Comprehensive guide to India's Data Protection Board - powers, functions, structure and operations
The digital landscape of India is set for a significant transformation with the enforcement of the Digital Personal Data Protection Act, 2023 ("DPDP Act"). At the core of the legislation stands the Data Protection Board of India ("Board"), a powerful regulatory body poised to reshape how business organisations will handle the personal data of the Data Principals in India and across the borders.
As the enforcement of this legislation comes closer, it is pertinent to understand the shape, structure and powers of this regulatory body.
Section 18 of the DPDP Act provides for the establishment of the Board by the Central Government. It is tasked with overseeing compliance with India's data protection regulations. Far from being a mere advisory body, the Board operates with the powers of a civil court as stipulated under Section 28(7), giving it significant authority to investigate breaches, adjudicate disputes, and impose substantial penalties.
This independent regulatory body represents the enforcement arm of the DPDP Act, with jurisdiction to impose penalties of up to ₹250 Crore per violation. The scale of these potential penalties underscores the importance of the Board in the data protection ecosystem of India.
Section 27 of the DPDP Act has equipped the Board with extensive powers and functions which extend beyond simple oversight. These include:
The Board is empowered to take immediate actions whenever they are notified of the data breach. For instance, it can issue orders requiring certain measures to be taken to minimise the damage arising from the breach incident, has the authority to investigate the data breach and is empowered to impose penalties for the violation of the provisions of the legislation.
As per the Draft DPDP Rule, the businesses are required to:
The Board has the power to extend this 72 hour notice requirement window in cases where it receives a written request from the Data Fiduciary.
The Board is empowered to take actions following a Data Principals' complaint pertaining to the violations of his/ her rights guaranteed by the legislation. The Board can also investigate the organisations that fail to meet their obligations as stipulated in the legislation.
The Data Protection Board is empowered to investigate the complaints filed against the Consent Managers and can take actions against them in case they fail to fulfill their obligations under the legislation.
The Board has the authority to investigate the matters referred to it by the Central and the State Governments. It can take actions based on the directions of the court. Furthermore, it can specifically conduct an investigation into the intermediaries, such as the social media platforms, as and when required by the Government.
The Data Protection Board is empowered to issue binding directions to any individual after they were given the chance of being heard. These directions must be recorded with reasons and must be complied by the individuals to whom they are issued.
The Data Protection Board is empowered to modify, suspend, withdraw or cancel any of its directions. The same can be done on the basis of the representations made by the affected individuals or on the basis of the references from the Central Government.
The remedial measures laid down under the legislation portray the flexible enforcement approach that the Board is empowered to adopt while granting remedies to the aggrieved party. These include:
The Board can issue temporary directives during investigations to prevent ongoing harm
Disputes may be referred to mediation for amicable resolution
Businesses can proactively commit to specific corrective actions to address compliance issues before they escalate
The Board will consist of a Chairperson and multiple Members, all appointed by the Central Government. These members will:
A distinctive feature of the Board is its functioning as a digital office. The Draft DPDP Rules indicate that the Board will adopt "techno-legal measures" to ensure digital operations, including:
This digital approach aligns with modern governance principles and aims to streamline regulatory processes, potentially leading to faster complaint resolution and more efficient interactions between the DPB and regulated entities.
The legislative framework establishes a three-tier appeal process against the decisions of the Board:
Challenges against the orders of the Board can be brought before the Telecom Disputes Settlement and Appellate Tribunal (TDSAT). The period of limitation for filing such an appeal is sixty (60) days from the date of receipt of the order or direction of the Board against which the appeal is sought.
Appeals against the decision of the TDSAT shall lie before the Supreme Court of India as per Section 18 of the Telecom Regulatory Authority of India Act, 1997. Such an appeal has to be filed within ninety (90) days from the date of the decision or order of the TDSAT.
The Board retains the authority to modify, suspend, or withdraw its own directives if circumstances warrant
This structured appeal system provides businesses with opportunities to seek review of DPB decisions while ensuring that fundamental data protection principles are upheld.
The Data Protection Board of India represents the enforcement backbone of India's new data protection regime. With its extensive powers, digital operations, and significant authority to impose penalties, the Board will undoubtedly reshape how businesses approach data protection compliance in India.
While the Board has not yet been officially established, its imminent formation signals the beginning of a new era in Indian data privacy regulation. Businesses that prepare now, by updating their data practices, strengthening consent mechanisms, and establishing robust compliance programs, will be better positioned to navigate this evolving regulatory landscape.
At this juncture, organizations should stay informed about developments and adapt their compliance strategies accordingly. In this new privacy landscape, proactive engagement with regulatory requirements will be key to avoiding penalties and building trust with customers and regulatory authorities alike.
Reach out to Data>Nuance to ensure compliance with the provisions of the DPDPA and ensure your practices meet legal standards while safeguarding your business from regulatory penalties. Let's make compliance effortless—before regulators make it expensive!