Sections 18–26 · G.S.R. 844(E) · Rules 17–21

Data Protection Board of India

The Data Protection Board of India is the institutional body established under Chapter V of the DPDP Act to inquire into matters such as personal data breaches and to perform other functions provided in the Act, including aspects of Consent Manager oversight and monetary penalties.

What the Act and Rules say about the Board

Sections 18–26 of the Digital Personal Data Protection Act, 2023 establish the Data Protection Board of India and address composition, appointment, terms, removal, proceedings, officers and related institutional matters. The Central Government notified establishment of the Board by G.S.R. 844(E). Provisions establishing the Board formed part of the early commencement set under the November 2025 notifications; always verify dates against the Gazette text for your planning.

Rules 17–21 of the Digital Personal Data Protection Rules, 2025 elaborate Board-related machinery: appointment of the Chairperson and other Members through Search-cum-Selection Committees (Rule 17); salary, allowances and service conditions (Rule 18 and Fifth Schedule); procedure for meetings and authentication of orders (Rule 19); functioning of the Board as a digital office that may adopt techno-legal measures without requiring physical presence (Rule 20); and appointment and service conditions of officers and employees (Rule 21 and Sixth Schedule). Rule 19 also addresses inquiry timelines (completion within six months from receipt under Section 27, extendable for recorded reasons by further periods not exceeding three months at a time).

The Board’s functions under the Act include inquiring into personal data breaches and imposing penalties as provided (see DPDP penalties), among other powers such as those relating to Consent Manager registration conditions. Appeals from Board orders or directions lie to the Appellate Tribunal under the Act and Rule 22. This page does not invent complaint portals or step-by-step filing workflows beyond what the statute and Rules state.

What it means in practice

For organisations, the Board is the enforcement and inquiry institution to plan for — especially for breach intimations under Rule 7, responses to inquiries, and awareness of penalty exposure under Section 33. Governance programmes should name owners for Board correspondence, evidence preservation and escalation to counsel.

Watch official Board and MeitY publications for procedural detail as the digital office model matures. Do not assume GDPR-style supervisory authority practices apply unchanged. Track commencement so that institutional readiness is not confused with full operational enforceability of every Fiduciary obligation.

Individuals and organisations should use channels the Board publishes when seeking to make complaints or respond to proceedings. ConsentifyAI provides educational context only and does not intermediate Board filings.

Common mistakes

  • Assuming the Board’s establishment means every operational DPDP Rule has already commenced.
  • Inventing complaint workflows or forms that the Board has not published.
  • Equating the Board with a European data protection authority and importing foreign procedure by analogy.

Official source

ConsentifyAI’s explanation is educational. Authoritative text is published by the Government of India / MeitY.

Information on this page is provided for general educational and implementation-planning purposes. It is not legal advice. Organizations should assess their specific obligations with qualified legal or privacy professionals.