The Data Protection Board of India: How It Works and What Enforcement Will Look Like

    Understand how the Data Protection Board of India operates under the DPDPA, including its powers, enforcement process, and what Data Fiduciaries can expect when a potential violation is investigated.

    OneConsentBlog
    8 min read
    Saturday, 5 September 2026
    Illustration showing the Data Protection Board of India overseeing the DPDPA enforcement process, from customer complaints and investigations to hearings, penalties, directions, and appeals.

    If you handle personal data for your organisation, you need to understand a regulatory body most compliance teams have not dealt with before: the Data Protection Board of India, known as the DPBI. It enforces the Digital Personal Data Protection Act, 2023 (DPDPA), and unlike many earlier Indian regulatory bodies, it is built to run digitally, move on its own initiative, and carry real investigative teeth once it is fully staffed.

    What Is the Data Protection Board of India

    The Data Protection Board of India was established under Section 18 of the DPDPA, 2023, through a notification dated 13 November 2025. It sits within Chapter V of the Act, alongside the provisions governing its composition, appointment process, and internal procedure (Sections 18 to 26).

    Section 19 sets up a Chairperson and up to four Members, appointed by the Central Government on the recommendation of two separate Search-cum-Selection Committees: one for the Chairperson, chaired by the Cabinet Secretary, and one for the Members, chaired by the Secretary of MeitY. Members are meant to carry experience across law, technology, data governance, and public administration, so the panel can handle cases that mix legal questions with technical ones.

    A note on current status. As of September 2026, the Chairperson and Members of the DPBI have not yet been appointed. MeitY invited applications for these posts in May 2026, and issued a further notification on the appointment process in June 2026. The Board exists as a statutory body under Section 18, but its adjudicatory functions will only become active once the Chairperson and Members take office. Organisations should treat the Board's enforcement powers as a near-term certainty to prepare for, not as something already running day-to-day complaints. This is worth checking again closer to your compliance planning date, since appointments could be finalised at any point.

    Once it is running, the Board will function entirely online. Rule 20 of the DPDP Rules, 2025, requires it to use techno-legal measures so complaints, hearings, and orders proceed without anyone appearing in person or filing physical paperwork. Expect your future interactions with the DPBI, from a notice to a hearing, to run through a digital portal, much like your existing filings on the GST Network or MCA21.

    How a Complaint Reaches the Board

    Under the right of grievance redressal in Section 13 of the DPDPA, and the timelines fixed by Rule 14 of the DPDP Rules, a Data Principal, the individual whose personal data is involved, must first raise the grievance with your organisation directly, as the Data Fiduciary. You then have a maximum window of 90 days to resolve it.

    The matter reaches the Board only if your process fails to resolve the complaint within that window, or the individual remains unsatisfied with your outcome. A grievance you handle well inside your own organisation rarely turns into a Board matter.

    Section 28(5) also lets the Board open an inquiry on its own initiative, without any complaint filed, where it has reason to believe a systemic issue needs examination. A clean complaint record is a good sign, but it is not the only thing the Board looks at.

    What Powers the Board Holds Under the Act

    Once an inquiry is underway, Section 28(7) gives the Board the same powers as a civil court under the Code of Civil Procedure, 1908, for specific purposes. This includes summoning any person and examining them on oath, receiving evidence on affidavit, requiring the production of documents, and inspecting data, books, registers, or other records relevant to the inquiry.

    Claims about the Board's powers get overstated in practice, so it helps to know the limit. Section 28(8) blocks these powers from reaching into your physical operations: the Board and its officers cannot prevent access to your premises, and cannot take custody of equipment or anything that would disrupt your day-to-day functioning. Its authority runs through documents, testimony, and records. Section 28(9) lets it call on police or government officers if an inquiry needs that support, and Section 28(10) lets it issue interim orders during an inquiry, after giving you a hearing.

    A well-organised, auditable set of consent records and data governance documentation is the single most useful asset your organisation can hold if an inquiry ever reaches you.

    What Happens After an Inquiry Is Accepted

    Under Section 28, the process follows a defined sequence. Your organisation is notified of the inquiry and given an opportunity to respond before any hearing takes place, so a Board proceeding is never decided without your side being heard. A hearing follows, conducted digitally in line with Rule 20, and the Board records its reasons in writing at each stage, as required under Section 28(6).

    At the end of the inquiry, the Board can close the matter, or proceed to penalty proceedings under Section 33 if it finds the breach significant.

    How the Board Decides Penalty Amounts

    The Schedule to the Act sets penalty ceilings by category of violation, up to ₹250 crore for a failure to implement reasonable security safeguards, with lower ceilings for other categories such as breach notification failures or Data Principal rights violations. Within that ceiling, Section 33(2) requires the Board to weigh seven specific factors before setting the actual amount:

    • The nature, gravity, and duration of the breach

    • The type and nature of the personal data affected

    • Whether the breach was repetitive

    • Whether your organisation gained an advantage, or avoided a loss, as a result of the breach

    • What action you took to mitigate the effects, and how quickly you took it

    • Whether the penalty amount is proportionate, given the need to secure compliance and deter future breaches

    • The likely impact of the penalty on your organisation

    Read this list plainly. An organisation with a documented, functioning consent and governance programme, and prompt mitigation steps when something goes wrong, sits in a stronger position under Section 33(2) than one that shows up with nothing.

    What Happens If You Want to Dispute the Outcome

    Under Section 29, any penalty or direction issued by the Board can be appealed to the Appellate Tribunal. Once the Tribunal issues its order, Section 30 gives that order the same enforceability as a decree of a civil court, meaning it can be executed directly, without a fresh civil suit.

    Sections 31 and 32 also give the Board room to resolve matters outside a full penalty proceeding, through alternate dispute resolution or by accepting a voluntary undertaking from your organisation to take specific corrective steps. Both routes are worth understanding as part of your response options if an inquiry ever reaches you, alongside a formal hearing.

    Preparing Your Organisation for a Fully Staffed Board

    The DPBI's statutory design is already fixed under the Act and the DPDP Rules, 2025. The open question is when its Chairperson and Members take office and its adjudicatory functions go live, and given the pace of notifications through 2026, that is likely a matter of months. The steps worth taking now do not depend on that date:

    • Build and maintain a grievance redressal process that can resolve complaints within the 90-day window set by Rule 14, so most grievances never reach the Board.

    • Keep consent records, data processing logs, and governance documentation in a form you can produce on short notice if Section 28 powers are ever exercised against your organisation.

    • Document your breach response and mitigation steps as they happen, since Section 33(2) treats how quickly you act as a direct factor in penalty amount.

    • Check which of your data processing activities fall under Significant Data Fiduciary obligations, since several of the higher penalty tiers in the Schedule apply specifically to that category.

    Read more: DPDPA Compliance Checklist Before Enforcement

    Treat these as ongoing habits, and your organisation stays in a stronger position no matter when the DPBI reaches full strength.

    Where OneConsent Fits Into This

    A defensible position with the Data Protection Board of India rests on what you can produce: auditable consent records, a documented grievance workflow with clear timestamps, and data governance processes your team can point to without scrambling to reconstruct them after the fact.

    OneConsent is a consent management platform built for these requirements. It is not the Board-registered Consent Manager entity defined under Rule 4 of the DPDP Rules. That is a separate category, registered directly with the Board, with its own registration and net worth conditions. OneConsent instead helps you centralise consent records, manage grievance timelines against the 90-day window, and maintain the governance trail your organisation would need to produce if an inquiry ever reached you.

    Visit oneconsent.ai to see how the platform maps to the specific obligations covered in this article.

    If you would like to walk through how this applies to your organisation's current setup, you can book a demo with our team.

    Frequently Asked Questions

    Have more questions?

    Search our full DPDP knowledge base for more answers.

    See it live

    See OneConsent in action

    Get a personalised walkthrough of how OneConsent helps your teams stay DPDPA compliant.

    • 30-minute walkthrough
    • DPDPA-ready by design
    • Tailored to your stack