Data Protection Board of India Takes Shape: Enforcement Architecture Under the DPDP Act 2023
- Kaustav Chowdhury

- 2 days ago
- 7 min read
Introduction
The Digital Personal Data Protection Act, 2023 (DPDP Act), which received Presidential assent on 11 August 2023, established the Data Protection Board of India (DPBI) as the primary adjudicatory body for data protection disputes in the country. The Government subsequently notified the Digital Personal Data Protection Rules, 2025 (DPDP Rules) on 13 November 2025, bringing into force several key provisions of the Act, including those relating to the establishment and functioning of the Board. Despite this legislative and regulatory progress, the operationalisation of the DPBI has been delayed, with the Chairperson and Members of the Board yet to be appointed as of mid-2026.
This article examines the enforcement architecture under the DPDP Act, the structure and powers of the Board, the phased implementation timeline prescribed by the DPDP Rules, the Consent Manager framework, the obligations imposed on Significant Data Fiduciaries, and the current status of the Board's operationalisation. For professionals managing compliance frameworks, our guide on filing a whistleblower complaint under the Whistle Blowers Protection Act provides a parallel discussion of statutory complaint mechanisms in India.
Legislative Background: The DPDP Act, 2023
The Digital Personal Data Protection Act, 2023, is India's first comprehensive data protection legislation, replacing the earlier framework that relied primarily on Section 43A of the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. The DPDP Act establishes a rights-based framework for the protection of digital personal data, imposing obligations on Data Fiduciaries (entities that determine the purpose and means of processing personal data) and conferring rights on Data Principals (the individuals whose data is processed).
The Act creates a comprehensive regulatory architecture that includes the establishment of the DPBI as the adjudicatory body, a consent-based framework for data processing, rights for Data Principals including the right to access, correction, and erasure, obligations for Data Fiduciaries regarding data security, breach notification, and data retention, and a penalty framework with fines of up to Rs. 250 crore for non-compliance. The penalty provisions make the DPDP Act one of the more stringent data protection laws globally in terms of maximum financial penalties.
DPDP Rules, 2025: Operationalising the Framework
The Government notified the DPDP Rules on 13 November 2025, providing the operational details necessary to implement the Act. The Rules follow a phased implementation approach, with different provisions coming into force at different times.
Rules 1, 2, and 17 to 21 became effective immediately upon notification, covering preliminary matters, definitions, and provisions relating to the establishment and functioning of the DPBI. Rule 4, which governs the Consent Manager framework, takes effect one year from the date of notification, in November 2026. The remaining Rules (3, 5 to 16, 22, and 23), covering the substantive obligations of Data Fiduciaries including notice, consent, data processing, data security, breach notification, and Data Principal rights, come into force eighteen months from the date of notification, in May 2027.
This phased approach provides Data Fiduciaries with an implementation runway to redesign their data processing workflows, build or procure compliance infrastructure, train personnel, and conduct internal audits. However, the delay in appointing the Board means that the enforcement mechanism remains inactive even as the compliance deadlines approach. Understanding regulatory compliance timelines is essential for businesses, and our article on RBI's proposed FEMA Foreign Investment Rules 2026 provides another example of evolving regulatory frameworks.
Structure and Composition of the DPBI
Under the DPDP Act, the Data Protection Board of India consists of a Chairperson and up to four Members. The Board is designed as a quasi-judicial body, not a policy-making regulator. Its primary function is the adjudication of disputes, enforcement of statutory obligations, and imposition of monetary penalties for non-compliance with the Act and the Rules.
The Chairperson and Members must have appropriate knowledge and practical experience in fields relevant to data protection, including data governance, administration or implementation of consumer protection laws, dispute resolution, information and communication technology, digital economy, law, regulation, or techno-regulation. At least one Member must be an expert in the field of law. The Chairperson and Members hold office for a term of two years and are eligible for re-appointment.
The Board is intended to operate as a digital-first institution. The DPDP Act provides that all proceedings before the Board shall be conducted in the digital mode, with physical hearings being the exception rather than the rule. This design choice reflects the Government's broader push toward digital governance and is consistent with the digital nature of the data that the Board is tasked with protecting.
Appointment Process
The selection of the Chairperson and Members follows a structured process through a Search-cum-Selection Committee. For the Chairperson, the Committee is chaired by the Cabinet Secretary and includes the Secretaries of the Department of Legal Affairs and the Ministry of Electronics and Information Technology (MeitY), along with two experts with relevant expertise. For Members, the Committee is chaired by the Secretary of MeitY and includes the Secretary of the Department of Legal Affairs and two experts.
MeitY has issued invitations for applications for the positions of Chairperson and Members of the Board. However, as of mid-2026, the appointments have not been finalised. The delay in appointments has been a subject of concern among data protection professionals, industry stakeholders, and civil society organisations, who argue that the absence of an operational Board creates a regulatory vacuum during a period when data processing activities continue to grow in scale and complexity.
Enforcement Powers of the Board
Once operational, the DPBI will have significant enforcement powers under the DPDP Act. The Board will be empowered to receive and investigate complaints from Data Principals regarding alleged violations of the Act by Data Fiduciaries. It will also have the power to initiate suo motu inquiries into personal data breaches and instances of non-compliance.
The Board's enforcement toolkit includes the power to issue directions for mitigation and remediation of data breaches, impose monetary penalties in accordance with the Schedule to the Act, and issue orders requiring Data Fiduciaries to take specific corrective actions. The maximum penalty under the Act is Rs. 250 crore, applicable for failure to take reasonable security safeguards to prevent personal data breaches. Other violations attract penalties ranging from Rs. 10,000 to Rs. 200 crore, depending on the nature and gravity of the default.
Appeals against the Board's orders lie before the Telecom Disputes Settlement and Appellate Tribunal (TDSAT), providing a specialised appellate mechanism. This appellate pathway was chosen to leverage TDSAT's existing expertise in technology-related disputes. For understanding other statutory complaint mechanisms, see our guide on filing an investor complaint with SEBI.
Implementation Timeline and Compliance Deadlines
The phased implementation timeline under the DPDP Rules creates a sequence of compliance milestones that Data Fiduciaries must prepare for. The immediate provisions (effective November 2025) relate to the Board's establishment and certain administrative matters. The Consent Manager framework (Rule 4) becomes operative in November 2026, requiring Data Fiduciaries to integrate with registered Consent Managers for consent collection and management. The substantive compliance obligations (Rules 3, 5 to 16, 22, and 23) become operative in May 2027, requiring full compliance with notice, consent, data processing, security, breach notification, and Data Principal rights provisions.
For Significant Data Fiduciaries (SDFs), which are entities notified by the Government based on factors such as the volume and sensitivity of data processed, additional obligations apply, including the mandatory appointment of a Data Protection Officer based in India, the conduct of annual Data Protection Impact Assessments (DPIAs), independent annual audits, and restrictions on certain cross-border data transfers.
The Consent Manager Framework
Rule 4 of the DPDP Rules introduces the Consent Manager as a formally recognised class of intermediary within the data protection ecosystem. A Consent Manager is an entity registered with the DPBI that provides Data Principals with a single interface to give, manage, review, and withdraw consents across multiple Data Fiduciaries. This model draws inspiration from Account Aggregator frameworks in the financial sector, where consent-based data sharing is facilitated through registered intermediaries.
Consent Managers must meet specific eligibility criteria: they must be incorporated in India with a minimum net worth of Rs. 2 crore, and they cannot simultaneously act as Data Fiduciaries or Data Processors for the same Data Principal whose consent they manage. This separation is designed to prevent conflicts of interest and ensure that the Consent Manager operates as a neutral facilitator of consent. The corporate governance framework for such entities is relevant, and our guide on conducting a board meeting under the Companies Act discusses governance standards applicable to Indian companies.
The Consent Manager framework is expected to become operational in November 2026, giving both Consent Manager applicants and Data Fiduciaries time to develop the technical infrastructure for integration. The framework is expected to create a new category of regulated technology service providers, with potential implications for competition, innovation, and data portability in the Indian digital ecosystem.
Current Status and Road Ahead
As of August 2026, the DPBI remains in a pre-operational state. While the legislative framework (DPDP Act) and the operational rules (DPDP Rules, 2025) are in place, the absence of appointed Chairperson and Members means that the Board cannot receive complaints, conduct inquiries, or impose penalties. This creates a gap between the statutory framework and its enforcement, particularly as the first substantive compliance deadline (Consent Manager integration in November 2026) approaches.
The transition to active enforcement is expected by late 2026, contingent on the completion of the appointment process. Industry stakeholders should use the current window to prepare for compliance, including conducting internal data audits, mapping data flows, redesigning consent mechanisms, implementing technical safeguards, and training personnel on data protection obligations. Companies subject to the ESOP framework should note the data protection implications of employee data processing, as discussed in our article on designing and implementing an ESOP under the Companies Act.
The enforcement architecture under the DPDP Act, once the Board becomes operational, is expected to be robust and consequential. With maximum penalties of Rs. 250 crore, mandatory breach notification requirements, and a digital-first adjudication process, the DPBI has the potential to significantly influence data governance practices in India. The cross-border enforcement of data protection obligations also raises questions that intersect with the Supreme Court's approach to transnational legal recognition.
Conclusion
The Data Protection Board of India represents the centrepiece of India's data protection enforcement architecture under the DPDP Act, 2023. While the legislative and regulatory framework is largely in place, the Board's operationalisation depends on the timely appointment of its Chairperson and Members. With key compliance deadlines approaching in November 2026 and May 2027, Data Fiduciaries must begin their preparation now, regardless of the Board's operational status. The phased implementation timeline provides a structured pathway for compliance, and organisations that invest in early preparation will be better positioned to navigate the regulatory landscape when active enforcement begins.

Comments