At a glanceThe Data Protection Board of India (DPB) is the independent regulator that enforces India’s DPDP Act. It inquires into personal data breaches, hears complaints from people whose data has been mishandled, and can impose penalties of up to ₹250 crore on the companies responsible. It runs as a “digital by design” office — complaints, hearings and decisions happen online — and it acts on complaints, breach reports, or government references, not on its own whim.
Educational resource only. This explains what the Data Protection Board is under India’s Digital Personal Data Protection Act, 2023 (DPDP Act); it is not formal legal advice.
What is the Data Protection Board of India?
The Board is the enforcement body the DPDP Act creates — the referee that decides whether a company broke the rules and what it should pay. The Act sets the rights and duties; the Board is who you turn to when a Data Fiduciary (the organisation that decides why and how your data is used) ignores them.
It is established as an independent body (Section 18), with a Chairperson and members appointed by the central government. Think of it less as a police force patrolling the internet and more as a specialist tribunal: it doesn’t go looking for wrongdoing everywhere, but when a breach is reported or a person complains, it has real teeth to inquire and penalise.
What does the Board actually do?
Its job is threefold — investigate, decide, and penalise — plus direct urgent fixes when data is actively at risk. In practice the Board’s powers (Section 27) cover:
- Responding to breaches. When a company reports a personal data breach, the Board can direct urgent remedial or mitigation measures — steps to contain the damage — and then inquire into how it happened.
- Hearing complaints. If you believe a business mishandled your personal data or ignored your rights, the Board can inquire into your complaint.
- Imposing penalties. Where it finds a breach of the Act’s obligations, it can levy financial penalties, tier by tier, up to ₹250 crore for the most serious failures.
- Issuing and revising directions. It can order a company to do (or stop doing) something, and modify those directions on review.
Crucially, the Board also has the powers of a civil court for parts of its inquiry — summoning people, requiring documents — so a company can’t simply refuse to engage.
Why is it “digital by design”?
The Board is built to run online, so you shouldn’t need to travel to a courtroom to be heard. The Act requires it to function, as far as practicable, as a digital office (Section 28): complaints are received digitally, and the allocation, hearing and pronouncement of cases are meant to happen through electronic means.
Hearings can be held over audio-visual link, with physical presence required only where the Board thinks it’s genuinely necessary for a fair inquiry. For an ordinary person filing a complaint about, say, a company that won’t delete their Aadhaar copy, this is the point that matters most — the process is designed to be reachable from a phone, not gatekept by legal machinery.
When can the Board step in?
The Board acts when something brings a matter to it — it doesn’t launch inquiries on a hunch. Under the Act it can begin on any of these triggers:
- a complaint from a Data Principal (the person the data is about);
- an intimation of a personal data breach from a company;
- a reference from the central or a state government; or
- a direction from a court.
There’s one practical gate for individuals: you’re expected to raise your grievance with the business first — through its grievance officer or Data Protection Officer (DPO) — and only approach the Board if that fails. (The step-by-step is in the filing guide.)
What the Board is not
It’s an enforcer of the law, not a small-claims court that pays you compensation. Two distinctions are worth holding onto, because they’re widely misunderstood:
- Penalties are not payouts. Money the Board collects as penalties goes to the Consolidated Fund of India — the government’s account — not to the individuals affected. The Board can order a company to fix its behaviour; it is not the route to personal damages.
- It’s the first rung, not the final word. The Board’s decisions can be appealed to a specialist tribunal, so its ruling isn’t necessarily the end of the road (see the enforcement piece).
FAQ
Is the Data Protection Board the same as a court?
No. It’s a specialist regulatory body that inquires into DPDP Act breaches and imposes penalties. It has some court-like powers for its inquiries, but appeals against its orders go to a separate Appellate Tribunal.
Can the Board start an investigation on its own?
Broadly, no — it acts on a complaint, a reported breach, a government reference, or a court direction, rather than initiating inquiries entirely on its own motion.
Will the Board get my money back or pay me compensation?
No. Penalties it imposes go to the government, not to affected individuals. Its role is to enforce the law and penalise breaches, not to award you damages.
Do I have to go to Delhi to be heard?
No. The Board is designed to work as a digital office, with complaints and hearings handled electronically wherever practicable.