CHAPTER VI - POWERS, FUNCTIONS AND PROCEDURE OF BOARD
Section 28 - Procedure to be followed by Board
Official text
(1)The Board shall function as an independent body and shall, as far as practicable, function as a digital office, with the receipt of complaints and the allocation, hearing and pronouncement of decisions in respect of the same being digital by design, and adopt such techno-legal measures as may be prescribed.
(2)The Board may, on receipt of an intimation or complaint or reference or directions as referred to in sub-section (1) of section 27, take action in accordance with the provisions of this Act and the rules made thereunder.
(3)The Board shall determine whether there are sufficient grounds to proceed with an inquiry.
(4)In case the Board determines that there are insufficient grounds, it may, for reasons to be recorded in writing, close the proceedings.
(5)In case the Board determines that there are sufficient grounds to proceed with inquiry, it may, for reasons to be recorded in writing, inquire into the affairs of any person for ascertaining whether such person is complying with or has complied with the provisions of this Act.
(6)The Board shall conduct such inquiry following the principles of natural justice and shall record reasons for its actions during the course of such inquiry.
(7)For the purposes of discharging its functions under this Act, the Board shall have the same powers as are vested in a civil court under the Code of Civil Procedure, 1908, in respect of matters relating to—
(a)summoning and enforcing the attendance of any person and examining her on oath;
(b)receiving evidence of affidavit requiring the discovery and production of documents;
(c)inspecting any data, book, document, register, books of account or any other document; and
(d)such other matters as may be prescribed.
(8)The Board or its officers shall not prevent access to any premises or take into custody any equipment or any item that may adversely affect the day-to-day functioning of a person.
(9)The Board may require the services of any police officer or any officer of the Central Government or a State Government to assist it for the purposes of this section and it shall be the duty of every such officer to comply with such requisition.
(10)During the course of the inquiry, if the Board considers it necessary, it may for reasons to be recorded in writing, issue interim orders after giving the person concerned an opportunity of being heard.
(11)On completion of the inquiry and after giving the person concerned an opportunity of being heard, the Board may for reasons to be recorded in writing, either close the proceedings or proceed in accordance with section 33.
(12)At any stage after receipt of a complaint, if the Board is of the opinion that the complaint is false or frivolous, it may issue a warning or impose costs on the complainant.
Cross-references
Section 28
CORRESPONDING RULE(S)
Commentary
2. Overall structure of Section 28
Section 28 establishes the procedure through which the Data Protection Board considers and determines matters received under Section 27.
It creates a staged process:
- Receipt of intimation, complaint, reference or court direction.
- Preliminary assessment of whether sufficient grounds exist.
- If grounds are insufficient, reasoned closure; if grounds are sufficient, reasoned commencement of formal inquiry.
- Evidence gathering and inquiry following natural justice.
- Interim order, if necessary.
- Final opportunity of hearing.
- Reasoned closure, or action under Section 33.
The provision deliberately separates:
-
receipt of a matter;
-
preliminary screening;
-
commencement of a formal inquiry;
-
evidence gathering;
-
interim protection;
-
final hearing;
-
closure or monetary penalty.
Receipt of a complaint, breach intimation or Government reference does not itself prove non-compliance. The Board must first determine whether sufficient grounds exist to justify a formal inquiry and must ultimately decide the matter through a reasoned and fair process.
2.1 Independent and digital functioning
3. The Board must function independently
Section 28(1) requires the Board to function as an independent body.
The requirement concerns the Board’s exercise of its statutory functions. It must decide whether a breach occurred by applying:
-
the DPDPA;
-
the DPDP Rules;
-
the evidence before it;
-
applicable legal principles;
-
the requirements of natural justice.
A complaint, Government reference or court direction activates the Board’s jurisdiction but does not predetermine the result. The Board must independently assess whether sufficient grounds exist, whether the alleged breach is established and whether a penalty is warranted.
This is particularly important where a matter reaches the Board through:
-
the Central Government;
-
a State Government;
-
a court direction;
-
a complaint against a significant private or governmental Data Fiduciary.
The referring authority is the source of the matter, not the adjudicator of the breach.
3.1 Institutional structure and decisional independence
The Central Government retains significant institutional functions concerning the Board, including:
-
appointment of the Chairperson and Members;
-
prescription of service conditions;
-
prior approval of appointments of officers and employees;
-
references under Section 27;
-
other powers expressly assigned under the Act.
Nevertheless, Section 28 requires the Board to exercise its inquiry and adjudicatory functions independently.
The DPDPA does not reproduce the GDPR formulation requiring supervisory authorities to act with “complete independence.” The GDPR also contains more detailed guarantees concerning external influence, instructions, staffing and resources. The DPDPA’s express guarantee is framed principally as functional independence in the Board’s procedure.
4. Digital by design
The Board must, as far as practicable, function as a digital office.
The DPDPA defines a digital office as an office adopting an online mechanism through which proceedings are conducted digitally from receipt to disposal.
Section 28 specifically contemplates digital handling of:
-
receipt of complaints;
-
allocation of complaints;
-
hearings;
-
pronouncement of decisions.
The digital model is therefore intended to apply throughout the lifecycle of a proceeding rather than being limited to electronic filing.
4.1 “As far as practicable”
The qualification recognises that a wholly digital procedure may not be suitable in every circumstance.
Physical or alternative procedures may be necessary where:
-
particular evidence cannot be effectively examined digitally;
-
a physical record or system requires inspection;
-
accessibility needs require another arrangement;
-
technical failure prevents meaningful participation;
-
the Board lawfully requires physical presence;
-
fairness or evidentiary reliability demands another procedure.
Digital procedure is the statutory default, but it must not override natural justice or practical necessity.
5. Rule 20: Functioning as a digital office
Final Rule 20 reinforces Section 28 by providing that the Board shall function as a digital office.
The Board may adopt techno-legal measures to conduct proceedings without requiring the physical presence of an individual. This operates without prejudice to the Board’s power to:
-
summon a person;
-
enforce attendance;
-
examine the person on oath.
Techno-legal measures may support:
-
identity authentication;
-
electronic filing;
-
secure service of notices;
-
digital submission of evidence;
-
remote hearings;
-
electronic recording;
-
digital signatures;
-
secure access to case materials;
-
electronic pronouncement and communication of orders.
The technological design must preserve:
-
authenticity;
-
integrity of evidence;
-
confidentiality;
-
meaningful access;
-
reasonable opportunity to participate;
-
reliable proof of service;
-
an adequate record for appeal.
The fact that a proceeding is digital does not make participation optional. Where the Board lawfully summons a person, that person remains bound to attend through the mode directed by the Board.
5.1 No absolute entitlement to a physical hearing
Section 28 and Rule 20 do not create an absolute right to insist on an in-person hearing.
The relevant question is whether the procedure adopted gives the person a meaningful opportunity to:
-
understand the case;
-
access relevant material;
-
present evidence;
-
answer adverse material;
-
make submissions.
Where those safeguards can be effectively provided digitally, a physical hearing may not be necessary.
Equally, the Board should not insist on a digital method that materially disadvantages a person because of disability, lack of technical access or system failure.
5.2 Commencement of Board action
6. Receipt of a matter under Section 27
Section 28(2) permits the Board to act when it receives an intimation, complaint, reference or direction contemplated by Section 27(1).
The principal gateways are:
-
a personal data breach intimation under Section 8(6);
-
a Data Principal’s complaint against a Data Fiduciary;
-
a Central Government or State Government reference;
-
a court direction;
-
a Data Principal’s complaint against a Consent Manager;
-
an intimation concerning breach of a Consent Manager’s registration condition;
-
a Central Government reference concerning an intermediary’s breach of Section 37(2).
These gateways define how the Board’s jurisdiction is activated. The Board is not given an unrestricted power under Section 28 to inquire into any privacy issue without a statutory basis under Section 27.
6.1 Scope of the resulting inquiry
The inquiry should remain connected with the matter that triggered the Board’s jurisdiction.
Example
For example, if a complaint concerns refusal of erasure, the Board may examine:
-
whether Section 12 applied;
-
whether the personal data was processed on the basis described in Section 12;
-
whether the specified purpose continued;
-
whether retention was required by law;
-
whether the Data Fiduciary properly handled the grievance.
The complaint does not automatically justify an unrestricted investigation of every processing activity undertaken by the organisation.
However, the complainant need not identify the precise statutory provision or possess all internal evidence before approaching the Board. If the substance of the complaint discloses a possible DPDPA breach, the Board may investigate the connected facts necessary to determine compliance.
6.2 Internal grievance redressal and access to the Board
7. Data Principal must ordinarily first approach the Data Fiduciary or Consent Manager
A Data Principal’s route to the Board under Sections 27 and 28 must be read with Section 13(3).
Section 13(3) requires the Data Principal to exhaust the opportunity of redressing her grievance under Section 13 before approaching the Board.
The ordinary DPDPA enforcement sequence is therefore:
- Exercise of right or privacy concern.
- Request or grievance to the Data Fiduciary or Consent Manager.
- Internal grievance opportunity exhausted.
- Complaint to the Data Protection Board.
- Screening and inquiry under Section 28.
- Appeal to the Appellate Tribunal.
The Data Principal need not accept an unsatisfactory response. The requirement is to exhaust the opportunity for internal redress, not to obtain a favourable answer.
The opportunity may ordinarily be exhausted where:
-
a final substantive response is received and the Data Principal remains dissatisfied; or
-
the published grievance-response period expires without an effective response.
An organisation should not be able to prevent access to the Board by:
-
creating endless internal review stages;
-
refusing to classify the communication as a grievance;
-
leaving the grievance permanently open;
-
issuing acknowledgements without a substantive response.
7.1 Other Section 27 gateways are unaffected
The exhaustion requirement applies to the Data Principal’s approach to the Board. It does not condition every statutory gateway under Section 27.
The Board may independently receive:
-
a Section 8(6) breach intimation;
-
a Government reference;
-
a court direction;
-
an intimation concerning a Consent Manager’s registration breach;
-
an intermediary-related reference under Section 37.
Those routes do not depend on prior internal grievance redressal by a Data Principal.
7.2 Preliminary assessment
8. Sufficient grounds to proceed
The Board must determine whether there are sufficient grounds to proceed with an inquiry.
This is a threshold assessment, not a final adjudication of liability.
The Board should determine whether the information before it establishes an adequate basis for formal examination. Relevant matters may include:
-
whether the alleged processing falls within the DPDPA;
-
whether the respondent is subject to the relevant obligation;
-
whether the alleged facts, if proved, could amount to a breach;
-
whether the complainant is the relevant Data Principal or is lawfully acting for her;
-
whether internal grievance redressal was exhausted where required;
-
whether an express exemption applies;
-
whether some intelligible factual basis supports the allegation;
-
whether the matter is within the Board’s statutory jurisdiction.
The threshold should not be so demanding that the complainant must prove the entire breach before the Board uses its evidence-gathering powers.
A Data Principal will often lack access to:
-
audit records;
-
processing logs;
-
processor contracts;
-
internal security information;
-
recipient records;
-
system configurations.
Requiring complete proof at the preliminary stage would make the inquiry mechanism ineffective.
At the same time, the Board is not required to open a full inquiry where:
-
the allegation is entirely unsupported;
-
the matter plainly falls outside the Act;
-
the right relied upon does not apply;
-
an express exemption clearly disapplies the obligation;
-
the complainant has not exhausted Section 13 where required;
-
the allegation could not constitute a DPDPA breach even if accepted.
9. Closure for insufficient grounds
If the Board determines that sufficient grounds do not exist, it may close the proceeding.
The Board must record reasons in writing.
The reasons should identify the material basis for closure, such as:
-
lack of jurisdiction;
-
failure to exhaust internal grievance redressal;
-
absence of a sufficient factual basis;
-
non-applicability of the obligation or right relied upon;
-
application of a Section 17 exemption;
-
the matter being unrelated to the complainant’s personal data;
-
the alleged facts not amounting to a breach under the Act.
The obligation to record reasons is important because it:
-
demonstrates actual consideration of the case;
-
allows the complainant to understand the outcome;
-
disciplines the Board’s exercise of discretion;
-
permits meaningful appellate review;
-
supports consistency across cases.
9.1 Meaning of “may” close
The use of “may” does not mean the Board may commence a coercive formal inquiry without sufficient grounds.
It permits the Board to take an appropriate preliminary step, such as seeking essential clarification, before deciding whether to close the matter.
The Board should not use preliminary scrutiny as an indefinite or unrestricted investigation. A formal inquiry should follow the sufficient-ground determination required by Section 28(5).
9.2 Formal inquiry
10. Reasons for commencement
Where the Board finds sufficient grounds, it may commence a formal inquiry.
It must record reasons in writing.
The reasons should identify:
-
the suspected breach;
-
the factual basis supporting inquiry;
-
the provision potentially involved;
-
the person whose compliance is to be examined;
-
the general scope of the inquiry.
The reasons need not contain a final finding. The Board must avoid prejudging the matter before hearing the respondent and examining the evidence.
A reasoned commencement decision protects the respondent from an undefined or arbitrary investigation and ensures that evidence-gathering remains connected with the statutory issue.
11. Inquiry into the affairs of any person
The Board may inquire into the affairs of any person to ascertain whether that person:
-
is complying with the DPDPA; or
-
has complied with the DPDPA.
The expression “person” is wider than “Data Fiduciary.” Depending on the applicable Section 27 gateway, the inquiry may concern:
-
a Data Fiduciary;
-
Significant Data Fiduciary;
-
Consent Manager;
-
intermediary;
-
another person whose conduct is directly relevant to the statutory issue.
The power is not an unrestricted authority to examine every aspect of a person’s affairs. The inquiry must remain directed at determining compliance with the DPDPA in connection with the matter lawfully before the Board.
11.1 Current and historical compliance
The words “is complying with or has complied with” cover:
-
ongoing processing;
-
past processing;
-
a completed personal data breach;
-
a historical refusal of a right;
-
subsequent remediation;
-
continuing effects of earlier non-compliance.
Remediation after the event does not necessarily erase the earlier breach. It may nevertheless affect:
-
the need for further directions;
-
mitigation;
-
the amount of penalty;
-
acceptance of a voluntary undertaking.
11.2 Data Processors
The Board may need to inspect systems or evidence held by a Data Processor to determine whether the Data Fiduciary complied with its obligations.
Section 8(1) keeps the Data Fiduciary responsible for processing undertaken on its behalf. The Board should therefore distinguish:
-
the Data Fiduciary’s statutory responsibility;
-
the processor’s factual conduct;
-
independent processing undertaken by the processor for its own purpose.
11.3 Natural justice and recorded reasons
12. Natural justice governs the inquiry
The Board must conduct the inquiry according to the principles of natural justice.
The core requirements ordinarily include:
-
an impartial decision-maker;
-
notice of the allegations;
-
access to the substance of adverse material;
-
a meaningful opportunity to respond;
-
consideration of relevant evidence;
-
a reasoned decision.
12.1 Notice of the case
The person concerned should be informed of:
-
the conduct under examination;
-
the statutory obligation allegedly breached;
-
the relevant factual allegations;
-
the potential consequences;
-
the material on which the Board proposes to rely.
A vague statement that the person may have failed to comply with the DPDPA would ordinarily be insufficient for a meaningful defence.
12.2 Opportunity to respond
The person should be able to:
-
provide documents;
-
explain technical and organisational measures;
-
dispute factual allegations;
-
invoke statutory exceptions;
-
identify exemptions;
-
challenge the legal interpretation;
-
explain remediation;
-
make submissions on penalty.
12.3 Impartiality
A Member with a relevant financial, professional, personal or other interest must not participate in the matter.
Rule 19 separately requires a Member who has an interest in an agenda item not to participate in or vote on it. The same principle supports impartial adjudication under Section 28.
12.4 Natural justice does not require a civil trial
The Board is not required to replicate every procedure of an ordinary civil court.
The intensity of the procedure may depend on:
-
seriousness of the alleged breach;
-
complexity of the matter;
-
evidence involved;
-
possible monetary penalty;
-
urgency;
-
possible effect of an interim order.
A digital hearing, written submissions or a combination of methods may satisfy natural justice if the affected person receives a fair and effective opportunity to present the case.
13. Reasons during the inquiry
Section 28(6) requires the Board to record reasons for actions taken during the inquiry.
This requirement is broader than a duty to give reasons only in the final order.
Reasons may be required for material actions such as:
-
commencement of inquiry;
-
expansion of its scope;
-
significant evidence-production directions;
-
use of inspection powers;
-
interim orders;
-
extension of the inquiry period;
-
closure;
-
final adverse findings.
Not every minor administrative step requires a lengthy order. The detail required should correspond with:
-
significance of the action;
-
effect on the person concerned;
-
interference with operations;
-
need for later review.
The reasons should show the relationship between:
-
the statutory power;
-
the relevant facts;
-
the measure taken;
-
its necessity.
13.1 Civil-court-like powers
14. Limited conferral of civil-court powers
For discharging its functions, the Board receives the same powers as a civil court under the Code of Civil Procedure, 1908 in relation to the matters listed in Section 28(7).
This does not make the Board a civil court for all purposes.
Its:
-
jurisdiction;
-
remedies;
-
penalties;
-
appeal mechanism;
continue to arise under the DPDPA.
The civil-court analogy gives the Board compulsory evidence-gathering powers necessary for an effective inquiry.
15. Summoning and examination on oath
The Board may:
-
summon any person;
-
enforce attendance;
-
examine the person on oath.
This may apply to:
-
officers of a Data Fiduciary;
-
technical personnel;
-
employees;
-
processors;
-
auditors;
-
witnesses;
-
complainants;
-
persons possessing relevant records or knowledge.
A lawful summons is compulsory.
The examination may occur digitally where the Board’s techno-legal arrangements preserve:
-
identity;
-
reliability;
-
procedural fairness;
-
evidentiary integrity.
The power to examine on oath means that evidence before the Board carries formal legal seriousness. Knowingly providing false evidence may attract consequences under the applicable law.
16. Affidavits, discovery and production
The Board may:
-
receive evidence by affidavit;
-
require discovery;
-
compel production of documents.
16.1 Affidavit evidence
A person may provide sworn written evidence. The Board may still require oral or digital examination where clarification or testing of the evidence is necessary.
16.2 Discovery
Discovery enables identification and disclosure of relevant material within a person’s possession or control.
16.3 Production
The Board may require the actual production of relevant documents or records.
Such material may include:
-
privacy notices;
-
consent records;
-
withdrawal records;
-
processor contracts;
-
audit reports;
-
access logs;
-
data-flow records;
-
security policies;
-
breach-response documentation;
-
notification records;
-
retention schedules;
-
grievance files;
-
correspondence;
-
decisions affecting Data Principals.
The demand must remain relevant to the inquiry. Section 28 does not authorise indiscriminate access to every record held by the person.
17. Inspection of data and records
The Board may inspect:
-
data;
-
books;
-
documents;
-
registers;
-
books of account;
-
other documents.
The express reference to “data” allows examination of digital systems and records rather than limiting the Board to paper documents.
Depending on the inquiry, inspection may involve:
-
databases;
-
access logs;
-
consent platforms;
-
system records;
-
breach artefacts;
-
security configurations;
-
data-sharing records;
-
backups;
-
transaction histories.
17.1 Confidentiality and third-party information
Material inspected by the Board may include:
-
trade secrets;
-
cybersecurity information;
-
third-party personal data;
-
commercially sensitive records;
-
confidential communications.
Confidentiality does not automatically defeat a lawful inspection demand. The Board must nevertheless handle the information only for its statutory function and protect it against unnecessary disclosure.
17.2 Legal professional privilege
Section 28 does not expressly remove legal professional privilege.
The Board’s civil-court-like powers should therefore be exercised consistently with legally recognised privilege. A document does not become producible merely because the Board requests it if the document is protected under applicable privilege law.
17.3 Restrictions on disruptive investigation
18. No prevention of access to premises
The Board and its officers cannot prevent access to premises.
This means the Board cannot effectively seal or shut down premises while conducting an inquiry.
The provision reflects the Board’s adjudicatory and regulatory character rather than giving it unrestricted search-and-seizure powers comparable to criminal enforcement authorities.
19. No disruptive custody of equipment or items
The Board or its officers cannot take equipment or another item into custody where doing so may adversely affect the person’s day-to-day functioning.
This protects against seizure of operationally essential assets such as:
-
production servers;
-
essential computers;
-
network infrastructure;
-
critical storage systems;
-
devices needed for ordinary business continuity.
The restriction requires the Board to prefer less disruptive methods where they can secure the necessary evidence, including:
-
production of certified copies;
-
secure data exports;
-
inspection in place;
-
preservation directions;
-
authenticated forensic copies;
-
read-only system access.
The section does not absolutely prohibit taking every item into custody. The prohibition applies where custody may adversely affect day-to-day functioning. Any custody must still have a legal basis and must remain necessary and proportionate.
19.1 Public-officer assistance cannot circumvent the restriction
The Board cannot use police or Government assistance to do indirectly what subsection (8) prevents it from doing directly.
The limits concerning interruption of premises and essential equipment continue to apply when another officer assists the Board.
19.2 Assistance from police and Government officers
20. Requisition of assistance
The Board may require the services of:
-
a police officer;
-
an officer of the Central Government;
-
an officer of a State Government.
It is the duty of the requested officer to comply.
The assistance may be relevant to:
-
enforcing attendance;
-
facilitating lawful inspection;
-
securing cooperation;
-
accessing Government-held records;
-
maintaining order;
-
carrying out another lawful procedural step.
The assisting officer does not acquire the Board’s adjudicatory authority.
The officer cannot independently:
-
determine that a breach occurred;
-
decide the case;
-
impose a penalty;
-
issue the Board’s final order.
The Board remains responsible for the inquiry and the exercise of statutory power.
20.1 Interim orders
21. Conditions for interim intervention
During an inquiry, the Board may issue an interim order if it considers the order necessary.
Before issuing the order, the Board must:
-
give the person concerned an opportunity of being heard; and
-
record its reasons in writing.
An interim order operates before the final determination and should protect the effectiveness of the inquiry or prevent continuing harm.
Possible purposes may include:
-
preventing continued exposure of personal data;
-
preserving evidence;
-
restricting an ongoing high-risk activity;
-
preventing frustration of the final order;
-
maintaining an existing position until the facts are determined.
21.1 Interim order must not predetermine the penalty
An interim order should not be used to impose what is effectively a final penalty before the inquiry is completed.
Its nature should remain:
-
temporary;
-
protective;
-
necessary;
-
connected with the pending inquiry.
21.2 Hearing requirement
Section 28(10) expressly requires a pre-order hearing.
Where urgency exists, the hearing may be expedited, but it must remain meaningful. The person should be able to address:
-
factual foundation;
-
statutory authority;
-
necessity;
-
proposed duration;
-
operational effect;
-
alternative measures.
21.3 Difference from urgent breach directions
An interim order under Section 28(10) differs from an urgent breach-mitigation direction under Section 27(1)(a).
| Measure | Principal purpose |
|---|---|
| Section 27(1)(a) urgent direction | Immediate remediation or mitigation of a personal data breach |
| Section 27(2) direction | Effective discharge of the Board’s functions generally |
| Section 28(10) interim order | Temporary protection during a pending inquiry |
The Board should identify the correct statutory power and comply with the safeguards attached to that power.
21.4 Completion of inquiry
22. Final opportunity of being heard
After completing the inquiry, the Board must give the person concerned an opportunity of being heard before issuing its final determination.
This final opportunity should allow the person to address:
-
evidence gathered;
-
proposed adverse findings;
-
legal conclusions;
-
alleged statutory breach;
-
mitigation;
-
proposed monetary penalty;
-
Section 33 factors.
A hearing given at an earlier stage may not be sufficient if the inquiry subsequently produces new adverse evidence or expands the issues.
23. Final closure
The Board may close the proceeding after inquiry where it does not find a basis for action under Section 33.
Reasons must be recorded in writing.
Final closure may occur where:
-
the alleged breach is not proved;
-
the obligation did not apply;
-
the respondent complied with the Act;
-
the evidence remains insufficient;
-
a statutory exemption applies;
-
the complaint rests on an incorrect interpretation.
Final closure differs from preliminary closure:
-
preliminary closure means insufficient grounds existed to begin inquiry;
-
final closure means an inquiry occurred but did not justify penalty action.
24. Proceeding under Section 33
Where the Board determines that a breach occurred, it may proceed under Section 33.
The Board must identify:
-
the statutory obligation breached;
-
the applicable penalty entry in the Schedule;
-
the maximum amount;
-
the factors relevant to penalty;
-
the reasons supporting the particular amount.
The Board should consider matters such as:
-
nature and gravity of the breach;
-
duration;
-
type and nature of personal data affected;
-
repetitive character;
-
gain obtained or loss avoided;
-
mitigation;
-
proportionality and effectiveness.
The maximum penalty is not the default penalty.
A technical or isolated failure should not automatically attract the statutory maximum. Equally, remediation after discovery does not necessarily erase a completed breach, though it may materially affect the amount.
25. No compensation jurisdiction
Section 28 does not authorise the Board to award compensation or damages to a Data Principal.
A penalty imposed under Section 33 is regulatory. Under Section 34, the amounts recovered are credited to the Consolidated Fund of India.
They are not paid to the complainant.
A Data Principal may receive practical redress through:
-
correction;
-
erasure;
-
cessation or alteration of processing;
-
compliance directions;
-
breach mitigation.
However, the DPDPA does not contain a general compensation right equivalent to Article 82 GDPR.
25.1 Inquiry period
26. Six-month period under Rule 19
Final Rule 19 requires the Board to complete an inquiry within six months from receipt of the relevant:
-
intimation;
-
complaint;
-
reference;
-
direction under Section 27.
The Board may extend the period:
-
for reasons recorded in writing;
-
for no more than three months at a time.
The six-month period begins with receipt of the matter, not merely with the subsequent decision to commence formal inquiry. Preliminary assessment is therefore included within the overall timeline.
The words “at a time” permit successive extensions, but each extension requires:
-
a fresh decision;
-
written reasons;
-
a period not exceeding three months.
The Rule does not expressly state that an inquiry becomes void automatically when the period expires. However, excessive or unexplained delay may be relevant to:
-
natural justice;
-
prejudice;
-
appellate review;
-
reasonableness of the Board’s procedure.
26.1 False or frivolous complaints
27. Warning or costs against the complainant
At any stage after receiving a complaint, the Board may issue a warning or impose costs if it considers the complaint false or frivolous.
This power must be exercised cautiously because it operates alongside the Data Principal’s statutory right to complain.
27.1 False complaint
A complaint may be false where the complainant knowingly:
-
fabricates the alleged incident;
-
submits materially false facts;
-
produces fabricated evidence;
-
falsely claims to be the affected Data Principal;
-
falsely claims that a request or grievance was made.
A complaint is not false merely because:
-
the allegation is not proved;
-
the complainant misunderstood the law;
-
the Data Fiduciary provides a satisfactory explanation;
-
the Board closes the matter.
27.2 Frivolous complaint
A complaint may be frivolous where it is manifestly without a serious basis or is filed abusively rather than to obtain genuine redress.
It is not frivolous merely because:
-
the amount of personal data is limited;
-
the organisation considers the issue minor;
-
the complainant is unrepresented;
-
the complaint is emotionally worded;
-
investigation is inconvenient;
-
the Board ultimately disagrees.
27.3 Opportunity of hearing
Section 28(12) does not expressly repeat the hearing requirement. However, the general natural-justice obligation in Section 28(6) supports giving the complainant an opportunity to answer a proposed finding of falsity or frivolousness, particularly before costs are imposed.
The Board should record reasons identifying:
-
what was false or frivolous;
-
the evidence supporting that conclusion;
-
why a warning or costs were appropriate.
27.4 Costs versus Section 15 penalty
Costs under Section 28(12) are different from the monetary penalty for breach of the Data Principal duty under Section 15(d).
-
Section 28(12) allows a procedural costs order or warning in the complaint proceeding.
-
Breach of Section 15 may attract the statutory penalty prescribed in the Schedule through the applicable enforcement process.
The two consequences should not be treated as identical.
27.5 Comparison with the GDPR
28. No single corresponding GDPR provision
Section 28 has no exact one-to-one equivalent under the GDPR.
Comparable elements are distributed across:
-
Article 52, concerning supervisory-authority independence;
-
Article 57, concerning tasks and complaint handling;
-
Article 58, concerning investigative and corrective powers;
-
Article 77, concerning complaints;
-
Article 78, concerning judicial remedies against supervisory authorities;
-
Article 79, concerning judicial remedies against controllers and processors;
-
Article 82, concerning compensation;
-
Article 83, concerning administrative fines.
The GDPR leaves many detailed procedural questions to Member State procedural law, subject to EU law, natural justice and effective judicial protection.
29. Parallel remedies under the GDPR
The GDPR gives a data subject parallel regulatory and judicial remedies.
Under Article 77, the data subject may complain to a supervisory authority.
Under Article 79, the data subject may bring judicial proceedings against a controller or processor where she considers that her GDPR rights have been infringed.
Article 79 operates without prejudice to the administrative or non-judicial remedies available under the GDPR, including the Article 77 complaint route.
Accordingly, the data subject is not generally required by the GDPR to:
-
complain to the controller first;
-
exhaust an internal grievance mechanism;
-
approach the supervisory authority before going to court;
-
wait for the supervisory-authority proceeding to conclude before pursuing judicial relief.
The regulatory and judicial routes may be pursued concurrently:
- Alleged GDPR infringement.
- Either a complaint to the supervisory authority under Article 77, or court action against the controller or processor under Article 79.
- Both routes may proceed independently or in parallel.
The Court of Justice has confirmed that the Article 77 and Article 79 remedies may be exercised concurrently and independently. Member State procedural rules may coordinate the proceedings and address contradictory outcomes, but may not undermine the effectiveness of either remedy.
Article 82 separately allows compensation claims where a person has suffered material or non-material damage from a GDPR infringement.
30. Sequential redress under the DPDPA
The DPDPA adopts a more sequential model.
The ordinary route is:
-
the Data Principal approaches the Data Fiduciary or Consent Manager;
-
she uses the internal grievance mechanism under Section 13;
-
she exhausts that opportunity;
-
she complains to the Data Protection Board;
-
the Board acts under Sections 27 and 28;
-
an aggrieved person may appeal to the Appellate Tribunal under Section 29.
Unlike Article 79 GDPR, the DPDPA does not create a parallel general statutory cause of action allowing a Data Principal to sue the Data Fiduciary or Data Processor directly in a civil court for a DPDPA infringement while simultaneously pursuing the Board process.
Section 39 further bars civil courts from entertaining suits or proceedings concerning matters that the Board is empowered to determine and prevents injunctions concerning action taken or proposed under the Act.
This does not remove every judicial remedy. Depending on the circumstances, a person may retain:
-
constitutional remedies;
-
remedies under another statute;
-
legally distinct contractual or private-law claims;
-
an appeal under Section 29;
-
further judicial review under the applicable legal framework.
The important point is that the DPDPA itself does not reproduce the GDPR’s parallel Article 79 controller-facing judicial remedy.
30.1 Comparative position
| Issue | GDPR | DPDPA |
|---|---|---|
| Internal complaint to controller before regulator | Not generally required | Internal grievance ordinarily must be exhausted |
| Regulatory complaint | Article 77 | Sections 13, 27 and 28 |
| Direct judicial action against controller or processor | Article 79 expressly provides it | No equivalent general DPDPA action |
| Regulator and court routes | May proceed concurrently | Primarily sequential statutory route |
| Compensation | Express Article 82 remedy | No equivalent general compensation provision |
| Appeal against regulator | Judicial remedy under Article 78 | Appeal to Appellate Tribunal under Section 29 |
| Civil-court jurisdiction | No comparable general GDPR bar | Section 39 bars matters entrusted to the Board |
The difference is substantive, not merely procedural.
Under the GDPR, the data subject may simultaneously seek:
-
regulatory enforcement;
-
judicial injunction or other relief;
-
compensation where applicable.
Under the DPDPA, the Data Principal ordinarily moves through internal grievance redressal, the Board and the statutory appellate process.
31. Independence
GDPR Article 52 requires supervisory authorities to act with complete independence.
The DPDPA states that the Board shall function as an independent body but does not reproduce all of Article 52’s detailed institutional safeguards.
Both frameworks require independent adjudication. The GDPR provides a more developed institutional-independence architecture, while Section 28 places the independence requirement directly within the Board’s inquiry procedure.
32. Screening and duty to investigate
The DPDPA expressly requires the Board to determine whether sufficient grounds exist before commencing an inquiry.
The GDPR does not prescribe an identical universal threshold formulation. Supervisory authorities must handle complaints and investigate their subject matter to the extent appropriate.
The Court of Justice has recognised that GDPR supervisory authorities possess discretion in choosing corrective measures, but that discretion is not unlimited. Where intervention is necessary to remedy an infringement and ensure full enforcement of the GDPR, the authority must act appropriately. Its complaint decision remains subject to effective judicial review.
The shared principle is that an enforcement authority may screen and prioritise matters but must:
-
examine complaints fairly;
-
apply the correct legal standard;
-
give adequate reasons;
-
remain subject to review.
33. Investigative powers
Under Article 58 GDPR, supervisory authorities possess an express catalogue of investigative powers, including:
-
ordering information;
-
conducting data-protection audits;
-
reviewing certifications;
-
notifying alleged infringements;
-
obtaining access to personal data and information;
-
accessing premises and processing equipment under applicable procedural law.
Section 28 gives the Indian Board a more adjudicatory set of civil-court-like powers:
-
summons;
-
attendance;
-
examination on oath;
-
affidavits;
-
discovery;
-
document production;
-
inspection of data and records.
The DPDPA separately limits disruption by preventing the Board from blocking access to premises or taking essential equipment into custody where day-to-day functioning may be affected.
34. Corrective and interim powers
Article 58(2) GDPR expressly lists corrective powers such as:
-
warnings;
-
reprimands;
-
compliance orders;
-
rectification or erasure;
-
temporary or permanent restrictions;
-
processing prohibitions;
-
withdrawal of certification;
-
suspension of data flows;
-
administrative fines.
The DPDPA distributes comparable functions across:
-
urgent breach directions under Section 27(1)(a);
-
general directions under Section 27(2);
-
interim orders under Section 28(10);
-
penalties under Section 33.
The Indian Board’s direction power is broadly worded but must remain within the Act and comply with the attached requirements of necessity, hearing and recorded reasons.
35. False or frivolous complaints
Section 28 expressly authorises warning or costs for a false or frivolous complaint.
The GDPR does not contain an identical general costs provision. Article 57(4) permits a supervisory authority to charge a reasonable fee or refuse to act where requests are manifestly unfounded or excessive, particularly because of repetition.
The DPDPA provision is more explicitly sanction-oriented. It should therefore be applied carefully to avoid chilling genuine complaints.
35.1 Key interpretive conclusions
36. A full inquiry is not mandatory for every complaint
The Board may screen out matters lacking sufficient grounds.
However, the threshold must not be turned into a requirement that the Data Principal establish the entire breach without access to the respondent’s internal evidence.
The complainant must present a sufficient basis for inquiry, not complete proof of liability.
37. Reasons are required throughout the process
Reasons are required for:
-
preliminary closure;
-
commencement of inquiry;
-
material actions during inquiry;
-
interim orders;
-
final closure;
-
proceeding under Section 33;
-
extension of the inquiry period.
Reasoned procedure is one of Section 28’s principal safeguards.
38. Digital procedure must remain fair and accessible
Digital-by-design functioning does not excuse:
-
defective service;
-
inaccessible systems;
-
exclusion of persons with disabilities;
-
inability to inspect evidence;
-
unreliable authentication;
-
treatment of technical failure as deliberate non-participation.
Technology is the means of procedure, not a substitute for natural justice.
39. Civil-court powers are limited to specified purposes
The Board does not become a civil court generally.
Its civil-court-like powers support evidence gathering and adjudication under the DPDPA. Its jurisdiction and remedies remain limited by the Act.
40. Investigation must avoid unnecessary operational disruption
The Board may compel evidence and inspect systems but must avoid disrupting premises or taking essential equipment into custody.
The provision favours effective but minimally disruptive investigative methods.
Conclusion
Section 28 creates a staged, digitally administered and reasoned inquiry process for the Data Protection Board.
The Board must:
-
function independently;
-
determine whether sufficient grounds exist;
-
record reasons for closure or commencement;
-
follow natural justice;
-
use its compulsory evidence powers within statutory limits;
-
avoid unnecessary operational disruption;
-
provide hearings before interim and final adverse action;
-
close the proceeding or proceed under Section 33 through a reasoned decision.
Rule 19 requires inquiries ordinarily to be completed within six months, subject to reasoned extensions of no more than three months at a time. Rule 20 requires the Board to operate as a digital office while preserving its power to compel attendance and examine persons on oath.
The Board may warn or impose costs for a false or frivolous complaint, but that power must be exercised cautiously and consistently with natural justice.
The most important comparison with the GDPR concerns access to remedies. The GDPR permits the data subject to pursue a supervisory-authority complaint and a judicial action against the controller or processor concurrently. The DPDPA ordinarily requires the Data Principal first to use the Data Fiduciary’s or Consent Manager’s grievance mechanism, exhaust that opportunity, then approach the Board and thereafter use the statutory appellate route.
Key point
The controlling proposition is that Section 28 gives the Board substantial investigative and adjudicatory powers, but places them within a structured process based on threshold scrutiny, decisional independence, natural justice, written reasons, non-disruptive evidence gathering, digital accessibility, final hearing and appellate accountability. Unlike the GDPR’s parallel regulatory and judicial remedies, the DPDPA ordinarily requires sequential redress through the Data Fiduciary or Consent Manager, the Board and the Appellate Tribunal.
Reproduced from official sources for reference. Not legal advice. In case of any discrepancy, the text published in the Gazette of India prevails.