Chapter 6 — Exposure, Enforcement and Board Oversight
1. The question the board actually asks
A director may ask the question this chapter exists to answer: “What happens to us if we get this wrong?” It is a fair question, and it deserves a better answer than the two it usually receives. The first bad answer is the tabloid one — “₹250 crore” — a single terrifying number stripped of its statutory context, which then distorts every downstream decision. The second is the reassurance one — “the Board has discretion, it will be fine” — a comfortable sentence that dissolves the first time a Section 28 inquiry opens. Both answers fail because both ignore what the statute actually built.
What the statute built is a multi-headed enforcement machinery that commences in stages, prices specific failures at specific ceilings, and calibrates every penalty through seven named factors. Understanding it properly serves the board twice over: it sizes the exposure honestly, and — the chapter’s real argument — it shows the board exactly which controls buy down which exposure, connecting programme decisions with evidence and operational exposure. Controls do not transfer statutory liability or guarantee a penalty discount.
The chapter’s structure follows the machinery’s structure: the institution, the Schedule, the factors, the scenario model, the board dashboard, and the walkthroughs that connect them. The order matters because the board’s first instinct is to skip to the number; the chapter insists on the machinery first, because the number without the machinery is exactly the tabloid error the chapter is trying to prevent.
The institutional layer and the substantive enforcement powers have different commencement dates. The Schedule sets maxima for specified breaches, not predicted prices. The board can require timely response, evidence preservation and transparent cost assumptions without pretending those controls determine the regulator’s future monetary decision.
2. The enforcement machinery, with actors and dates separated
Established does not mean appointed or operational. GSR 843(E) commences Sections 18 to 26 on 13 November 2025. GSR 844(E) establishes the Board and places its head office in the National Capital Region. GSR 845(E) states that the Board shall consist of four members; it does not name or appoint them. Section 2(q) includes the Chairperson within “Member”, whereas the retained recruitment notice describes a Chairperson plus four other Members. That inconsistency is preserved as QL-003; this chapter does not resolve it by silently choosing a headcount. Recruitment is not proof of appointment or of a staffed receiving channel (ACT:100,595–610[3]; RECRUIT:19–24[9]). Establishment and composition sources are EST:51–57[6] and MEMBERS:49–52[7]. Commencement is separately enumerated at COMM:49–59[5].
Rules 17–21 govern appointments, service terms, meetings, digital office and staffing in the institutional tranche. A legal ability to operate digitally does not prove that a portal has received an actual filing. The book therefore records the instrument, actual appointment evidence and verified channel as different fields. Sections 38–43 are miscellaneous provisions: consistency, civil jurisdiction, rule-making, parliamentary laying, Schedule amendment and difficulty-removal powers, not an offences/prosecution block.
Commencement follows each function. Section 27(1)(d), concerning a Consent Manager registration-condition breach, is scheduled for 13 November 2026 with Section 6(9) and Rule 4. The other Section 27 functions, Sections 28 to 34 and Sections 36 to 37 are in the 13 May 2027 core tranche. The early CM function’s relationship with deferred inquiry/penalty machinery remains an interpretation question, QL-006; neither all penalties nor all functions can simply be moved earlier. Section 36 empowers the Central Government, not the Board, to call for information from the Board, fiduciaries or intermediaries. It is not an immediately operative Board information power (ACT:703–705,861–863[3]; COMM:53–59[5]).
The retained commencement notice does not establish retroactive penalties for core duties before they commence. Preparing records now is an author recommendation for readiness and any independently applicable law; it is not a conclusion that the deferred core already governed all conduct from November 2025.
The entry point matters. Section 27(1)(a) acts on breach intimation under Section 8(6), including urgent remedial/mitigation measures and inquiry. Clause (b) concerns a principal complaint about the specified fiduciary breach/rights, a Central or State Government reference, or court directions. Clause (c) concerns a principal complaint about a CM’s obligations; (d) its registration conditions; (e) a Central Government reference concerning an intermediary’s Section 37(2) breach. This is not a free-standing general own-motion route invented by the author. Under Section 27(2), directions require hearing and written reasons; Section 27(3) provides the stated modification/suspension/withdrawal/cancellation route (ACT:689–717[3]).
Inquiry is not an automatic fine. Section 28(3)–(6) requires the Board to determine sufficient grounds, record reasons and follow natural justice. Insufficient grounds may close proceedings. Its enumerated civil-court powers concern attendance/oath, evidence/discovery and inspection; Section 28(8) restricts preventing access to premises or taking equipment/items into custody so as adversely to affect day-to-day functioning. Interim orders under (10) require hearing and reasons. Completion under (11) can close proceedings or proceed under Section 33 after hearing. Rule 19(9) supplies a six-month inquiry period from receipt of the Section 27(1) input, extendible by up to three months at a time with recorded reasons; an already commenced procedural Rule does not itself accelerate the underlying Act function (ACT:718–762[3]; RULES:1348–1374[4]).
Significance is a separate penalty predicate, not a notification threshold. Under Section 33(1), the Board must determine on conclusion of an inquiry that the person’s breach of the Act or Rules is significant before it may impose a monetary penalty specified in the Schedule; the person must also be given an opportunity of being heard before imposition. Even with that determination and hearing, “may” preserves discretion: a penalty is not automatic. If determining the amount to impose, the Board shall have regard to the Section 33(2) factors set out below. Sufficient grounds to inquire, the concluded significance determination and assessment of amount are distinct steps (ACT:827–846[3]).
Rule 7 has a different actor and trigger: on becoming aware of any personal-data breach, the Data Fiduciary shall notify each affected Data Principal, to the best of its knowledge and without delay, and give the Board the initial description without delay. The detailed Board information follows within seventy-two hours of awareness, or such longer period as the Board may allow on a written request. The Section 33 significance predicate creates no exemption from these notification duties and no permission to wait for the Board’s inquiry or significance determination (RULES:1112–1139[4]). These duties retain the commencement qualification above; the distinction does not accelerate their legal effect.
Challenge and resolution routes differ. Section 29 permits appeal to the Appellate Tribunal within sixty days of receipt of the Board order/direction, with sufficient-cause late admission. The Tribunal endeavours to dispose within six months and records reasons for exceeding that period; this is not an absolute six-month disposal guarantee. Rule 22 supplies digital form/fee mechanics and fee reduction/waiver discretion. Section 30 concerns execution as a decree; Section 31 allows the Board to direct an attempt at mediation, not compelled settlement (ACT:765–808[3]; RULES:1384–1399[4]).
Under Section 32, the Board may accept an undertaking at any stage of an Section 28 proceeding. It can involve action within the Board-determined time, abstention or publicity; accepted terms can be varied with the giver’s consent. Acceptance bars proceedings as regards its contents except the breach route in (5). Failure to adhere to an accepted term is deemed a breach and can lead, after hearing, to Section 33. The Act does not prescribe an automatic discount or make the entire matter disappear regardless of compliance (ACT:809–824[3]).
Other consequences have conditions. Section 34 sends realised penalties to the Consolidated Fund of India, not to principals as compensation under this provision. Section 35 protects specified good-faith statutory action. Section 37 requires a written Board reference intimating penalties on a fiduciary in two or more instances and advising public-interest blocking; the Central Government/authorised officer must hear the fiduciary, be satisfied as to necessity/expediency in the public interest and record reasons before directing blocking. It is not automatic shutdown after one incident, nor a power delegated to a commercial sponsor (ACT:847–884[3]).
3. The Schedule: statutory maxima, not predicted costs
The Schedule identifies seven breach categories. The table is generated from the same retained Schedule record used in Appendix A. Amounts are enacted maxima, subject to the applicable Section 33 process; they are neither a tariff nor a finding that each listed failure has occurred.
| Item | Breach (paraphrase) | Statutory maximum, not expected loss | Control discussion |
|---|---|---|---|
| 1 | Failure to take reasonable security safeguards under Section 8(5) | ₹250 crore | 15 |
| 2 | Failure to give the Board or affected Data Principal breach intimation under Section 8(6) | ₹200 crore | 16 |
| 3 | Additional obligations in relation to children under Section 9 | ₹200 crore | 13 |
| 4 | Additional SDF obligations under Section 10 | ₹150 crore | 19 |
| 5 | Data Principal duties under Section 15 | ₹10,000 | 4,12 |
| 6 | Breach of an accepted voluntary undertaking under Section 32 | Up to the extent applicable for the breach in respect of which the Section 28 proceeding was instituted | 6 |
| 7 | Any other provision of the Act or Rules | ₹50 crore | 2,6 |
Source: ACT-SCHEDULE — research/legal/evidence/01_dpdp_act_2023_gazette.txt:1010–1045; Section 33 process/factors apply.
A single incident can raise distinct safeguard and notification questions. It does not follow from the arithmetic sum of two maxima that a settled ₹450-crore aggregate cap or mandatory additive penalty applies. The statutory application, findings and aggregation treatment require legal analysis; QL-008 retains that boundary. No combined maximum is used as an expected loss in this chapter.
Section 42 allows the Central Government to amend the Schedule by notification, subject to an increase no greater than twice the amount originally enacted and the specified effective date. This is a separate notification power, not permission for this model to double an exposure automatically (ACT:967–973[3]). The current lookup must therefore track versions without assuming a later instrument was issued or absent after an incomplete search.
The seven statutory factors and what evidence can show
The exact wording below is generated from ACT:836–846[3], also used in Appendix A. These are the matters the Board shall have regard to; the statute supplies no numerical weights or assured mitigation rebate.
| Clause | Exact Section 33(2) wording |
|---|---|
| (a) | the nature, gravity and duration of the breach; |
| (b) | the type and nature of the personal data affected by the breach; |
| (c) | repetitive nature of the breach; |
| (d) | whether the person, as a result of the breach, has realised a gain or avoided any loss; |
| (e) | whether the person took any action to mitigate the effects and consequences of the breach, and the timeliness and effectiveness of such action; |
| (f) | whether the monetary penalty to be imposed is proportionate and effective, having regard to the need to secure observance of and deter breach of the provisions of this Act; and |
| (g) | the likely impact of the imposition of the monetary penalty on the person. |
Source: ACT:836–846[3]. These are not weighted model coefficients.
For (a), record occurrence, detection, awareness, containment and recovery separately. Detection is not necessarily the start of the breach, and containment does not necessarily end every consequence. In CASE-001 the stipulated occurrence is 09:00, detection 09:10, awareness 09:20 and containment 09:35 on 10 June 2027. The thirty-five-minute occurrence-to-containment interval is not the twenty-five-minute detection interval or the fifteen-minute awareness interval. Recovery has no supplied timestamp and remains unknown. None of these alone establishes the complete legal duration.
For (b), preserve affected data type/nature rather than guessing a price from a sensitivity label. For (c), distinguish confirmed repeated breach from repeated alerts about one event. For (d), separate actually evidenced gain/loss avoidance from an assumed control-budget saving. Under (e), record the action, when it occurred and what evidence supports effectiveness, including failed deliveries or incomplete processor responses. A signed plan demonstrates intent; it does not demonstrate completed mitigation.
Factor (f) concerns proportionality and effectiveness having regard to observance and deterrence. Factor (g) concerns the likely impact of the penalty on the person; it is not an automatic small-business exemption or guaranteed ceiling reduction. The board can improve the factual record it presents but cannot predetermine how these factors will be weighed. A passed local fixture does not justify claiming that a statutory fine falls by a calculated percentage.
4. The tension: one terrifying number versus an honest band
The tension in board-level exposure analysis is between the communicable and the true.
The single-number pull. “₹250 crore” fits in a headline, lands in a minute, and provokes the board’s attention like nothing else in the privacy brief. The risk register wants a number; the audit committee wants a number; the number is available, so it gets used — often multiplied by a guessed probability and called “expected loss.”
The honest-band pull. But the number is a ceiling — the top of a range the Board will set using seven factors, on facts not yet known, after a process not yet run, for a breach not yet suffered. Using the ceiling as the expected loss is not conservatism; it is a modelling error that corrupts every downstream decision: controls priced against a phantom get over-funded or dismissed as absurd, and neither reaction survives contact with an actual inquiry.
The failure modes:
- Max-penalty-as-EV. The ₹250-crore-will-happen model: distorts prioritisation, exhausts credibility, and — when the feared event never arrives in that shape — quietly discredits the whole programme.
- The comfortable shrug. The mirror error: “the Board has discretion, penalties will be modest” — an argument that casually hands the Section 33(2) factors to the adverse factual record, without investing in effective controls or evidence.
A useful model therefore keeps two ledgers: statutory categories with no predicted award, and operational consequences estimated from explicit assumptions. Controls can be evaluated against the latter through bounded scenarios. Their effect on a future penalty remains an unquantified legal question; a board should not buy an apparently precise answer by assigning invented weights to Section 33.
5. A reproducible operational-cost scenario
CASE-001 / INC-001 is hypothetical, set in June 2027 under the frozen-law assumption, not a measured incident. The occurrence and response milestones are fixed by the dossier. For cost illustration only, assume 4,000 affected adults and the following incremental response work. These are teaching parameters, not vendor quotations, rates observed in the Company, or estimates of a statutory fine.
| Cost component | Hypothetical quantity and unit rate | Direct cost |
|---|---|---|
| Technical triage/containment | 60 hours × ₹2,000 | ₹1,20,000 |
| Legal review/notification preparation | 24 hours × ₹3,000 | ₹72,000 |
| Principal support | 40 hours × ₹1,500 | ₹60,000 |
| Notice delivery budget | 4,000 recipients × ₹5 | ₹20,000 |
| Service interruption contribution foregone | 4 hours × ₹20,000/hour | ₹80,000 |
| Direct total | Sum of separate incremental components | ₹3,52,000 |
| Planning contingency | 20% of direct total | ₹70,400 |
| Budgeted case total | Direct plus contingency | ₹4,22,400 |
Hours/rates exclude ordinary payroll already charged elsewhere; the interruption line is assumed contribution foregone, not revenue added again to profit loss. This scope excludes penalties, litigation, compensation under other law, long-run reputation, insurance recovery and taxes. Excluding them makes the budget incomplete as total enterprise loss, not an optimistic estimate of those unmeasured values. The contingency is an author planning choice and must not be renamed a statistical confidence interval.
The sensitivity run changes one parameter family at a time (recipient count, labour quantities together, or outage duration). Doubling affected recipients to 8,000 raises the budgeted total to ₹4,46,400; doubling all three labour quantities gives ₹7,24,800; increasing interruption from four to twelve hours gives ₹6,14,400. These outputs are calculated locally in calculations.json, not copied from a forecast. They explain which assumptions dominate this small budget and identify evidence worth collecting, such as actual support load. They do not establish that one control caused a measured saving.
For an optional annual planning sensitivity, stipulate probability 0.05, 0.10 or 0.20 of exactly one such case and zero otherwise during the year. Multiplying by ₹4,22,400 yields ₹21,120, ₹42,240 and ₹84,480. This is a Bernoulli toy expectation for the defined operational cost, not an empirically estimated likelihood or expected DPDP liability. Repeat events, dependence and severity variation are excluded. An organisation lacking frequency data should show these assumptions rather than describe incidents as “unlikely” without provenance.
An alternative rehearsed-response budget assumes 40 technical hours and two interruption hours, keeping other inputs fixed. Its budgeted cost is ₹3,26,400: a hypothetical ₹96,000 difference from the base, conditional on those unverified operational changes. No drill output demonstrates this saving here. A real comparison would need comparable scope, evidence that the controls changed the quantities, and costs of building/running the controls. Statutory maxima remain in a separate table, never multiplied into this difference.
6. Board oversight: the dashboard and the standing questions
The standing questions. Five, each answerable only from the machinery this book has built: Which obligations are demonstrably in control, and which are residual (the Chapter 22 grid)? Where are the material unresolved exposures — sector conflicts, SDF status, cross-border positions (Chapters 5, 18, 19)? Is every control plane funded with a named owner (Chapters 1, 24)? Is the breach posture rehearsed — drills run, clocks known (Chapter 16)? And is the register current at the latest cut-off (Chapter 2, 36)?
The dashboard. Re-issued on cut-off and on change (Chapter 36’s rhythm), carrying: the legal-status snapshot (live / one-year / eighteen-month composition — the board should watch the May 2027 line approach); the control-effectiveness heat-map (the grid’s PASS/FAIL by obligation); the assumption-based operational-cost sensitivities (this chapter’s model, versioned); the open residuals (named, owned, dated); and the regulatory-change feed (what the loop caught).
The dashboard below is a completed synthetic snapshot, not a completed programme. A red issue can stay red across reviews; pressure to show progress must not overwrite missing evidence. Comparing snapshots requires unchanged metric definitions and explicit scope changes. Legal-status confidence, implementation readiness and measured performance belong in different columns.
Board standing agenda — the quarterly rhythm. The dashboard is not a static report; it is a living instrument, and the board’s interaction with it should be structured:
- Legal-status review. Are there new commencement notifications? Has the Board issued guidance? Has any sector circular changed a register row? (Answers: the Chapter 36 trigger list, the compliance team’s regulatory-change feed.)
- Control-effectiveness review. The heat-map’s red and amber items — what is the remediation plan, what is the target date, what evidence will close them? (Answers: the Chapter 22 grid, with dates and owners.)
- Assumption review. Which operational quantities changed, and what measured evidence supports the change? Which legal categories may be engaged but remain unquantified? Preserve model version, exclusions and calculation output; do not turn a drill pass into a penalty estimate.
- Residual review. Are the open residuals the same as last quarter? Have any been closed? Have any new ones opened? (Answers: the residual register, dated.)
- Drill and incident review. Has the breach playbook been rehearsed? Were the clocks met? What did the drill find? Have any actual incidents occurred, and what did the post-incident review conclude? (Answers: Chapter 16’s drill log, Chapter 22’s fixture results.)
7. Completed board dashboard and decisions
Snapshot Q02-DASHBOARD-01 is for CASE-001 at a Q02-local illustrative review time, 13 June 2027 15:00 +05:30. It is not EVT-025, which remains the dossier’s June 2028 disposal-eligibility review. The local packet provides dashboard.json. Its status is synthetic_review_incomplete, not independent acceptance. No actual board meeting, notice transmission or infrastructure test is claimed.
| Item / linked case object | Snapshot status and evidence boundary | Owner / decision / next evidence |
|---|---|---|
| Legal baseline | Retained scheduled core assumed in force unchanged; current entity-law opinion not supplied | Legal owner revalidates instruments and actual applicability before real use |
| SDF status / ENT-001 | not_designated; no authentic designation provided | Sponsor retains proportionate voluntary readiness; no Rule 13 compliance assertion |
| Marketing withdrawal / WITHDRAW-001, PUR-002 | Synthetic denial story only; processor completeness not proven | Marketing/operations keep purpose stopped; require actual end-to-end evidence before claiming control effectiveness |
| Processor erasure / ACK-001 | Acceptance not established by this chapter | Supplier owner retains exception; request scope-specific receipt and independent verification, not a blanket green |
| Incident / INC-001 | Occurrence, detection, awareness and containment stipulated; recovery unknown | Incident lead records unresolved recovery and exposure facts |
| Principal notice / NOTICE-DP-001, DELIVERY-001 | Queue starts 09:40; delivery failure EVT-020 persists as an escalation | Operations retry/reconcile and record receipt per channel; queue acceptance is not delivery |
| Board initial / NOTICE-BOARD-001 | Prepared EVT-019; dispatch and receipt not established | Legal incident lead must obtain actual evidence; no “timely filed” status |
| Board detailed / NOTICE-BOARD-002 | Prepared 12 June 16:00, before 13 June 09:20 calculated deadline; preparation not submission | Same owner resolves final dispatch/receipt; no allowed extension is assumed |
| Foreign backup / FLOW-004, DEC-004 | Unapproved, isolated pending sourced decision/reroute | Legal/infrastructure keep restriction; re-papering alone is not clearance |
| Training/reuse / PUR-003, DEC-001, DEC-005 | Stopped for missing authority | Product owner must establish lawful route before ingestion; marketing permission does not transfer |
| Operational cost / Q02-COST-01 | ₹4,22,400 base teaching budget; sensitivities are assumptions | Finance gathers actual hours/outage impact; excludes penalty prediction |
| Independent readiness | Pending; no reviewer approval or successful system evidence furnished | Sponsor cannot declare acceptance on this chapter’s local arithmetic checks |
The proposed board decision funds the Chapter 1 package subject to its separate conditions, prioritises notification failure reconciliation and retains the backup/training restrictions. An alternative of closing the incident because containment occurred is rejected: containment does not establish notification completion, recovery or processor erasure. A budget decision cannot waive a mandatory duty. The proposed decision is a teaching specimen, not a signed resolution.
A second, separate counterfactual considers a fiduciary with an authenticated SDF notification after the relevant provisions commence. Section 10/Rule 13 would require the applicable DPO, independent auditor, DPIA/audit cadence, assessor/auditor significant-observations report and algorithmic diligence; any specified-data transfer restriction needs its own stated trigger. The correct action is to map notification/effective date and evidence obligations, not turn a build plan green. This counterfactual does not alter ENT-001’s base not_designated status or manufacture a notification number (ACT:404–440[3]; RULES:1276–1293[4]).
8. What remains for the reader and the reviewer
The retained Section 28 procedure, Section 32 mechanics, Rule 7 clocks and Section 33 factors are source facts now read, not unavailable homework. Genuine residuals remain: Board appointments/composition evidence (QL-003), bounded later-instrument assurance (QL-004), early CM enforcement interaction (QL-006), and aggregation/practice under Section 33 (QL-008). There is no supplied counsel approval of aggregation and no modelled aggregate award.
For actual reliance, counsel must review entity-specific exposure and current instruments; operators must supply real transmissions, control results and recovery evidence. Independent book review is still pending. The local calculation verifies arithmetic only; a source hash verifies bytes only. Neither certifies legal compliance or programme effectiveness.
Bridge to the next chapter
The foundational perimeter is now mapped — scope, grounds, rights, selected sector overlays and staged enforcement — with source facts separated from application questions and hypothetical operational costs. Part I ends, and the book turns from what the law requires to how an enterprise actually operates it: first, by knowing what it holds. Chapter 7 opens Part II with Discovery, Processing Inventory and Data-Flow Mapping.
References (sources retained)
- DPDP Act 2023 — research/legal/evidence/01_dpdp_act_2023_gazette.txt (Sections 18 to 26, 28–37, 38–43; Section 33 and the Schedule).
- Commencement GSR 843(E) — research/legal/evidence/02_gsr_843e_commencement.txt; Board establishment/membership GSR 844(E)/845(E); Rules GSR 846(E) (Rule 7, Rule 22, Rule 23).
- Chapters 2 (the register the dashboard reads), 15/16/13/19 (the four priced control planes), 22 (the evidence Section 33(2)(e) weighs), 24/36 (the rhythm the dashboard runs on).
Source key and provenance legend
Physical references use newline-based line numbers in the following retained source paths; each numbered reference resolves to its original source URL. Review date: 15 September 2026. Full calculated hashes and source versions: out/remediation/Q02/source-manifest.json. The Q01 baseline and its bounded official-update limitations remain controlling; no later-law absence or entity certification is asserted.
- ACT:
research/legal/evidence/01_dpdp_act_2023_gazette.txt— Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023).[3] - RULES:
research/legal/evidence/05_gsr_846e_dpdp_rules_2025.txt— Digital Personal Data Protection Rules, 2025, G.S.R. 846(E).[4] - COMM:
research/legal/evidence/02_gsr_843e_commencement.txt— G.S.R. 843(E), DPDP Act commencement notification.[5] - EST:
research/legal/evidence/03_gsr_844e_board_establishment.txt— G.S.R. 844(E), establishment of Data Protection Board of India.[6] - MEMBERS:
research/legal/evidence/04_gsr_845e_board_members.txt— G.S.R. 845(E), number of members of Data Protection Board of India.[7] - CORR:
research/legal/evidence/06_gsr_892e_corrigendum.txt— Corrigenda to G.S.R. 846(E), G.S.R. 892(E).[8] - RECRUIT:
research/legal/evidence/07_board_recruitment_notice_2026.txt— Filling up the post of Chairman & Members in the Data Protection Board of India.[9]
Sources
[3] https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf [4] https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf [5] https://www.meity.gov.in/static/uploads/2025/11/c56ceae6c383460ca69577428d36828b.pdf [6] https://www.meity.gov.in/static/uploads/2025/11/cc217843dc3bcb37b2b05bcc3b4e031f.pdf [7] https://www.meity.gov.in/static/uploads/2025/11/f6c0837972422cf79d890bfe84cc04d6.pdf [8] https://www.meity.gov.in/static/uploads/2025/12/3c7ebbae0e5456f493f486e6845df86b.pdf [9] https://www.meity.gov.in/static/uploads/2026/05/53b1bcf01cab9a0adde463e73fbc3417.pdf
Contents · Reader guide and citation conventions · Artifact index