Inside India's Data Protection Board: What It Can Do and Why It Still Isn't Fully Running

 Nearly a year after India notified the rules that were meant to bring its data protection regulator to life, the Data Protection Board of India still doesn't have a Chairperson in the seat. That gap between "established in law" and "operating in fact" is worth understanding, because it doesn't mean businesses get a pass. It means the enforcement machinery is being assembled while the underlying obligations are already binding.

Here's what the Board is, what it will be able to do once it's staffed, and what's actually happened so far.

A Regulator Born From a Privacy Judgment

The Board's roots trace back to the Supreme Court's 2017 ruling in Justice K.S. Puttaswamy v. Union of India, which declared privacy a fundamental right and set off years of legislative drafting. The Digital Personal Data Protection Act finally passed in August 2023. Getting a statute onto the books is one thing; building the institution to enforce it is another, and that took another two years. The Digital Personal Data Protection Rules, 2025 were notified on November 13, 2025, bringing into force the specific rules (17 through 21) that govern how the Board is constituted, staffed, and run.

On paper, the Board now exists as a statutory body corporate. In practice, staffing has moved slowly. MeitY wrote to every Union Ministry, state government, and union territory in May 2026 inviting nominations for the Chairperson and Member posts, and followed up with another notification in June. Based on the most recent public reporting available, the Search-cum-Selection Committees, one headed by the Cabinet Secretary for the Chairperson role, another headed by the MeitY Secretary for other Members, were still working through nominations rather than finalising appointments.

What the Board Is Actually For

Strip away the procedural detail and the Board's job is narrow: decide whether a company mishandled someone's personal data, and if so, what to do about it. It sits above roughly 44 sections of the DPDP Act as the body responsible for turning statutory rights into enforceable outcomes.

Under Section 27, the Board can act in several triggering situations. A company reports a data breach, and the Board can order immediate remedial steps and then investigate. A consumer's complaint about a company's handling of their data goes unresolved internally, and it escalates to the Board. A state government, the central government, or even a court can refer a matter directly. Registered Consent Managers, the intermediaries the Act created to manage user consent on a company's behalf, can also land in front of the Board if they breach their own obligations or registration conditions.

Once a matter is in front of it, the Board's powers look a lot like a civil court's. It can summon people and examine them under oath. It can demand documents, registers, and data. It can inspect a company's processing facilities, with safeguards meant to avoid disrupting business operations unnecessarily. It can issue interim orders mid-inquiry. And at the end of the process, it can impose financial penalties, with the Schedule to the Act capping the most serious violations at ₹250 crore.

None of that happens without process, though. Section 28 requires the Board to follow natural justice at every stage: notice of the allegations, a genuine opportunity to respond, and a written, reasoned order. A poorly justified Board decision is a decision that's vulnerable the moment it's appealed.

How a Complaint Actually Moves

Most matters start well before they ever reach the Board. The Act requires companies (Data Fiduciaries, in the statute's language) to maintain a grievance redressal channel, and a data principal generally has to exhaust that internal route first. Only once that fails, or the company ignores it, does the door to the Board open.

From there, the sequence is fairly linear. The Board first checks whether there's a prima facie case worth pursuing; if not, it closes the file, but has to explain why in writing. If there is a case, a formal inquiry follows: documents get summoned, evidence gets recorded, and the company being investigated gets a real chance to respond, including the option to offer a voluntary undertaking under Section 32 rather than contest the matter outright. The process ends with a written order, a penalty, a remedial direction, acceptance of the undertaking, or dismissal.

None of this is designed to happen in a physical courtroom. Section 18(3) requires the Board to operate "as far as practicable" as a digital office, with complaints, hearings, and decisions handled online. That's a meaningful design choice for a country where a complainant in a small town and a company headquartered in Mumbai shouldn't need to be in the same city to have a matter heard.

If You Disagree, There's an Appeal Route, With a Clock Attached

A Board order isn't the end of the line. Section 29 lets an aggrieved party appeal to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT), the existing tribunal Parliament chose rather than building a brand-new one. The appeal has to be filed within 60 days, and appealing a financial penalty typically requires putting up 50% of it as a deposit. TDSAT is expected to dispose of appeals within about six months, and its orders can be challenged further, but only at the High Court or Supreme Court, and only on substantial questions of law. Ordinary civil courts are barred from touching matters that fall within the Board's jurisdiction at all.

That structure has attracted some criticism from legal commentators, who point out that TDSAT was built to handle telecom and broadcasting disputes, not data protection questions, and that routing all DPDP appeals through it may not be the ideal long-term fit. Whether that changes down the line is an open question. For now, it's the only appellate path available.

What the Staffing Delay Actually Means for Businesses

It's tempting to read "the Board isn't fully staffed" as "nothing to worry about yet." That reading doesn't hold up. Breach notification duties, consent obligations, and grievance redressal timelines under the Act and the 2025 Rules are already in force regardless of who's sitting on the Board bench on a given day. When the Board is fully staffed, and enforcement activity begins in earnest, the businesses caught flat-footed will be the ones that treated the staffing gap as a grace period rather than a preparation window.

The practical checklist is the same either way: know what personal data you hold and where, keep consent and grievance records that can actually be produced on demand, have a tested breach response process, and hold your processors and vendors to the same standard you're held to. None of that depends on whether the Board has a Chairperson this quarter.

Comments

Popular posts from this blog

Data Deletion in 2026: Why Your Business Needs a Compliance Workflow Now

The Future of Data Protection in India

Empowering the Indian Consumer: Navigating Your Rights as a Data Principal