DPDP NavigatorAct 2023 · Rules 2025
All guides
Legal Intelligence

Understanding the Data Protection Board of India's Procedure and Powers

23 Jul 202610 min read

The Board is the Act's front-line enforcement body. Here is what it can actually do, how a matter reaches it, and where its powers stop.

What the Board is and how it is constituted

The Data Protection Board of India is established under Section 18 of the Act as an independent body tasked with enforcement and adjudication rather than broad policy-making. Its composition, appointment process, terms of service, and administrative support are dealt with in the surrounding sections, with the central government retaining significant control over appointments and the Board's operating framework.

This design choice, an executive-appointed adjudicatory body rather than a fully independent regulator in the mould of some other statutory commissions, has drawn comment from commentators who would have preferred greater structural independence. The government's counter-position is that a leaner, digitally-native Board can move faster on individual cases than a heavier regulatory bureaucracy. Both views have some basis, and how it plays out will depend heavily on the Board's actual case handling once it is fully operational.

How a matter gets to the Board

Matters reach the Board principally through two channels: references made by the central government or its instrumentalities, and complaints made by Data Principals or Consent Managers, typically after a grievance to the Data Fiduciary itself has not been resolved satisfactorily. Data breach intimations required under Section 8(6) can also trigger Board scrutiny, since the Board is a natural recipient of information about significant incidents.

The Act envisions the Board conducting inquiries under a process described in general terms in the statute, with procedural detail, such as timelines, evidentiary standards, and hearing formats, left substantially to the Board's own procedure and to the Rules. Organisations should expect the practical experience of a Board inquiry to be shaped as much by early Board practice as by the bare text of the Act.

What the Board can order

Where the Board finds a significant breach of a Fiduciary's or Processor's obligations, it can, per Sections 27 through 30, impose monetary penalties within the ceilings set out in the Schedule, direct remedial or mitigating action, and in some circumstances accept a voluntary undertaking in place of, or during, a fuller inquiry. It also has powers analogous to a civil court for certain procedural matters, such as summoning and examining witnesses, which underscores its adjudicatory rather than purely administrative character.

What the Board does not appear to have, at least on the Act's current text, is a broad independent power to issue binding sector-wide codes of practice the way some overseas regulators do. Its remit is oriented toward individual cases and references rather than general rule-making, which stays with the central government.

Appeal beyond the Board

A person aggrieved by a Board order can appeal, under Section 29, to the Appellate Tribunal, understood to be the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) functioning in this additional capacity. This gives affected fiduciaries a further review layer before any question of approaching the higher courts arises.

Where to go next

For a fuller walk-through of what triggers an inquiry versus a voluntary undertaking, see the companion guide on voluntary undertakings, and use the Readiness Assessment to gauge how well your breach-response and grievance-handling processes would hold up if a complaint escalated to the Board.