DPDPA Section 20: Salary, Allowances, and Term of Office for the Data Protection Board

DPDPA Section 20: Salary, Allowances, and Term of Office for the Data Protection Board

Ensure your business meets all regulatory requirements with our comprehensive guide to data privacy compliance. Protect user data and avoid hefty fines.

Himanshu Jotwani

Written by

Himanshu Jotwani

Date

Read time

5 min

Most companies read privacy laws looking for fines and penalties. They skip the administrative sections. But DPDPA Section 20 isn’t just bureaucratic housekeeping. It dictates the compensation framework and tenure for the Chairperson and Members of the Data Protection Board.

It anchors three operational realities: pay is set by rules, it cannot be cut mid-term, and every appointee gets exactly two years before facing reappointment.

This is not trivia. If your organization is going to engage with the Board, understanding how its leadership is appointed, protected, and rotated is how you forecast regulatory continuity and decision-making tempo.

What Section 20 Says

Section 20 establishes a rigid framework for the people enforcing the law:

  • Salary, allowances, and other terms and conditions of service for the Chairperson and Members will be prescribed by rules. The referenced rule is Rule 17.
  • Once appointed, these terms cannot be varied to the disadvantage of the Chairperson or Members.
  • Each appointee holds office for two years and may be reappointed.

The Act does not list the actual rupees or enumerate specific travel allowances. It defers the math to the prescribed rules. But it hardcodes the minimum protections for sitting members and the exact length of their runway.

How to Read “Such as May Be Prescribed”

In legislative drafting, “such as may be prescribed” is code for the Central Government setting the specifics through subordinate legislation. For the DPDP board members salary and perks, that specific vehicle is Rule 17.

Two consequences flow from that:

  • The Act sets the floor. Rules can add detail, but they cannot contradict the statute. A rule cannot shorten the two-year term or allow mid-term changes that disadvantage a sitting member.
  • Assumptions are liabilities. Do not assume any specific allowance or benefit exists unless it appears in the relevant rule or an official notification.

If you are building internal playbooks, cite the Act for tenure and the non-detriment clause. Cite Rule 17 for the operational detail once published.

The Non-Detriment Clause Explained

Section 20 includes a critical safeguard: you cannot reduce a sitting member’s salary, allowances, or service conditions after they take the job.

Illustration of a shield protecting a document, representing the non-detriment clause in DPDPA Section 20.

This is not just an HR policy. It is an independence mechanism.

  • It removes financial leverage. Decision-makers cannot be financially squeezed during their term for making unpopular rulings.
  • It stabilizes operations. Members are not distracted by mid-stream changes to their livelihood that could create conflicts.
  • It enforces administrative discipline. Any future policy shift on compensation applies prospectively to the next batch of appointees, not retroactively to the current ones.

For stakeholders, this means the Board’s leadership has a protected runway to adjudicate matters without external financial pressure.

Tenure, Continuity, and Reappointment

The data protection board india tenure is exactly two years. The Chairperson and Members are eligible for reappointment. The Act does not impose a cap on the number of reappointments,any such limits would need to come from rules or appointment notifications, provided they do not contradict the statute.

The practical implications of a two-year clock:

  • Expect a biennial rhythm. Turnover is a realistic planning factor. Reappointments can smooth transitions, but the composition of the Board is guaranteed to face a decision point every 24 months.
  • Plan for panel shifts. If you have ongoing matters, recognize that panel continuity may be managed through reappointment or case allocation practices. Do not assume an ongoing case will restart because of a scheduled term end, but do build buffers for leadership changes around term transitions.
  • Watch the notifications. Official reappointment announcements are your best signal for institutional continuity.
Illustration showing a calendar with a two-year cycle, representing the Data Protection Board’s term.

What This Means for Operators and Compliance Teams

Even though Section 20 governs the Board’s internal terms, it dictates your external engagement strategy.

  • Case planning and timelines. Two-year terms introduce a predictable ticking clock. For complex or multi-year programs, factor in potential changes in the decision-makers reading your briefs.
  • Consistency of approach. Compensation that cannot be weaponized mid-term creates an independent Board. Expect them to take firm, consistent positions within their statutory mandate.
  • Resourcing signals. The existence of prescribed allowances and formal service conditions suggests a well-supported, structured bureaucracy. Prepare your submissions accordingly.

Treat this as a governance anchor. It tells you the Board is designed to function with protected leadership and defined terms, which drastically reduces the risk of ad hoc shifts during active proceedings.

Boundaries and Misconceptions to Avoid

  • Do not guess the numbers. Do not infer specific salary bands, travel benefits, or medical coverage from the Act. Those live in Rule 17 and related notifications.
  • Do not invent hierarchies in tenure. Section 20 sets a two-year term for both the Chairperson and the Members, with eligibility for reappointment.
  • Do not expect retroactive cuts. Existing members are immune to adverse changes in salary introduced after their appointment. The statute forbids it.
  • Do not rely on commentary. Illustrative or hypothetical compensation examples are not binding. Only the Act and prescribed rules control.

Align your internal guidance to the statutory text and the applicable rule. Everything else is noise.

Operational Takeaways for Engagement

If you expect to stand before the Board, operationalize these basics:

  • Calendar the cycles. Track anticipated term completions and reappointment announcements so you aren’t surprised by a new panel in the middle of an ongoing engagement.
  • Build durable case files. Assume that any change in composition requires a clean file handover. Maintain clear, indexed records and a narrative that survives a change in personnel.
  • Keep it formal. The Board’s protected status and structured service terms mean informal shortcuts will not save you. Precision and completeness will.
  • Avoid the appearance of influence. Standardized, prescribed compensation reduces the tolerance for inducements. The consequences for trying will be severe.

This is solid governance architecture. It gives the Board a stable footing, which gives you a predictable regulator.

Why This Matters Beyond the Text

Compensation set by rule and protected from adverse change removes a common vector for political pressure. Fixed, renewable two-year terms create a forced cadence for leadership planning. Together, these provisions balance independence with accountability through periodic appointments.

For regulated entities, this translates to a Board that is process-driven, time-bound, and insulated from mid-term policy shocks. Stable regulators reward disciplined execution. They penalize disorganization.

Turning statutory text into reliable operations is the hard part. Calendars, document control, role clarity, and escalation paths are what actually carry you through real investigations and hearings. At Regodit, we built our platform to operationalize requirements exactly like these,giving you a structured way to track regulator engagement and keep your compliance posture consistent, even when the Board’s composition changes.

Disclaimer: The views and explanations shared in this blog are based on our team's understanding of the relevant compliance frameworks. While every effort has been made to ensure accuracy, readers are encouraged to refer to the original legal provisions and official notifications for authoritative guidance. Please reach out to us at connect@solsphere.ai.

Keep reading

All blogs →