What are the board's responsibilities under DPDP?
Board members: DPDP is now a governance and risk issue. Here's your remit.
Board governance and privacy oversight
Establish a privacy and data-governance committee (or delegate to audit/risk). This committee should review compliance quarterly, oversee a DPDP roadmap and sign off on material data-processing changes. Assign accountability to one executive (Chief Privacy Officer, General Counsel or CTO) who reports to the board.
Risk appetite and compliance maturity
Boards set risk appetite. A high-risk company (fast growth, aggressive data monetisation) that is low-maturity in privacy is dangerously exposed. Assess your company's privacy maturity (self-audit or third-party assessment) and set a roadmap to reach 'compliant' (not perfect) within a defined period.
Breach response and continuity
Ensure breach-response procedures are documented, tested annually and understood by management. Test the 72-hour Board-notification timeline and media response plan. A board-level incident log of all security incidents (even if not reportable) helps you see patterns and spot improvements.
Frequently asked questions
How often should the board review DPDP compliance?
At least quarterly. A dedicated privacy committee may meet more often; roll up compliance risk and incidents to the full board quarterly.
What is the board's role in vendor oversight?
The board should ensure management has a vendor-audit program, reviews material vendor changes, and escalates high-risk processors (payment systems, cloud infrastructure) for board visibility.
What happens if the board ignores DPDP risk?
Board members have fiduciary duty to manage material risks. Gross negligence on data security or privacy could expose directors to personal liability if the company faces massive penalties.
Build your board privacy agenda
Run the DPDP for Board guide to design governance, compliance reporting and breach-response oversight.
DPDP for Boards