DPDP 3.3.3: DPDP and Blockchain – Case Study 3 – When the Ledger Never Forgets – Kaveri’s KYC That Lived Forever

The Scenario

Kaveri runs a small trading firm. As part of onboarding a fintech lending platform, she completed a KYC process in 2022. The platform had built its KYC infrastructure on a consortium blockchain shared across six lenders.

In 2024, Kaveri closed her account and formally requested that her KYC data be removed. The fintech replied that the KYC records were permanent, shared across the consortium, and could not be altered because that would “break the chain’s integrity.”

Meanwhile, one lender in the consortium — located in a foreign jurisdiction — faced a regulatory investigation. Kaveri’s personal data was accessed by foreign law enforcement as part of that investigation, without her knowledge.

The Two DPDP Act Violations

Violation one: Section 12(3) — erasure right denied. The fintech’s architecture made it structurally impossible to honour a statutory right. That is a compliance failure attributable to design, not a force majeure.

Violation two: Rule 15 of the DPDP Rules, 2025 — foreign state access restrictions. Rule 15 prohibits a Data Fiduciary from enabling foreign governments or their instrumentalities to access personal data of Indian Data Principals except through legal channels prescribed by Indian law. Kaveri’s data was accessed by a foreign authority through a consortium node without any such channel being invoked.

This is precisely the data sovereignty concern that the Puttaswamy judgment (2018) framed when it recognised informational self-determination as a fundamental right. The Supreme Court observed that humans forget, but the internet does not. Blockchain amplifies this observation: not only does the internet not forget — the chain mathematically cannot.

The IS Audit  Perspective

IS Audit course material of ICAI notes that credential security on blockchain is only as strong as the access point, and that not all participants in a public or consortium chain can be assumed to have equivalent governance standards. Furthermore, Section on Governance and Controls requires that organisations assessing blockchain solutions audit cross-border data flows as a primary governance item.

The Compliance Architecture Fix

Consortium blockchain participants must establish a data governance charter before deployment, specifying: which personal data categories may be written on-chain; cross-border node participation restrictions consistent with Rule 15; erasure and key-revocation protocols binding on all nodes; and a Data Processor contract between the consortium and each member lender covering DPDP Act obligations.

Kaveri’s case is not hypothetical. Indian KYC infrastructure today sits at exactly this intersection.

The Central Compliance Question for Blockchain Deployments

The immutability of blockchain is not, by itself, illegal under the DPDP Act. However, placing personal data directly on an immutable ledger without designing for erasure is a compliance failure. The DPDP Act does not prohibit blockchain. It requires that every technology deployment — including blockchain — be architected so that Data Principal rights can be exercised.

There are four questions every organisation must answer before writing personal data to a blockchain:

One. Can we honour a Section 12(3) erasure request without breaking the chain? If not, the architecture must change before deployment.

Two. Does every node in our network have a written Data Processor agreement under Section 8(2)?

Three. Do any nodes sit in foreign jurisdictions? If so, does Rule 15 governance apply, and is it documented?

Four. Have we used off-chain storage with on-chain hashes, or encryption-at-rest with key deletion on erasure, to build in a compliance exit?

IS Audit study material by ICAI frames this governance requirement clearly: organisations implementing or assessing blockchain solutions must evaluate legal and compliance risk as a first-order item, not an afterthought. The DPDP Act makes this mandatory. The deadline is 13 May 2027.

What Responsible Blockchain and DPDP Compliance Looks Like

The DPDP Act does not ask organisations to abandon blockchain. It asks them to build it responsibly. Consequently, the organisations that will navigate this intersection well are those that:

Design data architecture around erasure rights from day one. Keep personal data off the immutable ledger wherever possible. Use encryption and key management as a proxy for deletion where off-chain storage is not feasible. Govern every node as a Data Processor. Apply Rule 15 restrictions to every cross-border node participant. And audit the entire architecture annually under IS Audit 3.0 standards.

Blockchain is a powerful technology. The DPDP Act is a serious law. Used together — with care — they are compatible. Used carelessly, they create the hardest compliance problems in India’s data protection landscape. Disclaimer

The contents of this post are intended for general awareness and informational purposes only. They do not constitute legal opinion, professional advice, consultancy, statutory interpretation, or a recommendation to act in any particular manner.

The Digital Personal Data Protection Act, 2023, related rules, notifications, regulatory guidance and judicial interpretations may evolve from time to time. The applicability of the law may also vary depending on the facts, sector, nature of data processing, organisational role, contractual terms and compliance framework.

Readers should not rely solely on this post for making legal, business, HR, technology, data-processing or compliance decisions. Specific advice from a qualified legal, privacy, cybersecurity, governance or compliance professional should be obtained before acting on any matter discussed.

The author / publisher shall not be responsible for any loss, liability, claim, penalty or consequence arising from reliance on the contents of this post without independent professional advice.


Authors:
This article has been co-authored by CA. Sunil Elayadath and CA. Karthik Narayanan S, Partners of Karthik & Sunil, together with Mr. Dhanesh P. K., Designated Partner, DSK Sustainability Tech.

DPDP 3.3.3: DPDP and Blockchain – Case Study 3 – When the Ledger Never Forgets – Kaveri’s KYC That Lived Forever

DPDP 3.3.2 : DPDP and Blockchain – Case Study 2 – Meera’s Story

She withdrew consent. The blockchain remembered anyway.

Meera consented to her medical data being stored on a hospital’s blockchain network. Three years later, she withdrew that consent and asked for her records to be removed.

The hospital recorded her withdrawal correctly. However, her personal data had already been distributed across six network nodes. Those nodes — each holding a copy — were not instructed to delete anything.

Under Section 6(4) of the DPDP Act, 2023, withdrawal of consent must be as easy as giving it. Under Section 8(1), the Data Fiduciary must cease all processing upon withdrawal. Under Section 8(2), every entity processing personal data on the Data Fiduciary’s behalf — effectively, every node — must operate under a written contract limiting processing to the specified purpose.

Meera’s hospital had a consent withdrawal mechanism. However, they had no node governance framework. That gap is the compliance failure.

IS Audit 3.0 Study material of  ICAI (Module 6) flags precisely this risk: not all data on a distributed ledger should be accessible to others, and interoperability between chains creates additional exposure that is often overlooked in deployment planning.

Three things organisations deploying blockchain for sensitive personal data must do:

→ Map every node as a potential Data Processor. Execute written contracts under Section 8(2) before deployment.
→ Design consent withdrawal to trigger cascading deletion or encryption-key revocation across all nodes simultaneously.
→ Never write raw personal data to the chain. Use pseudonymous identifiers on-chain, with personal data in a governed, erasable off-chain repository.

Meera’s hospital is rebuilding its architecture. Consequently, the cost is now far higher than it would have been at design stage.

The DPDP Act compliance deadline is 13 May 2027. Node governance is not optional.

Disclaimer

The contents of this post are intended for general awareness and informational purposes only. They do not constitute legal opinion, professional advice, consultancy, statutory interpretation, or a recommendation to act in any particular manner.

The Digital Personal Data Protection Act, 2023, related rules, notifications, regulatory guidance and judicial interpretations may evolve from time to time. The applicability of the law may also vary depending on the facts, sector, nature of data processing, organisational role, contractual terms and compliance framework.

Readers should not rely solely on this post for making legal, business, HR, technology, data-processing or compliance decisions. Specific advice from a qualified legal, privacy, cybersecurity, governance or compliance professional should be obtained before acting on any matter discussed.

The author / publisher shall not be responsible for any loss, liability, claim, penalty or consequence arising from reliance on the contents of this post without independent professional advice.


Authors:
This article has been co-authored by CA. Sunil Elayadath and CA. Karthik Narayanan S, Partners of Karthik & Sunil, together with Mr. Dhanesh P. K., Designated Partner, DSK Sustainability Tech.

DPDP 3.3.2 : DPDP and Blockchain – Case Study 2 – Meera’s Story

DPDP 3.3.1 : DPDP and Blockchain – Case Study 1

“The blockchain won’t let me delete your data.” That is not a legal answer under Indian law.

Arjun resigned from his employer and asked them to erase his personal data. His HR team apologised — the data was on their blockchain-based verification system and, they said, could not be deleted.

Under Section 12(3) of the DPDP Act, 2023, every Data Principal has a statutory right to erasure. The Data Fiduciary must comply — unless retention is necessary for a specified purpose or legal obligation. The DPDP Act creates no exception for immutable ledgers.

Furthermore, Section 8(1) places non-derogable liability on the Data Fiduciary. An organisation cannot transfer that liability to its technology architecture.

IS Audit 3.0 by ICAI identifies legal and compliance uncertainty as a primary blockchain risk. Before the DPDP Act, that uncertainty was structural. Today, the law is clear.

The compliance design choices are not complicated — but they must be made at the architecture stage, not after deployment:

→ Store personal data off-chain. Record only a hash on the ledger. Delete the off-chain data on erasure request.
→ Alternatively, encrypt personal data before writing to the chain. On erasure request, delete the encryption key. The block remains — but it is unreadable.
→ For permissioned chains, build node-level governance with erasure-triggering protocols.

Arjun’s employer had an immutable ledger. However, they did not have an erasure plan. Those are two different problems — and only one of them was a technical constraint.

The DPDP Act compliance deadline is 13 May 2027. Blockchain architectures processing personal data today need an erasure design now.

Disclaimer

The contents of this post are intended for general awareness and informational purposes only. They do not constitute legal opinion, professional advice, consultancy, statutory interpretation, or a recommendation to act in any particular manner.

The Digital Personal Data Protection Act, 2023, related rules, notifications, regulatory guidance and judicial interpretations may evolve from time to time. The applicability of the law may also vary depending on the facts, sector, nature of data processing, organisational role, contractual terms and compliance framework.

Readers should not rely solely on this post for making legal, business, HR, technology, data-processing or compliance decisions. Specific advice from a qualified legal, privacy, cybersecurity, governance or compliance professional should be obtained before acting on any matter discussed.

The author / publisher shall not be responsible for any loss, liability, claim, penalty or consequence arising from reliance on the contents of this post without independent professional advice.


Authors:
This article has been co-authored by CA. Sunil Elayadath and CA. Karthik Narayanan S, Partners of Karthik & Sunil, together with Mr. Dhanesh P. K., Designated Partner, DSK Sustainability Tech.

DPDP 3.3.1 : DPDP and Blockchain – Case Study 1

DPDP Meets Emerging Technologies — Episode 3 – Introduction on Blockchain & DPDP

Blockchain and DPDP compliance


Blockchain and DPDP compliance do not come easily together — and that tension is one of the least-discussed compliance risks in India today.

Blockchain promises transparency, tamper-resistance, and decentralised trust. The DPDP Act, 2023 promises individuals the right to have their personal data erased. These two commitments point in opposite directions. The ledger wants to remember everything. The law says individuals have the right to be forgotten.

As organisations across India deploy blockchain in finance, supply chains, healthcare records, and identity verification, this conflict moves from theoretical to urgent. The full compliance deadline under the DPDP Act is 13 May 2027. Moreover, if your organisation’s blockchain architecture stores personal data today, the design decisions you make now will be far harder to reverse later.

Follow us to know more about this in the coming days.

DPDP Meets Emerging Technologies — Episode 3 – Introduction on Blockchain & DPDP