5 mins

DPDP Act Section 18: The Data Protection Board as a Digital Regulator

A guide for General Counsels on Section 18 of the DPDP Act and the DPDP Rules 2025, explaining the establishment of the Data Protection Board of India and the operational shift to digital evidence filing.

Written byVipul Abhishek· Former Advocate, Supreme Court of India

Last updated:

Under Section 18 of the Digital Personal Data Protection Act, 2023, the Central Government establishes the Data Protection Board of India. The DPDP Rules 2025 structure this regulatory body to operate primarily through electronic platforms. Routine compliance filings and evidentiary submissions occur entirely online. Legal departments face a compressed timeline for responses during an inquiry. Verifiable digital records dictate the outcome of regulatory scrutiny. A digital regulator processes data breaches and consent disputes rapidly through designated web portals. The speed of inquiry changes the baseline for enterprise readiness.

Section 18(1) authorizes the Central Government to notify the establishment of the Board. Section 18(2) defines it as a body corporate with perpetual succession and a common seal. This statute grants the Board the specific power to acquire, hold, and dispose of property. It can contract, sue, or be sued in its own name. Section 18(3) states the Central Government will notify the physical location of the headquarters. The DPDP Rules 2025 confirm that despite this physical footprint, enterprise legal teams interface with the regulator through digital platforms. This electronic architecture replaces traditional physical hearings with virtual dispute resolution. Counsel prepares digital dockets instead of printed briefs.

The jurisdiction of the Board derives from Section 3 of the Act. Section 3(a) applies the law to the processing of digital personal data within the territory of India. This covers data collected in digital form or digitized subsequently. Section 3(b) extends this reach to processing outside India if the activity relates to offering goods or services to Data Principals within the territory. Section 3(c) provides specific exemptions. It exempts personal data processed by an individual for personal or domestic purposes. It also exempts personal data made publicly available by the Data Principal or by a person under a legal obligation to do so. Legal teams map cross-border data flows against these parameters. This mapping verifies exactly when the Board holds authority over foreign processing operations.

When an incident triggers an inquiry, the Data Fiduciary faces a strict evidentiary burden. The legal department produces evidence digitally. The Board examines the metadata of consent logs, access controls, and breach notification timelines to verify compliance. This digital nature of hearings forces a transition to automated logging systems. Generating defensible records requires precise coordination across IT, security, and legal departments. If a Data Principal files a grievance regarding withdrawn consent, the enterprise uploads a digital timestamp. This specific electronic record proves the deletion of the data. General Counsels configure systems with technical teams to lock these logs against tampering. The metadata itself becomes the primary evidence of compliance.

1. Centralize the evidence architecture. The legal team and the Data Protection Officer require a unified digital repository. This system collects consent logs, data breach response records, and vendor contracts in real time. Disparate regional systems create delays during a rapid inquiry. A centralized data room operates as the primary review environment before the enterprise submits any response to the Board portal. Legal personnel verify the timestamp accuracy of every digital file. This oversight prevents accusations of evidence tampering. An unverified database export carries little weight during a virtual hearing. The organization builds an internal standard for extracting verifiable files.

2. Revisit vendor indemnity clauses. Data Processors handle high volumes of personal data on behalf of the fiduciary. Contracts require strict service level agreements regarding breach notifications and data retrieval. The General Counsel writes specific indemnities covering financial exposure if a vendor fails to supply required digital evidence. If the Board requests server logs during a virtual hearing, the processor delivers them immediately. Contractual penalties apply if vendor delays lead to adverse inferences by the regulator. The fiduciary remains legally responsible to the Board, and it cannot shift regulatory liability to the processor. Indemnities provide financial recovery after the fiduciary pays the penalty.

3. Establish a digital filing workflow. Enterprises designate specific personnel authorized to upload official responses to the Board. Access to the regulatory portal requires strict internal controls. The General Counsel mandates formal legal review before any outgoing submission. Submitting incorrect digital evidence creates permanent compliance liabilities. A documented upload protocol prevents unauthorized employees from sharing privileged technical data with the regulator. It ensures the legal team curates exactly what the Board reviews. Technical personnel often lack the specific legal context required to filter extraneous database logs. The established workflow inserts a lawyer between the raw data extraction and the final regulatory upload.

The Board adjudicates compliance failures and investigates data breaches. It has the power to levy financial penalties based on the Schedule of the Act. A failure to take reasonable security safeguards to prevent a personal data breach exposes the entity to penalties up to INR 250 crore. During a virtual hearing, the quality of a digital audit trail directly influences the outcome. The Board weighs the completeness of records when determining aggravating or mitigating factors. Incomplete electronic logs increase the risk of maximum penalty exposure. The digital interface leaves no room to delay proceedings by claiming physical documents are lost in transit. The regulator expects immediate availability of structured compliance evidence. Fiduciaries prepare these files long before a formal notice arrives.

Section 1 of the Act covers its title and commencement. Section 1(2) allows the Central Government to appoint different dates for different provisions. This phased rollout means the activation of the Board and the enforcement of specific fiduciary duties happen on distinct timelines. General Counsels track these staggered notifications in the Official Gazette. The DPDP Rules 2025 structure the procedural requirements for engaging with this electronic body. Securing a legal defense against the regulator requires verifiable evidence trails. Data Fiduciaries that automate their compliance logging reduce their financial exposure during an inquiry. Legal teams check whether current consent and breach workflows meet the exact digital evidence standards of the Board by running a gap assessment at freescan.complydp.com.

Sources

Frequently asked questions

Does the Data Protection Board of India operate physically or digitally?

Under Section 18 of the Digital Personal Data Protection Act, 2023, the government establishes the Board. While it will have a notified physical headquarters, the DPDP Rules 2025 operationalize filings and hearings primarily through electronic platforms.

How does a digital regulator impact outside counsel spend?

A digital-first regulator requires rapid, structured electronic evidence during inquiries. Legal teams relying on outside counsel to manually gather compliance logs face higher costs and slower response times.

What penalty exposure does the Data Protection Board manage?

The Board adjudicates compliance failures and data breaches. Based on the Schedule of the Act, it can impose financial penalties up to INR 250 crore for failing to implement reasonable security safeguards to prevent a breach.

How should General Counsels adjust vendor contracts for Board readiness?

Contracts require strict service level agreements for breach reporting and digital evidence retrieval. The General Counsel confirms indemnities cover situations where a Data Processor causes a delay in a mandatory Board submission.

When do we need to finalize our digital evidence workflows?

Section 1(2) of the Act allows the government to enforce provisions on different dates. Legal teams implement defensible digital compliance architectures immediately to handle potential inquiries as the Board operationalizes.