A company in Bengaluru gets a breach notice from the Data Protection Board of India. Nobody in the compliance team has ever dealt with the Board before, because until recently, it barely existed outside the text of a statute. Now it’s asking questions, and the clock is running.
That scenario is becoming less hypothetical by the month. The Digital Personal Data Protection Act, 2023 (DPDP Act) gave India its data protection law. The Digital Personal Data Protection Rules, 2025 gave it teeth. And the Data Protection Board of India (DPBI) is the body that will actually use them, investigating breaches, hearing complaints, and deciding who pays what.
If you run compliance, legal, HR, or operations at an Indian business, you need to know how this Board is built, what it can do to you, and how a matter actually moves from a data principal’s complaint to a final, enforceable order. This guide walks through all of it in plain terms, grounded in the actual sections of the Act and the 2025 Rules, not marketing gloss.
This piece sits inside our broader DPDP Act complete guide.
What Is the Data Protection Board of India?
The Data Protection Board of India is the adjudicatory body set up under Section 18 of the DPDP Act, 2023. Strip away the legal language and it functions much like a specialised, digital-first tribunal for personal data disputes. It investigates personal data breaches, hears complaints from individuals (called Data Principals under the Act) against companies and organisations (Data Fiduciaries), and decides whether penalties or corrective directions are warranted.
It is not a policy body. It doesn’t write rules or issue guidance notes the way a ministry might. Its job is narrower and more concrete: look at a specific complaint or breach, apply the Act, and issue a reasoned order. That makes it closer in spirit to a consumer forum or the erstwhile Competition Commission bench structure than to a rule-making regulator like SEBI or TRAI, even though people often reach for those comparisons.
For a compliance officer, the practical takeaway is this: the Board is the forum where your organisation’s DPDP obligations stop being theoretical and start being tested.
Why Was the Board Created?
India’s journey to a dedicated data protection regulator was long. The Supreme Court’s 2017 Puttaswamy judgment recognised privacy as a fundamental right and effectively put the government on notice that a data protection law was overdue. Several draft bills came and went before Parliament passed the DPDP Act in August 2023.
A statute without an enforcement mechanism is mostly a statement of intent, though. Lawmakers knew this, so Chapters V and VI of the Act (Sections 18 to 28) are dedicated entirely to building the Board: how it’s constituted, who can sit on it, and what procedure it must follow. The Digital Personal Data Protection Rules, 2025, notified on November 13, 2025, filled in the operational detail, with Rules 17 to 21 governing exactly how the Board gets staffed and how it runs its affairs.
The underlying logic is straightforward. Rights on paper (access, correction, erasure, grievance redressal, the right to nominate) need somewhere to go when a company ignores them. The Board is that place.
Who Sits on the Board? Composition and Appointment
Under Section 19(1), the Board consists of a Chairperson and such number of Members as the Central Government decides to notify. The Act doesn’t fix a rigid headcount; it leaves room for the government to scale the Board based on caseload.
What the Act does fix is eligibility. Section 19(3) requires the Chairperson and Members to be people of “ability, integrity and standing” with special knowledge or practical experience in fields like data governance, law, dispute resolution, information and communication technology, the digital economy, regulation, or techno-regulation. At least one Member must be a legal expert. This isn’t a board stacked purely with technocrats or purely with lawyers; the statute deliberately wants both.
How are they picked? Not by direct government appointment alone. Section 19(2) routes appointments through a Search-cum-Selection Committee, and the 2025 Rules spell out who sits on that committee:
- For the Chairperson: a committee headed by the Cabinet Secretary, joined by the Secretary of the Department of Legal Affairs, the Secretary of MeitY, and two subject-matter experts.
- For other Members: a committee headed by the MeitY Secretary, joined by the Secretary of Legal Affairs and two domain experts.
Once appointed, the Chairperson and Members serve a two-year term and are eligible for reappointment under Section 20(2). Section 21 lists disqualifications, insolvency, conviction involving moral turpitude, physical or mental incapacity, a conflicting financial interest, or having “abused” the position in a way that’s prejudicial to the public interest. Crucially, nobody can be removed without first getting an opportunity to be heard. That’s a deliberate independence safeguard: the executive can’t simply sack a Member it dislikes without due process.
Here’s how the full appointment chain looks:
Where and How Does the Board Function?
The Board’s headquarters sits in the National Capital Region, per the government’s November 2025 notification. But physical geography matters less here than it usually does for a regulator, because Section 18(3) requires the Board to function “as far as practicable” as a digital office. Complaints, hearings, evidence, and decisions are meant to be digital by design. There’s no expectation that a business in Coimbatore or a data principal in Guwahati needs to travel to Delhi to be heard.
This digital-first mandate is one of the more genuinely forward-looking parts of the Act. It also means your organisation’s own record-keeping needs to be equally digital and equally organised, because the Board will expect documents, consent logs, and audit trails to be producible electronically, not dug out of a filing cabinet.
What Powers Does the Board Have?
Section 27 lays out the Board’s powers and functions in specific, triggering scenarios. It can act:
- On intimation of a personal data breach under Section 8(6), directing urgent remedial or mitigation measures and then inquiring into the breach itself.
- On a complaint by a Data Principal about a breach by a Data Fiduciary, or on a reference from the Central or a State Government, or on a court’s direction.
- On a complaint about a Consent Manager’s breach of its obligations.
- On intimation that a Consent Manager has breached a condition of its registration.
- On a Central Government reference concerning an intermediary’s breach of Section 37(2).
Once it decides to act, the Board’s toolkit is genuinely wide. It can:
- Issue binding directions after hearing the person concerned and recording written reasons (Section 27(2)).
- Conduct suo motu inquiries, meaning it doesn’t need to wait for a complaint to land in its inbox.
- Summon and examine witnesses on oath, exactly like a civil court under the Code of Civil Procedure, 1908 (Section 28(7)).
- Demand documents, data, registers, and books of account.
- Inspect processing premises, with safeguards built in so inspections don’t needlessly disrupt business operations.
- Pass interim orders while an inquiry is still underway.
- Impose monetary penalties up to the ceilings set out in the Schedule to the Act, capped at ₹250 crore for the most serious contraventions (we cover the full penalty tiers in our penalties and enforcement structure guide).
- Accept voluntary undertakings from a Data Fiduciary under Section 32, essentially letting an organisation commit to specific corrective steps, sometimes in exchange for a lighter outcome.
Every one of these powers comes with a natural justice string attached. Section 28(6) requires the Board to follow principles of natural justice throughout, and to record reasons for its actions as it goes. This isn’t a rubber-stamp body; a poorly reasoned order is an order that’s vulnerable on appeal.
When Can a Matter Reach the Board?
A matter typically reaches the Board through one of five routes:
- An unresolved grievance. Section 13 gives Data Principals the right to grievance redressal directly from the Data Fiduciary or Consent Manager. Only once that internal channel is exhausted can the individual approach the Board.
- A breach notification. Under Section 8(6), Data Fiduciaries must notify the Board (and, in prescribed cases, affected individuals) of a personal data breach. That notification itself can trigger Board action.
- A suo motu inquiry. The Board can start looking into a matter on its own, without waiting for anyone to complain.
- A government or judicial reference. The Central Government, a State Government, or a court can refer a matter to the Board.
- A Consent Manager related complaint or intimation, covering both obligation breaches and registration condition breaches.
If you’re a Data Fiduciary, route one and route two are the ones that should worry you most day-to-day, because they’re the ones directly shaped by how well your internal grievance handling and breach response actually work.
How Does the Complaint and Inquiry Process Work, Step by Step?
Here’s where a lot of compliance teams get lost, because the Act’s language is precise but scattered across several sections. Laid out sequentially, the process looks like this:
Step 1: Internal grievance. The Data Principal raises the issue with the organisation’s Grievance Officer first. This isn’t optional; Section 13(3) requires the internal route to be exhausted before the Board gets involved.
Step 2: Escalation. If the grievance goes unresolved or the response is unsatisfactory, the individual can now approach the Board. Separately, a breach notification or a suo motu trigger can start the process without this step.
Step 3: Complaint filed digitally. Consistent with Section 18(3), the complaint is meant to be lodged, allocated, and tracked through the Board’s digital systems.
Step 4: Prima facie review. Under Section 28(3), the Board first decides whether there are sufficient grounds to proceed. If not, it closes the matter, but only after recording its reasons in writing (Section 28(4)). This isn’t a formality the Board can skip; a closure without reasons is a closure that invites challenge.
Step 5: Formal inquiry. Where grounds exist, the Board inquires into the affairs of the person concerned to establish compliance or non-compliance (Section 28(5)). This is where the civil-court-style powers kick in: summons, document production, affidavits, and premises inspection, all conducted under natural justice principles.
Step 6: Hearing and response. The organisation gets a genuine opportunity to present its defence. This is also the stage where a voluntary undertaking under Section 32 can be offered, an option worth discussing with legal counsel early rather than late.
Step 7: Reasoned written order. The Board issues its decision: a penalty within the Schedule’s limits, remedial directions, acceptance of a voluntary undertaking, or dismissal of the complaint.
Visually, the flow looks like this:
A point worth underlining here: nothing in this process happens instantly, and nothing in it rewards a disorganised compliance function. An inquiry can demand consent records, data mapping documentation, breach logs, and vendor contracts on relatively short notice. Organisations that already maintain these as a matter of routine (rather than scrambling to assemble them after a notice arrives) are the ones that come out of an inquiry with far less exposure.
What Happens If You Disagree With an Order? The Appeal Route
A Board order isn’t the final word. Section 29 gives any aggrieved person the right to appeal to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT), which Parliament designated as the Act’s appellate forum rather than creating a brand-new tribunal from scratch.
A few procedural details matter here:
- The appeal must be filed within 60 days of receiving the Board’s order, though TDSAT has discretion to condone delay for sufficient cause.
- Appealing a monetary penalty typically requires depositing 50% of the penalty amount.
- TDSAT is expected to dispose of appeals within roughly six months.
- TDSAT’s own orders are executable as decrees of a civil court under Section 30, and can be further appealed to the High Court or Supreme Court, but only on substantial questions of law.
- Section 26 bars ordinary civil courts from entertaining any matter that falls within the Board’s jurisdiction, so this appellate ladder is effectively the only route available.
Here’s the full chain:
It’s worth flagging that TDSAT’s suitability as the DPDP appellate body has drawn genuine criticism from legal commentators, some of whom argue a tribunal built for telecom disputes doesn’t naturally carry data protection expertise. Whether that changes in future amendments is worth watching, but for now, TDSAT is where DPDP appeals land.
Is the Board Actually Operational Right Now?
This is the question we get asked most often, and it deserves an honest answer rather than a marketing one.
The legal architecture is complete. The DPDP Rules, 2025 were notified on November 13, 2025, and Rules 17 to 21, governing the Board’s constitution, procedure, and terms of service, took effect that same day. On paper, the Data Protection Board of India exists as a body corporate with a defined mandate.
Staffing it is a different matter. MeitY issued a formal call in May 2026, addressed to every Union Ministry, State, and Union Territory, inviting nominations for the Chairperson and Member posts, followed by a further notification in June 2026. Based on the latest publicly available reporting at the time of writing, the Search-cum-Selection Committees have been actively soliciting names, but a Chairperson and Members had not yet been formally appointed. In practice, this means the institutional framework is real and the selection machinery is moving, but the Board’s day-to-day adjudicatory function is still in the process of becoming fully operational.
We’d rather tell you that plainly than let you assume otherwise. It also changes nothing about your obligations. Breach notification duties, consent requirements, and grievance redressal timelines under the Act and Rules apply regardless of whether the Board has a sitting Chairperson on a given day. If anything, an unstaffed Board is a narrow window to get your house in order before the enforcement machinery is fully running. Given how quickly this is developing, check the latest notifications on meity.gov.in or with your legal counsel before assuming any particular status.
What This Means for Data Fiduciaries: Getting Ready
Whether the Board is staffed today or six months from now, the practical preparation is identical. A few things consistently separate organisations that handle a Board inquiry smoothly from those that don’t:
- A live, accurate data registry. You need to know what personal data you hold, where it sits, who processes it, and why, before anyone asks.
- Documented consent trails. Consent collection, withdrawal, and purpose limitation records that can be produced on demand, not reconstructed after the fact.
- A working grievance redressal process, since Section 13 exhaustion is the front door to most Board complaints. A grievance that sits unanswered for weeks is the fastest way to end up in front of the Board.
- A tested breach response plan, including the internal workflow for the 72-hour type notification obligations under Section 8(6).
- Vendor and processor oversight, since a breach originating with a third-party processor still lands on the Data Fiduciary’s doorstep.
- Audit-ready documentation, meaning records that hold up as evidence, not just internal notes.
This is exactly the operational gap RuleExpert’s platform is built to close. Our Data Registry keeps a live, centralised inventory of personal data across your systems. Our Consent Manager module handles the full consent lifecycle with an audit trail. DSR Automation manages Data Principal requests within statutory timelines with approval workflows built in. Breach Management gives you a structured, documented process for the exact kind of incident that can trigger Board scrutiny. And our DPDP Scorecard gives you an honest readiness assessment before a regulator asks the question for you.
If you’d rather see how this fits your specific setup than read about it in the abstract, book a demo with RuleExpert and we’ll walk through it against your actual data flows.
Mistakes Organisations Make With the Board
A few recurring patterns show up in how businesses misjudge the Board:
- Treating it like a distant, toothless body because it isn’t fully staffed yet. The obligations it will enforce are already in force. Waiting to prepare until the Board sends a notice is preparing too late.
- Assuming internal grievance redressal is a formality. Since exhausting Section 13 is often a precondition to a Board complaint, how you handle that first-line grievance matters enormously. A dismissive or slow internal response often becomes Exhibit A in the eventual complaint.
- Underestimating the Board’s civil-court powers. Section 28(7) isn’t decorative language. Summons, document demands, and premises inspection are real tools, and stonewalling them tends to backfire.
- Not knowing where the Consent Manager fits. Complaints against a registered Consent Manager follow a slightly different trigger than complaints against a Data Fiduciary directly; our Consent Manager guide covers that distinction in more depth.
- Missing the 60-day appeal window. TDSAT can condone delay, but “sufficient cause” is not a guaranteed escape hatch. Treat the window as firm.
- Skipping the voluntary undertaking conversation. Section 32 exists for a reason. Organisations that engage constructively during an inquiry, rather than only contesting it, sometimes land in a materially better place.
Frequently Asked Questions
What is the Data Protection Board of India? It’s the independent adjudicatory body set up under Section 18 of the DPDP Act, 2023, responsible for investigating personal data breaches, hearing complaints from Data Principals, and imposing penalties or directions on Data Fiduciaries and Consent Managers.
Is the Data Protection Board of India functional yet? The Board’s legal and procedural framework has been in force since the DPDP Rules, 2025 were notified on November 13, 2025. As of the most recent public reporting, the appointment of its Chairperson and Members was still underway through the Search-cum-Selection Committee process. Confirm the current status with MeitY’s official notifications, since this is actively changing.
Who can file a complaint with the Data Protection Board? A Data Principal whose grievance with a Data Fiduciary or Consent Manager under Section 13 has gone unresolved can approach the Board. The Board can also act on breach notifications, government or court references, and its own suo motu inquiries.
What powers does the Data Protection Board have? Under Sections 27 and 28, the Board can inquire into breaches, summon witnesses and documents, inspect premises, issue binding directions, accept voluntary undertakings, and impose monetary penalties, all while following civil-court style procedure and natural justice.
How much penalty can the Data Protection Board impose? Penalties are capped by the Schedule to the DPDP Act, with the most serious contraventions attracting fines of up to ₹250 crore per instance. See our penalties and enforcement structure guide for the full tier breakdown.
Where is the Data Protection Board of India located? Its headquarters is in the National Capital Region, but the Board is designed to function as a digital office under Section 18(3), so proceedings are conducted online rather than requiring physical appearance in Delhi.
Who appoints the Chairperson of the Data Protection Board? The Central Government appoints the Chairperson on the recommendation of a Search-cum-Selection Committee headed by the Cabinet Secretary, as prescribed under the DPDP Rules, 2025.
What’s the difference between the Data Protection Board and a court? The Board is a specialised, quasi-judicial adjudicatory body, not a court of general jurisdiction. It follows civil-court style procedure for evidence and summons but its own orders are appealable only to TDSAT and, on legal questions, to higher courts, since Section 26 bars ordinary civil courts from hearing matters within its jurisdiction.
Can you appeal a Data Protection Board order? Yes. Under Section 29, an aggrieved party can appeal to TDSAT within 60 days of the order, generally after depositing 50% of any penalty. TDSAT’s decision can be further appealed to the High Court or Supreme Court on substantial questions of law.
Do I need to exhaust internal grievance redressal before approaching the Board? Generally, yes. Section 13(3) requires a Data Principal to first pursue the grievance redressal process offered by the Data Fiduciary or Consent Manager before escalating to the Board, except where the matter reaches the Board through a different route, such as a breach notification or a government reference.
RuleExpert is an AI-powered DPDP compliance infrastructure platform. If your organisation needs to build audit-ready processes before the Data Protection Board comes fully online, book a demo and we’ll show you where the gaps are.
Nitin Ray is a Compliance Manager at RuleExpert with expertise in DPDP compliance, data privacy, consent management, and governance. He helps organizations implement practical compliance frameworks and automation strategies to meet the requirements of India’s Digital Personal Data Protection Act, 2023.

3 Comments
Comments are closed.