Data Protection Board of India:
how it works, from the company's side.
How the Board is constituted, how a matter reaches it, what an inquiry involves, when a voluntary undertaking ends it, how the penalty is set, and how to appeal to TDSAT within sixty days.
Last updated Published by TryTrustableNot legal advice
What is the Data Protection Board of India?
The Data Protection Board of India is the body that enforces the DPDP Act. It receives breach intimations and complaints, inquires into them, issues directions, accepts voluntary undertakings and imposes penalties of up to ₹250 crore per instance. It was established on 13 November 2025 and works as a digital office.
Section 18 established the Board as a body corporate from a date the Government notifies; that date was 13 November 2025, when Rules 17 to 21 also came into force. Its head office is in the National Capital Region. Section 19 says it has a Chairperson and as many Members as the Government notifies, all people of ability, integrity and standing with expertise in fields such as data governance, consumer protection, dispute resolution, ICT, the digital economy, law or techno-regulation, and at least one an expert in law. Section 20 sets a two-year term, with re-appointment allowed.
The Rules fill in the rest:
| Rule | What it provides |
|---|---|
| 17 | Two Search-cum-Selection Committees. For the Chairperson: the Cabinet Secretary, the Secretaries of Legal Affairs and MeitY, and two experts. For other Members: the MeitY Secretary, the Legal Affairs Secretary and two experts. The Government appoints from their recommendations. |
| 18 and Fifth Schedule | Consolidated salary of ₹4.5 lakh a month for the Chairperson and ₹4 lakh for each Member, without house or car; no pension or gratuity for Board service. |
| 19 | Meetings: quorum of one-third of the membership, majority decisions with a casting vote, recusal for interest, emergency action by the Chairperson ratified later. Rule 19(9): an inquiry must finish within six months, extendable by up to three months at a time with reasons. |
| 20 | The Board functions as a digital office and may use techno-legal measures to run proceedings without anyone attending in person, while keeping the power to summon and examine on oath. |
| 21 and Sixth Schedule | Officers and employees, largely on deputation from government bodies for up to five years. |
From Rules 17 to 21 of the DPDP Rules 2025, in force since 13 November 2025.
Who sits on it. PIB's November 2025 explainer described a Board of four members. MeitY's circular of 6 May 2026 invited applications for one Chairperson and four Members, with a minimum age of 55 and a tenure of two years or until 65, whichever is earlier, followed by an advertisement allowing thirty days to apply. LiveLaw reported on 1 August 2026 that no Chairperson or Members had been appointed. We have found no appointment notification as of 28 September 2026; the DPDP regulatory tracker will record it.
How does a matter reach the Data Protection Board?
A matter reaches the Board in one of five ways under section 27(1): your own breach intimation, a Data Principal's complaint, a reference from the Central or a State Government, a court's direction, or, for Consent Managers, a complaint or an intimation of a breach of registration conditions. A complainant must first use your grievance process.
| Route | Section | What the company should expect |
|---|---|---|
| Your breach intimation | 27(1)(a) | The Board may direct urgent remedial or mitigation measures, then inquire and penalise. Rule 7 requires the full report within 72 hours of becoming aware. |
| A Data Principal's complaint | 27(1)(b) | About a breach, a failed obligation or a refused right. Section 13(3) requires her to exhaust your grievance redressal first. |
| Government reference or court direction | 27(1)(b) | No grievance step; the Board proceeds on the reference or direction. |
| Consent Manager complaint or registration breach | 27(1)(c), (d) | Only for registered Consent Managers, not for companies running their own consent platform. |
| Reference about an intermediary | 27(1)(e) | Where an intermediary fails to comply with a blocking direction under section 37(2). |
Because of section 13(3), the grievance record is the first exhibit in most complaints. Rule 14(3) makes you publish your grievance response period, and it cannot exceed ninety days. A grievance answered late, or with a form letter, is the start of a weak file. The CERT-In and DPDP breach reporting comparison covers the intimation route in detail.
What happens in a Data Protection Board inquiry?
The Board first decides whether there are sufficient grounds to inquire, and closes the matter with reasons if not. If it proceeds, it follows natural justice, can summon people, take evidence, inspect data and documents, and issue interim orders after a hearing. It must finish within six months unless it records reasons to extend.
Section 28 sets the procedure step by step:
1. Screening. Sufficient grounds, or closure with written reasons (28(3)–(4)).
2. Inquiry. Into the affairs of any person, to see whether it is or was complying (28(5)), on the principles of natural justice, with reasons recorded throughout (28(6)).
3. Civil-court powers. Summoning and examining on oath, discovery and production of documents, and inspection of any data, book, register or document (28(7)). The Board may not block access to premises or take equipment in a way that disrupts day-to-day business (28(8)).
4. Interim orders. After hearing you, with written reasons (28(10)).
5. Outcome. After a further hearing, the Board closes the proceedings or moves to a penalty under section 33 (28(11)). A complaint it finds false or frivolous can earn the complainant a warning or costs (28(12)).
Two exits sit alongside. Under section 31 the Board may send a complaint to mediation. Under section 32 it may accept a voluntary undertaking. Civil courts have no jurisdiction over matters the Board is empowered to decide (section 39), and everything runs digitally: the Act says complaints, hearings and decisions should be digital by design (28(1)), and Rule 20 lets the Board hold proceedings without physical presence.
How does a voluntary undertaking under section 32 work?
At any stage of proceedings the Board may accept a voluntary undertaking from the company to take, or stop, a specified action within a time the Board fixes, and possibly to publicise it. Acceptance bars further proceedings on what it covers. Breaking the undertaking is itself a breach, with a penalty up to the ceiling for the original breach.
Under section 32, the terms can be varied later only with the company's consent. The bar covers the contents of the undertaking, not everything else the inquiry might have found. And item 6 of the Schedule sets the penalty for breaching it at up to the amount applicable to the breach for which the proceedings began, so an undertaking offered on a security failure keeps a ₹250 crore ceiling behind it.
An undertaking is most credible when it is specific and evidenced: a control, an owner, a date, and a way for the Board to see it working. That is easier to offer when the evidence already exists.
How does the Board decide the penalty amount?
The Board can impose a penalty only if, at the end of an inquiry and after a hearing, it finds the breach significant. It then sets an amount up to the Schedule's ceiling for that head, weighing seven factors in section 33(2), from the breach's gravity and duration to how quickly and effectively the company mitigated it.
| Section 33(2) | Factor | What moves it in your favour |
|---|---|---|
| (a) | Nature, gravity and duration of the breach | Detecting and stopping it quickly. |
| (b) | Type and nature of the personal data affected | Minimisation, so less sensitive data was there to lose. |
| (c) | Repetitive nature of the breach | A first occurrence, and fixes that held. |
| (d) | Gain realised or loss avoided | No commercial benefit from the failure. |
| (e) | Mitigation, and its timeliness and effectiveness | A dated record of what you did and when. |
| (f) | Whether the penalty is proportionate and effective | Evidence of a working programme, not a one-off. |
| (g) | Likely impact of the penalty on the person | Relevant to smaller companies. |
Penalties go to the Consolidated Fund of India (section 34), not to affected people. And under section 37, after penalties in two or more instances, the Board can advise the Government to block public access to a Data Fiduciary's platform in India. The ceilings by head are in the DPDP penalty schedule, and the penalty calculator adds them up for your case.
How do you appeal a Data Protection Board order?
Any person aggrieved by a Board order or direction can appeal to the Telecom Disputes Settlement and Appellate Tribunal within sixty days of receiving it, under section 29. The Tribunal may admit a late appeal for sufficient cause, should try to decide within six months, and hears appeals digitally.
Rule 22 (in force from 13 May 2027) requires the appeal to be filed in digital form, with the same fee as an appeal under the TRAI Act unless the Tribunal's Chairperson reduces or waives it, paid by UPI or another RBI-authorised system. The Tribunal is not bound by the Code of Civil Procedure but follows natural justice. Its orders are executable as civil-court decrees (section 30), and a further appeal lies under section 18 of the TRAI Act, to the Supreme Court.
When does the Board get its enforcement powers?
The Board's constitution provisions took effect on 13 November 2025, but its powers to inquire, direct and penalise under sections 27 to 33 commence on 13 May 2027 with the substantive duties. The exception is the power over breaches of Consent Manager registration conditions, which starts on 13 November 2026.
The staggered commencement notification of 13 November 2025 is summarised in the Internet Freedom Foundation's statement: sections 18 to 26 at once, section 6(9) and section 27(1)(d) after one year, and the rest after eighteen months. In practice the Board needs members before it can act at all. What a company can do now is build the record it will want to show: consent evidence, breach logs, grievance answers and dated controls. The evidence ledger is built for that.
Related guides: children's data and verifiable parental consent, cross-border data transfer, Significant Data Fiduciary duties, data retention and erasure and the dated DPDP regulatory tracker. The DPDP Act and Rules 2025 guide sets out the whole timetable, and the DPDP penalty schedule what each failure can cost.
The things people ask us
Has the Data Protection Board of India been set up?
It was established on 13 November 2025 under section 18 of the DPDP Act, as a body corporate headquartered in the National Capital Region. Its members had not been appointed when LiveLaw reported on 1 August 2026; MeitY invited applications for a Chairperson and four Members on 6 May 2026. We found no appointment notification as of 28 September 2026.
Can a Data Principal complain to the Board straight away?
No. Section 13(3) requires her to exhaust the Data Fiduciary's or Consent Manager's grievance redressal first. Rule 14(3) caps the response period you publish at ninety days. A complaint that reaches the Board is therefore usually one your own grievance process has already seen, and your answer is part of the record.
How long does a Data Protection Board inquiry take?
Rule 19(9) requires the Board to complete an inquiry within six months of receiving the intimation, complaint, reference or direction. The Board may extend that by up to three months at a time, recording its reasons in writing each time. There is no fixed limit on the number of extensions.
What is a voluntary undertaking under section 32?
A commitment the Board may accept at any stage of proceedings, to take or refrain from an action within a time it sets, and possibly to publicise it. Once accepted, it bars proceedings on its contents. Breaching it is itself a breach of the Act, and the Schedule allows a penalty up to the ceiling for the original breach.
How do you appeal a Data Protection Board order?
To the Telecom Disputes Settlement and Appellate Tribunal, within sixty days of receiving the order or direction, under section 29. The Tribunal may admit a late appeal for sufficient cause, aims to decide within six months, and works digitally under Rule 22. A further appeal lies to the Supreme Court under section 18 of the TRAI Act.
When can the Board start imposing penalties?
The Board's powers to inquire and penalise under sections 27, 28 and 33 commence with the substantive duties on 13 May 2027, except the power over breaches of Consent Manager registration conditions, which commences on 13 November 2026. It also needs appointed members to act, which as of 28 September 2026 we had not seen notified.
The first exhibit is usually your own website.
Most complaints start with something a user saw. The free scan shows what your site does before anyone consents, which is the first thing a complaint about consent will test.