Data privacy
Data Protection Board of India: Its Role Under the DPDP Act
The Data Protection Board of India (DPBI) is the independent regulator established under the Digital Personal Data Protection (DPDP) Act, 2023 to enforce India's data-protection law.
It investigates personal-data breaches, hears complaints from citizens, directs remedial action, and can impose penalties of up to ₹250 crore on organisations that fail to protect personal data. For years, India protected personal data with a patchwork of IT-Act rules. That era is ending. With the DPDP Act, 2023 and the DPDP Rules, 2025 now notified, India has a dedicated privacy regulator with real teeth: the Data Protection Board of India. If your organisation handles the personal data of Indian citizens - and almost every business does - understanding this Board is no longer optional. This article explains what it is, what powers it holds, and what you must do before it turns its attention to you.
What Is the Data Protection Board of India?
The Data Protection Board of India is a statutory, independent body created by the DPDP Act to oversee compliance with India's data-protection regime. Its job is to enforce the rights the Act grants to individuals (called Data Principals) and the obligations it places on organisations (called Data Fiduciaries). The Board functions as a largely digital-first authority - complaints, inquiries and proceedings are designed to be handled online.
When Was the Data Protection Board Established?
The DPDP Act received presidential assent in August 2023, but it needed subordinate rules to become operational. Those arrived when the government notified the DPDP Rules, 2025 in November 2025, alongside a phased enforcement plan. Provisions relating to the setup of the Data Protection Board of India were made effective first, so the Board itself is now a live institution while other obligations phase in over the following 12–18 months.
Key Functions and Powers of the Data Protection Board
Under the DPDP Act, the Data Protection Board of India holds significant enforcement powers:
- Investigate data breaches - inquire into personal-data breaches and non-compliance, on complaint or reference.
- Impose financial penalties - levy penalties up to the limits set out in the Act's schedule.
- Direct remedial measures - order urgent action to protect affected Data Principals.
- Regulate consent managers - register, and where necessary suspend or cancel, consent-manager registrations.
- Function digitally - conduct proceedings as a digital office, with inquiries generally concluded within defined timelines.
What Penalties Can the Data Protection Board Impose?
These figures are per the Act's penalty schedule and are assessed by the Board based on the nature and gravity of the failure. For most organisations, the headline number to remember is the ₹250 crore exposure for inadequate security safeguards.
| Type of failure | Maximum penalty |
|---|---|
| Failure to take reasonable security safeguards to prevent a breach | Up to ₹250 crore |
| Failure to notify a personal-data breach | Up to ₹200 crore |
| Breach of obligations relating to children's data | Up to ₹200 crore |
| Breach of additional obligations for Significant Data Fiduciaries | Up to ₹150 crore |
| Breach of general duties by a Data Principal | Up to ₹10,000 |
How the Data Protection Board Affects Your Business
If you are a Data Fiduciary, the Board's existence changes your day-to-day obligations under the DPDP Act:
- Breach notification - you must inform the Board and affected individuals, with the Rules prescribing prompt notification of Data Principals.
- Consent and notice - personal data must be collected against clear, plain-language notice and valid consent.
- Data erasure - personal data must be deleted once its purpose is served or consent is withdrawn.
- Significant Data Fiduciaries - large-scale processors face extra duties, including annual Data Protection Impact Assessments and independent audits reported to the Board.
DPDP Act Compliance Timeline
This staggered timeline is a gift: it gives organisations a genuine window to get compliant before the heaviest obligations bite. The businesses that use that window - rather than waiting - will avoid the last-minute scramble.
The fastest way to know where you stand is a structured review. DataOps runs DPDP compliance gap analysis that maps your current data practices against the DPDP Act and Rules, then hands you a prioritised roadmap to close the gaps.
- Immediate - provisions setting up the Data Protection Board of India took effect on notification.
- ~12 months - consent-manager provisions commence.
- ~18 months - the core operational duties (notice, security safeguards, breach notification, retention and SDF obligations) come into force.
Frequently Asked Questions
- What is the Data Protection Board of India?
- It is the independent regulator established under the DPDP Act, 2023 to enforce India's data-protection law - investigating breaches, hearing complaints and imposing penalties of up to ₹250 crore.
- What is the maximum penalty under the DPDP Act?
- The maximum penalty is ₹250 crore, applied for failure to take reasonable security safeguards to prevent a personal-data breach.
- When did the DPDP Rules come into effect?
- The DPDP Rules, 2025 were notified in November 2025, with obligations phased in over roughly 12–18 months and the Data Protection Board established immediately.
- Who does the DPDP Act apply to?
- It applies to any organisation (a Data Fiduciary) that processes the digital personal data of individuals in India, regardless of size - from start-ups to large enterprises and multinationals.