From complaint to penalty: how the Data Protection Board process works
By dpdprules.org editorial team · Reviewed by dpdprules.org source verificationPublished · Last reviewed
The short answer
Section 27 lists what moves the Data Protection Board: breach intimations, complaints by Data Principals against Data Fiduciaries or Consent Managers, references by governments or courts, and intimations about Consent Manager registration breaches. Under section 28 the Board works, as far as practicable, as a digital office, first determines whether there are sufficient grounds, then inquires following the principles of natural justice with the powers of a civil court, and on completion either closes the proceedings or moves to penalties under section 33. False or frivolous complaints can draw a warning or costs. Any person aggrieved by a Board order may appeal to the Appellate Tribunal, the TDSAT, within sixty days under section 29. The Board itself was established on 13 November 2025, but sections 27 to 34 sit in the commencement group computed to 13 May 2027, except section 27(1)(d) at 13 November 2026; both computed dates are interpretation until officially confirmed.
The penalty caps in the Schedule get the headlines, but they arrive only at the end of a defined pipeline. Sections 27 to 29 set out that pipeline: what starts the Data Protection Board moving, how its inquiry must run, and where its orders can be challenged.
What moves the Board
Section 27(1) lists five triggers. A breach intimation under section 8(6) lets the Board direct urgent remedial or mitigation measures, inquire and impose penalty. A Data Principal's complaint against a Data Fiduciary is the broadest gateway:
"on a complaint made by a Data Principal in respect of a personal data breach or a breach in observance by a Data Fiduciary of its obligations in relation to her personal data or the exercise of her rights under the provisions of this Act, or on a reference made to it by the Central Government or a State Government, or in compliance of the directions of any court, to inquire into such breach and impose penalty as provided in this Act;"
Section 27(1)(b) of the DPDP Act 2023.
The remaining triggers cover complaints against Consent Managers, intimations of Consent Manager registration breaches, and Central Government references about intermediaries under section 37(2). The Board can also issue binding directions after a hearing, and can modify, suspend, withdraw or cancel them.
How the inquiry runs
Section 28 makes the Board, as far as practicable, a digital office: receipt of complaints, allocation, hearing and pronouncement are digital by design. The sequence has a filter at the front. The Board first determines whether there are sufficient grounds to proceed; with insufficient grounds it closes the proceedings with recorded reasons. With sufficient grounds it inquires, and the inquiry is bound in one sentence:
"The Board shall conduct such inquiry following the principles of natural justice and shall record reasons for its actions during the course of such inquiry."
Section 28(6) of the DPDP Act 2023.
For the inquiry the Board holds the powers of a civil court: summoning and examining on oath, receiving evidence and requiring production of documents, and inspecting data and records. Two limits protect operations: the Board and its officers may not prevent access to premises or take into custody equipment or items that may adversely affect a person's day to day functioning. Interim orders are possible with recorded reasons after a hearing. On completion, the Board either closes the proceedings or proceeds to penalties in accordance with section 33. And the pipeline guards its own gate: a complaint the Board considers false or frivolous can draw a warning or costs on the complainant.
Where Board orders are challenged
"Any person aggrieved by an order or direction made by the Board under this Act may prefer an appeal before the Appellate Tribunal."
Section 29(1) of the DPDP Act 2023.
The Appellate Tribunal is the TDSAT, the Telecom Disputes Settlement and Appellate Tribunal, borrowed from the telecom regime by the definition in section 2(a). The appeal window is sixty days from receipt of the order, extendable for sufficient cause. The Tribunal is directed to endeavour to dispose of the appeal within six months, recording reasons if it cannot, and it too functions digitally by design. Its orders are executable as decrees of a civil court under section 30, and further appeal follows the route in the Telecom Regulatory Authority of India Act 1997.
The timing picture
The institution and its powers commence separately. The Board itself was established on 13 November 2025 by notification G.S.R. 844(E), and the establishment sections, 18 to 26, are in force. The enforcement pipeline, section 27 except clause (1)(d), and sections 28 to 34, sits in the group due eighteen months from the notification gazette, computed as 13 May 2027; section 27(1)(d), on Consent Manager registration breaches, arrives with the one year group, computed as 13 November 2026. Both computed dates are interpretation until officially confirmed. For organisations, the sequence work is the same either way: the obligations whose breach feeds this pipeline commence on the same computed dates, and the company action plan tool orders that work. For individuals, the rights assistant explains the grievance channel that must be exhausted before the Board is approached.
Related tool
Compliance Plan
Generate one company level action plan and see the work for your role first.
Open
Related tool
Individual Rights Assistant
Understand your rights as an individual and the channels a Data Fiduciary must offer.
Open
Section 33, official text with sources →DPDP timeline with verified milestones →
Sources cited on this page
- [1]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 27, p. 14. Published 11 August 2023. Official source ↗ · Official requirement · Verified 17 August 2026Section 27(1)(b), one of the five triggers in section 27(1).
- [2]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 28, p. 14. Published 11 August 2023. Official source ↗ · Official requirement · Verified 17 August 2026Section 28(6). Section 28 begins on Gazette page 14 and concludes on page 15.
- [3]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 29, p. 15. Published 11 August 2023. Official source ↗ · Official requirement · Verified 17 August 2026Section 29(1). Section 29 begins on Gazette page 15 and concludes on page 16. Section 2(a) defines the Appellate Tribunal as the Telecom Disputes Settlement and Appellate Tribunal established under section 14 of the Telecom Regulatory Authority of India Act, 1997.
- [4]Notification establishing the Data Protection Board of India (G.S.R. 844(E)), p. 2. Published 13 November 2025. Official source ↗ · Official requirement · Verified 17 August 2026Notification G.S.R. 844(E), published 13 November 2025, establishing the Board under section 18.
- [5]Commencement notification for the Digital Personal Data Protection Act, 2023 (G.S.R. 843(E)), (c), p. 2. Published 13 November 2025. Official source ↗ · Official requirement · Verified 17 August 2026Notification G.S.R. 843(E) places section 27, except section 27(1)(d), and sections 28 to 34, in the group that comes into force eighteen months from the date of publication of the notification gazette. Paragraph (b) places section 27(1)(d) in the one year group.
- [6]Commencement notification for the Digital Personal Data Protection Act, 2023 (G.S.R. 843(E)), p. 1. Published 13 November 2025. Official source ↗ · Interpretation, requires judgment · Verified 17 August 2026The calendar dates 13 May 2027 and 13 November 2026 are computed from the printed publication date of 13 November 2025 and are presented as interpretation until officially confirmed.
data protection boardinquiryappealappellate tribunalsection 28