India’s Data Protection Board was formally set up and notified on November 13, 2025. The Data Protection Board is an entity set up by the Digital Personal Data Protection Act, 2023.
It is the first adjudicatory forum in the implementation of the DPDPA. The Board exists, with its office in New Delhi, but there are no members yet. Once appointed, the Board will not have much to do as the effective date of operationalising the DPDPA is May, 2027. However, even if the DPDPA comes into force, the Board appears to be a passive entity which is corporate-centric rather than citizen-centric.
-
A toothless board?
The functions of the Board are set out in Section 27 of the DPDPA.
These are:
=> On receiving notification about a data breach from a data fiduciary, direct any urgent remedial or mitigation measures and start an investigation
=> On a complaint by the user, reference by the Government or order of the Court, inquire into the complaint and impose penalties.
=> On a complaint by the user regarding a Consent Manager, inquire into the complaint and impose penalties.
=> On receiving information on breach of Consent Manager registration conditions, inquire and impose penalties.
=> On reference by the Central government of breach of directions on blocking of access, inquire and impose penalties.
=> Issue directions to any person for effective discharge of its functions provided an opportunity to be heard is granted to the person.
No suo motu powers: None of the functions of the Board involve a suo motu inquiry by the Board. The only provision that resembles a suo motu inquiry is the investigation into consent managers. However, given that it is still qualified with the condition that some information must be received, the Board will likely be required to provide some source that provided the information. Besides, this provision only relates to consent managers that are again heavily regulated corporate entities.
-
Can the Board stop processing on user complaint?
The obvious answer to this question should be a resounding yes. After all, what data protection board does not have the power to direct an entity to stop processing personal data if it prima facie finds them to be in breach? The Indian Data Protection Board.
The Board has power to direct urgent remedial action or mitigation measures only on receipt of a notification from the entity processing the personal data that there is a leak.
On a user complaint, the Board can only inquire and impose penalties.
There is a weak argument that the Board has powers to issue interim orders when undertaking an inquiry. These interim orders possibly allow the Board to restrict processing by the Data Fiduciary (and the processor downstream) that is in breach of the DPDPA. Although sound logic, it breaks down when encountering legal principles.
The Board is a statutory body. It is settled law that no statutory body can exercise a power that is not granted to it by statute. The DPDPA does not appear to empower the Board to issue any remedial measures on user complaints.
-
Statutory interpretation finds the Board lacking
Further, principles of statutory interpretation do not support the remedial powers as well. Two principles are relevant here - (i) all the words of the legislature must be given effect to and (ii) nothing should be read into provisions that the legislature intends to leave out.
The first principle squarely applicable would mean that since the provision on data breach explicitly provides the Board power to issue interim measures and the provision on user complaint does not, it is clear that the Board is not empowered in the latter case.
Support for the restricted power of the Board can also be found when referring to the previous iterations of the DPDPA, specifically the iteration just before the final act came out, the Digital Personal Data Protection Bill, 2022. The interim order provision in the Bill clearly stated that the Board can issue directions to any person to prevent non-compliance with the provisions of the Bill.
This has been dropped from the Bill as it was legislated into an Act. The exclusion of the provision clearly supports the assertion that the Board cannot issue any interim orders halting processing when it inquires on the basis of a complaint, reference or a court order. Furthermore, the previous iterations i.e. the 2018 and the 2019 bills explicitly provided cease and desist powers to the Board. These provisions were gradually diluted and eventually dropped.
The legislative intent is clear - the Board cannot halt processing based on a user complaint. Therefore, it will not be appropriate to read in such powers whatever be the expansive scope of the words of the statute’s provisions.
Unfortunately, what it means is that the Board can only initiate an inquiry and impose penalties. The underlying logic possibly being that the Data Fiduciary stops any unlawful processing and undertakes mitigation measures to avoid a fine or reduce the quantum of fine imposed. Effectiveness of this logic is yet untested.
-
Implications
Personal data is volatile. Once released in public, there is no putting the genie back in the bottle. The user becomes a helpless actor in a transaction where it is their own personal data that is in question. This is problematic.
The 250 cr. cap on fines is high but this also allows the Data Fiduciaries to buy non-compliance. Once the personal data is acquired or processed, say by an AI model, there is no need for the specific data points. However, personal data still persists. I hope this interpretation is false and the Board exercises powers to stop processing. But until decided so by a Court, it appears that the Board is a barking dog that wont bite.