Concept
Data Protection Board of India
The enforcement body established under section 18, which is in force. Most of its core work is not in force yet. Receiving breach intimations and complaints and inquiring under section 27 commence on 13 May 2027, as does section 28 on the Board's procedure, although Rule 20, in force since 13 November 2025, already provides that the Board shall function as a digital office. From 13 May 2027, individuals can approach it only after exhausting the organisation's grievance channel under section 13(3). One exception is section 27(1)(d), inquiry into breaches of a Consent Manager's registration conditions, which commences on 13 November 2026. The 13 May 2027 and 13 November 2026 dates are computed from the notification, so treat them as interpretation until officially confirmed.
“Board” means the Data Protection Board of India established by the Central Government under section 18
Read section 2 of the Act, where this term is defined →Rule 19 of the DPDP Rules 2025 →Rule 20 of the DPDP Rules 2025 →
DPDP grievance redressal: what Rule 14(3) says about 90 days →
Sources cited on this page
- [1]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 2(c), p. 2. Published 11 August 2023. Official source ↗ · Official requirement · Verified 17 August 2026In force since 13 November 2025