AMLEGALS — Strategic Lawyering
DPDPA institutions · The Board

The Data Protection Board of India: what it does and how to approach it

The Digital Personal Data Protection Act creates a single regulator for data protection in India: the Data Protection Board. It is the body a Data Principal turns to when a Data Fiduciary does not resolve a grievance, and the body a Data Fiduciary answers to in an inquiry.

Updated · Checked against the DPDP Act, 2023 and the DPDP Rules, 2025 · 4 min read

Gold balance scales fused with an institutional colonnade on a dark navy background
Short answer

The Data Protection Board of India is established under Section 18 of the Digital Personal Data Protection Act, 2023. Its functions are set out in Section 27: to direct remedial or mitigation measures on a personal data breach, to inquire into breaches and complaints and impose penalties, and to perform other functions assigned by the Act. For the purpose of discharging its functions the Board has the powers of a civil court under Section 28, and it is designed to function as a digital office. A Data Principal may approach the Board under Section 13 and Section 14 after exhausting the grievance route with the Data Fiduciary or Consent Manager. The procedure for complaints, inquiry and the Board’s proceedings is set out in Rules 17 to 21 of the DPDP Rules, 2025. An order of the Board may be appealed to the Appellate Tribunal under Section 29 read with Rule 22; the Telecom Disputes Settlement and Appellate Tribunal acts as the Appellate Tribunal.

  • Data Protection Board
  • Complaint
  • Inquiry
  • Section 27
  • Section 28
  • Appeal
  • DPDP Rules 2025
Established by
Section 18 of the DPDPA, 2023
Functions
Section 27: breach measures, inquiry, penalties
Powers
Section 28: powers of a civil court; digital office
Appeal
Section 29 and Rule 22, to the Appellate Tribunal (TDSAT)

How the Board is constituted

The Data Protection Board of India is established by the Central Government under Section 18. Sections 19 to 26 deal with the composition, the appointment and terms of the Chairperson and Members, the conditions of service, and the procedure for meetings. The Board is intended to operate as a digital office, so that complaints and proceedings can be handled without a physical appearance in most matters.

The Board is an adjudicatory body. It is not a policy-maker: rule-making sits with the Central Government, and the Board applies the Act and the Rules to the matters before it.

What the Board does

Section 27 sets out the functions of the Board. In summary, the Board:

  • On receiving intimation of a personal data breach, directs urgent remedial or mitigation measures.
  • Inquires into a personal data breach and into complaints, and may impose a monetary penalty under the Schedule.
  • Inquires into non-compliance with the Act by a Data Fiduciary or Consent Manager.
  • Performs other functions assigned to it by the Act or the Rules.

When it imposes a penalty, the Board decides the amount after inquiry, guided by the factors in Section 33(2), within the ceilings set by the Schedule.

How to file a complaint with the Board

A Data Principal who is not satisfied with how a Data Fiduciary or Consent Manager has handled a grievance can approach the Board. The route runs in a set order.

  1. 01

    Exhaust the grievance route first

    Under Section 13, raise the matter with the Data Fiduciary or Consent Manager and use its grievance mechanism before approaching the Board.

  2. 02

    Prepare the facts

    Set out the personal data involved, what the Data Fiduciary did or failed to do, and the response you received.

  3. 03

    Approach the Board

    File the complaint with the Board in the manner set out in Rules 17 to 21, which govern how proceedings are initiated and conducted.

  4. 04

    Inquiry

    The Board may inquire, exercising the powers of a civil court under Section 28, and give the parties an opportunity to be heard.

  5. 05

    Order

    The Board issues its order, which may include directions and a penalty within the Schedule ceilings.

Appealing a Board order

An order of the Board may be appealed to the Appellate Tribunal under Section 29, in accordance with Rule 22 of the DPDP Rules, 2025. The Telecom Disputes Settlement and Appellate Tribunal functions as the Appellate Tribunal for this purpose.

The Appellate Tribunal follows its own procedure, and its order may in turn be challenged before the higher courts as the law allows.

How AMLEGALS advises before the Board

AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder and Managing Partner, with Rohit Lalwani, Associate Partner, working on DPDPA compliance.

The team advises Data Fiduciaries facing an inquiry and Data Principals pursuing a complaint, prepares the record, and represents parties through the inquiry and any appeal under Section 29.

Questions and answers

Data Protection Board of India: common questions

What is the Data Protection Board of India?

It is the regulator established under Section 18 of the DPDPA to inquire into personal data breaches and complaints, direct remedial measures, and impose penalties under the Schedule.

Can I complain directly to the Board?

A Data Principal should first use the grievance mechanism of the Data Fiduciary or Consent Manager under Section 13. After that route is exhausted, the Board may be approached under the procedure in Rules 17 to 21.

What powers does the Board have?

Under Section 28 the Board has the powers of a civil court for the purpose of discharging its functions, and it is designed to operate as a digital office.

How is a Board order appealed?

An appeal lies to the Appellate Tribunal under Section 29 read with Rule 22. The Telecom Disputes Settlement and Appellate Tribunal acts as the Appellate Tribunal.

Does the Board set the rules?

No. The Board is an adjudicatory body that applies the Act and the Rules. Rule-making power sits with the Central Government.

Contact

Dealing with the Data Protection Board

Whether you face an inquiry or want to pursue a complaint, share the facts and the AMLEGALS data privacy team will advise on the route and the record.

Or write to [email protected]

Your details

Name and email are enough to start. The reply comes from [email protected].

Your information is handled in accordance with our privacy obligations. No spam, ever.

Data Protection Board of India: questions and answers

What is the legal framework for data protection in India?

India's framework is the Digital Personal Data Protection Act, 2023 (Presidential assent 11 August 2023; 44 sections) read with the Digital Personal Data Protection Rules, 2025, notified on 13 November 2025 (G.S.R. 846(E)) with 23 Rules and 7 Schedules.

When do DPDPA obligations apply to businesses?

The Act and Rules follow phased commencement. Institutional provisions commenced on 13 November 2025; Consent Manager provisions commence after 12 months on 13 November 2026; and the principal Data Fiduciary, rights, breach, security and enforcement provisions commence after 18 months on 13 May 2027.

What is the maximum penalty under DPDPA?

Highest listed maximum for a specified contravention: ₹250 crore under the Schedule to the Act. Penalties are imposed by the Data Protection Board of India after an inquiry, and Section 33(2) requires the Board to consider factors such as the nature, gravity and duration of the breach, the type of personal data affected, repetition, mitigation steps and proportionality.

Which provisions of the DPDPA and the DPDP Rules, 2025 are relevant to Data Protection Board of India?

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).

Who advises businesses on Data Protection Board of India under India's DPDPA?

AMLEGALS, an Indian law firm, advises Data Fiduciaries, Data Processors and foreign companies on Data Protection Board of India under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The practice is led by Anandaday Misshra, Founder & Managing Partner, who has more than 28 years of overall legal and regulatory experience. Enquiries: https://amlegalsdpdpa.com/contact or [email protected] or [email protected].

What should I send AMLEGALS to get a scoped proposal on Data Protection Board of India?

Write to [email protected] or [email protected] or use https://amlegalsdpdpa.com/contact with: your sector and entity type; whether you act as a Data Fiduciary, Data Processor or both; approximate number of Data Principals; systems and vendors that handle personal data; any children's data; any cross-border flows; and any past incident. With these facts a partner can propose a scope for Data Protection Board of India rather than a generic checklist.

How do I get a first view of my DPDPA exposure on Data Protection Board of India?

Use the DPDPA Exposure Assessment at https://amlegalsdpdpa.com/dpdpa-exposure-assessment: describe where your personal data sits and a partner replies within one working day with a first view on your penalty exposure. Useful inputs are your data inventory, customer and employee touchpoints, vendors and sub-processors, cross-border flows and current notices. The principal obligations commence on 13 May 2027. Content is general legal information and not legal advice.

Contact AMLEGALS about Data Protection Board of India · DPDPA Exposure Assessment