6 mins
What happens if the Data Protection Board sends a notice?
A detailed guide for General Counsel on responding to a Data Protection Board of India inquiry. Covers timelines, evidence requirements under Section 33, and how to manage regulatory defensibility.
Last updated:
What happens if the Data Protection Board sends a notice?
A notice from the Data Protection Board of India initiates a formal regulatory inquiry under the Digital Personal Data Protection Act, 2023. The Board issues these notices when it receives an escalated complaint or a mandatory breach report. General Counsel receive demands for compliance records, consent logs, and breach mitigation details. Legal departments face immediate deadlines to organize evidence. They have to demonstrate lawful processing and prepare for a hearing under Section 33 of the Act.
Section 13 sets the prerequisite for individual complaints. A Data Principal has a statutory obligation to exhaust the company grievance mechanism before approaching the Board. Under Section 13(1), a Data Fiduciary or Consent Manager provides readily available means of grievance redressal. This covers acts or omissions regarding obligations under the Act or the exercise of Data Principal rights. The Board checks this exhaustion requirement before issuing a formal notice to the company.
The prescribed response period acts as a strict trigger. Under Section 13(2), the Data Fiduciary or Consent Manager shall respond to grievances within the timeline prescribed by the DPDP Rules, 2025. Missing a deadline by a single day gives the individual the legal right to escalate the matter. General Counsel track these response deadlines closely. If the Data Protection Officer ignores a request, the individual petitions the regulator directly.
The Board is not the only entity with investigative reach. Section 36 gives the Central Government the authority to require information from any Data Fiduciary or intermediary. The government calls for this data for the purposes of the Act. This creates a dual-track risk environment. Legal teams field inquiries from the Board regarding specific complaints while managing broad information requests from the Central Government. With 252 days remaining until the DPDP compliance deadline of 13 May 2027, legal leaders build data retrieval systems to handle both channels.
Failing to answer a Section 36 directive carries specific legal consequences. The Central Government has broad authority to require information. General Counsel treat these demands with the same urgency as a formal Board notice. A Data Fiduciary furnishes the exact information the government calls for. Evasive answers or incomplete data sets trigger escalated regulatory scrutiny. Legal leaders build dedicated communication channels to manage these high-stakes government interactions.
The inquiry process follows a specific statutory sequence. The Board outlines the alleged violation and requests factual documentation. Legal teams produce historical data handling records to answer the notice. Section 33(1) guarantees the company an opportunity of being heard before the Board imposes any monetary penalty. The company uses this hearing to present its defense and mitigation evidence. A failure to furnish the requested information promptly limits the ability of the company to present a strong case during the hearing.
The opportunity of being heard under Section 33(1) operates as a formal administrative procedure. The company presents its defense through legal counsel or authorized representatives. The Board reviews the submitted evidence and questions the Data Fiduciary on its data protection practices. Legal teams prepare comprehensive briefs detailing the technical safeguards in place at the time of the alleged violation. The outcome of this hearing dictates whether a monetary penalty applies.
If the Board determines a significant breach occurred, it assesses specific factors under Section 33(2) to calculate the monetary penalty. Regulators evaluate the nature, gravity, and duration of the breach. They examine the type and nature of the personal data affected. The Board looks at the repetitive nature of the breach. A history of similar violations severely weakens the company position during a hearing. Regulators determine whether the person realized a gain or avoided a loss as a result of the violation. They review whether the company took action to mitigate the effects and consequences of the breach. The Board assesses the timeliness and effectiveness of that specific response.
Defensibility depends on a verifiable evidence trail. When the Board investigates a complaint, oral arguments hold less weight than time-stamped records. Outside counsel spend increases when companies scramble to locate fragmented compliance data across different business units. The Data Protection Officer leads the factual compilation. General Counsel directs the overall legal strategy. Regulatory interactions require privileged review of internal breach reports and security assessments. Legal teams coordinate with IT so the evidence provided matches the regulator request exactly. Document retention policies dictate how far back the Board requests historical processing logs. Companies retain sufficient records to defend against delayed complaints without violating the data minimization principles in the Act.
General Counsel prepare three primary categories of evidence to satisfy Board inquiries.
1. Lawful processing records. This includes itemised notice logs, verifiable parental consent mechanics required under the Rules, 2025, or documentation proving a Section 7 legitimate use applies. Consent is the primary basis for processing, except where Section 7 legitimate uses apply. These logs form the foundation of any regulatory defense against an unlawful processing charge.
2. Grievance redressal logs. The company proves it provided readily available means of grievance redressal under Section 13(1). The records show the exact date the complaint arrived. They document the date the Data Fiduciary responded. This evidence proves the individual failed to exhaust their internal remedies under Section 13(3) or confirms the company met its statutory response deadline.
3. Mitigation actions and vendor compliance records. Legal teams submit logs showing the immediate steps taken to contain the breach to satisfy the mitigation factor in Section 33(2)(e). The Board reviews data processor agreements for clear liability allocation.
Data Fiduciaries cannot deflect regulatory responsibility by blaming their vendors. The Act holds the Data Fiduciary accountable for the actions of its data processors. If a third-party processor causes the data breach, the Data Fiduciary remains entirely liable to the Board. General Counsel enforce limitation of liability terms in the processor contract. They negotiate strong indemnification provisions to recover the cost of Board inquiries and subsequent penalties.
Surviving a Board inquiry without severe penalties requires strict operational readiness. Manual spreadsheets fail when the regulator demands the exact consent status of specific Data Principals in India during a 72-hour breach reporting window. Automated compliance systems provide the structured, unalterable records necessary to defend the company position. The Board demands precise answers, and companies need immediate access to their compliance archives to provide them.
What to do next
Legal departments should build their inquiry response framework now.
1. Audit your internal grievance redressal mechanism so it resolves complaints quickly, keeping disputes away from the Board.
2. Review all data processor contracts to clarify liability allocation for data breaches and establish rapid information-sharing protocols.
3. Centralize consent records and data handling logs into a single repository for rapid retrieval during a regulatory inquiry.
ComplyDP maps your digital workflows against DPDP obligations, creating the automated evidence trails regulators demand. Run a self-check at freescan.complydp.com to evaluate your inquiry readiness before the 2027 enforcement deadline.
Sources
Frequently asked questions
Can a Data Principal complain directly to the Data Protection Board?
Section 13 of the Digital Personal Data Protection Act, 2023 requires individuals to exhaust the company grievance mechanism first. They approach the Board only if the Data Fiduciary fails to resolve the issue within the timeline prescribed by the DPDP Rules, 2025.
What factors does the Board consider before imposing a penalty?
Section 33(2) outlines specific mitigation factors the Board evaluates. Regulators look at the nature and duration of the breach, the type of personal data affected, and repetitive violations. The Board also assesses whether the company took timely action to mitigate the consequences.
Are we liable if our vendor causes the data breach that triggers a notice?
Yes. The Data Fiduciary holds sole regulatory liability for protecting the personal data of Data Principals in India, even when using a processor. General Counsel rely on strong contract indemnities to recover costs from the vendor after facing the Board.
How much time do we have to respond to a regulatory inquiry?
The exact response window depends on the specific notice issued by the Board or Central Government under Section 36. In the event of a breach, the DPDP Rules, 2025 require an initial report to the Board within 72 hours. This demands immediate data retrieval capabilities.
What is the primary defense against an unlawful processing complaint?
General Counsel produce verifiable consent logs or evidence proving a Section 7 legitimate use. Consent is the primary basis for processing, except where Section 7 applies. Automated, time-stamped records provide a strong legal defense against Board inquiries.
ComplyDP