DPO practice editorial insights
  • llms-full.txt

Error Identified

Significant Data Fiduciary obligations were mis-attributed across Rules: DPO appointment to Rule 11, the Data Auditor to Rule 12, and the DPIA to Rule 14. Under the final DPDP Rules 2025, all additional SDF obligations — DPIA, independent data audit, and algorithmic-software due diligence — sit in Rule 13, read with Section 10. Rule 11 concerns guardians of persons with disabilities; Rule 12 concerns exemptions for certain children-related processing; Rule 14 prescribes the manner of exercising Data Principal rights.

Correction Applied

All SDF obligation references re-cited to Section 10 read with Rule 13 (DPO under Section 10(2)(a); Data Auditor and DPIA under Rule 13; algorithmic-software due diligence under Rule 13(3)). Rule 11, 12 and 14 references restored to their correct subjects.

Statutory Basis

Section 10, Rules 11, 12, 13 and 14 of the DPDP Rules 2025.

Factual Accuracy

Pages Affected

  • DPDPA Ecosystem — E-commerce and OTT/Media sector entries

Error Identified

Two sector entries referred to "data portability rights" of Data Principals. The DPDPA does not confer a right to data portability. Sections 11 and 12 provide rights of access, correction and erasure; there is no analogue to GDPR Article 20.

Correction Applied

Portability references removed and replaced with the actual statutory rights of access, correction and erasure.

Statutory Basis

Sections 11 and 12 of the DPDPA 2023. Cf. GDPR Article 20 — no analogous provision in the DPDPA.

Found an error? Write to [email protected] with the page URL, the specific text, and the statutory basis for your concern.

This log is maintained under the AMLEGALS Editorial Policy.