What is the Data Protection Board of India — powers and enforcement

What is the Data Protection Board of India — powers and enforcement
Regulator

What is the Data Protection Board of India — powers and enforcement

The Data Protection Board is India's new data protection regulator. Here is what it can do and how it will enforce the DPDP Act.

Quick Answer: The Data Protection Board of India (DPBI) is an independent statutory body established under the DPDP Act 2023 to adjudicate complaints about violations of the Act and to impose penalties on Data Fiduciaries that fail to comply. The Board is not a sector regulator — it has jurisdiction across all industries and data processing activities. It operates as a digital-first regulator: complaints must be filed online, proceedings may be conducted digitally, and orders will be published. The Board can investigate, hold enquiries, and impose financial penalties ranging from ₹10,000 (for minor violations) to ₹250 crore (for the most serious failures). Its orders can be appealed to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT). The Board is not yet operational — its constitution and procedures will be notified alongside the DPDP Rules.

What are the powers of the Data Protection Board?

The Board has the power to: receive and investigate complaints from Data Principals; conduct its own-motion inquiries into suspected violations; issue summons and require production of documents; hold hearings (digitally or physically); impose financial penalties; direct Fiduciaries to comply with the Act and Rules; refer matters to sector regulators where the violation also involves their jurisdiction; and publish its orders. It does not have the power to award compensation to Data Principals — compensation claims must go to civil courts. The Board's primary function is enforcement through penalties and compliance directions.

How does the Board receive and process complaints?

Data Principals who believe their rights have been violated can file a complaint with the Board — but must first attempt to resolve the matter through the Fiduciary's own grievance mechanism. If the grievance mechanism does not resolve the complaint satisfactorily, the Principal can escalate to the Board. The Board will be digital-first: complaints are expected to be filed through an online portal, and hearings may be conducted virtually. The Board can reject complaints that are manifestly frivolous, vexatious, or outside its jurisdiction.

What penalty structure does the DPDP Act establish?

The Act sets penalty tiers based on the type of violation: failure to implement security safeguards leading to a breach — up to ₹250 crore; failure to notify the Board of a breach — up to ₹200 crore; violation of additional obligations for Significant Data Fiduciaries (DPO appointment, DPIA, Data Audit) — up to ₹150 crore; failure to observe children's data protection obligations — up to ₹200 crore; breach of any other provision — up to ₹50 crore; and each individual violation can attract up to ₹10,000 in penalties in less serious cases. These are ceiling figures — actual penalties are discretionary based on the Board's assessment.

What factors does the Board consider when determining penalties?

When deciding the quantum of penalty, the Board considers: the nature, gravity, and duration of the non-compliance; the type and sensitivity of data involved; the volume of data principals affected; whether the violation was wilful or negligent; whether the Fiduciary took remedial steps; whether the violation had a significant impact; whether the Fiduciary benefited commercially from the violation; and whether it is a repeat violation. Proactive remediation, genuine cooperation, and a strong compliance programme are mitigating factors.

Can Board orders be appealed?

Yes. Orders of the Data Protection Board can be appealed to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) within 60 days of the order. TDSAT orders can be further appealed to the High Court and ultimately the Supreme Court. The Board's penalty orders are stayed during appeal in some circumstances. However, Board orders that are not appealed in time become final and are enforceable as a decree of a civil court — including for recovery of financial penalties.

How does the Board relate to other sectoral regulators?

The DPDP Board operates alongside sector regulators: RBI, SEBI, IRDAI, TRAI, and CCI all have their own data-related powers and obligations. When a data protection violation also violates a sectoral regulation, the Board may refer the matter to the relevant sector regulator. The relationship between the Board and sector regulators — including how jurisdictional overlaps are handled — will be clarified by Rules and inter-regulator coordination mechanisms. Regulated entities should expect to potentially deal with both the Board and their sector regulator in significant incidents.

Frequently asked questions

When will the Data Protection Board become operational?

The Board has not yet been constituted as of mid-2026. The DPDP Act notified the framework in August 2023, but the Board's constitution requires appointment of the Chairperson and members, which depends on the notification of DPDP Rules. The government has indicated enforcement is expected around May 2027. Track the Ministry of Electronics and IT (MeitY) website for updates on the Rules notification and Board constitution timeline.

Can the Board act against foreign companies?

The DPDP Act applies to processing of personal data of Indian data principals, including by companies outside India. The Board has extraterritorial jurisdiction to the extent that Indian law applies — which covers processing 'in connection with offering goods and services to Data Principals in India.' Enforcing Board orders against a foreign company with no Indian presence is practically difficult, but entities with Indian operations, assets, or business presence are fully within enforcement reach.

Can a Fiduciary negotiate with the Board to settle a penalty?

The Act provides for voluntary undertakings — a Fiduciary can voluntarily commit to remediation steps before or during proceedings, which the Board may accept as a basis for resolving the matter without a full penalty order. This is similar to consent orders in securities regulation. The Board has discretion on whether to accept voluntary undertakings. This provision incentivises early, genuine remediation over protracted enforcement proceedings.

Prepare for Data Protection Board enforcement

Niti Bharat's DPDP Enforcement Defence Pack prepares your organisation for Board inquiries — compliance documentation, penalty mitigation strategy, and grievance mechanism design.

Get the Enforcement Defence Pack
Previous Post Next Post

Get Free DPDP Checklist