Advanced Search Options : ❯
Section 28 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
The Board must operate independently and, as far as practicable, through a digital office. It must determine whether sufficient grounds exist before commencing an inquiry, record reasons for closure or further action, and conduct inquiries according to principles of natural justice. The Board has specified civil-court powers for evidence gathering and inspection, but cannot disrupt day-to-day functioning by restricting premises access or taking custody of essential equipment. Interim orders require a hearing and recorded reasons, while false or frivolous complaints may result in warnings or costs.
Section 27 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Upon intimation of a personal data breach, the Data Protection Board may order urgent remedial or mitigation measures, inquire into the breach, and impose prescribed penalties. It may investigate specified breaches involving Data Fiduciaries, Consent Managers, and intermediaries on prescribed complaints, references, or directions. After hearing the person concerned and recording written reasons, it may issue binding directions. On an affected person's representation or Central Government reference, it may modify, suspend, withdraw, or cancel directions, subject to conditions.
Section 26 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
The Chairperson exercises general superintendence over the Board's administrative matters and may issue directions. Board officers may be authorised to scrutinise intimations, complaints, references and correspondence. The Chairperson may also authorise individual Members or groups of Members to perform Board functions and conduct proceedings, and may allocate proceedings among them.
Section 25 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Public-servant status is conferred on the Chairperson, Members, officers and employees of the Data Protection Board of India when acting, or purporting to act, under the Digital Personal Data Protection Act, 2023. They are deemed to be public servants for the purposes of the Indian Penal Code.
Section 24 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Section 24 authorises the Data Protection Board of India to appoint officers and employees necessary for efficient discharge of its functions, subject to prior approval of the Central Government. Prescribed terms and conditions govern appointment and service. The staffing framework takes effect from 13 November 2025.
Section 23 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
The Board must follow prescribed procedures for meetings and business, including digital meetings, and authenticate its orders, directions and instruments as prescribed. Proceedings remain valid despite vacancies, constitutional or appointment defects, and non-merits procedural irregularities. If the Chairperson is unable to act owing to absence, illness or another cause, the senior-most Member performs the Chairperson's functions until duties resume.
Section 22 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Resignation by the Chairperson or any other Member becomes effective upon the earliest specified event, including permission to relinquish office, lapse of three months, appointment of a successor, or expiry of term. Vacancies must be filled by fresh appointment. Former office-holders are subject to a one-year post-tenure employment restriction, requiring prior approval and disclosure of employment with Data Fiduciaries involved in proceedings initiated by or before them.
Section 21 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Section 21 disqualifies persons from appointment or continuation as Chairperson or Member where they are insolvent, convicted of an offence involving moral turpitude, physically or mentally incapable, or hold interests likely to prejudice official functions. Abuse of office prejudicial to the public interest is also a disqualification. Removal by the Central Government requires that the concerned Chairperson or Member be given an opportunity to be heard.
Section 20 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Service conditions of the Chairperson and other Members of the Data Protection Board of India are to be prescribed, and their salary, allowances and other terms cannot be varied to their disadvantage after appointment. They hold office for a two-year term and are eligible for re-appointment.
Section 19 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
The Data Protection Board of India comprises a Chairperson and a notified number of Members, appointed by the Central Government in the prescribed manner. Appointees must demonstrate ability, integrity and standing, with special knowledge or practical experience in governance, legal, technological, economic, regulatory, consumer-protection or dispute-resolution fields, or another field considered useful to the Board. At least one appointee must be a law expert.
Section 18 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Section 18 establishes the Data Protection Board of India with effect from 13 November 2025, following appointment by the Central Government. The Board is a body corporate with perpetual succession and a common seal. Subject to the Act, it may acquire, hold and dispose of movable and immovable property, enter into contracts, and sue or be sued in its corporate name. Its headquarters must be located at a place notified by the Central Government.
Section 17 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Section 17 establishes exemptions from specified data-protection obligations. Chapter II, subject to retained requirements, Chapter III and section 16 do not apply to processing for legal claims, judicial or regulatory functions, offence-related purposes, foreign contracts concerning data principals outside India, approved corporate restructurings, and assessment of a loan defaulter's financial position subject to disclosure law. The Digital Personal Data Protection Act, 2023 does not apply to notified State processing on specified public-interest grounds or to qualifying research, archiving and statistical processing.
Section 16 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Section 16 permits the Central Government to restrict a Data Fiduciary's transfer of personal data for processing in specified foreign countries or territories. Indian laws imposing higher protection or stricter overseas-transfer restrictions remain applicable to particular personal data, Data Fiduciaries, or classes of Data Fiduciaries. Commencement is specified as eighteen months from 13 November 2025.
Section 15 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Data Principals must comply with applicable laws when exercising rights, avoid impersonation and suppression of material information, and refrain from lodging false or frivolous grievances or complaints. Personal data provided for documents, unique identifiers, identity proofs, or address proofs must not omit material information. Correction or erasure requests must contain only verifiably authentic information.
Section 14 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Section 14 gives a Data Principal the right to nominate another individual in the prescribed manner. The nominee may exercise the Data Principal's rights upon death or incapacity. Incapacity means inability to exercise those rights due to unsoundness of mind or bodily infirmity.
Section 13 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Data Fiduciaries and Consent Managers must provide readily available means for Data Principals to seek redress for acts or omissions affecting personal-data obligations or the exercise of rights. They must respond to every grievance within the prescribed period applicable to the relevant class. Data Principals must exhaust this grievance-redressal opportunity before approaching the Board.
Section 12 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Data Principals may seek correction, completion, updating and erasure of personal data processed with prior consent, subject to applicable legal requirements and procedures. Data Fiduciaries must correct inaccurate or misleading data, complete incomplete data and update data upon request. Erasure must follow a prescribed request unless retention is necessary for the specified purpose or compliance with law.
Section 11 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
A Data Principal who has previously given consent for personal-data processing may request a summary of processed data, related processing activities, and prescribed information from the relevant Data Fiduciary. The Data Principal may also obtain the identities of other Data Fiduciaries and Data Processors with whom the data has been shared, and a description of the data shared. This disclosure does not apply to legally authorised sharing pursuant to a written request for specified law-enforcement or cyber-incident purposes.
Section 10 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Significant Data Fiduciaries must appoint an India-based Data Protection Officer accountable to their board or similar governing body and acting as the grievance-redressal contact. They must appoint an independent data auditor to evaluate compliance and conduct periodic Data Protection Impact Assessments, periodic data audits, and prescribed additional measures. Designation may follow an assessment of personal-data volume and sensitivity, risks to Data Principals' rights, and potential effects on sovereignty, electoral democracy, State security, and public order.
Section 9 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Processing of personal data of a child, or of a person with disability who has a lawful guardian, requires verifiable consent from the parent or lawful guardian in the prescribed manner. Processing likely to cause a detrimental effect on a child's well-being is prohibited. Data Fiduciaries must not track or behaviourally monitor children, or direct targeted advertising at them. Prescribed exemptions and age-based exemptions for verifiably safe processing may apply.