DPDP Sections6 mins

Sections 18 & 19 Explained: Navigating the Data Protection Board of India

A definitive guide for enterprise General Counsel on Sections 18 and 19 of the DPDP Act, 2023, read alongside the DPDP Rules, 2025. Learn how the Data Protection Board is established, its digital-first mandate, and how to build regulatory defensibility.

Written byVipul Abhishek· Former Advocate, Supreme Court of India · ComplyDP Co-Founder

Last updated:

The Digital Personal Data Protection Act, 2023 establishes the Data Protection Board of India under Sections 18 and 19. As outlined in Section 1, the Central Government holds the power to appoint different dates for the enforcement of different provisions through notifications in the Official Gazette. Crucially, the functional and procedural mechanics of the Board are governed by the DPDP Rules, 2025. For a General Counsel managing enterprise risk, the operationalization of the Board represents a fundamental shift in regulatory engagement and liability management. The Board is legislatively designed to function as a digital office, requiring enterprises to maintain systematic digital evidence rather than relying on manual paper trails when responding to regulatory inquiries or consumer complaints.

Statutory Anchors For The Regulatory Body

Under Section 18 of the Act, the Data Protection Board of India is formally established as a body corporate by the Central Government. It holds perpetual succession and a common seal. Importantly, Section 18(2) grants the Board the explicit power to contract, as well as to acquire, hold, and dispose of property, both movable and immovable. The Board is empowered to sue or be sued in its own name, giving it autonomous legal standing. Furthermore, Section 18(3) states that the Central Government is responsible for designating the headquarters of the Board through official notification, establishing its physical base even as the DPDP Rules, 2025 guide its operation primarily as a digital entity.

Board Composition And Technical Expertise

Section 19 dictates the composition, appointments, and expected expertise of this regulatory body. Under Sections 19(1) and 19(2), the Act specifies that the Central Government will appoint a Chairperson and such number of other Members as it may notify. The specific manner of these appointments, as well as their terms, is prescribed by the DPDP Rules, 2025. Crucially, Section 19(3) mandates that these individuals must be persons of ability, integrity, and standing who possess special knowledge or practical experience in highly specific fields. These statutory domains include data governance, administration or implementation of laws related to social or consumer protection, dispute resolution, information and communication technology, digital economy, law, regulation, or techno-regulation. This signals the creation of a highly technical, multidisciplinary regulator capable of deeply interrogating complex enterprise data architectures, algorithms, and privacy engineering standards.

Navigating The Digital Office Mandate

The legislative intent, operationalized through the procedural frameworks in the DPDP Rules, 2025, positions the Data Protection Board to operate primarily as a digital office, functioning through a techno-regulatory approach. Routine hearings, evidentiary submissions, and judgments are expected to be handled electronically rather than through physical tribunals. This dramatically alters the traditional regulatory engagement model for Indian corporate law. Enterprise legal teams cannot rely on manual, reactive evidence gathering when a complaint is filed or an inquiry is launched. Defensibility now requires instant, streamlined access to privileged review materials, automated consent logs, and immutable audit trails configured specifically for digital submission.

Preparing For Regulatory Interaction

1. Architect the breach reporting workflow. The DPDP Act mandates reporting personal data breaches to the Data Protection Board alongside intimation to affected Data Principals without delay. The General Counsel must ensure that internal incident response playbooks align with this prompt reporting obligation. The necessary evidence artifact for the Board is a robust, time-stamped digital incident log generated directly by your enterprise compliance platform, proving swift detection and reporting.

2. Audit and secure consent architectures. Consent remains a primary legal basis for processing personal data, except where Section 7 legitimate uses apply. To satisfy the Board's evidentiary standards, enterprises must maintain verifiable, tamper-proof records of the itemised notices presented and the precise consent obtained. The expected evidence artifact for the Board is a version-controlled digital consent ledger that clearly demonstrates the exact linguistic terms agreed to by the Data Principal at a specific, verifiable timestamp.

3. Fortify processor oversight and renegotiate indemnities. The Board holds the principal Data Fiduciary legally accountable for any downstream processor failures or unauthorized disclosures. Legal teams must rigorously review limitation of liability clauses and enforce strict, comprehensive data processing agreements. The key evidence artifact here is a fully executed, digitally signed contract demonstrating clear vendor audit rights, backed by regular security compliance reports submitted to the General Counsel for ongoing oversight.

Penalties For Regulatory Non-Compliance

Engaging poorly with the Data Protection Board carries severe financial consequences that directly impact the corporate bottom line and brand reputation. Under the Schedule of the Act, failing to observe personal data breach reporting obligations to the Board can result in penalties reaching up to 250 crore rupees. Separately, the failure to fulfill general obligations owed to Data Principals can attract regulatory fines up to 50 crore rupees.

When determining the exact penalty amount, the Board weighs specific statutory aggravating and mitigating factors. These include the nature, gravity, and duration of the default, the type of personal data impacted, as well as any immediate actions taken by the enterprise to mitigate harm. A lack of structured digital evidence severely limits your safe harbour arguments and exposes the enterprise to maximum regulatory fines, as you will be unable to prove your proactive compliance measures to the Board.

Deadline Pressure And Next Steps

As the Central Government prepares to notify enforcement dates under Section 1(2) and rolls out the procedural mechanisms of the DPDP Rules, 2025, time is running out to establish your regulatory engagement strategy and upgrade legacy vendor contracts. Enterprise legal functions must digitize their privacy compliance architectures immediately. Building true, sustainable defensibility against Board inquiries requires months of systems integration, vendor renegotiation, and comprehensive policy overhauls across the organization.

Check whether your current enterprise data setup satisfies the precise, digital-first documentation standards expected by the Data Protection Board. Evaluate your overall regulatory defensibility, map out your breach response readiness, and identify critical legal risks with a definitive section-level assessment at freescan.complydp.com.

Sources

Frequently asked questions

How is the Data Protection Board of India structured under the DPDP Act?

Under Sections 18 and 19, the Board is established as a body corporate capable of suing and being sued. The Central Government appoints its Chairperson and Members, with the specific manner of appointment prescribed by the DPDP Rules, 2025. Members must possess specialized knowledge in fields like data governance, law, consumer protection, dispute resolution, and information technology.

What happens if an enterprise fails to report a data breach to the Board?

Under the Schedule of the DPDP Act, failing to observe breach reporting obligations to the Data Protection Board can result in financial penalties of up to 250 crore rupees. The Board will require digital, timestamped evidence of swift reporting.

Where is the headquarters of the Data Protection Board located?

Section 18(3) states that the Central Government will notify the location of the Board's headquarters. Despite having a physical headquarters, the Board is statutorily designed, and guided by the DPDP Rules, 2025, to function primarily as a digital office, handling submissions and inquiries electronically.