Part of our complete guide to DPDP in India
Quick answer: The DPDP Act’s enforcement structure runs through a single body – the Data Protection Board of India – which investigates complaints and breaches, conducts inquiries with civil-court-like powers, and imposes DPDP Act Penalties of up to ₹250 crore per instance under Chapter 8 of the Act.
Before a penalty is ever imposed, the Board follows a defined process: a complaint or breach report, an inquiry under Section 28, an opportunity to be heard, and – where the Board finds the breach “significant” – a penalty decision under Section 33 that weighs specific factors like gravity, repetition, and mitigation. Organisations can also resolve matters through a voluntary undertaking (Section 32) or alternate dispute resolution (Section 31) before a case reaches a final penalty order. Board decisions are appealable to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) within 60 days.
Most coverage of DPDP penalties stops at the rupee figures. This guide goes past that – into how the Data Protection Board actually reaches a penalty decision, what happens at each stage of an inquiry, and what a business can realistically do before, during, and after one. If you want the full penalty-ceiling table by violation category, that’s covered in our complete guide’s penalty breakdown – this piece focuses on the machinery behind those numbers.
What Triggers a Board Inquiry
An inquiry can begin through more than one route:
- A complaint from a Data Principal, after exhausting the Data Fiduciary’s own grievance redressal mechanism first – Section 13(3) requires an individual to raise their grievance with the organisation directly before escalating to the Board. This is a structural detail worth building into your own compliance programme: a genuinely responsive internal grievance process is a real, practical filter that keeps disputes from reaching the Board at all.
- A data breach notification the Board receives directly from a Data Fiduciary under its breach-reporting obligations.
- A reference from the Central Government or a court, directing the Board to examine a specific matter.
- A suo motu inquiry the Board initiates on its own, where it has reason to examine an organisation’s practices independent of any specific complaint – for instance, following public reporting of a large-scale breach.
The Investigation and Adjudication Process, Step by Step
Section 28 sets out the Board’s procedure. In practice, an inquiry moves through a consistent sequence:
- Initiation – the Board takes up a matter through one of the trigger routes above.
- Notice and information gathering – the Board exercises its Section 19 powers to call for documents, records, and explanations from the organisation under inquiry, and can summon individuals to give evidence.
- Opportunity to be heard – before any penalty is imposed, Section 33(1) requires the Board to give the person or organisation under inquiry an opportunity of being heard. This isn’t a formality; it’s the stage where an organisation’s documentation, remediation record, and cooperation genuinely shape the outcome.
- Determination of “significance” – the Board must first determine that a breach is “significant” before penalty proceedings under Section 33 apply. The Act doesn’t reduce this to a fixed numeric threshold, leaving the Board discretion to weigh the breach’s actual seriousness rather than applying a mechanical trigger.
- Order – the Board issues its decision: a penalty, binding directions (such as requiring a specific remediation plan or process overhaul), or a finding of no violation.
- Appeal window – the affected party has 60 days to appeal the order to the TDSAT.
No fixed statutory timeline governs how long an inquiry itself takes – the Act doesn’t mandate a specific number of days for the Board to conclude a matter, though principles of natural justice require the process to proceed within a reasonable time. In practice, this means inquiry duration will likely vary with case complexity, and organisations should not assume a fast resolution either way.

How Penalty Amounts Are Actually Determined
Once the Board has determined a breach is significant, Section 33(2) sets out the specific matters it must have regard to before fixing the amount – this is the part of the enforcement structure that actually decides where, within a penalty ceiling running up to ₹250 crore, a given case lands:
- The nature, gravity, and duration of the breach.
- The type and nature of personal data affected – a breach involving highly sensitive categories of data is treated more seriously than one involving low-sensitivity data.
- Whether the breach is repetitive – a first-time lapse and a recurring failure are not weighed the same way.
- Whether the organisation gained, or avoided a loss, as a result of the breach – the Board considers whether the non-compliance was incidental or whether it created a financial or competitive advantage.
- Mitigation efforts and cooperation – whether the organisation took prompt corrective action, self-reported, and cooperated with the inquiry, versus resisting or delaying it.
- Proportionality – the Board weighs the penalty against what’s actually needed to secure effective future compliance, rather than defaulting to the maximum ceiling as a starting point.
This is the detail that gets lost when penalty discussions stop at the rupee figures: the ceiling in the Schedule is a maximum, not a default. Two organisations found to have breached the same provision can face very different penalty amounts depending on how they’re positioned against these factors – which is precisely why documentation, incident response speed, and cooperation aren’t just good practice, they’re direct, quantifiable levers on financial exposure.

The Voluntary Undertaking Mechanism
This is one of the most practically useful, and least discussed, parts of the DPDP Act’s enforcement structure. Under Section 32, the Board may accept a voluntary undertaking from any person, at any stage of a Section 28 proceeding, in respect of observing the Act’s provisions.
A voluntary undertaking can include a commitment to take specific action within a Board-determined timeframe, to refrain from certain action, and – notably – the Board may require the undertaking to be publicised. Once the Board accepts a voluntary undertaking, it acts as a bar on further proceedings regarding the matters covered by that undertaking, effectively closing the case on those specific issues without a formal penalty order.
This functions similarly to consent-order or settlement mechanisms found in securities and competition law – it gives an organisation under inquiry a route to resolve a matter by committing to corrective action, rather than litigating the full penalty question. It is not, however, a way to avoid accountability entirely: if an organisation fails to adhere to the terms of an accepted undertaking, that failure is itself deemed a breach of the Act, and the Board can proceed to a full penalty determination under Section 33 after giving the organisation a further opportunity to be heard.
For an organisation facing a Board inquiry, this makes early, credible engagement – proposing concrete corrective action rather than only contesting the allegation – a genuinely strategic option worth having legal counsel evaluate early in the process, not as an afterthought once a penalty order is already imminent.
Alternate Dispute Resolution
Section 31 gives the Board the discretion to refer parties to mediation, arbitration, or another alternate dispute resolution mechanism where it considers the matter suitable for that route, rather than proceeding through the full inquiry-and-penalty process. This provides another off-ramp within the enforcement structure, distinct from the voluntary undertaking mechanism, and reinforces that the Act’s design favours resolution and corrective action over adversarial litigation wherever the specific facts of a matter make that appropriate.

Appeals: TDSAT and Beyond
A party aggrieved by a Board order can appeal to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) within 60 days of the order, under Section 29. TDSAT was originally constituted for telecom disputes but has been designated as the appellate body for DPDP Act matters as well.
Orders passed by TDSAT on appeal are executable as a decree of a civil court under Section 30 – meaning an appellate order carries the same enforceability as a formal civil court judgment, without a separate enforcement proceeding needed. Beyond TDSAT, further appeal would proceed through the ordinary constitutional appellate hierarchy on legal questions, consistent with how appellate tribunal decisions are generally reviewed in Indian law.
Where the Penalty Money Actually Goes
A detail that surprises people who assume penalty structures work like a private-damages system: under Section 34, all sums realised by way of penalties imposed by the Board are credited to the Consolidated Fund of India – the government’s general treasury account. Penalty money under the DPDP Act does not go to the affected Data Principal as compensation. Individual remedies for actual harm suffered, where relevant, would need to be pursued through separate legal avenues rather than through the Board’s penalty mechanism itself.
Exclusive Jurisdiction and Government Oversight of the Board
Two structural features round out the enforcement picture:
Bar of civil court jurisdiction (Section 39). Civil courts are barred from entertaining any suit or proceeding on a matter the Board is empowered to determine under the Act – meaning organisations and individuals cannot route around the Board by filing a parallel civil suit on the same issue. The Board is the exclusive first-instance forum for DPDP Act matters.
Power to call for information (Section 36) and Central Government direction (Section 37). The Central Government retains a power to issue directions to the Board for efficient administration of the Act, and separate information-gathering powers exist under the Act to support enforcement. This keeps the Board answerable within the broader administrative structure even while it functions independently in its adjudicatory decisions.
Common Mistakes During an Enforcement Scenario
Treating the Board like a court that will passively wait for a formal defence. The Board has active investigative powers under Section 19 and can compel information – a defensive, minimal-disclosure posture tends to read as non-cooperation, which Section 33(2) explicitly weighs against the organisation.
Ignoring the voluntary undertaking option. Organisations sometimes default straight to contesting an allegation in full, without evaluating whether an early, credible corrective commitment under Section 32 would resolve the matter faster and with less exposure.
Assuming grievance redressal at the company level is optional. Because Section 13(3) requires individuals to exhaust a Data Fiduciary’s own grievance process first, an organisation without a functioning internal mechanism effectively pushes every dispute straight to the Board – the opposite of what a well-designed grievance process is meant to achieve.
Confusing the appeal window with extra preparation time. The 60-day window under Section 29 is for filing an appeal against an order already made – it isn’t additional time to assemble evidence that should have been produced during the original inquiry.
Assuming penalty exposure is fixed regardless of conduct. As covered above, the Schedule sets ceilings, not defaults – treating a maximum figure as inevitable ignores the real, documented effect that mitigation and cooperation have on the Board’s final determination.
Preparing Your Organisation for a Board Inquiry
The organisations that navigate a Board inquiry well share a common trait: they aren’t starting from zero when the inquiry begins. Practical readiness looks like:
- A functioning internal grievance mechanism that resolves disputes before they reach the Board, satisfying Section 13(3) in substance, not just on paper.
- Retrievable documentation – data inventory, consent records, security safeguard evidence, breach logs – that can be produced quickly under a Section 19 information request, not reconstructed under deadline pressure.
- A pre-identified internal owner for coordinating any Board inquiry, so the organisation isn’t deciding who’s in charge of the response after a notice has already arrived.
- Legal counsel briefed in advance on the voluntary undertaking and ADR mechanisms, so they’re evaluated as live options early in a proceeding rather than considered only after a penalty order is close.
- A documented remediation track record – evidence that past gaps, however minor, were identified and fixed – since the Board explicitly weighs an organisation’s compliance history.
This is exactly the kind of standing readiness that manual, ad hoc compliance tracking struggles to sustain. RuleExpert’s Audit-Ready Documentation and Breach Management capabilities are built for this specific moment – centralised documentation, activity logs, version history, and evidence repositories that stay current, so that if a Board inquiry begins, your organisation is retrieving records, not reconstructing them.
Book a demo with RuleExpert →]
Best Practices
- Build your grievance mechanism to actually resolve disputes, not just to technically exist – it’s your first, and best, line of defence against matters escalating to the Board.
- Treat documentation as a standing requirement, not an inquiry-time task. The evidence the Board will ask for is the same evidence a strong compliance programme should already be generating continuously.
- Loop in legal counsel on the voluntary undertaking option early, not as a last resort once a penalty order is nearly final.
- Don’t confuse the penalty ceiling with the likely outcome. Model realistic exposure based on the Section 33(2) factors, not just the maximum figure in the Schedule.
- Track your compliance history deliberately. Since the Board weighs prior conduct, a documented pattern of proactive fixes is a genuine asset if you’re ever under inquiry.
Frequently Asked Questions
1. What is the Data Protection Board of India? The Data Protection Board of India is the adjudicatory body established under Chapter 6 of the DPDP Act to investigate complaints and breaches, conduct inquiries, and impose penalties for non-compliance. It functions as a digital office and is not a rule-making regulator.
2. How does a DPDP Act inquiry actually start? An inquiry can begin through a Data Principal’s complaint (after exhausting the Data Fiduciary’s own grievance process), a breach notification, a reference from the Central Government or a court, or a suo motu inquiry the Board initiates on its own.
3. Can a company negotiate or settle a DPDP penalty before it’s imposed? Yes, in effect. Section 32 allows the Board to accept a voluntary undertaking from an organisation at any stage of a proceeding, committing to specific corrective action. Accepting the undertaking bars further proceedings on the matters it covers, though failing to honour it is treated as a fresh breach.
4. What factors does the Board consider when deciding a penalty amount? Under Section 33(2), the Board considers the nature, gravity and duration of the breach, the type of personal data affected, whether the breach is repetitive, whether the organisation gained or avoided loss from it, and the organisation’s mitigation and cooperation.
5. Can a DPDP Act penalty be appealed? Yes. A Board order can be appealed to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) within 60 days under Section 29. TDSAT’s own orders are executable as a civil court decree.
6. Where does the money from DPDP Act penalties go? Under Section 34, all penalty amounts collected by the Board are credited to the Consolidated Fund of India – the government treasury – not paid out to affected individuals as compensation.
7. Can I go to a civil court instead of the Data Protection Board? No. Section 39 bars civil courts from entertaining suits or proceedings on matters the Board is empowered to determine under the Act, making the Board the exclusive forum for DPDP Act disputes.
8. Does the Data Protection Board have court-like powers during an inquiry? Yes. Under Section 19, the Board has the powers and duties of a civil court under the Code of Civil Procedure, 1908 – it can summon witnesses, examine them on oath, and compel the production of documents.
9. Is there a fixed timeline for how long a Board inquiry takes? No specific timeline is mandated by the Act itself. Principles of natural justice require the process to proceed within a reasonable time, but duration will vary with the complexity of the matter.
10. What is alternate dispute resolution under the DPDP Act? Under Section 31, the Board has discretion to refer a matter to mediation, arbitration, or another ADR mechanism where it considers the case suitable, offering a route to resolve disputes outside the full inquiry-and-penalty process.
Conclusion
The rupee figures attached to DPDP Act penalties get most of the attention, but the structure behind them – how the Data Protection Board investigates, what it weighs before fixing an amount, and the settlement-like options available before a case reaches a final order – is what actually determines outcomes in practice. A ₹250 crore ceiling is a maximum exposure, not a predetermined result, and the gap between the two is shaped by documentation, cooperation, and how early an organisation engages with mechanisms like the voluntary undertaking.
Understanding this structure isn’t just useful if you’re ever under inquiry – it’s a direct input into how a compliance programme should be built in the first place, since every factor the Board weighs is something an organisation can demonstrably strengthen well before an inquiry ever begins. For the complete penalty-ceiling breakdown by violation category, see our complete guide to DPDP in India.
[Book a Demo with RuleExpert →]
Nitin Ray is a Compliance Manager at RuleExpert with expertise in DPDP compliance, data privacy, consent management, and governance. He helps organizations implement practical compliance frameworks and automation strategies to meet the requirements of India’s Digital Personal Data Protection Act, 2023.
