Understand how the DPB will investigate violations, what triggers penalties, and what you can do now to reduce your exposure.
The Data Protection Board of India is the statutory regulator established under the DPDP Act 2023 to enforce the Act, adjudicate complaints, and impose penalties. It is expected to be constituted in 2026 and become fully operational for enforcement by May 2027. The DPB will have powers to investigate, call for information, conduct hearings, and impose financial penalties on Data Fiduciaries and Consent Managers.
The DPB is modelled on a digital-first approach — complaints will be filed online, hearings can be conducted virtually, and the process is designed to be faster than traditional court proceedings. This means violations will be investigated relatively quickly once the DPB is operational.
Yes. The DPDP Act explicitly lists voluntary remediation, good-faith action, and cooperation with the DPB as factors that the adjudicating officer must consider in determining penalties. Companies that self-report breaches, take prompt remedial action, and cooperate fully with investigations are likely to face significantly lower penalties than those that conceal violations or obstruct investigations. This is a strong incentive to have a documented breach response programme and a clear internal escalation path.
A practical one-page guide: what to do if you receive a DPB inquiry, what records you need, and how to demonstrate good-faith compliance.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.