The Data Protection Board of India Exists in Law, Has a Pay Scale and a Selection Committee, and Has No Members Yet
Key Takeaways
- G.S.R. 844(E) of 13 November 2025 established the Board as a body corporate with its head office in the National Capital Region, and sections 18 to 26 of the Act commenced that day
- MeitY's 6 May 2026 circular invited applications for one Chairperson and four Members; this publication found no notification of any appointment as at 21 September 2026
- The Board's complaint and inquiry powers in sections 27 and 28, and appeals under section 29, commence eighteen months after 13 November 2025, except section 27(1)(d), which commences on 13 November 2026
- Rule 19(9) gives the Board six months to complete an inquiry, extendable by up to three months at a time with reasons recorded
- A voluntary undertaking accepted under section 32 bars proceedings on its contents, and breaching it is itself a breach of the Act
Established on Paper, Not Yet Staffed
Section 18(1) of the Digital Personal Data Protection Act, 2023 provides that the Board comes into existence on a date the Central Government appoints by notification. That notification is G.S.R. 844(E), published in the Gazette of India, Extraordinary, on 13 November 2025. It establishes the Data Protection Board of India with effect from publication and fixes its head office in the National Capital Region. Section 18(2) makes the Board a body corporate with perpetual succession, able to hold property, contract, and sue and be sued in its own name.
A body corporate is not the same thing as a functioning adjudicator. On 6 May 2026, MeitY's Personnel-I Section issued a circular, F. No. 2(1)/2026-Pers.I, to all ministries, state chief secretaries and MeitY's attached offices, inviting applications for one post of Chairperson and four posts of Member so that a panel of names could go to a Search-cum-Selection Committee. A shorter advertisement asked for applications within 30 days of its publication in the Employment News.
The supporting staff was still being recruited in July. A Digital India Corporation advertisement of 13 July 2026 sought a Consultant (Techno-Legal) on contract for the "Digital office for Data Protection Board", with applications closing on 28 July 2026.
As at 21 September 2026, this publication found no Gazette notification, MeitY document or Press Information Bureau release announcing the appointment of a Chairperson or any Member. What follows therefore describes the statutory design, and the parts of it that are not yet in force are identified as such.
How the Board Is Constituted
Section 19(1) leaves the size of the Board to notification: a Chairperson and "such number of other Members as the Central Government may notify". The Press Information Bureau's background note on the Rules described the Board as consisting of four members, and MeitY's May 2026 circular sought one Chairperson and four Members.
Section 19(3) sets the qualifications for all of them: persons of ability, integrity and standing with special knowledge or practical experience in data governance, administration or implementation of laws on social or consumer protection, dispute resolution, information and communication technology, digital economy, law, regulation or techno-regulation, or any other field the Central Government considers useful. At least one must be an expert in law.
Appointment runs through two committees under rule 17 of the Digital Personal Data Protection Rules, 2025, which came into force on publication on 13 November 2025:
| Post | Committee chair | Other members |
|---|---|---|
| Chairperson, rule 17(1) | Cabinet Secretary | Secretaries in charge of the Department of Legal Affairs and of MeitY, and two experts of repute |
| Member, rule 17(2) | Secretary, MeitY | Secretary in charge of the Department of Legal Affairs, and two experts of repute |
Under rule 17(3) the Central Government appoints after considering the suitability of those the committee recommends. Rule 17(4) protects the committees' work from challenge on the ground of a vacancy or a defect in their constitution.
The May 2026 circular adds eligibility conditions that are not in the Act. Applicants must be Indian citizens, hold at least a bachelor's degree, have at least five years of the special knowledge or experience section 19(3) describes, and be at least 55 years old on the closing date. A Chairperson must have held a post equivalent to Additional Secretary to the Government of India or above, or a position not more than one level below the head of a reputed academic, policy or research institution or a company with ₹100 crore paid-up capital or ₹500 crore turnover. For Members the bar is Joint Secretary or two levels below such a head.
Section 20(2) fixes a two-year term with eligibility for re-appointment; the circular describes the tenure as not exceeding two years or until age 65, whichever is earlier. The Fifth Schedule to the Rules sets a consolidated monthly salary of ₹4,50,000 for the Chairperson and ₹4,00,000 for each Member, without house or car. Section 21 lists five grounds of disqualification, from insolvency to abuse of position, and bars removal without a hearing. Section 22(3) imposes a one-year bar on accepting any employment after leaving office without Central Government approval, and a duty to disclose any later job with a Data Fiduciary that faced proceedings before that member.
Rule 19 governs meetings. The Chairperson fixes date, time, place and agenda; one-third of the membership is the quorum; questions are decided by majority of those present and voting, with a casting vote for the chair; a Member with an interest in an item may not vote on it; and in an emergency the Chairperson may act alone, recording reasons, provided the action is reported to all Members within seven days and laid before the next meeting for ratification. Section 23(2) provides that no act of the Board is invalid merely because of a vacancy or a defect in its constitution.
A Digital Office by Statute
The Act defines the Board's working method before it defines its powers. Section 2(m) describes a "digital office" as one that adopts an online mechanism in which proceedings, from receipt of an intimation, complaint, reference, direction or appeal through to disposal, are conducted online or in digital mode. Section 28(1) then requires the Board to function as an independent body and, as far as practicable, as a digital office, with the receipt of complaints and the allocation, hearing and pronouncement of decisions "digital by design".
Rule 20, already in force, states that the Board shall function as a digital office and may adopt techno-legal measures to conduct proceedings without anyone's physical presence, without prejudice to its power to summon a person and examine her on oath. The PIB background note says citizens will be able to file complaints online and track them through a dedicated portal and mobile application; this publication has not located such a portal in operation and does not describe one.
Staffing follows the same model. Section 24 lets the Board appoint officers and employees with the Central Government's prior approval, and the Sixth Schedule to the Rules provides for deputation for up to five years from central and state government, statutory bodies and public sector enterprises, and from the National Institute for Smart Government on market-guided pay.
Complaints, References and Intimations
Section 27(1) lists five ways a matter reaches the Board:
- (a) an intimation of a personal data breach from a Data Fiduciary under section 8(6), on which the Board may direct urgent remedial or mitigation measures, inquire and impose a penalty. The intimation duty itself is the subject of this publication's post on breach intimation
- (b) a complaint by a Data Principal about a personal data breach or a fiduciary's failure in its obligations to her or her rights; a reference from the Central or a State Government; or compliance with a court's directions
- (c) a complaint by a Data Principal against a Consent Manager
- (d) an intimation that a Consent Manager has breached a condition of its registration
- (e) a reference from the Central Government about an intermediary's breach of section 37(2)
Two gates stand in front of an individual complaint. Section 13(3) requires a Data Principal to exhaust the fiduciary's or Consent Manager's own grievance redressal before approaching the Board. And section 28(12) allows the Board, at any stage after a complaint is received, to issue a warning or impose costs on a complainant whose complaint it considers false or frivolous.
Commencement is staggered inside this one section. The commencement notification, G.S.R. 843(E), brings section 27(1)(d) into force one year after 13 November 2025, alongside section 6(9), which requires Consent Managers to register with the Board. The rest of section 27, and sections 28 to 34, commence eighteen months after 13 November 2025. Until then the Board has no power in force to receive complaints under section 27(1)(b).
Inquiry, Hearing and Interim Measures
Section 28 sets the procedure once a matter arrives. The Board first decides whether there are sufficient grounds to proceed. If not, it may close the matter with written reasons. If so, it may inquire into the affairs of any person to establish whether that person is complying or has complied with the Act, following the principles of natural justice and recording reasons as it goes.
For the inquiry, section 28(7) gives the Board a civil court's powers under the Code of Civil Procedure to summon and examine on oath, receive evidence on affidavit, and inspect any data, book, register or other document. Section 28(8) restrains it at the same time: the Board and its officers may not prevent access to premises or take custody of equipment where that may adversely affect a person's day-to-day functioning. Section 28(9) allows it to requisition police officers and central or state government officers to assist.
Section 28(10) allows interim orders during an inquiry, after a hearing and for recorded reasons. Separately, section 27(2) lets the Board issue binding directions after a hearing, and section 27(3) lets it modify, suspend, withdraw or cancel them on a representation or a Central Government reference. At the end, section 28(11) leaves two outcomes: close the proceedings, or proceed to a penalty under section 33, which requires the Board to find the breach "significant".
Rule 19(9), already in force, sets the clock: an inquiry must be completed within six months of receiving the intimation, complaint, reference or direction under section 27, unless the Board extends it for recorded reasons, by no more than three months at a time. The rule does not cap the number of extensions.
Section 39 bars civil courts from entertaining any suit or proceeding on a matter the Board is empowered to decide, and bars any court or other authority from granting an injunction against action taken under the Act.
Voluntary Undertakings and Mediation
Two sections let a matter end without a penalty. Under section 31, where the Board considers a complaint may be resolved by mediation, it may direct the parties to attempt mediation before a mediator they agree on or one provided for under other Indian law.
Section 32 is more distinctive. At any stage of section 28 proceedings, the Board may accept a voluntary undertaking from any person about observance of the Act. The undertaking may commit the person to act, or to refrain from acting, within a time the Board sets, and may include publicising the undertaking. Its terms may later be varied with the giver's consent. Acceptance bars proceedings under the Act on the undertaking's contents. Breaking it is deemed a breach of the Act, and the Schedule sets the penalty for breaching an accepted undertaking at up to the amount applicable to the breach for which the section 28 proceedings were brought.
Appeals to the Appellate Tribunal
No new appellate body was created. Section 2(a) makes the Appellate Tribunal the Telecom Disputes Settlement and Appellate Tribunal established under section 14 of the Telecom Regulatory Authority of India Act, 1997, and section 44(1), which commenced on 13 November 2025, substitutes sub-clauses in clause (c) of section 14 of that Act so that the list there names "the Appellate Tribunal under the Digital Personal Data Protection Act, 2023".
- Time limit (section 29(2) and (3)). Sixty days from receipt of the Board's order or direction, extendable where the tribunal is satisfied there was sufficient cause for delay
- Disposal (section 29(6) and (7)). The tribunal is to endeavour to decide within six months, and must record reasons in writing where it does not
- Further appeal (section 29(9)). Section 18 of the TRAI Act applies to appeals against the tribunal's own orders
- Enforcement (section 30). The tribunal's order is executable as a civil court decree, or may be sent to a local civil court to execute
- Filing (rule 22). Appeals are filed digitally, with the same fee as a TRAI Act appeal unless the tribunal's Chairperson reduces or waives it, payable by UPI or another RBI-authorised system; the tribunal is not bound by the Code of Civil Procedure but by natural justice, and functions as a digital office
Section 29 and rule 22 are both in the eighteen-month tranche. Until they commence, and until the Board has members to make an order, there is nothing for the tribunal to hear under the Act.
Frequently Asked Questions
Has the Data Protection Board of India been constituted?
Who selects the Chairperson and Members?
Can a Data Principal complain to the Board now?
How long does the Board have to finish an inquiry?
What is a voluntary undertaking under the DPDP Act?
Where do appeals from the Board go, and how long is there to file?
Sources
Everything above is reported from these documents. Follow them to verify.
- The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023), as published in the Gazette of India (MeitY) (August 11, 2023) statute
- G.S.R. 844(E), notification establishing the Data Protection Board of India, 13 November 2025 (November 13, 2025) regulation
- G.S.R. 843(E), notification appointing commencement dates for the Digital Personal Data Protection Act, 2023, 13 November 2025 (November 13, 2025) regulation
- Digital Personal Data Protection Rules, 2025, G.S.R. 846(E), 13 November 2025 (November 13, 2025) regulation
- MeitY, F. No. 2(1)/2026-Pers.I, Appointment to the post of Chairperson and Other Members in the Data Protection Board of India (May 6, 2026) agency release
- MeitY, advertisement: Filling up the post of Chairman and Members in the Data Protection Board of India agency release
- Digital India Corporation, Advt. No. N-22030/149/2024-DIC, Consultant (Techno-Legal) for the digital office of the Data Protection Board (July 13, 2026) agency release
- Press Information Bureau, DPDP Rules, 2025 Notified: background note (November 17, 2025) agency release
Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.