Skip to main content

The 3rd and main DPDP commencement date is computed as 13 May 2027, which is interpretation until officially confirmed.

Sources last verified on 9 October 2026. Methodology

Is the Data Protection Board operational? 2 separate reasons it is not

Enforcement

By · Primary sources verified by dpdprules.orgPublished · Last reviewed 15 min read

Is the Data Protection Board of India operational?

The short answer

No, and for 2 independent reasons that are usually run together. First, no appointment of a Chairperson or of any Member has been located in the primary record: the Board was established on 13 November 2025 by notification G.S.R. 844(E), MeitY was still inviting applications by a circular of 6 May 2026, and no appointment notification has been located, in a search of official channels on 28 August 2026 or in MeitY's published document library as enumerated on 7 October 2026. Second, the Board's enforcement powers are not in force. Notification G.S.R. 843(E) commenced sections 18 to 26, which constitute the Board, on publication on 13 November 2025, and placed section 27, which carries its powers and functions, in the 18 month group, computed here as 13 May 2027 and interpretation until officially confirmed; the one exception is clause (d) of section 27(1), on breach of a Consent Manager's registration conditions, which is in the 1 year group, computed as 13 November 2026 and interpretation until officially confirmed. So appointing members would not by itself create a complaint route.

More answered questions →

Diagram: 2 gaps, not 1. The same diagram appears further down this article, where it is described in full.

The Data Protection Board of India is not operational, and almost every account of why gives only half the reason. There are 2 gaps, they are independent of each other, and closing the one everybody discusses would not open a route for anybody.

2 gaps, not 1: why the Data Protection Board cannot take a complaint, and why appointing members would not change that. Gap 1, no members: the Board was established on 13 November 2025 by G.S.R. 844(E), its strength notified as 4 members by G.S.R. 845(E), and a MeitY circular of 6 May 2026 invites applications, but no appointment notification was located in MeitY's published document library as enumerated on 7 October 2026. Neither section 19(2) nor Rule 17(3) requires an appointment to be gazetted, so absence is weak evidence either way. Gap 2, no powers: sections 18 to 26 are in force, so the Board is constituted and may hold property, contract, sue and hire staff, but section 27, its powers and functions, is not in force, and neither are sections 28 to 34 on inquiry, appeal and penalty. That is the half most accounts leave out: staffing the Board would not by itself open a route for anybody. The sequence the notifications set runs from the Board existing on 13 November 2025, to Consent Manager registration under Rule 4, section 6(9) and section 27(1)(d) on the computed date 13 November 2026, to complaints from individuals under section 27(1)(b) and (c) and sections 28 to 34 on the computed date 13 May 2027. Both future dates are computed from the publication date printed on Gazette issue No. 757 and are interpretation until officially confirmed.

Gap 1: no appointment to the Board has been located

The Board exists. Notification G.S.R. 844(E) established it on 13 November 2025, with its head office in the National Capital Region, and G.S.R. 845(E) of the same date notified, under section 19(1), that the Board "shall consist of four members". Section 19(1) speaks of a Chairperson "and such number of other Members as the Central Government may notify", and MeitY's own circular of 6 May 2026 advertises 1 post of Chairperson and 4 posts of Member, so the 4 are read here as Members besides the Chairperson. That reading is this site's, not something 845(E) says.

Being established is not the same as being staffed. On 6 May 2026 MeitY issued circular F. No. 2(1)/2026-Pers.I, addressed to the Secretaries of all Ministries and Departments, the Chief Secretaries of all States and Union Territories and its own bodies, under the subject "Appointment to the post of Chairperson and Other Members in the Data Protection Board of India (DPBI) — regarding." That circular invites applications, in its own words for "preparing a panel of names to be considered by a Search-cum-Selection Committee", which is the machinery Rule 17 of the DPDP Rules 2025 requires and which has been in force since publication under Rule 1(2). The words "appointed" and "hereby appoints" do not appear anywhere in its 6 pages. It is evidence of a process running, not of a process finished.

A search of official channels on 28 August 2026 located no appointment notification. Since then, apart from the 29 August refetch of MeitY's Board page described below, MeitY's published document library has been read: as enumerated on 7 October 2026 and kept on file, 6 of its records have titles naming the Board. They are the 3 records the library dates 14 November 2025 on its establishment and composition, the circular and the advertisement of 6 May 2026 inviting applications, and an item of 25 June 2026 whose own title begins Archived, and none of them is an appointment, judged on the copies held here for the circular and the advertisement and on the record titles for the rest. That reading is narrower than the 28 August search, which has not been repeated, because a published library is not the Gazette. Either way it is a statement about what we could find rather than a certified negative, and 3 limits are worth stating. MeitY's own Data Protection Board page gave us nothing to read: meity.gov.in/data-protection-board-of-india loaded in a browser on 27 August 2026 rendered blank, and refetched on 29 August 2026 it answers HTTP 200 with 3,285 bytes containing no Board content at all. That 200 carries no information, and we can show it rather than assume it. On 29 August 2026 we requested 4 paths on that host: the Board page, meity.gov.in/data-protection-board, the unrelated meity.gov.in/data-protection-framework, and meity.gov.in/dpbi, a path we invented for the test and which certainly does not exist. All 4 returned HTTP 200 and the identical 3,285 bytes, the same SHA256. So the host answers every path with one shell, and a 200 from it is not evidence that a page exists, let alone that it is empty. It also refuses some automated fetchers with HTTP 403, which is a fact about the client rather than about the page. What follows is only that we could read nothing there, so an appointment published only on that page could in principle have been missed. Neither section 19(2) of the Act nor Rule 17(3) of the Rules requires an appointment to be published in the Official Gazette, so the absence of a Gazette notification is weak evidence in either direction. And secondary legal commentary published on 1 August 2026 reports a further MeitY notification of 6 June 2026 about the appointment process, which we have not been able to obtain, so the primary trail on file stops at 6 May 2026 rather than being complete. What we can say is that the archived primary material shows a selection process at the application stage, and that nothing in the source registry records an appointment.

This is the gap that gets written about. It is also the one that would be easiest to close, and closing it would change less than most readers expect.

Gap 2: the Board's powers are not in force

Notification G.S.R. 843(E) appointed the Act's commencement in 3 groups, which the overview of DPDP sets out side by side. The first group took effect on publication:

Official requirement · Notification G.S.R. 843(E), (a)

"the date of publication of this notification in the Official Gazette as the date on which the provisions of sub-section (2) of section 1, section 2, sections 18 to 26 sections 35, 38, 39, 40, 41, 42, 43, and sub- sections (1) and (3) of section 44 of the said Act shall come into force"

The missing comma and the broken word are as printed. Sections 18 to 26 are the Board's constitution: establishment, composition, qualifications for appointment, salaries and terms, disqualifications, resignation and removal, officers and employees, and the procedure it is to follow. All of that is live now.

Section 27 is not in that list. Section 27 is the section that gives the Board its powers and functions, and clause (c) of the notification places it in the 18 month group, "section 27 except clause (d) of sub-section (1) of the said section". Sections 28 to 34, which carry the inquiry procedure, appeals to the Appellate Tribunal and the penalty machinery, are in the same group. Computed from the printed publication date, that group is due on 13 May 2027, and that calendar date is interpretation until officially confirmed.

So the Board today is a body that lawfully exists, may lawfully be staffed, and holds none of the powers and functions in section 27. What paragraph (a) does give it is institutional rather than regulatory. Section 18(2) makes it a body corporate with power to acquire, hold and dispose of property, to contract and to sue or be sued. Section 24 lets it appoint officers and employees with the previous approval of the Central Government, which Rule 21 repeats. Section 26 gives the Chairperson general superintendence over administrative matters, the power to have an officer scrutinise anything addressed to the Board, and the power to allocate proceedings among Members. Rules 17 to 21 have been in force since publication under Rule 1(2). None of that lets the Board act on a breach, a complaint or a reference.

Which means a complaint has nowhere to go, twice over

The 2 routes an individual would use are in section 27(1):

ClauseWhat it coversCommences
(a)Acting on a breach intimation from a Data Fiduciary, including urgent remedial directions18 month group
(b)A complaint by a Data Principal about a breach, about a Data Fiduciary's obligations or about the exercise of her rights, and also a Central or State Government reference or a court direction18 month group
(c)A complaint by a Data Principal about a Consent Manager's obligations18 month group
(d)An intimation that a Consent Manager has breached a condition of its registration1 year group
(e)A Central Government reference about an intermediary under section 37(2)18 month group

Read that table against the notification and the sequencing becomes visible. The first of the section 27 powers the Board will hold is clause (d), and it arrives with section 6(9), on registration of Consent Managers with the Board, in the 1 year group computed as 13 November 2026, interpretation until officially confirmed. Clause (d) is not a complaint route at all: it is triggered by an intimation that a Consent Manager has breached a condition of its registration.

Rule 4 of the DPDP Rules 2025 lands in the same 1 year group under Rule 1(3), and it is the substantive half of the pair. Rule 4 has a would be Consent Manager apply to the Board, lets the Board inquire into the application and register or reject it, lets it, after a hearing, direct a Consent Manager to take measures where it is not adhering to its conditions and obligations, and lets it, after a hearing and where satisfied that it is necessary in the interests of Data Principals, suspend or cancel a registration by order for reasons recorded in writing. Those functions carry their own procedure inside the rule. Clause (d) of section 27(1) does not: it points at inquiry and penalty, and the inquiry procedure in section 28 and the penalty power in section 33 are both in the 18 month group. So on this site's reading the 1 year date gives the Board a working registration function under Rule 4 and a section 27 trigger whose consequences are not yet in force. That reading is interpretation, and nothing in the Act or the Rules addresses the overlap.

The Board's first work is administering Consent Manager registration, not hearing from individuals. Complaints under clauses (b) and (c) follow 6 months later, with the rest of the framework. Who has to register, and on what conditions, is the subject of Rule 4 and who it applies to.

That is the sequence the 2 notifications set, and it explains why appointing a Chairperson tomorrow would not give anybody a complaint to file. There would be a Board, correctly constituted under provisions already in force, whose first substantive work arrives in November 2026 and concerns Consent Managers and nothing else. Whether the sequence was intended to run that way is not stated in either instrument and is not claimed here.

What the Wikipedia article on the Board says, checked against the instruments

Wikipedia's article on the Data Protection Board of India is an openly editable page, and at the revision checked for this update it tells a reader that the Board has a Chairperson. That revision was saved on 15 June 2026 and was still the current revision when we checked it on 28 August 2026. Its infobox carries a chief1_name field holding a personal name, with chief1_position set to "Chairperson", and no citation is attached to either field. We do not reprint the name: the permanent link in the sources panel below opens that exact revision, so anybody can read that field's value as it stood, and see the field names themselves by opening the same revision in raw form.

The saved date is not the date the name appeared, either. The edit summary on that revision is a citation cleanup, so the field is older than 15 June 2026 and we have not established when it was added. No entry in the article's reference list is presented as a source for an appointment. The 1 untitled MeitY PDF in that list is the citation for the Rules sentence below, and we have now identified it. Its URL sits on the legacy writereaddata path that MeitY has since reorganised away from: on 28 August 2026 it answered HTTP 404 to 2 of our clients and HTTP 403 to a third, which is a fact about our retrieval and not about the file. The Internet Archive holds a capture of that same URL taken on 8 January 2025, and the file it returns is byte for byte identical, by SHA256, to the copy of the draft DPDP Rules this site already archives.

No appointment notification for a Chairperson or Member of the Data Protection Board of India has been located: a search of official channels on 28 August 2026 found none, and none was located in MeitY's published document library as enumerated on 7 October 2026, judged on the copies held here for the 6 May 2026 circular and advertisement and on the record titles for the rest. That is a statement about what a search found rather than a certified negative. The most recent official document held here about the Board's appointment is MeitY's circular of 6 May 2026 inviting applications, whose SHA256 we rechecked against the copy MeitY serves on 9 October 2026 and found unchanged, together with the undated advertisement issued alongside it, also unchanged that day. The library's later item of 25 June 2026 is listed under a title beginning Archived and, judged on that title, is not an appointment. Legal commentary published on 1 August 2026 says the same thing in terms, that the Board has no appointed Chairperson and no appointed Members.

Nothing here is a claim about the person whose name that field holds. The entry is an uncited edit to a page anybody may edit, including anybody who reads this; what can be checked is the primary record, and no appointment has been located in it. The revision is linked from the sources panel so the check can be repeated after the page changes.

Three further statements on that revision do not survive a check against the instruments. The left column quotes that revision as a reader sees it, with the page's internal link markup resolved to the words it displays; the sources panel below quotes the same passages from the archived wikitext, which is the form the revision is served in and the form our quotes are machine checked against.

What that revision statesWhat the instrument says
"According to the section 18 of the Digital Personal Data Protection Act, 2023, the board shall consist a Chairperson."Section 18 is headed Establishment of Board. It establishes the Board, makes it a body corporate and provides for its headquarters to be at such place as the Central Government may notify. The words Chairperson and Member do not appear in it. Composition is section 19(1): the Board "shall consist of a Chairperson and such number of other Members as the Central Government may notify".
"Under the Digital Personal Data Protection Rules, 2025, the board shall consist a Chairperson along with members who will be appointed as per the extant rules."The Rules do not fix the composition, and the document cited for this sentence is not the Rules. It is G.S.R. 02(E) of 3 January 2025, the DRAFT published for consultation and superseded 10 months later by the notified Rules, G.S.R. 846(E), identified from the Internet Archive capture of the cited URL and matched by SHA256 to the copy archived here. Composition is fixed by section 19(1) of the Act: G.S.R. 845(E), made under it, notifies that the Board "shall consist of four members", and reading those 4 as Members besides the Chairperson is this site's inference, corroborated by the 1 Chairperson post and 4 Member posts in MeitY's circular of 6 May 2026. Even the draft does not fix the composition: its rule 16 is the same Search cum Selection Committee machinery that became Rule 17 on notification, and what the Rules prescribe is the manner of appointment under section 19(2), the Central Government appointing "after considering the suitability of individuals recommended" by those committees.
A list headed Powers and functions, opening "The Data Protection Board shall exercise and perform its powers on receipt of an intimation of personal data breach under sub-section (6) of section 8"That follows section 27(1)(a), which is not in force. Nor are the other items: alternate dispute resolution is section 31, voluntary undertakings section 32, and advising the Government to block is section 37, all in the same 18 month group. Nothing on the list says so, and one item still refers to "the provisions of the Bill".

The first 2 of those name the wrong enabling provision, which is a citation error rather than a claim about the law's effect. The third is the one that matters here, because it describes powers the Act has not commenced as though the Board holds them today. That is the distinction the whole of Gap 2 above turns on, and neither the encyclopedia entry nor most summaries of it draw it.

The error matters in a specific way. A reader who believes the Board is staffed and operational may also believe there is a complaint route open to them today, spend time preparing one, and conclude that the law has failed them when nothing happens. The accurate position is less dramatic and more useful: there is no route yet, the dates are known, and the sequence is published.

What is actually available today

Not the Act's own machinery. Sections 11 to 14 carry the individual rights, and section 13 is the right to grievance redressal from a Data Fiduciary or Consent Manager, with section 13(3) requiring that route to be exhausted before the Board is approached. Sections 11 to 17 are all in the same 18 month group as section 27, so neither the right nor the remedy is in force. The rest of that run is not rights at all: section 15 is the Data Principal's duties, section 16 is the Central Government's power to restrict, by notification, transfers outside India and section 17 is the exemptions.

What has not gone away is the framework the DPDP Act will eventually displace. Sub section (2) of section 44, which is the sub section that amends the Information Technology Act, 2000 by omitting section 43A and the rule making power in clause (ob) of section 87(2), sits in the 18 month group too, while only sub sections (1) and (3) commenced on publication. Until 44(2) commences, the pre DPDP position under the IT Act continues to stand rather than having been replaced. Section 43A of that Act is now quoted on this site, in can I sue under the DPDP Act. This site does not yet hold an official copy of the rules made under that Act, so we do not describe what they require; what we can say from the commencement notification alone is that the DPDP Act has not yet displaced them.

When to look again

2 dates, both computed and both labelled interpretation until officially confirmed: 13 November 2026, when section 6(9), section 27(1)(d) and Rule 4 commence, and 13 May 2027, when section 27 otherwise, sections 28 to 34, sections 11 to 17 and Rules 3, 5 to 16, 22 and 23 commence. An appointment could be notified at any time before either, and it would not move either date.

If you want the machinery itself rather than its status, how the Board will handle a complaint, an inquiry and an appeal sets out the process from the provisions, including the only clock the Act puts on the Board itself.

How the Board will handle complaints and penalties →What is in force under the DPDP framework →Section 27, official text with sources →

Data Protection BoardSection 27CommencementMyth correction

Share this: