KYCKART
KYCKART Guide · September 2026Regulatory Explainer

What Is the Data Protection Board of India? Powers, Penalties and How a Complaint Against a BFSI Institution Actually Proceeds

The Data Protection Board of India was established on 13 November 2025, but its complaint, inquiry and penalty powers commence in stages from the one-year mark. An operational look at what is live today, what commences later, and what it means for BFSI compliance teams.

calendar_monthSeptember 9, 2026
schedule16 min read
library_books20 Cited Sources
personBhanujeet Choudhary, Head of Compliance
What Is the Data Protection Board of India? Powers, Penalties and How a Complaint Against a BFSI Institution Actually Proceeds

The Data Protection Board of India is the adjudicating body established under Section 18 of the Digital Personal Data Protection Act, 2023 to inquire into personal data breaches and complaints and to impose monetary penalties. It was formally set up by MeitY notification G.S.R. 844(E) dated 13 November 2025, with its head office in the National Capital Region.

The sections that give the Board its complaint, inquiry, appeal and penalty machinery, Sections 27 to 34, commence eighteen months after that date, apart from Section 27(1)(d), which commences at the one-year mark. As of LiveLaw’s 1 August 2026 reporting no Chairperson and no Members had been appointed. The Board exists in law today and cannot yet receive a complaint, hold an inquiry, or fine anyone.

01KYCKART Regulatory Analysis

What the Board Is and Where It Sits

Statutory identity, executive parentage, and quasi-judicial composition

Section 18 of the DPDP Act provides that the Central Government establishes the Board by notification, and that it is a body corporate with perpetual succession and a common seal, able to acquire property, enter contracts, and sue or be sued, with its head office at a place the Central Government notifies. The establishing notification, G.S.R. 844(E), was issued in exercise of powers under sub-sections (1) and (3) of Section 18.

The Board sits under the Ministry of Electronics and Information Technology. MeitY issued both the establishment notification and the DPDP Rules, 2025, and MeitY’s Secretary sits on the Search-cum-Selection Committee for Members.

On composition, Section 19 provides that the Board consists of a Chairperson and such number of other Members as the Central Government notifies. Appointees must be persons of ability, integrity and standing with special knowledge or experience in fields including data governance, administration or implementation of laws relating to social or consumer protection, dispute resolution, information and communication technology, digital economy, law, regulation or techno-regulation, and at least one Member must be an expert in the field of law. PIB’s official backgrounder on the DPDP Rules describes a fully digital Data Protection Board of India “which will consist of four members”, and records that appeals against the Board’s decisions go to the Appellate Tribunal, TDSAT.

Under Section 20, the Chairperson and Members hold office for a term of two years and are eligible for re-appointment, and their salary and terms cannot be varied to their disadvantage after appointment.

The Board’s function is adjudicatory. Every power in Section 27(1) is triggered by an intimation, a complaint, a Central Government reference or a court direction reaching the Board, and Section 28(2) repeats that the Board acts on one of those four triggers. The comparison table further down sets that against how RBI penalises a bank.

For the Act’s own history, passage and rights catalogue, see our explainer on the DPDP Act. For who counts as a data fiduciary and what its obligation set covers, see data fiduciary under the DPDP Act, and for the processor side, data processor under the DPDP Act.

02KYCKART Regulatory Analysis

What Is in Force Today, and What Commences Later

The three-stage gazette timeline and the structural gap under Section 39

MeitY notification G.S.R. 843(E) dated 13 November 2025 brought the DPDP Act into force in three stages:

CommencesSections of the DPDP Act
On publication (13 November 2025)Section 1(2), Section 2, Sections 18 to 26, Sections 35, 38, 39, 40, 41, 42, 43, and Section 44(1) and (3)
One year from publicationSection 6(9) and Section 27(1)(d)
Eighteen months from publicationSections 3 to 17 (except 6(9)), Sections 27(1)(a)-(c) and (e)-(h), Sections 27(2)-(3), Sections 28 to 34, 36, 37, and Section 44(2)

Sections 18 to 26 are the Board’s establishment, composition, appointment, terms of service, officers and meetings provisions. Sections 27 to 34 are its powers, inquiry procedure, appeal route, mediation, voluntary undertakings and penalty provisions. Read the two buckets against each other and the effect of the notification is that the institution is live and the machinery is not.

The Rules follow the same shape. The Digital Personal Data Protection Rules, 2025 were notified as G.S.R. 846(E), New Delhi, dated the 13th November 2025 under sub-sections (1) and (2) of Section 40 of the Act, after a draft (G.S.R. 02(E), 3 January 2025) and public consultation. Rule 1 sets three stages: “Rules 1, 2 and 17 to 21 shall come into force on the date of their publication in the Official Gazette. Rule 4 shall come into force one year after the date of publication of this Gazette. Rules 3, 5 to 16, 22 and 23 shall come into force eighteen months after the date of publication of this Gazette.” PIB records that the Rules were finalised after nationwide consultations in Delhi, Mumbai, Guwahati, Kolkata, Hyderabad, Bengaluru and Chennai drawing 6,915 inputs, and describes an eighteen-month phased compliance period.

Two things to note about dates. Both instruments say “eighteen months after the date of publication” rather than naming a date, so 13 May 2027 is a computed date, not a stated one: the one-year stage computes to 13 November 2026 on the same basis. And the gazette instruments themselves are dated 13 November 2025, while the PIB backgrounder dates the Rules to 14 November 2025. This piece uses the date printed on the instrument.

The gap Section 39 creates

Section 39, which bars civil courts from entertaining any suit or proceeding in respect of any matter the Board is empowered over, and bars any court or authority from granting an injunction against action taken under the Act, is in the first bucket. It has been in force since 13 November 2025.

Two procedural rules are also already live. Rule 19(9) sets the inquiry clock: “The inquiry by the Board shall be completed within a period of six months from the date of receipt of the intimation, complaint, reference or direction under section 27 of the Act, unless such period is extended by it, for reasons to be recorded in writing, for a further period not exceeding three months at a time.” Rule 20provides that the Board shall function as a digital office and may adopt techno-legal measures to conduct proceedings without requiring anyone’s physical presence, without prejudice to its power to summon and examine a person on oath.

Meanwhile, Section 13(3), which requires a Data Principal to exhaust the Data Fiduciary’s or Consent Manager’s own grievance-redressal mechanism before approaching the Board, sits in the eighteen-month bucket along with the rest of Sections 11 to 17. So the gateway to the Board and the Board’s power to receive anything through it commence together.

03KYCKART Regulatory Analysis

What the Board Can Do Once Sections 27 to 34 Commence

The statutory penalty ceilings and inquiry factors under Section 33

Section 27(1) sets out the Board’s powers. On receiving intimation of a personal data breach, it can direct urgent remedial or mitigation measures, inquire into the breach and impose a penalty. It can inquire into a complaint by a Data Principal about a Data Fiduciary’s breach of its obligations, or act on a reference by the Central Government or a direction of a court. It can inquire into a complaint about a Consent Manager’s breach of its obligations, and on intimation of a Consent Manager’s breach of its registration conditions, inquire and impose a penalty. On a Central Government reference, it can inquire into an intermediary’s breach of Section 37(2) obligations. Of these, only the Consent Manager registration-condition limb, Section 27(1)(d), commences at the one-year mark rather than at eighteen months.

Under Section 27(2), after giving an opportunity of being heard and recording reasons in writing, the Board may issue such directions as it considers necessary. Section 27(3) lets it modify, suspend, withdraw or cancel a direction on a representation or a Central Government reference.

On penalties, Section 33(1) provides that if the Board determines on conclusion of an inquiry that a breach of the Act or Rules is significant, it may, after giving the person an opportunity of being heard, impose the monetary penalty specified in the Schedule. Section 33(2) lists the factors it must weigh in setting the amount: the nature, gravity and duration of the breach; the type and nature of the personal data affected; the repetitive nature of the breach; whether the person realised a gain or avoided a loss; whether the person acted to mitigate effects and consequences, and how timely and effective that action was; whether the penalty is proportionate and effective for securing observance and deterrence; and the likely impact of the penalty on the person.

Read the Schedule and Section 33(2) together and the structure is a ceiling per breach category, with repetition treated as a factor in fixing the amount inside that ceiling.

#BreachCeiling
1Failure to take reasonable security safeguards to prevent a personal data breach, s.8(5)₹250 crore
2Failure to give the Board or affected Data Principals notice of a personal data breach, s.8(6)₹200 crore
3Breach of additional obligations in relation to children, s.9₹200 crore
4Breach of additional obligations of a Significant Data Fiduciary, s.10₹150 crore
5Breach of the Data Principal’s duties, s.15₹10,000
6Breach of a term of a voluntary undertaking accepted by the Board, s.32Up to the extent applicable for the underlying breach
7Breach of any other provision of the Act or Rules₹50 crore
The highest penalty up to ₹250 crore applies to failure of a Data Fiduciary to maintain reasonable security safeguards.

: PIB backgrounder on the DPDP Rules, 2025

The same backgrounder confirms that failure to notify the Board or affected individuals of a breach, and violations of obligations relating to children, can each attract penalties of up to ₹200 crore, and that any other violation of the Act or Rules by a Data Fiduciary may attract penalties up to ₹50 crore.

No Indian institution has been penalised under the DPDP Act. Section 33 is not yet in force and the Board had no appointed members as of 1 August 2026.

04KYCKART Regulatory Analysis

How a Complaint Against a BFSI Institution Will Proceed

The screening stage, civil powers, timeline caps, and the TDSAT/Supreme Court ladder

This is the procedure that applies once Sections 27 to 34 commence:

  • The Data Principal goes to the institution before the Board. Section 13(3)requires a Data Principal to exhaust the institution’s own grievance-redressal mechanism before approaching the Board.
  • Once commenced, the Board will screen before it inquires. Under Section 28, the Board functions as an independent body and, as far as practicable, as a digital office, with receipt of complaints and the allocation, hearing and pronouncement of decisions digital by design (28(1)). It may act on an intimation, complaint, reference or direction under s.27(1) (28(2)). It first determines whether there are sufficient grounds to proceed with an inquiry (28(3)), and if not, may close proceedings for reasons recorded in writing (28(4)).
  • If it proceeds, it has civil-court powers with one operational limit. Where there are sufficient grounds, the Board may inquire into the affairs of any person (28(5)) following the principles of natural justice and recording reasons (28(6)). It holds civil-court powers of summoning, examining evidence and inspecting documents (28(7)). It may not prevent access to premises or take custody of equipment in a way that adversely affects day-to-day functioning (28(8)). It may issue interim orders after a hearing and for recorded reasons (28(10)).
  • There is a clock. Rule 19(9) requires the inquiry to be completed within six months of receipt of the intimation, complaint, reference or direction, extendable by the Board for recorded reasons for a further period not exceeding three months at a time.
  • The inquiry will end in one of two ways. On completion, after a hearing, the Board either closes the proceedings or proceeds under Section 33 (28(11)). Where it considers a complaint false or frivolous, Section 28(12) lets it issue a warning or impose costs on the complainant.
  • Two off-ramps exist. Section 31 lets the Board direct parties to mediation where it thinks a complaint can be resolved that way, and Section 32 provides for voluntary undertakings. Both are in the eighteen-month bucket.

Appeal runs to TDSAT, then the Supreme Court

Section 29 gives any person aggrieved by an order or direction of the Board an appeal to the Appellate Tribunal within sixty days of receiving the order, with condonation of delay for sufficient cause. The Tribunal may confirm, modify or set aside the order after hearing the parties, shall endeavour to dispose of the appeal within six months and record reasons in writing if it cannot, functions as far as practicable as a digital office, and applies procedures from Sections 14A, 16 and 18 of the TRAI Act, 1997.

The Appellate Tribunal for DPDP purposes is TDSAT, the Telecom Disputes Settlement and Appellate Tribunal. Rule 22governs the mechanics: the appeal is filed in digital form as the Tribunal may decide, accompanied by a fee of the same amount as applies to an appeal under the TRAI Act, 1997 (unless reduced or waived by the Tribunal’s Chairperson), payable digitally via UPI or another RBI-authorised payment system, and the Tribunal is not bound by the Code of Civil Procedure, 1908 but is guided by the principles of natural justice. Rule 22 is itself in the eighteen-month bucket.

From TDSAT, a further appeal lies to the Supreme Court under Section 18 of the TRAI Act, 1997 within ninety days of the order appealed against, extendable for sufficient cause, on one or more of the grounds specified in Section 100 of the Code of Civil Procedure, 1908. No appeal lies against an interlocutory order or an order made with the consent of the parties.

05KYCKART Regulatory Analysis

What the DPDP Rules Require a Data Fiduciary to Have in Place

The operational obligations taking effect at the eighteen-month mark

Each item below is a specific Rule obligation, and each sits in the eighteen-month bucket under Rule 1(4) rather than applying today:

  • 1. A notice that tells the customer how to complain to the Board

    Rule 3requires the notice to be independently understandable, to give in clear and plain language an itemised description of the personal data and the specified purpose plus a specific description of the goods, services or uses enabled, and to give the particular communication link for the fiduciary’s website or app along with a description of other means by which the Data Principal may withdraw consent with comparable ease, exercise her rights under the Act, and make a complaint to the Board.

  • 2. A published rights-request route

    Rule 14(1) requires the Data Fiduciary, and where applicable the Consent Manager, to prominently publish on its website or app the means by which a Data Principal may make a request to exercise her rights, and the particulars such as a username or other identifier required to identify her.

  • 3. A grievance system that answers within ninety days

    Rule 14(3)requires prominent publication of the grievance-redressal system “within a reasonable period not exceeding ninety days” and implementation of technical and organisational measures to ensure the system actually responds within that period.

  • 4. Access logs retained for a year

    Rule 6(1) sets minimum reasonable security safeguards: encryption, obfuscation, masking or virtual tokens; access controls on computer resources; visibility on access to personal data through appropriate logs, monitoring and review to enable detection, investigation and remediation of unauthorised access; backups for continued processing; retention of such logs and personal data for one year unless another law requires otherwise; contractual provision for security safeguards in the fiduciary-processor contract; and appropriate technical and organisational measures.

  • 5. A breach-notification runbook with a seventy-two-hour tail

    Rule 7requires the Data Fiduciary, on becoming aware of a personal data breach, to intimate each affected Data Principal without delay through her user account or registered channel with the breach’s nature, extent and timing, the consequences relevant to her, mitigation measures implemented, safety measures she may take, and business contact information for a person who can answer her queries. It must also intimate the Board without delay with the breach’s nature, extent, timing, location and likely impact, followed within seventy-two hours (or a longer period the Board allows on written request) by updated and detailed information, the broad facts and reasons leading to the breach, mitigation measures implemented or proposed, findings on who caused it, remedial measures to prevent recurrence, and a report on the intimations given to affected Data Principals.

  • 6. An annual DPIA and audit, if designated significant

    Rule 13(1) and (2) require a Significant Data Fiduciary, once every twelve months from the date it is notified as such, to undertake a Data Protection Impact Assessment and an audit, and to have the person carrying them out furnish a report to the Board containing significant observations.

06KYCKART Regulatory Analysis

What the Published Commentary Says About the Board

Autonomy critiques and the absence of appointments in legal commentary

Two published pieces on the Board are summarised below as their authors made them. Both are argument, not statute:

SFLC.in: “Data Protection Board of India: A Watchdog without Teeth”

Published 5 February 2025

SFLC.in’s critique, published against the draft Rules and before the final Rules were notified, argues that neither the Act nor the draft rules safeguard the Board’s autonomy; that the selection committee’s composition means “it is the executives that will be appointing the Chairperson and members”; that the Justice Srikrishna Committee had recommended including the Chief Justice of India or a nominee in the appointments process, as the Competition Act, 2002 does; that the Board holds civil-court powers under Section 28(7) while its governance structure does not match quasi-judicial independence standards; and that members’ terms are subordinated to Central Civil Services rules, limiting protective tenure.

LiveLaw: “India’s Data Protection Board: Established In Law, Absent In Fact”

Published 1 August 2026 by Dr. Raghvendra Kumar Chaudhary

Dr. Chaudhary reports that two Search-cum-Selection Committees had solicited nominations by communications dated 6 May 2026 and 6 June 2026, and that no Chairperson and no Members had been appointed. Its argument is that without appointed members the Board cannot receive representations, hold hearings or issue orders; that courts, citing the Madhya Pradesh High Court in Parth Sharma v. Union of India, have been directing litigants to exhaust the statutory remedy before a Board that is not functioning; and that India inverted the GDPR sequence by creating rights before standing up the regulator.

07KYCKART Regulatory Analysis

Data Protection Board vs. RBI

How the two regulatory regimes differ in trigger, quantum, and statutory standing

How an adjudication under the DPDP Act compares structurally with an RBI supervisory enforcement on a bank:

DimensionData Protection Board of IndiaRBI (banks)
Source of powerSection 18 and Section 27 of the DPDP Act, 2023Section 47A(1)(c) read with Sections 46(4)(i) and 56 of the Banking Regulation Act, 1949
What triggers actionAn intimation, complaint, Central Government reference or court direction under Section 27(1)A statutory inspection, followed by a show-cause notice, the bank’s reply and a personal hearing
What it penalisesA breach of the DPDP Act or Rules that the Board determines, on conclusion of an inquiry, is significantDeficiencies in regulatory compliance, for example a bank failing to put in place a system of periodic review of risk categorisation of accounts at least once in six months
Illustrative quantumCeilings by breach category, up to ₹250 crore₹50,000 on Walchandnagar Sahakari Bank Ltd. for non-compliance with certain RBI directions on Know Your Customer, March 2026
Appeal routeTDSAT within sixty days, then the Supreme Court under Section 18 of the TRAI Act, 1997Outside this piece’s scope, which covers the DPDP appeal route only
Do the two stack?Section 38 provides that the DPDP Act is in addition to and not in derogation of any other law in force, and prevails over a conflicting law to the extent of the conflictRBI records that imposition of a monetary penalty is without prejudice to any other action RBI may initiate against the bank

The RBI action above is a banking-law penalty under the Banking Regulation Act, 1949. It is not a DPDP action, and it is included as an illustration of how a supervisory penalty is framed. RBI’s own release records that the action is “based on deficiencies in regulatory compliance and is not intended to pronounce upon the validity of any transaction or agreement entered by the bank with its customers.”

08KYCKART Regulatory Analysis

What This Means for BFSI Compliance Teams

Practical interpretations for sequencing technical and governance controls

The following is interpretation of the claims cited above, not a further statement of law.

Read together, the commencement notification and Section 39 describe a window in which the bar on court jurisdiction operates ahead of the Board’s own powers. Section 39’s bar on civil-court jurisdiction over matters the Board is empowered over has been in force since 13 November 2025, while Sections 27 to 34, apart from Section 27(1)(d) at the one-year mark, do not commence for eighteen months, and no Chairperson or Members had been appointed as of 1 August 2026. The practical implication is that neither side of a data-protection dispute has the forum the Act contemplates for it during this window, which is the gap the LiveLaw piece describes when it reports courts directing litigants to a Board that is not functioning.

A second reading concerns the sequencing. Rules 19 and 20, which set the six-month inquiry clock and the digital-office mandate, are in the immediate-commencement bucket, while the powers those rules govern are in the eighteen-month bucket. This suggests the procedural scaffolding was put in place ahead of the jurisdiction it will carry, which is consistent with PIB’s description of an eighteen-month phased compliance period.

For a compliance team deciding what to build first, the cited provisions suggest an order. Section 33(2) directs the Board to weigh how timely and effective a person’s mitigation was, and separately to weigh the repetitive nature of the breach, within a ceiling set per breach category. Set that against Rule 7’s seventy-two-hour requirement for detailed follow-up to the Board and Rule 6(1)’s requirement to retain access logs and personal data for one year, and the reading is that the log-retention and monitoring capability is what makes a seventy-two-hour report answerable at all. An institution that stands up Rule 6(1) logging only on the day Rule 7 begins to bite has no retained history to report from, because the one-year retention window Rule 6(1) specifies would only start running at that point.

A last reading concerns the relationship with RBI. Section 38 makes the DPDP Act additive to other laws in force, and RBI’s own framing records that a monetary penalty is without prejudice to any other action. Read together, these suggest that an RBI finding on non-compliance with certain KYC directions and the DPDP obligations are separate items, running on different triggers, under different statutes, at different scales, so closing out one addresses the obligation it arises under. On timing, Sections 27 to 34 have not commenced, so the DPDP side of that comparison cannot yet be inquired into or penalised. The DPDP Schedule’s top ceiling is ₹250 crore, against the ₹50,000 in the single RBI action cited above, though a ceiling and one illustrative penalty are not like-for-like figures.

KYCKART Regulatory Analysis

Frequently Asked Questions

Core regulatory details on Board constitution, penalties, and appeals

This piece is a regulatory explainer, not legal advice. The DPDP Act’s section text used here is drawn from a secondary aggregator and the gazette notifications from third-party mirrors of the official gazette scans; verify against the official MeitY publication before relying on it operationally.

BC
Bhanujeet Choudhary
Head of Compliance, KYCKART · Published September 9, 2026

DPDP Preparedness

Preparing Your Customer Onboarding and Data Infrastructure for DPDP Compliance?

Connect with our regulatory engineering specialists to understand how KYCKART ensures verifiable consent logs, automated audit trails, and strict data security safeguards across your banking workflows.

Speak with Our Compliance Teamarrow_forward