5 minutes
Data Protection Board of India Powers Under the DPDP Act 2023
A detailed legal breakdown of the Data Protection Board of India, covering its authority to investigate breaches, impose monetary penalties, and evaluate corporate compliance under the DPDP Act 2023 and Rules 2025.
Last updated:
Section 27 of the Digital Personal Data Protection Act, 2023 defines the powers and functions of the Data Protection Board of India. The Board holds the statutory authority to enforce compliance across enterprises processing personal data. On receipt of a personal data breach intimation, it directs urgent remedial measures. It inquires into corporate compliance failures and acts directly on complaints filed by Data Principals. State or Central Governments can also refer cases to the Board for investigation. Section 33 outlines the penal authority of this body. Following a formal inquiry, the Board levies civil monetary penalties that reach up to 250 crore rupees per breach.
Section 18 establishes the Data Protection Board of India as a body corporate with perpetual succession and a common seal. The Central Government appoints the effective date of its establishment by notification. The Board operates as an independent legal entity. It holds the power to acquire, hold, and dispose of both movable and immovable property. The Board enters into contracts and sues or is sued in its own name. Enterprise legal teams face a distinct regulatory body equipped to initiate direct enforcement actions. Investigations begin the moment a compliance failure surfaces. The Central Government determines and notifies the location of the Board headquarters.
Section 27 limits and directs the functional scope of the Board. A Data Fiduciary submits a personal data breach intimation under Section 8. The Board reviews this notice and immediately mandates mitigation measures to contain the operational fallout. Formal inquiries start through multiple channels. A Data Principal files a complaint regarding unfulfilled rights. A court issues specific directions for investigation. The Board examines the internal records of the Data Fiduciary. Investigators determine if the company observed its statutory obligations regarding data processing. Fiduciaries face strict regulatory scrutiny over their consent logs and notice mechanisms.
The DPDP Rules, 2025 operationalise the exercise of these Section 27 powers. A Data Fiduciary submits a detailed breach report to the Board within 72 hours of discovery. This specific reporting window forces legal departments to map incident response protocols ahead of time. Automated systems track the exact minute a security team identifies an anomaly. Missing the 72-hour deadline immediately triggers a separate compliance violation. The Board penalises the delay independently of the underlying security failure. Corporate counsel relies on continuous monitoring tools to maintain readiness for rapid regulatory reporting.
Section 33 regulates the imposition of monetary penalties against non-compliant entities. The Board concludes an inquiry and determines if a significant breach of the Act or Rules occurred. The Act caps financial penalties at 250 crore rupees for failing to implement reasonable security safeguards. Fines reach up to 200 crore rupees for failing to notify the Board and affected Data Principals of a breach. The regulator provides the accused person an opportunity of being heard before finalising the penalty. This procedural step requires legal teams to present documented evidence of corporate compliance.
The Board calculates specific fine amounts based on statutory criteria. Section 33(2) mandates that investigators weigh exact factors before issuing a penalty order. Evaluators assess the nature, gravity, and duration of the breach. They analyse the type and nature of the personal data affected by the incident. A long-standing vulnerability yields a higher fine than a contained single-day exploit. The Board examines the repetitive nature of the breach across the enterprise. Financial impact assessments determine if the offending person realised a financial gain or avoided a loss due to the non-compliance.
Section 33(2)(e) focuses directly on corporate mitigation efforts. The Board considers whether the enterprise took timely and effective action to mitigate the effects and consequences of the breach. Verifiable audit trails limit corporate liability during an inquiry. Legal leaders rely on documented records that prove swift incident response and accurate notice issuance. The regulator evaluates the exact timeline of these internal actions. Companies presenting clean automated compliance logs face lower final penalty amounts. Fragmented manual records complicate the defense strategy and extend the duration of the Board inquiry.
The Data Fiduciary remains entirely accountable for the actions of its third-party vendors under the DPDP Act. The Data Protection Board of India penalises the Fiduciary, not the Data Processor, for downstream compliance failures. Legal departments execute rigorous audits on all active vendor contracts. They negotiate strict indemnity clauses and establish clear limitation of liability carve-outs. Poor downstream oversight results in direct Fiduciary exposure when the Board opens a Section 27 investigation. Enterprises track vendor data practices using automated compliance platforms to detect unauthorised processing.
Legal teams occasionally misinterpret the jurisdiction of the Board based on foreign regulatory frameworks. The Data Protection Board of India does not issue cross-border transfer approvals. It does not restrict specific countries on its own authority. Cross-border data flows are generally permitted unless the Central Government notifies a negative list restricting specific territories. The Board enforces lawful processing standards within India. Consent operates as the primary basis for processing, except where Section 7 legitimate uses apply. Enterprise systems log this consent to satisfy regulatory inquiries.
Another regulatory misconception involves data classification and criminal liability. The DPDP Act 2023 contains no separate category for highly confidential or restricted personal information. The Board applies the exact same processing rules to all personal data regardless of its intrinsic nature. The enforcement mechanism relies exclusively on civil monetary penalties. The Board possesses no statutory authority to order the criminal imprisonment of corporate directors or officers. Financial sanctions target the corporate entity directly.
Enterprises need to complete their internal compliance audits before the regulatory enforcement window opens. Exactly 252 days remain until the DPDP hard compliance deadline of 13 May 2027. Legal departments require distinct systems that generate pristine consent records. They deploy mechanisms to verify parental consent and log granular Data Principal requests. Relying on manual spreadsheets creates unmanaged risk when facing a targeted Section 27 inquiry. The Board requests immediate access to these logs upon receiving a valid Data Principal complaint.
Defending a regulatory inquiry demands instant retrieval of operational facts and system logs. Gaps in data mapping or delayed breach reporting weaken safe harbour arguments before the Board. Legal leaders use automated platforms to monitor continuous compliance and track vendor obligations. Clear visibility into corporate data flows facilitates rapid privileged review during an active investigation. Discover hidden vulnerabilities in your enterprise data workflows by running a targeted assessment at freescan.complydp.com.
Sources
Frequently asked questions
What is the maximum penalty the Data Protection Board of India can impose?
Section 33 of the DPDP Act 2023 caps financial penalties at 250 crore rupees per breach for failing to implement reasonable security safeguards. The Board calculates the exact fine based on statutory factors like the gravity of the incident and the mitigation efforts undertaken by the company.
How quickly must a company report a data breach to the Board?
Under the DPDP Rules, 2025, a Data Fiduciary must submit a detailed breach report to the Data Protection Board of India within 72 hours of discovering the incident. Affected Data Principals must also receive an intimation without delay.
Can the Data Protection Board of India send executives to prison?
No. The DPDP Act 2023 decriminalises data protection offenses in India. The Board possesses the authority to levy civil monetary penalties but cannot order criminal imprisonment for corporate officers or directors.
Does the Board manage cross-border data transfer restrictions?
No. The Data Protection Board of India does not restrict cross-border data flows. Data transfers are generally permitted unless the Central Government issues a negative list restricting transfers to notified countries or territories.
When does the Data Protection Board of India begin enforcing penalties?
Enforcement relies on the conclusion of the implementation period. Enterprises face a strict timeline, with exactly 252 days remaining until the DPDP hard compliance deadline of 13 May 2027, after which the Board exercises its full penal authority.
ComplyDP