DPDP Glossary

Data Protection Board

The Data Protection Board of India established under the Act to inquire into breaches and perform other functions as provided.

Sections 18–26

What it means

The Data Protection Board of India is established under the Act (Sections 18–26) to inquire into personal data breaches and perform other functions the statute assigns — including matters connected with Consent Manager registration conditions and penalties under Section 33. It is an institutional actor, not a private compliance vendor.

Worked example

After a significant personal data breach, a Fiduciary’s Rule 7 / Section 8(6) intimation path includes the Board (and affected Principals as provided). Separately, disputes about Consent Manager registration conditions are Board-facing issues — not customer-support tickets inside a SaaS tool.

In practice

Know when your playbooks escalate to the Board versus internal grievance channels. Read Board functions against the Act rather than importing foreign “DPA” assumptions wholesale. For organisational framing beyond this definition, see the Board topic page.

Data Protection Board of India →

Source

Sections 18–26 · Official text (PDF)

Educational summary based on the Digital Personal Data Protection Act, 2023 and Rules, 2025. Not legal advice.

Further reading

← Back to glossary