Is the Data Protection Board operational? 2 separate reasons it is not
By Abhijeet Singh · Primary sources verified by dpdprules.orgPublished · Last reviewed 8 min read
The short answer
No, and for 2 independent reasons that are usually run together. First, the Board has no appointed Chairperson or Members: it was established on 13 November 2025 by notification G.S.R. 844(E), the number of Members was fixed at 4 by G.S.R. 845(E), and MeitY was still inviting applications by a circular of 6 May 2026. We have located no appointment notification as at 26 August 2026. Second, and less noticed, the Board's powers are not in force. Notification G.S.R. 843(E) brought sections 18 to 26 into force on publication, which constitute the Board, but placed section 27, which contains its powers and functions, in the group commencing 18 months after publication, computed as 13 May 2027 and interpretation until officially confirmed. The one exception is clause (d) of section 27(1), on breach of a Consent Manager's registration conditions, which commences at 1 year, computed as 13 November 2026. So the first of the Board's section 27 powers to commence concerns Consent Manager registration, not complaints from individuals. Rule 4 of the DPDP Rules 2025 commences in the same 1 year group under Rule 1(3) and gives the Board its registration, suspension and cancellation functions, while the inquiry procedure in section 28 and the penalty power in section 33 that clause (d) points to are both in the 18 month group. Appointing members would not by itself create a complaint route.

The Data Protection Board of India is not operational, and almost every account of why gives only half the reason. There are 2 gaps, they are independent of each other, and closing the one everybody discusses would not open a route for anybody.
Gap 1: the Board has no members
The Board exists. Notification G.S.R. 844(E) established it on 13 November 2025, with its head office in the National Capital Region, and G.S.R. 845(E) of the same date notified, under section 19(1), that the Board "shall consist of four members". Section 19(1) speaks of a Chairperson "and such number of other Members as the Central Government may notify", and MeitY's own circular of 6 May 2026 advertises 1 post of Chairperson and 4 posts of Member, so the 4 are read here as Members besides the Chairperson. That reading is this site's, not something 845(E) says.
Being established is not the same as being staffed. On 6 May 2026 MeitY issued circular F. No. 2(1)/2026-Pers.I, addressed to the Secretaries of all Ministries, the Chief Secretaries of all States and Union Territories and its own bodies, under the subject:
"Appointment to the post of Chairperson and Other Members in the Data Protection Board of India (DPBI) — regarding."
That circular invites applications, in its own words for "preparing a panel of names to be considered by a Search-cum-Selection Committee", which is the machinery Rule 17 of the DPDP Rules 2025 requires and which has been in force since publication under Rule 1(2). The words "appointed" and "hereby appoints" do not appear anywhere in its 6 pages. It is evidence of a process running, not of a process finished.
As at 26 August 2026 we have located no appointment notification. That is a statement about what we could find rather than a certified negative, and 3 limits are worth stating. MeitY's own Data Protection Board page could not be retrieved on that date, returning an access error, so an appointment published only there could in principle have been missed. Neither section 19(2) of the Act nor Rule 17(3) of the Rules requires an appointment to be published in the Official Gazette, so the absence of a Gazette notification is weak evidence in either direction. And secondary legal commentary published on 1 August 2026 reports a further MeitY notification of 6 June 2026 about the appointment process, which we have not been able to obtain, so the primary trail on file stops at 6 May 2026 rather than being complete. What we can say is that the archived primary material shows a selection process at the application stage, and that nothing in the source registry records an appointment.
This is the gap that gets written about. It is also the one that would be easiest to close, and closing it would change less than most readers expect.
Gap 2: the Board's powers are not in force
Notification G.S.R. 843(E) commenced the Act in 3 groups. The first group took effect on publication:
"the date of publication of this notification in the Official Gazette as the date on which the provisions of sub-section (2) of section 1, section 2, sections 18 to 26 sections 35, 38, 39, 40, 41, 42, 43, and sub- sections (1) and (3) of section 44 of the said Act shall come into force"
The missing comma and the broken word are as printed. Sections 18 to 26 are the Board's constitution: establishment, composition, qualifications for appointment, salaries and terms, disqualifications, resignation and removal, officers and employees, and the procedure it is to follow. All of that is live now.
Section 27 is not in that list. Section 27 is the section that gives the Board its powers and functions, and clause (c) of the notification places it in the 18 month group, "section 27 except clause (d) of sub-section (1) of the said section". Sections 28 to 34, which carry the inquiry procedure, appeals to the Appellate Tribunal and the penalty machinery, are in the same group. Computed from the printed publication date, that group is due on 13 May 2027, and that calendar date is interpretation until officially confirmed.
So the Board today is a body that lawfully exists, may lawfully be staffed, and holds none of the powers and functions in section 27. What paragraph (a) does give it is institutional rather than regulatory. Section 18(2) makes it a body corporate with power to acquire, hold and dispose of property, to contract and to sue or be sued. Section 24 lets it appoint officers and employees with the previous approval of the Central Government, which Rule 21 repeats. Section 26 gives the Chairperson general superintendence over administrative matters, the power to have an officer scrutinise anything addressed to the Board, and the power to allocate proceedings among Members. Rules 17 to 21 have been in force since publication under Rule 1(2). None of that lets the Board act on a breach, a complaint or a reference.
Which means a complaint has nowhere to go, twice over
The 2 routes an individual would use are in section 27(1):
| Clause | What it covers | Commences |
|---|---|---|
| (a) | Acting on a breach intimation from a Data Fiduciary, including urgent remedial directions | 18 month group |
| (b) | A complaint by a Data Principal about a breach, about a Data Fiduciary's obligations or about the exercise of her rights, and also a Central or State Government reference or a court direction | 18 month group |
| (c) | A complaint by a Data Principal about a Consent Manager's obligations | 18 month group |
| (d) | An intimation that a Consent Manager has breached a condition of its registration | 1 year group |
| (e) | A Central Government reference about an intermediary under section 37(2) | 18 month group |
Read that table against the notification and the sequencing becomes visible. The first of the section 27 powers the Board will hold is clause (d), and it arrives with section 6(9), on registration of Consent Managers with the Board, in the 1 year group computed as 13 November 2026. Clause (d) is not a complaint route at all: it is triggered by an intimation that a Consent Manager has breached a condition of its registration.
Rule 4 of the DPDP Rules 2025 lands in the same 1 year group under Rule 1(3), and it is the substantive half of the pair. Rule 4 has a would be Consent Manager apply to the Board, lets the Board inquire into the application and register or reject it, lets it direct a Consent Manager to take measures where it is not adhering to its conditions, and lets it suspend or cancel a registration by order for reasons recorded in writing. Those functions carry their own procedure inside the rule. Clause (d) of section 27(1) does not: it points at inquiry and penalty, and the inquiry procedure in section 28 and the penalty power in section 33 are both in the 18 month group. So on this site's reading the 1 year date gives the Board a working registration function under Rule 4 and a section 27 trigger whose consequences are not yet in force. That reading is interpretation, and nothing in the Act or the Rules addresses the overlap.
The Board's first work is administering Consent Manager registration, not hearing from individuals. Complaints under clauses (b) and (c) follow 6 months later, with the rest of the framework. Who has to register, and on what conditions, is the subject of Rule 4 and who it applies to.
That is the sequence the 2 notifications set, and it explains why appointing a Chairperson tomorrow would not give anybody a complaint to file. There would be a Board, correctly constituted under provisions already in force, whose first substantive work arrives in November 2026 and concerns Consent Managers and nothing else. Whether the sequence was intended to run that way is not stated in either instrument and is not claimed here.
What the common summaries get wrong
Summaries of this question in circulation in August 2026 commonly treat the Board as staffed and operational, and some state a mid 2026 appointment. No appointment appears in the primary material on file, and the most recent official document here is the circular of 6 May 2026 inviting applications. This paragraph is not a record of any particular answer from any particular service: no artefact was retained, so nothing is asserted beyond the primary position set out above.
The error matters in a specific way. A reader who believes the Board is operational may also believe there is a complaint route open to them today, spend time preparing one, and conclude that the law has failed them when nothing happens. The accurate position is less dramatic and more useful: there is no route yet, the dates are known, and the sequence is published.
What is actually available today
Not the Act's own machinery. Sections 11 to 14 carry the individual rights, and section 13 is the right to grievance redressal from a Data Fiduciary or Consent Manager, with section 13(3) requiring that route to be exhausted before the Board is approached. Sections 11 to 17 are all in the same 18 month group as section 27, so neither the right nor the remedy is in force. The rest of that run is not rights at all: section 15 is the Data Principal's duties, section 16 is the restriction on transfers outside India and section 17 is the exemptions.
What has not gone away is the framework the DPDP Act will eventually displace. Sub section (2) of section 44, which is the sub section that amends the Information Technology Act, 2000 by omitting section 43A and the rule making power in clause (ob) of section 87(2), sits in the 18 month group too, while only sub sections (1) and (3) commenced on publication. Until 44(2) commences, the pre DPDP position under the IT Act continues to stand rather than having been replaced. This site does not yet hold an official copy of the rules made under that Act, so we do not describe what they require; what we can say from the commencement notification alone is that the DPDP Act has not yet displaced them.
When to look again
2 dates, both computed and both labelled interpretation until officially confirmed: 13 November 2026, when section 6(9), section 27(1)(d) and Rule 4 commence, and 13 May 2027, when section 27 otherwise, sections 28 to 34, sections 11 to 17 and Rules 3, 5 to 16, 22 and 23 commence. An appointment could be notified at any time before either, and it would not move either date.
If you want the machinery itself rather than its status, how the Board will handle a complaint, an inquiry and an appeal sets out the process from the provisions, including the only clock the Act puts on the Board itself.
How the Board will handle complaints and penalties →What is in force under the DPDP framework →Section 27, official text with sources →