How the Board conducts an inquiry
Section 27 establishes the Data Protection Board of India. Section 28 gives the Board power to inquire into breaches of the Act. An inquiry may be initiated upon receiving a complaint from a Data Principal (after the Data Fiduciary’s grievance mechanism has been exhausted) or upon a reference by the Central Government or a State Government.
The Board must give the person against whom the inquiry is conducted a reasonable opportunity of being heard (Section 28(4)). Rules 17 to 21 prescribe the procedure for inquiries conducted by the Board.
The inquiry is conducted on the basis of evidence. The Board may direct the production of information and documents (Section 28(3)). The Board is not bound by the procedure of the Code of Civil Procedure, 1908 but must follow the principles of natural justice (Section 28(5)).
The factors the Board considers in determining the penalty
Section 33(2) lists the factors the Board must have regard to when determining the penalty:
- The nature, gravity and duration of the breach.
- The type and nature of the personal data affected by the breach.
- The repetitive nature of the breach.
- Whether the person gained or avoided any loss as a result of the breach.
- Whether the person took any action to mitigate the effects of the breach and the timeliness and effectiveness of such action.
- Whether the penalty is proportionate and effective, having regard to the need to ensure compliance with the provisions of the Act.
Penalty defence centres on the fifth factor: demonstrating the steps the organisation took to comply, the timing of those steps, and their effectiveness. This is where the evidence from audits, DPIAs, breach exercises, training records and remediation plans becomes relevant.
Penalty ceilings under the Schedule
The Schedule to the Act prescribes the maximum penalty for each category of breach:
| Breach category | Schedule reference | Maximum penalty |
|---|---|---|
| Failure to take reasonable security safeguards | Section 8(5) | Up to ₹250 crore |
| Failure to notify the Board and affected Data Principals of a breach | Section 8(6) | Up to ₹200 crore |
| Breach of duties relating to children | Section 9 | Up to ₹200 crore |
| Breach of additional obligations of Significant Data Fiduciary | Section 10 | Up to ₹150 crore |
| Breach of any other provision of the Act or Rules | Residual | Up to ₹50 crore |
| Breach of duties of Data Principal | Section 15 | Up to ₹10,000 |
These are ceilings, not fixed amounts. The Board determines the actual penalty based on the Section 33(2) factors after giving the person a reasonable opportunity of being heard.
The appeal route: Appellate Tribunal and High Court
Section 29 provides that any person aggrieved by an order of the Board may prefer an appeal to the Appellate Tribunal. Rule 22 prescribes the appeal procedure, including the time limit and the form of appeal.
Section 30 provides for a further appeal from the Appellate Tribunal to the High Court on any question of law. The High Court’s decision is final.
An appeal does not automatically stay the penalty. The Appellate Tribunal may grant a stay on such conditions as it considers fit.
What effective penalty defence looks like
Defence is not about the moment of the inquiry. It is about the evidence that exists by the time the inquiry happens. The Section 33(2) factors reward organisations that took steps to comply and to mitigate, and that can show when they took them.
- Audit trail: dated records of the compliance programme—the data map, notices, consent logs, vendor register, breach plan, training records, DPIA reports, audit reports, retention schedules and erasure records.
- Breach response: evidence that the breach plan was current, that notification was timely, and that steps were taken to limit harm.
- Remediation: evidence that identified gaps were closed and that changes were made after an incident or an audit finding.
- Governance: board-level awareness of the compliance programme, resource allocation, and escalation protocols.
An organisation that can produce dated evidence of each duty it performs is better positioned under every Section 33(2) factor than one that cannot.
How AMLEGALS represents organisations before the Board
AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder & Managing Partner. The team includes Rohit Lalwani, Associate Partner, who works on DPDPA compliance.
The firm assists with pre-inquiry preparation (assembling the evidence file), written representations to the Board, oral submissions during the hearing, and appeals before the Appellate Tribunal under Rule 22.

