DPDP for Boards and Directors: What Governance Oversight Actually Looks Like
Boards don't need to run compliance day-to-day, but they do need to ask the right questions and see the right evidence. A practical oversight framework.
Why this belongs on the board agenda at all
For organisations that qualify as a Significant Data Fiduciary under Section 10, board-level oversight isn't optional framing — the law expects a resident Data Protection Officer reporting to the board or a board committee, an independent data auditor, and periodic data protection impact assessments. But even outside that designation, personal data risk (breach exposure, regulatory penalties, reputational damage) is squarely within ordinary board risk-oversight duties.
The board's job is not to review individual consent notices or vendor contracts — it's to satisfy itself that management has a functioning programme, that resourcing matches the actual risk, and that material issues reach the board rather than staying buried in an operational team.
Questions worth asking management regularly
Do we know, with reasonable confidence, what personal data we hold, where it lives, and who has access — or is this still a work in progress? A vague answer here is itself informative.
What is our process for detecting and reporting a personal data breach, and has it ever been tested? Section 8(6) requires intimation to both the Board and affected Data Principals, and a programme untested until a real incident is a real gap.
Are our significant vendors and processors under contracts that meet Section 8(2) expectations, and when were they last reviewed? Are there any vendor relationships the board should be specifically aware of given the volume or sensitivity of data involved?
Do we have a named, published Data Protection Officer or contact person as required under Section 8(9), and does that person have the authority and access needed to do the job, or is it a title without resourcing?
What to expect if designated a Significant Data Fiduciary
A Section 10 designation brings specific obligations: a resident DPO reporting to the board, an independent data auditor, and periodic DPIAs. The board should expect to see DPIA findings and auditor reports directly, not just a summary that findings were 'addressed,' since these are precisely the mechanisms the law expects the board to oversee.
SDF status may also carry additional duties under the DPDP Rules around algorithmic due diligence and, in some cases, data localisation directions — the board's role is to confirm management has a credible plan for these, not to design the plan itself.
Where to go next
Ask management to walk the board through outputs from the Readiness Assessment and the Evidence Tracker as a standing agenda item, rather than a one-time presentation.