Summary

  • The DPB is the body established under the DPDP Act to oversee its enforcement.
  • It functions as an independent, digital-first office that can run proceedings without needing anyone to be physically present.
  • The Data Protection Board of India (DPB) was established in law on 13 November 2025 but its powers to inquire, adjudicate and impose penalties come into force on 13 May 2027.
  • The DPB investigates breaches, hears complaints and imposes penalties, and has the powers of a civil court for summoning people and examining evidence.
  • The DPB's orders can be appealed to the TDSAT and then the Supreme Court.
  • Mediation and voluntary undertakings serve as alternate dispute resolution mechanisms.
Close Button

Data Protection Board under the DPDP Act

Riddhi Swami

Content Specialist
September 22, 2026

Summary

  • The DPB is the body established under the DPDP Act to oversee its enforcement.
  • It functions as an independent, digital-first office that can run proceedings without needing anyone to be physically present.
  • The Data Protection Board of India (DPB) was established in law on 13 November 2025 but its powers to inquire, adjudicate and impose penalties come into force on 13 May 2027.
  • The DPB investigates breaches, hears complaints and imposes penalties, and has the powers of a civil court for summoning people and examining evidence.
  • The DPB's orders can be appealed to the TDSAT and then the Supreme Court.
  • Mediation and voluntary undertakings serve as alternate dispute resolution mechanisms.

Summary

  • The DPB is the body established under the DPDP Act to oversee its enforcement.
  • It functions as an independent, digital-first office that can run proceedings without needing anyone to be physically present.
  • The Data Protection Board of India (DPB) was established in law on 13 November 2025 but its powers to inquire, adjudicate and impose penalties come into force on 13 May 2027.
  • The DPB investigates breaches, hears complaints and imposes penalties, and has the powers of a civil court for summoning people and examining evidence.
  • The DPB's orders can be appealed to the TDSAT and then the Supreme Court.
  • Mediation and voluntary undertakings serve as alternate dispute resolution mechanisms.

What is the DPB?

The DPDP Act imposes several obligations on Indian businesses like consent collection, consent withdrawal, data security requirements etc., and proposes heavy penalties for any violations.

These new requirements are highly technical in nature, so assessing actual penalties will require a deeper, specialized technical understanding from the body enforcing it.

To achieve enforcement in a highly specialized and relevant way, the DPDP Act establishes a body known as the Data Protection Board to oversee the Act and enforce its requirements.

The DPB is given the powers of a civil court for summoning people, examining them on oath and inspecting evidence.

In essence, the DPB is the new regulator for privacy and consent in India with the ability to impose penalties on violators. Just like the RBI can impose penalties on Banks, or SEBI can impose penalties on stock brokers, the DPB can impose penalties on any Indian business for violations under the DPDP Act.

Has the Data Protection Board actually started working? What is its status?

While the DPB was technically established on 13 November 2025, (via a MeitY notification) - the chairperson and members are yet to be appointed.

Its powers to adjudicate and impose penalties only come into force on 13 May 2027. Therefore, in theory the DPB has been established but in practice it has no actual powers as of now.

What happens to a complaint filed today?
There's no functioning inquiry mechanism yet. Data Principals still have other remedies, like approaching courts, in the meantime.

What are the key powers and functions of the Data Protection Board?

The DPB is entrusted with 3 key functions under the DPDP Act:

  • Monitoring and oversight: Ensuring companies comply with the DPDP Act, with the ability to solicit reports from companies to report on their compliance.
  • Inquiry and adjudication: Investigation into data breaches as well as complaints made by Data Principals. The DPB may also offer an alternate dispute resolution (ADR) solution to resolve a matter without a full inquiry.
  • Imposing penalties: Once an inquiry concludes, the DPB determines and levies the penalty

What are the specific monitoring and oversight duties of the DPB?

The DPB has to ensure that Data Fiduciaries and Consent Managers meet their ongoing compliance obligations under the DPDP Act, by requiring them to submit regular reports, disclosures and audits:

  • Consent Manager obligations: the Consent Manager must submit the initial registration application, ongoing disclosure of its shareholding structure, periodic audit reports on its registration and get prior approval before any change of control from the DPB. (Rule 4(1); First Schedule, Part B)
  • Significant Data Fiduciary reporting: its Data Protection Impact Assessment and audit findings must be furnished to the DPB once every twelve months. (Rule 13(2))
  • Breach reporting: any Data Fiduciary must intimate the DPB without delay with a description of a breach, and within 72 hours with updated details. (Rule 7(2))

In essence, Consent Managers and Significant Data Fiduciaries must regularly, at fixed time intervals, submit reports to the DPB. All other data fiduciaries only need to submit reports when asked by the DPB or in event of data breach.

What are the specific inquiry and adjudication powers of the DPB?

The DPB can conduct an inquiry and initiate adjudication proceedings upon 4 events:

  • When it receives a breach intimation directly.(Section 27(1)(a))
  • When a Data Principal complains about a breach, about a Data Fiduciary, or against a Consent Manager. (Section 27(1))
  • When there's a breach of a Consent Manager's registration conditions. (Section 27(1)(d))
  • When an intermediary fails to comply with a government's blocking order. (Section 27(1)(e))

Alternate Dispute Resolution

The DPB can offer two ways to resolve a matter without a full inquiry: mediation and a voluntary undertaking.

  • Mediation: If the DPB thinks a complaint could be resolved through mediation, it can direct the parties to attempt this through a mediator. (Section 31)
  • Voluntary undertaking: During an inquiry, a person can offer the DPB a voluntary undertaking to stop some action, take some action, or publicise the undertaking. The DPB can accept it but cannot continue further proceedings on that same subject matter. If the person doesn't follow the undertaking, this breach will also be treated as a breach of the Act. (Section 32)

How does a DPB inquiry process work?

Step 1: The DPB needs to check for sufficient grounds before the stage of inquiry‍

The DPB conducts a pre-inquiry examination and decides if there are sufficient grounds to proceed. If not, it closes the matter and records its reasons in writing.

Step 2: Inquiry‍

If there are sufficient grounds to proceed, the DPB inquires into the person's/company's affairs.

During the inquiry, the DPB has the same powers as a civil court: summoning people and examining them on oath, receiving evidence, and inspecting documents and records.

Step 3: Issue interim orders or offer ADR, if needed‍

The DPB can issue interim orders while the inquiry is ongoing, if necessary.

It can also refer the matter to mediation, or accept a voluntary undertaking from the person, instead of continuing the inquiry. (Sections 31 and 32)

Step 4: Close or penalise‍

The DPB must close the inquiry within six months of the intimation, though it can extend this by up to three months at a time. (Rule 19(9)). Once the inquiry is done, the DPB either closes the matter or imposes a penalty.

If the DPB finds a complaint false or frivolous at any stage, it can warn the complainant or impose costs on them. (Section 28(12))

Does the DPB impose penalties?

Once an inquiry concludes if the DPB finds a breach, it can impose a monetary penalty based on:

  • the nature, gravity and duration of the breach;
  • the type and sensitivity of personal data involved;
  • whether the breach was repeated;
  • whether the person gained, or avoided a loss, because of it;
  • what the person did to mitigate the breach, and how quickly;
  • whether the penalty is proportionate, given the need to deter future breaches; and
  • the likely impact of the penalty on the person.

What is the maximum penalty that the DPB can impose under the DPDP Act?

The maximum penalty for a single violation is upto ₹250 crore for failing to take reasonable security safeguards under Section 8(5). If there is more than one violation in the same inquiry it can impose a separate penalty for each one, and these add up.

The penalty amount itself is tiered by the kind of breach. See the table for the maximum penalty amount for each type of breach:

Breach Maximum Penalty
Failing to take reasonable security safeguards (Section 8(5)) ₹250 crore
Failing to notify the DPB or Data Principal of a breach (Section 8(6)) ₹200 crore
Breach of obligations relating to children's data (Section 9) ₹200 crore
Breach of a Significant Data Fiduciary's additional obligations (Section 10) ₹150 crore
Breach of a Data Principal's duties (Section 15) ₹10,000
Breach of an accepted voluntary undertaking (Section 32) Same as the penalty for the original breach
Breach of any other provision of the Act or Rules ₹50 crore

How to appeal a DPB order?

If the DPB passes an order or direction and the party is not satisfied with the order, it can be appealed.

The TDSAT is the first appellate authority

  • The appeal must be filed within 60 days, in digital form, though TDSAT can excuse a delay for sufficient cause. (Rule 22)
  •  The TDSAT must try to dispose of appeals within six months, and must provide reasons in writing for any delay.

Further appeal to the Supreme Court

  • The TDSAT's order can be appealed in front of the Supreme Court, under the same mechanism that applies to TDSAT's other appellate orders. (Section 29(9))

Who does the DPB consist of?

The DPB consists of a Chairperson and Members who are appointed by the Central Government, on the recommendation of Search cum Selection Committees set up under the DPDP Rules. Each Member (including Chairperson) holds office for 2 years, but can be reappointed at the end of the term.

Chairperson Selection Committee‍

The committee to select the Chairperson of the DPB consists of:

  • Cabinet Secretary
  • Secretary of Legal Affairs
  • Secretary of MeitY
  • 2 outside experts

Committee to Select DPB Members‍

The committee to select the other two Members of DPB consists of:

  • MeitY secretary
  • Secretary of Legal Affairs
  • 2 experts

The Chairperson and Members must have ability, integrity and standing - with knowledge or experience in fields like data governance, dispute resolution or law. At least one Member must be a legal expert.

What Businesses Should Do to Avoid DPB action

The DPB isn't staffed and its powers aren't in force yet, but that's not a reason to wait. Here's how to be ready before they are.

  • Keep an auditable trail of your consents and compliance work, so you have a clear record to show the DPB if it ever asks.
  • Keep breach-reporting workflows ready, so a 72-hour DPB intimation and a Data Principal intimation can both go out on time.
  • If you were processing personal data before the Act's notice and consent requirements applied to you, send out the required notice to those Data Principals as soon as you reasonably can.
  • Put technical security measures in place now, such as encryption, access controls and audit logs, since failing to maintain reasonable security safeguards carries the highest penalty on the DPB's schedule.

Explore Leegality Consent Manager for your Business

Schedule a Demo Call

Compliance Deadline:

0 weeks away