CHAPTER VI - POWERS, FUNCTIONS AND PROCEDURE OF BOARD

Section 27 - Powers and functions of Board

Official text

(1)The Board shall exercise and perform the following powers and functions, namely:—

(a)on receipt of an intimation of personal data breach under sub-section (6) of section 8, to direct any urgent remedial or mitigation measures in the event of a personal data breach, and to inquire into such personal data breach and impose penalty as provided in this Act;

(b)on a complaint made by a Data Principal in respect of a personal data breach or a breach in observance by a Data Fiduciary of its obligations in relation to her personal data or the exercise of her rights under the provisions of this Act, or on a reference made to it by the Central Government or a State Government, or in compliance of the directions of any court, to inquire into such breach and impose penalty as provided in this Act;

(c)on a complaint made by a Data Principal in respect of a breach in observance by a Consent Manager of its obligations in relation to her personal data, to inquire into such breach and impose penalty as provided in this Act;

(d)on receipt of an intimation of breach of any condition of registration of a Consent Manager, to inquire into such breach and impose penalty as provided in this Act; and

(e)on a reference made by the Central Government in respect of the breach in observance of the provisions of sub-section (2) of section 37 by an intermediary, to inquire into such breach and impose penalty as provided in this Act.

(2)The Board may, for the effective discharge of its functions under the provisions of this Act, after giving the person concerned an opportunity of being heard and after recording reasons in writing, issue such directions as it may consider necessary to such person, who shall be bound to comply with the same.

(3)The Board may, on a representation made to it by a person affected by a direction issued under sub-section (1) or sub-section (2), or on a reference made by the Central Government, modify, suspend, withdraw or cancel such direction and, while doing so, impose such conditions as it may deem fit, subject to which the modification, suspension, withdrawal or cancellation shall have effect.

Cross-references

Section 27

Commentary

1.1 Detailed commentary, interpretive issues and comparison with the GDPR

Rule-numbering clarification: In the final DPDP Rules, 2025,Rule 20, not Rule 19, governs the Board’s functioning as a digital office. Final Rule 19 regulates Board meetings, authentication of its instruments and the period for completing inquiries.

2. Overall structure and function of Section 27

Section 27 is the principal provision identifying the matters that may activate the Data Protection Board’s inquiry and enforcement jurisdiction.

It performs three related functions:

  1. It identifies the statutory gateways through which a matter may reach the Board, including breach intimations, Data Principal complaints, Government references, court directions and Consent Manager registration-breach intimations.

  2. It empowers the Board to inquire into the alleged breach and impose a monetary penalty, where the inquiry establishes a breach for which the Act provides a penalty.

  3. It authorises the Board to issue binding directions and subsequently review those directions, subject to the safeguards in subsections (2) and (3).

Section 27 must be read with:

  • Section 8(6) for personal data breach intimations;

  • Section 13(3) for exhaustion of internal grievance redressal;

  • Section 28 for the procedure of inquiry;

  • Section 31 for alternate dispute resolution;

  • Section 32 for voluntary undertakings;

  • Section 33 and the Schedule for monetary penalties;

  • Section 37(2) for intermediary non-compliance;

  • Rules 19 and 20 for inquiry timing and digital functioning.

The basic enforcement sequence is:

  1. STATUTORY TRIGGER UNDER SECTION 27(1)
  2. PRELIMINARY DETERMINATION UNDER SECTION 28
  3. INQUIRY, IF SUFFICIENT GROUNDS EXIST
  4. OPPORTUNITY TO BE HEARD AND FACTUAL DETERMINATION
  5. DISMISSAL, DIRECTIONS, VOLUNTARY UNDERTAKING, ADR, OR MONETARY PENALTY AS LEGALLY APPLICABLE

Section 27 does not give the Board a broad, free-standing power to investigate any privacy-related matter it chooses. Its jurisdiction must arise through one of the routes identified in the Act.

3. Part I: Statutory gateways to the Board

4. Personal data breach intimation under Section 27(1)(a)

Section 27(1)(a) applies when the Board receives an intimation of a personal data breach under Section 8(6).

Section 8(6) requires the Data Fiduciary to intimate a personal data breach to:

  • the Board; and

  • each affected Data Principal, in the form and manner prescribed.

A breach intimation can activate three distinct Board responses:

  1. urgent remedial or mitigation directions;

  2. inquiry into the personal data breach; and

  3. imposition of a penalty where a breach of the Act is established.

These powers should not be treated as identical.

5. Urgent remedial or mitigation measures

The Board may direct urgent measures “in the event of a personal data breach.”

The immediate purpose is protective rather than punitive. The Board may intervene to reduce:

  • continuing exposure;

  • unauthorised access;

  • misuse;

  • loss of availability;

  • adverse consequences for affected Data Principals.

The precise direction will depend on the nature of the breach. It may potentially require measures directed at:

  • containing the incident;

  • securing compromised systems;

  • preserving relevant evidence;

  • restricting compromised access;

  • warning or assisting affected Data Principals;

  • preventing further disclosure.

Section 27 does not list a closed set of permitted mitigation measures. The direction must still be:

  • connected with the personal data breach;

  • directed to an appropriate person;

  • necessary for mitigation or remediation;

  • consistent with the Act.

The Board’s urgent direction is not itself a finding that the Data Fiduciary has violated Section 8(5) or another provision. Immediate containment may be necessary before responsibility, fault and penalty are determined.

6. Inquiry into the breach

After receiving an intimation, the Board may inquire into the breach.

The inquiry may examine matters such as:

  • whether a personal data breach occurred;

  • the nature, extent and duration of the breach;

  • personal data and Data Principals affected;

  • safeguards maintained under Section 8(5);

  • processor involvement;

  • the Data Fiduciary’s response;

  • whether notification obligations were observed;

  • whether another DPDPA obligation was breached.

The occurrence of a personal data breach does not necessarily establish a failure to take reasonable security safeguards. A system may suffer a breach despite reasonable safeguards. The inquiry must determine whether the Data Fiduciary failed to observe the statutory obligation, not merely whether an incident occurred.

7. Penalty

A penalty may be imposed only “as provided in this Act.”

Section 27 is therefore not an independent penalty schedule. The Board must identify:

  • the provision breached;

  • the applicable penalty entry in the Schedule;

  • the matters relevant under Section 33;

  • the factual basis supporting the penalty.

A breach in observing reasonable security safeguards under Section 8(5) may attract a penalty extending to ₹250 crore. A breach of the Section 8(6) notification obligation may attract a penalty extending to ₹200 crore. Those are statutory maxima, not automatic amounts for every breach.

8. Self-reporting does not create immunity

A Data Fiduciary that complies with Section 8(6) by reporting a breach does not thereby receive immunity from inquiry or penalty.

However, compliance with breach reporting is distinct from the underlying security issue. A Data Fiduciary may:

  • comply with Section 8(6) but still be found to have breached Section 8(5);

  • maintain reasonable safeguards but breach Section 8(6) by failing to notify;

  • comply with both, despite the occurrence of a breach.

The Board must assess each obligation independently.

9. Data Principal complaints against Data Fiduciaries under Section 27(1)(b)

Section 27(1)(b) creates the principal complaint route against a Data Fiduciary.

A Data Principal may complain about:

  1. a personal data breach;

  2. breach by a Data Fiduciary of an obligation relating to her personal data; or

  3. breach relating to the exercise of her rights under the Act.

The Board may then inquire into the alleged breach and impose a penalty as provided by the Act.

10. Complaint about a personal data breach

A complaint may be made even though the Data Fiduciary was independently required to intimate the breach under Section 8(6).

The complaint route is important where the Data Principal alleges that:

  • the breach was not reported;

  • the breach notification was incomplete;

  • remedial measures were inadequate;

  • the Data Fiduciary denied that a breach occurred;

  • the Data Principal discovered the incident independently.

The Board’s jurisdiction does not depend exclusively on the Data Fiduciary self-reporting the incident.

11. Complaint about Data Fiduciary obligations

The wording extends to breach of any applicable Data Fiduciary obligation in relation to the complainant’s personal data.

Depending on the circumstances, the complaint may concern:

  • notice;

  • consent;

  • processing beyond a specified purpose;

  • an invalid claim of legitimate use;

  • processor governance;

  • data accuracy;

  • technical and organisational measures;

  • security safeguards;

  • breach notification;

  • retention and erasure;

  • contact information;

  • grievance redressal;

  • children’s data;

  • SDF obligations.

The complaint must concern an obligation that actually applies to the processing. If an exemption under Section 17 disapplies the relevant obligation, Section 27 cannot recreate it through the complaint mechanism.

12. Complaint concerning exercise of rights

The complaint route also covers failures relating to Data Principal rights, including:

  • access under Section 11;

  • correction or erasure under Section 12;

  • grievance redressal under Section 13;

  • nomination under Section 14.

The underlying right remains subject to its own statutory conditions.

Example

For example, a complaint alleging breach of Section 12 must still account for:

  • Section 12’s prior-consent condition;

  • the specified-purpose retention exception;

  • legal-retention requirements;

  • any applicable Section 17 exemption.

Section 27 supplies the enforcement route. It does not enlarge the substantive right.

13. Exhaustion of internal grievance redressal

Section 27(1)(b) must be read with Section 13(3), which requires the Data Principal to exhaust the opportunity of grievance redressal with the Data Fiduciary or Consent Manager before approaching the Board.

Ordinarily, the sequence is:

  1. INITIAL RIGHTS REQUEST OR PRIVACY ISSUE
  2. INTERNAL GRIEVANCE UNDER SECTION 13
  3. RESPONSE OR EXPIRY OF PUBLISHED RESPONSE PERIOD
  4. COMPLAINT TO THE BOARD

The requirement is to exhaust the opportunity, not to obtain a satisfactory outcome.

The internal route may be exhausted when:

  • the Data Fiduciary gives a final substantive response and the Data Principal remains dissatisfied; or

  • the published grievance-response period expires without an effective response.

A Data Principal should not be required to pursue endless internal appeal levels that the Data Fiduciary creates merely to delay access to the Board.

14. Does exhaustion apply to every Section 27(1)(b) complaint?

The safer reading is that a Data Principal complaining under Section 27(1)(b) should ordinarily first use Section 13 because the complaint concerns the Data Fiduciary’s act or omission relating to her personal data or rights.

Where a complaint concerns a personal data breach, urgent protective action may be required. Section 13(3) does not expressly create an emergency exception, but internal exhaustion should not be interpreted as preventing the Board from acting upon:

  • an independent Section 8(6) breach intimation;

  • a Government reference;

  • a court direction;

  • another statutory trigger.

The complaint route and the breach-intimation route are separate gateways.

15. Government references and court directions

Section 27(1)(b) is not limited to Data Principal complaints.

The Board may also act:

  • on a reference made by the Central Government;

  • on a reference made by a State Government; or

  • in compliance with directions of a court.

16. Central or State Government reference

A Government reference can activate an inquiry even where no Data Principal complaint has been filed.

The reference must relate to a breach falling within the Board’s DPDPA jurisdiction. A Government cannot enlarge the Board’s statutory powers by referring a matter beyond the Act.

The Act does not prescribe in Section 27:

  • a mandatory reference format;

  • a minimum evidentiary threshold;

  • a requirement that a named Data Principal initiate the matter;

  • a separate limitation period.

The Board must still follow Section 28 and determine whether sufficient grounds exist to proceed.

17. Court direction

The Board may inquire in compliance with a court’s direction.

This allows a court dealing with a matter to direct the statutory Board to examine a DPDPA breach falling within its expertise.

A court direction is not itself necessarily a finding that the breach occurred. Unless the court has conclusively determined the factual or legal issue, the Board must conduct the inquiry contemplated by the Act.

The Board must comply with the direction while remaining within:

  • the subject matter referred;

  • its statutory powers;

  • the applicable inquiry procedure.

18. Internal exhaustion and non-complaint gateways

Section 13(3)’s exhaustion requirement is directed to a Data Principal approaching the Board.

It does not expressly condition:

  • Government references;

  • court directions;

  • breach intimations under Section 8(6).

Accordingly, those statutory routes should not be treated as unavailable merely because a Data Principal did not first pursue internal grievance redressal.

A Data Principal may complain that a Consent Manager failed to observe its obligations in relation to her personal data.

The Board may:

  • inquire into the alleged breach; and

  • impose a penalty as provided by the Act.

A Consent Manager occupies a specialised position. It enables Data Principals to give, manage, review and withdraw consent through an accessible, transparent and interoperable platform.

Potential complaint subjects may include:

  • inaccurate recording of consent;

  • failure to enable review or withdrawal;

  • failure to maintain consent records;

  • failure to make records available;

  • unauthorised reading of personal data contents;

  • security failures;

  • conflicts of interest;

  • non-compliance with platform obligations;

  • improper handling of Data Principal instructions.

The Consent Manager is not automatically responsible for every act of a Data Fiduciary connected to the platform.

If the Consent Manager correctly transmits a withdrawal but the Data Fiduciary continues processing, the principal breach lies with the Data Fiduciary.

If the Consent Manager fails to transmit or accurately record the withdrawal, the complaint may concern the Consent Manager.

A single incident may involve breaches by both entities. Their respective conduct must be assessed separately.

21. Processor and platform distinctions

The fact that a Consent Manager facilitates consent does not necessarily make it a Data Processor for every underlying processing operation.

Its statutory role and obligations must be assessed separately from the role of:

  • the Data Fiduciary seeking consent;

  • a processor handling the underlying personal data;

  • another Data Fiduciary holding and transferring the data.

Section 27(1)(d) applies when the Board receives an intimation that a Consent Manager has breached a condition of registration.

The Board may inquire into that breach and impose a statutory penalty.

This gateway differs from Section 27(1)(c).

SectionTriggerNature of alleged breach
27(1)(c)Complaint by a Data PrincipalConsent Manager obligation relating to her personal data
27(1)(d)Intimation of registration-condition breachCondition governing the Consent Manager’s registered status

A breach may engage both provisions. For example, a conflict-of-interest failure may:

  • breach a registration condition; and

  • affect a Data Principal’s consent management.

23. Source of the intimation

Section 27(1)(d) does not specify who must give the intimation.

Depending on the circumstances, the information may potentially come from:

  • an audit;

  • the Consent Manager;

  • another regulated entity;

  • a Government authority;

  • material otherwise lawfully placed before the Board.

The Board must still apply Section 28 before proceeding to a full inquiry.

24. Penalty and registration consequences

Section 27(1)(d) expressly mentions inquiry and penalty.

The Consent Manager framework separately permits the Board to suspend or cancel registration in accordance with the prescribed conditions and procedure.

Monetary penalty and registration action are legally distinct consequences. The Board should identify the source and conditions for each action rather than treating the word “penalty” in Section 27 as automatically including every registration measure.

25. Intermediary breach under Section 27(1)(e)

Section 27(1)(e) applies where the Central Government refers an intermediary’s breach of Section 37(2) to the Board.

Section 37 empowers the Central Government, in specified circumstances involving repeated Board penalties, to issue an order concerning access to information generated, transmitted, received, stored or hosted in a computer resource. Section 37(2) requires an intermediary to comply with that Government order.

If the intermediary fails to comply, the Central Government may refer the breach to the Board, which may inquire and impose a penalty as provided by the Act.

26. No direct Data Principal complaint under this paragraph

The gateway under Section 27(1)(e) requires a Central Government reference.

A Data Principal cannot directly invoke paragraph (e) as though it creates an individual complaint route against an intermediary for every failure.

27. Intermediary and Data Fiduciary roles

An intermediary may also be a Data Fiduciary for particular processing operations.

Its obligations must be analysed role by role:

  • a complaint about its own personal-data processing may fall under Section 27(1)(b);

  • failure to comply with Section 37(2) falls under Section 27(1)(e) through a Government reference.

28. Scope remains narrow

This provision does not give the Board general authority to enforce every obligation imposed on intermediaries under the Information Technology Act or its Rules.

The Board’s paragraph (e) jurisdiction concerns breach of Section 37(2) of the DPDPA.

29. Part II: Inquiry and penalty

30. “To inquire into such breach”

The matters listed in Section 27(1) do not automatically result in a finding or penalty.

The Board must inquire into the particular breach that activated its jurisdiction.

The inquiry must remain connected with:

  • the breach intimation;

  • complaint;

  • reference;

  • court direction;

  • registration-condition intimation.

Section 28 supplies the detailed procedural framework, including preliminary assessment, principles of natural justice, inquiry powers and closure where insufficient grounds exist.

31. Threshold before a full inquiry

Under Section 28, the Board must determine whether sufficient grounds exist to proceed.

This prevents every allegation from automatically becoming a complete adjudicatory inquiry.

If insufficient grounds exist, the matter may be closed for reasons recorded in writing.

32. Board’s investigatory powers

During an inquiry, the Board receives powers comparable to those of a civil court for specified purposes, including matters such as:

  • summoning and enforcing attendance;

  • examining persons on oath;

  • discovery and production;

  • receiving evidence;

  • inspecting data, books, documents and records.

Those powers arise under Section 28, not from Section 27 alone.

33. Inquiry timeline

Final Rule 19 states that an inquiry should be completed within six months from receipt of the relevant intimation, complaint, reference or direction under Section 27.

The Board may extend the period:

  • for reasons recorded in writing;

  • by no more than three months at a time.

The Rule does not expressly limit the Board to one extension. The words “at a time” permit successive reasoned extensions.

The expiry of the period does not expressly make the inquiry void automatically. However, unexplained or excessive delay may affect procedural fairness and can be relevant in appellate or judicial review.

34. Penalty is not the only possible outcome

Although Section 27(1) repeatedly refers to inquiry and penalty, the full statutory framework permits several possible outcomes:

  • closure for insufficient grounds;

  • dismissal after inquiry where no breach is established;

  • urgent mitigation directions;

  • binding directions under Section 27(2);

  • acceptance of a voluntary undertaking under Section 32;

  • reference to alternate dispute resolution under Section 31 where appropriate;

  • monetary penalty under Section 33.

A proven technical or procedural issue does not necessarily require the maximum penalty.

The Board must assess the penalty according to the statutory factors, including:

  • nature, gravity and duration of the breach;

  • type and nature of personal data affected;

  • repetitive nature of the breach;

  • gain or loss avoided;

  • mitigation;

  • proportionality and effectiveness.

35. No express compensatory jurisdiction

Section 27 authorises the Board to impose a statutory penalty. It does not expressly authorise the Board to award damages or compensation to the Data Principal.

Monetary penalties levied under the DPDPA are credited to the Consolidated Fund of India under Section 34. They are not automatically paid to the complainant.

A Data Principal may obtain practical redress through:

  • correction;

  • erasure;

  • cessation of processing;

  • mitigation directions;

  • compliance directions.

But Section 27 itself does not create a compensatory damages remedy.

36. Part III: Binding directions under Section 27(2)

37. Nature of the direction power

Section 27(2) gives the Board a broad but structured power to issue directions necessary for the effective discharge of its functions.

The Board may issue such directions to the person concerned, who is legally bound to comply.

This power is not confined to personal data breaches. It may be used in connection with the Board’s statutory functions where the requirements of subsection (2) are satisfied.

Possible directions may concern:

  • remediation of non-compliance;

  • cessation or alteration of an unlawful processing operation;

  • implementation of security measures;

  • completion of breach-related measures;

  • correction of a rights-handling mechanism;

  • steps necessary to give effect to the Act.

The direction must remain connected with the effective discharge of the Board’s statutory functions. It cannot be used to regulate matters outside the DPDPA.

38. Three safeguards before a direction

Before issuing a direction under Section 27(2), the Board must satisfy three requirements:

  1. the direction must be for the effective discharge of its functions under the Act;

  2. the person concerned must receive an opportunity of being heard;

  3. the Board must record reasons in writing.

These are cumulative safeguards.

39. Opportunity of being heard

The person concerned must have a meaningful opportunity to address:

  • factual basis;

  • proposed direction;

  • legal authority;

  • necessity;

  • practicability;

  • proportionality.

The exact form of hearing may vary. Section 27 does not invariably require an in-person oral hearing, particularly because the Board operates digitally. The opportunity must nevertheless be real and adequate.

40. Recorded reasons

The Board must explain why the direction is necessary.

Reasons support:

  • transparency;

  • accountability;

  • internal review under Section 27(3);

  • appeal under Section 29;

  • judicial review.

A direction stating only that compliance is “in the public interest” or “required under the Act,” without connecting the measure to the facts and statutory function, may not satisfy the requirement adequately.

41. Necessity and proportionality

Section 27(2) uses the words “as it may consider necessary.”

The Board must therefore connect the direction with the objective to be achieved. A direction should not impose a burden materially wider than required for effective discharge of the relevant function.

Although Section 27 does not expressly use the word “proportionate,” proportionality is relevant to the statutory necessity analysis and fair exercise of regulatory discretion.

42. Binding effect and non-compliance

The person receiving a Section 27(2) direction is bound to comply.

The person cannot treat the direction as advisory merely because:

  • she disagrees with it;

  • she intends to seek modification;

  • an appeal is contemplated.

Unless the direction is:

  • suspended;

  • modified;

  • withdrawn;

  • cancelled;

  • stayed by the Appellate Tribunal or another competent authority, it remains operative according to its terms.

The exact enforcement consequence of disobedience must be found in the applicable provisions of the Act. Section 27(2) states the binding obligation, but it should not be treated as an independent, unlimited contempt jurisdiction.

43. Difference between urgent directions and general directions

Section 27 contains two direction mechanisms.

43.1 Directions under Section 27(1)(a)

  • arise in the event of a personal data breach;

  • concern urgent remedial or mitigation measures;

  • are designed for immediate incident response.

43.2 Directions under Section 27(2)

  • support effective discharge of the Board’s functions generally;

  • require an opportunity of being heard;

  • require written reasons;

  • are not limited to breach containment.

Section 27(3) expressly refers to directions under either subsection (1) or subsection (2), confirming that both types may be reviewed.

A tricky issue is that urgent directions under Section 27(1)(a) may need to be issued before a full pre-direction hearing is practically possible. The express hearing requirement appears in subsection (2), not paragraph (1)(a). This drafting supports the Board acting rapidly under paragraph (1)(a), with subsequent representation and review under subsection (3).

The Board should nevertheless follow fair procedure compatible with the urgency, particularly where the direction is highly intrusive.

44. Part IV: Modification and review under Section 27(3)

45. Who may seek review of a direction?

A person affected by a direction issued under:

  • Section 27(1); or

  • Section 27(2), may make a representation to the Board.

The Central Government may also make a reference concerning the direction.

The expression “person affected” may be wider than the direct addressee.

A direction may affect:

  • a Data Fiduciary;

  • Consent Manager;

  • intermediary;

  • processor or service provider, depending on the terms;

  • another person whose rights or operations are directly affected.

A purely remote or ideological concern would not necessarily make the person “affected.” There should be a sufficient connection between the direction and the person’s legal or practical interests.

46. Board’s review options

After receiving a representation or Government reference, the Board may:

  • modify the direction;

  • suspend it;

  • withdraw it;

  • cancel it.

These outcomes have different effects.

46.1 Modification

The direction continues in altered form.

The Board may change:

  • scope;

  • timing;

  • technical requirement;

  • reporting obligation;

  • affected processing.

46.2 Suspension

The direction remains legally extant but its operation is temporarily paused, subject to the terms of suspension.

46.3 Withdrawal

The Board retracts the direction, ordinarily on the basis that it should no longer continue.

46.4 Cancellation

The direction is brought to an end through the Board’s formal decision.

The statute uses both “withdraw” and “cancel,” but does not define the exact distinction between them. Their effect must be determined from the Board’s order and the context.

47. Conditions attached to review relief

The Board may impose conditions governing the effect of:

  • modification;

  • suspension;

  • withdrawal;

  • cancellation.

Example

For example, relief may be conditional on:

  • completion of specified mitigation;

  • preservation of evidence;

  • periodic reporting;

  • restricted processing;

  • implementation of safeguards.

The conditions must remain connected with the subject matter and the Board’s statutory functions. Section 27(3) does not authorise unrelated commercial, punitive or extraneous conditions.

48. Representation is not the same as appeal

A representation under Section 27(3) asks the Board itself to reconsider a direction.

An appeal under Section 29 challenges an order or direction before the Appellate Tribunal.

The two remedies are distinct:

Representation under Section 27(3)Appeal under Section 29
Made to the BoardMade to the Appellate Tribunal
Concerns modification, suspension, withdrawal or cancellation of a directionChallenges an order or direction on appellate grounds
Allows the Board to respond to changed facts, implementation issues or initial urgencyProvides external appellate review
Does not automatically suspend the directionStay depends on an applicable order

Section 27 does not expressly state that a person must exhaust subsection (3) representation before appealing under Section 29.

Accordingly, the representation mechanism should not automatically be treated as a mandatory precondition to appeal unless another applicable provision requires it.

49. Does representation suspend the direction?

Section 27(3) does not state that filing a representation automatically suspends the direction.

The direction remains binding unless:

  • the Board suspends it;

  • the Board modifies, withdraws or cancels it;

  • the Appellate Tribunal grants appropriate relief;

  • another competent authority orders otherwise.

A person seeking urgent relief should therefore request suspension expressly rather than assume that the representation has a stay effect.

50. Part V: Digital functioning of the Board

51. Rule 20 and the digital office

Final Rule 20 provides that the Board shall function as a digital office.

The Board may adopt techno-legal measures to conduct proceedings without requiring physical presence, while preserving its power to:

  • summon a person;

  • enforce attendance;

  • examine that person on oath.

Digital functioning may cover:

  • receipt of complaints, intimations and references;

  • filing of documents;

  • service of notices;

  • hearings;

  • evidence;

  • communications;

  • orders.

The digital-office model does not reduce the requirements of:

  • natural justice;

  • secure authentication;

  • reliable evidence;

  • meaningful participation;

  • reasoned decision-making.

52. No automatic right to insist on physical hearing

Rule 20 permits proceedings without physical presence.

A party cannot necessarily insist upon an in-person hearing merely as a preference. The Board should consider whether the digital procedure provides a fair and effective opportunity to participate.

53. Board retains attendance powers

A digital proceeding is still compulsory where the Board lawfully summons a person.

The Board may enforce attendance and examine the person on oath through legally valid arrangements. Digital functioning does not convert participation into a voluntary interaction.

54. Part VI: Comparison with the GDPR

55. No exact one-to-one GDPR equivalent

Section 27 has no single exact counterpart in the GDPR.

Its functions are distributed across several GDPR provisions, principally:

  • Article 57, which defines supervisory-authority tasks;

  • Article 58, which defines investigative, corrective, authorisation and advisory powers;

  • Article 77, which establishes the data subject’s right to complain;

  • Article 83, which governs administrative fines;

  • Articles 60 to 66, which govern cooperation and urgent cross-border action.

Under the GDPR, national supervisory authorities monitor and enforce the Regulation, handle complaints, conduct investigations, issue corrective orders and impose administrative fines.

56. Institutional model

56.1 DPDPA

India has one central Data Protection Board of India. It functions as an adjudicatory and enforcement body under the DPDPA.

Its jurisdiction is activated through the statutory gateways in Section 27.

56.2 GDPR

Each EEA jurisdiction has one or more independent supervisory authorities. Cross-border processing is handled through:

  • lead supervisory authority arrangements;

  • cooperation among concerned authorities;

  • consistency mechanisms;

  • binding EDPB decisions in defined disputes.

The Data Protection Board of India should not be confused with the European Data Protection Board.

The EDPB primarily promotes consistent interpretation and resolves certain cross-border disputes. National supervisory authorities ordinarily investigate and enforce the GDPR. The Indian Board itself is the national enforcement institution.

57. Complaint rights

57.1 DPDPA

A Data Principal may complain to the Board about:

  • a personal data breach;

  • a Data Fiduciary’s applicable obligations;

  • exercise of her rights;

  • Consent Manager obligations.

The Data Principal must ordinarily exhaust the internal grievance mechanism before approaching the Board.

57.2 GDPR

Article 77 gives a data subject the right to lodge a complaint with a supervisory authority, particularly in the Member State of habitual residence, place of work or place of the alleged infringement.

The GDPR does not establish the same general requirement that the data subject first exhaust the controller’s internal grievance mechanism before approaching the supervisory authority.

This is an important procedural difference. The DPDPA inserts a mandatory internal-redress stage, while the GDPR generally permits more direct regulatory complaint access.

58. Own-initiative enforcement

58.1 GDPR

GDPR supervisory authorities can conduct investigations and take corrective action on their own initiative. Their powers include:

  • ordering information;

  • audits;

  • obtaining access to personal data and premises;

  • warnings and reprimands;

  • ordering compliance;

  • restricting or prohibiting processing;

  • ordering rectification, restriction or erasure;

  • suspending data flows;

  • imposing fines.

58.2 DPDPA

Section 27 is framed around specified triggers:

  • breach intimation;

  • complaint;

  • Government reference;

  • court direction;

  • Consent Manager registration-breach intimation;

  • Section 37 intermediary reference.

It does not expressly confer a comparably broad general own-motion power on the Board to investigate any suspected breach without one of the statutory triggers.

The Board’s ability to act upon information received should therefore be connected to an authorised gateway rather than assumed to be a universal suo motu power.

59. Investigative powers

59.1 GDPR

Article 58 expressly divides supervisory-authority powers into:

  • investigative;

  • corrective;

  • authorisation and advisory powers.

Investigative powers include audits, access to information, access to data and premises, and notification of alleged infringements.

59.2 DPDPA

Section 27 identifies when the Board may inquire.

The detailed inquiry powers appear in Section 28, including civil-court-like powers for specified purposes.

The structural difference is therefore:

  • GDPR Article 58 consolidates many powers in one provision;

  • DPDPA separates the Board’s jurisdictional triggers in Section 27 from its inquiry procedure and evidence-gathering powers in Section 28.

60. Corrective directions

60.1 GDPR

Article 58(2) provides an express catalogue of corrective measures, including:

  • warnings;

  • reprimands;

  • compliance orders;

  • rectification or erasure;

  • temporary or definitive processing restrictions;

  • withdrawal of certification;

  • suspension of data transfers;

  • administrative fines.

These corrective powers are distinct from, and may be used instead of or together with, fines. The EDPB recognises that GDPR enforcement measures range from warnings and reprimands to orders and administrative fines.

60.2 DPDPA

Section 27(2) uses a broad general formulation. The Board may issue directions it considers necessary for the effective discharge of its functions after:

  • hearing the affected person;

  • recording reasons.

The DPDPA does not reproduce the GDPR’s detailed catalogue of corrective measures.

This gives the Indian Board textual flexibility, but each direction must be justified through:

  • statutory purpose;

  • necessity;

  • reasons;

  • fair hearing.

The Board should not create a direction that contradicts an express provision or exemption in the Act.

61. Urgent action

61.1 DPDPA

Section 27(1)(a) expressly permits urgent remedial or mitigation directions after receipt of a personal data breach intimation.

61.2 GDPR

The GDPR allows supervisory authorities to impose temporary or definitive processing limitations under Article 58 and contains an urgent procedure under Article 66 for exceptional cross-border circumstances.

The GDPR’s urgent procedure operates within its multi-authority, cross-border enforcement system. Section 27(1)(a) is more directly tied to immediate response to a notified personal data breach.

62. Administrative fines

62.1 DPDPA

The Board imposes penalties according to:

  • Section 33;

  • the monetary ceilings in the Schedule;

  • the factors prescribed for determining the amount.

The penalties are fixed statutory maxima in rupees for categories of breach.

62.2 GDPR

Article 83 uses tiered maximum fines, including up to:

  • €10 million or 2% of worldwide annual turnover for specified infringements;

  • €20 million or 4% of worldwide annual turnover for more serious infringements, whichever is higher for undertakings. GDPR authorities must ensure fines are effective, proportionate and dissuasive.

The central difference is that:

  • the GDPR links corporate maximum fines to worldwide annual turnover;

  • the DPDPA Schedule specifies fixed maximum monetary amounts without a turnover-linked ceiling.

Both systems require case-specific determination rather than automatic imposition of the maximum.

63. Compensation and individual remedies

Neither Section 27 nor the GDPR’s supervisory-authority fine framework should be confused with compensation.

Under the GDPR, Article 82 separately provides a right to compensation for material or non-material damage.

The DPDPA does not contain an equivalent general compensation provision within Section 27. Board penalties are regulatory amounts credited to the Consolidated Fund of India, not compensation paid to the complainant.

64. Independence and appointment structure

GDPR Article 52 requires each supervisory authority to act with complete independence in performing its tasks and exercising its powers.

The Indian Board is established as a body corporate, but its Chairperson and Members are appointed by the Central Government, and several Section 27 gateways involve Government references.

This institutional difference should not be converted into a conclusion that the Board lacks adjudicatory duties of fairness. Its decisions remain subject to:

  • statutory procedure;

  • natural justice;

  • recorded reasons;

  • appeal to the Appellate Tribunal.

However, the DPDPA does not reproduce the GDPR’s complete-independence wording in Section 27.

65. Part VII: Important interpretive conclusions

66. The Board is not a continuous supervisory regulator in the same form as an EU DPA

Section 27 presents the Board principally as an inquiry, direction and penalty body responding to specified statutory triggers.

It does not expressly assign the same broad catalogue of ongoing functions found in GDPR Article 57, such as:

  • general monitoring of application;

  • awareness promotion;

  • advising Parliament;

  • approving certification criteria;

  • adopting standard contractual clauses.

Some policy, notification and rule-making functions remain with the Central Government under the DPDPA.

67. Complaint jurisdiction is personal-data specific

A complaint under paragraphs (b) or (c) must relate to:

  • the complainant’s personal data;

  • obligations owed in relation to that data;

  • exercise of her rights.

Section 27 does not create a general public-interest complaint mechanism for an unaffected person.

Government references and court directions can address wider or systemic matters through their own gateways.

68. Section 27 directions cannot override substantive limits

A direction cannot lawfully be used to:

  • recreate a right disapplied under Section 17;

  • require erasure where the Act expressly permits necessary legal retention;

  • impose a duty outside the DPDPA;

  • circumvent the applicable penalty ceilings;

  • confer compensatory damages not authorised by the Act.

The general direction power must operate within the substantive scheme of the DPDPA.

69. Mitigation, directions and penalty may coexist

The Board may respond to one matter through multiple measures.

Example

For example, a personal data breach may result in:

  1. urgent mitigation directions;

  2. a full inquiry;

  3. longer-term compliance directions;

  4. acceptance of a voluntary undertaking;

  5. a monetary penalty.

These measures serve different purposes:

  • mitigation addresses immediate risk;

  • directions secure compliance;

  • undertakings formalise corrective commitments;

  • penalties sanction established breach and deter repetition.

The Board must still avoid duplicative or disproportionate treatment and must apply each statutory power according to its own conditions.

Conclusion

Section 27 defines the Board’s core enforcement jurisdiction through five statutory gateways:

  • breach intimation by a Data Fiduciary;

  • complaint by a Data Principal against a Data Fiduciary;

  • complaint against a Consent Manager;

  • intimation of breach of Consent Manager registration conditions;

  • Central Government reference concerning intermediary non-compliance with Section 37(2).

Government references and court directions may also activate the Board’s inquiry jurisdiction under paragraph (b).

The section distinguishes among:

  • urgent breach mitigation;

  • formal inquiry;

  • monetary penalty;

  • binding directions;

  • subsequent modification, suspension, withdrawal or cancellation of directions.

A general direction under Section 27(2) requires a prior opportunity of hearing and written reasons. An affected person may seek review of a direction under Section 27(3), but the direction does not automatically stand suspended merely because a representation is filed.

Compared with the GDPR, the Indian framework is more trigger-based and adjudicatory. GDPR supervisory authorities have a broader express catalogue of investigative, corrective and advisory powers and may act on their own initiative. The Indian Board’s jurisdiction is channelled through the specific gateways in Section 27, while its investigation procedure appears separately in Section 28.

The GDPR expressly lists warnings, reprimands, processing bans, compliance orders, rectification, erasure, transfer suspensions and fines. Section 27 instead relies on a broad direction power bounded by necessity, hearing and recorded reasons. GDPR fines may be turnover-linked, while DPDPA penalties are governed by fixed ceilings in the Schedule.

Key point

The controlling proposition is that Section 27 gives the Data Protection Board a structured, trigger-based enforcement jurisdiction to contain personal data breaches, inquire into specified statutory failures, issue reasoned and binding compliance directions, review those directions and impose monetary penalties within the limits and procedures established by the DPDPA.

Reproduced from official sources for reference. Not legal advice. In case of any discrepancy, the text published in the Gazette of India prevails.