All templates
Board & Governance
Data Protection Committee Charter Template
A charter establishing the mandate, composition, and operating rhythm of an internal committee overseeing DPDP compliance.
Template
DATA PROTECTION COMMITTEE CHARTER
Organization: [Organization Name]
Approved By: [Board of Directors, on DD-MM-YYYY]
Charter Version: [1.0]
1. PURPOSE
The Data Protection Committee ("the Committee") is established to provide structured oversight of [Organization Name]'s compliance with the Digital Personal Data Protection Act, 2023 and its Rules, and to ensure privacy risk is considered at a governance level rather than left solely to operational teams.
2. MANDATE
The Committee shall:
(a) Review and endorse the Record of Processing Activities, Retention Schedule, and Vendor Risk Register at least [quarterly].
(b) Review all Data Protection Impact Assessments for new or materially changed high-risk processing activities before go-live.
(c) Oversee the organization's breach response, including review of entries in the Data Breach Log and confirmation that Board and Data Principal intimation timelines under Section 8(6) were met.
(d) Monitor the Rights Request Log for volume, SLA adherence, and recurring themes requiring process change.
(e) Where [Organization Name] qualifies as a Significant Data Fiduciary, oversee the annual DPIA and independent audit required under Section 10, and review algorithmic due-diligence for automated decision-making systems.
(f) Recommend updates to consent notices, privacy policies, and internal privacy training.
(g) Escalate material privacy risks or unresolved gaps to the Board of Directors.
3. COMPOSITION
The Committee shall comprise:
- [DPO Name] - Chair
- [Head of Legal / Compliance]
- [Head of Information Security / CISO]
- [Head of Engineering or Product]
- [Head of Human Resources] (for employee data matters)
- [Independent / External Advisor, if applicable]
Quorum: [A majority of members, including the Chair]
4. MEETING CADENCE
The Committee shall meet [monthly / quarterly], with additional ad-hoc meetings convened by the Chair in response to a significant breach, regulatory inquiry, or Board request. Minutes shall be recorded and retained as part of the Compliance Evidence Index.
5. REPORTING LINE
The Committee reports to [the Board of Directors / a designated Board Committee] through the Board Reporting Template for Privacy Metrics, submitted [quarterly / half-yearly].
6. DECISION AUTHORITY
The Committee may approve routine updates to internal registers and privacy notices. Any decision materially affecting the organization's risk posture - such as accepting a high residual risk on a DPIA, or a proposed cross-border transfer to a new jurisdiction - requires escalation to and sign-off by [the Board / designated Committee].
7. REVIEW OF THIS CHARTER
This Charter shall be reviewed [annually] by the Board of Directors, or earlier upon a material change to the Act, its Rules, or the organization's risk profile.
Approved:
[Board Chair Name / Designation]
Date: [DD-MM-YYYY]This template is a starting point, not legal advice. Have it reviewed by qualified counsel before use, and adapt bracketed placeholders to your organization's facts.