DPDP Sections • 6 mins
Section 28 Explained: DPBI Inquiry Powers and Evidence Demands
A definitive guide for compliance leaders on navigating Section 28 of the DPDP Act. Learn how the Data Protection Board of India conducts digital inquiries, what evidence it demands, and how to build regulator-ready audit trails.
Last updated:
Section 28 Explained The Data Protection Board Inquiry Powers
The Digital Personal Data Protection Act, 2023 establishes the Data Protection Board of India as the primary adjudicatory body for data disputes. Under Section 28, the Board exercises inquiry powers triggered by a breach intimation, a complaint from a Data Principal, or a reference from the government. Upon receiving a trigger, the Board assesses if sufficient grounds exist to proceed with a formal inquiry or closes the matter. For enterprise compliance teams, this section dictates exactly how you must interface with the regulator during an investigation and what evidence trails must be readily available.
Statutory Anchors In Section 28 And The Rules 2025
Section 28(1) explicitly states the Board shall function as an independent body and a digital office. The receipt of complaints, allocation of hearings, and pronouncements of decisions are digital by design. Section 28(2) empowers the Board to take action on intimations or complaints referenced in Section 27(1). Following the DPDP Rules, 2025 notified in November 2025, the Board requires highly structured digital evidence trails for any proceeding. When an enterprise files a breach report, Section 28(3) gives the Board authority to determine whether there are sufficient grounds to proceed with a full inquiry based on that initial filing. If grounds are lacking, Section 28(4) allows the Board to close the proceedings with reasons recorded in writing.
Who The Board Inquiry Powers Bind And When
The inquiry powers directly bind Data Fiduciaries and Significant Data Fiduciaries determining the purpose and means of processing personal data. As a Head of Compliance at a large enterprise, you are the primary control owner responsible for facing these inquiries and delivering the required evidence packs to the Board. The Board, established under Section 18, has the authority to summon attendance, examine individuals under oath, and inspect data repositories. If your enterprise processes digital personal data within India, or processes it outside India connected to offering goods or services to Data Principals in India, your operations fall under this jurisdiction and are subject to these inquiry powers.
Compliance Workflows And Evidence Expectations
Preparing for a Section 28 inquiry requires an audit-ready posture well before a complaint is filed. Relying on fragmented spreadsheets or disparate general governance tools will cause delays when the Board demands immediate digital evidence. Enterprise compliance teams must operationalise several specific capabilities.
1. Centralise your Record of Processing Activities. The compliance team must maintain an updated RoPA mapped to exact data flows. When the Board issues a summons, this artifact proves you understand your data inventory and have control over your data lifecycle.
2. Digitize consent artefacts. Consent is the primary basis for processing, except where Section 7 legitimate uses apply. Legal and IT teams must collaborate to produce verifiable digital timestamps of when consent was granted, withdrawn, or modified. A generic dashboard is insufficient. The Board expects granular evidence trails showing the exact itemised notice presented to the user as mandated by the Rules, 2025.
3. Institutionalise the breach response workflow. The Rules, 2025 mandate breach intimation to affected Data Principals without delay, alongside a detailed report to the Board within 72 hours. Managing this via email threads guarantees failure during a Board inquiry. The Chief Information Security Officer must have automated workflows to log incident detection, while the compliance team pre-drafts regulator intimations.
4. Maintain a Data Protection Impact Assessment repository. For Significant Data Fiduciaries, the Data Protection Officer must present documented DPIAs demonstrating how risks were mitigated. The Board will scrutinize this evidence pack during an inquiry to determine if reasonable safeguards were applied.
5. Map cross-border transfers accurately. Section 28 inquiries often demand evidence of where personal data travels. Under the DPDP framework, cross-border transfers are generally permitted unless the Central Government restricts transfer to notified countries or territories. Your RoPA must definitively prove no data is routed to jurisdictions on this negative list.
Penalty Exposure And Aggravating Factors
Failing to satisfy the Board during a Section 28 inquiry carries severe financial exposure. The Schedule to the DPDP Act outlines maximum penalties of 250 crore rupees for failing to take reasonable security safeguards leading to a personal data breach. Non-fulfillment of obligations concerning breach intimation to the Board carries penalties up to 200 crore rupees. During the inquiry, the Board assesses aggravating factors such as the duration of non-compliance, the nature of personal data affected, and whether the enterprise took corrective action promptly. Poor quality evidence trails or missing documentation directly contribute to negative findings and higher financial penalties.
Intersections With Other Legal Obligations
Section 28 inquiries often expose compliance gaps in overlapping obligations across the Act. A Board inquiry into a user complaint will test your Section 8 obligations regarding data accuracy, retention limits, and reasonable security safeguards. The inquiry process is directly linked to Section 27, which governs how the Board receives complaints from individuals who have already exhausted your internal grievance redressal mechanism. Finally, the Board's establishment, corporate identity, and overarching powers trace back to Section 18 of the Act.
Deadline Pressure And Next Steps
Building a regulator-ready compliance architecture is not a quick fix that can be handled at the last minute. Cross-team accountability between legal, IT, and security functions requires months of testing, vendor evaluation, and team adoption. Exactly 281 days remain until the DPDP hard compliance deadline of 13 May 2027. Decision makers must move past evaluating general tools and implement systems specifically designed to meet the DPBI digital-by-design evidence standards.
Ensure your current compliance setup can generate the exact digital evidence packs the Data Protection Board will demand during a Section 28 inquiry. Run a free gap check against the DPDP Act requirements at freescan.complydp.com today.
Sources
Frequently asked questions
How does the Data Protection Board conduct inquiries under the DPDP Act?
Under Section 28, the Board operates as a digital-by-design office. It receives complaints or breach intimations digitally and determines if sufficient grounds exist to proceed with a formal inquiry, requiring Data Fiduciaries to submit digital evidence packs.
What evidence must a Head of Compliance produce during a DPBI inquiry?
The Board will demand comprehensive audit trails, including a structured Record of Processing Activities and digital consent artefacts. Enterprises must also present records showing compliance with the Rules, 2025, such as proof of submitting 72-hour breach notification reports.
Does the Board penalise companies immediately upon receiving a complaint?
No. Section 28(3) requires the Board to first determine whether there are sufficient grounds for an inquiry. If grounds are insufficient, the Board will close the proceedings with written reasons, protecting enterprises from frivolous claims.
How long do we have to build our regulator-ready compliance architecture?
Exactly 281 days remain until the DPDP hard compliance deadline of 13 May 2027. Compliance teams must use this time to move away from fragmented spreadsheets and implement dedicated evidence-gathering systems to face potential inquiries.
Can we rely on our existing general GRC tools for DPDP Board inquiries?
General tools often lack the specific localized workflows required by the DPDP Rules, 2025. Facing a Section 28 inquiry requires dedicated capabilities like verifiable consent tracking, itemised notice generation, and DPBI-formatted breach reporting.
ComplyDP