DPDPA Section 22: Resignation, Vacancies, and Post-Tenure Restrictions for the Chairperson and Members

DPDPA Section 22: Resignation, Vacancies, and Post-Tenure Restrictions for the Chairperson and Members

Regulator exits require strict compliance. Unpack DPDPA Section 22 to master cooling-off periods, DPDP Act resignation rules, and post-tenure hiring risks.

Sahil Pugalia

Written by

Sahil Pugalia

Date

Read time

5 min

When a regulator steps down, they don’t just hand in a badge and walk away. The exit is as heavily regulated as the job itself. Under DPDPA Section 22, resigning from the Data Protection Board is not a unilateral decision,it is a calculated, multi-trigger process.

And what happens after they leave office is where the real compliance traps lie. This section is not theoretical. It creates hard operational boundaries for outgoing officials, the Central Government, and any private organisation hoping to hire them.

Who this section covers and why it matters

Section 22 applies to the Chairperson and any other Member appointed under the Act. It controls three specific mechanisms: how a resignation actually takes effect, how the resulting empty seat is filled, and the strict one-year cooling-off period that follows.

For compliance teams, this isn’t just administrative trivia. It dictates the continuity of active proceedings. For potential employers, it draws a bright red line: you cannot simply headhunt a former regulator without triggering DPDP Act resignation rules and mandatory conflict disclosures.

How a resignation takes effect

A Chairperson or Member cannot simply email a two-week notice and clear out their desk. They must give written notice to the Central Government, but the resignation only becomes effective on the earliest of four specific triggers:

  • The date the Central Government permits the person to relinquish office.
  • Three months from the date the Central Government receives the notice.
  • The date a duly appointed successor takes office.
  • The expiry of the current term.

What this means in practice:

There is no unilateral exit. Control of the timeline is shared between the government and objective triggers like the three-month mark.

Because the resignation can become effective earlier if a successor is appointed promptly, the effective date is fluid. Outgoing officials must be ready to transition without delay. Do not assume a fixed three-month runway. Treat the timeline as volatile and align case transfers accordingly.

Illustration of a calendar with a fluid timeline, representing the unpredictable nature of DPDPA Section 22 resignations.

Filling vacancies

When a seat empties,whether by resignation, removal, death, or any other reason,it must be filled through a fresh appointment in accordance with the Act.

The text does not accommodate stopgap arrangements. It requires a fresh appointment following the Act’s provisions, which means running the full statutory playbook all over again. For the Central Government, the mandate is speed. An empty seat stalls proceedings and delays decisions tied to the departing official.

The appointment process must begin the moment a resignation notice is received, not after it becomes effective.

One-year post-tenure employment restrictions

This is where regulatory hygiene meets the private sector. For one year from the date they cease to hold office, the Chairperson and any other Member are barred from accepting any employment, unless they obtain prior approval from the Central Government.

But the restriction goes deeper. If the former official accepts employment with a Data Fiduciary against whom proceedings were initiated by or before that official, this acceptance must be explicitly disclosed to the Central Government.

How to interpret this responsibly:

The Act does not define “employment” in this provision. A cautious compliance team will treat advisory roles, consulting gigs, and board seats as employment. When in doubt, seek approval.

The disclosure obligation is surgically attached to the official’s involvement in proceedings. If the person initiated or adjudicated a case involving a Data Fiduciary, any subsequent employment with that entity triggers the disclosure.

Controls for potential employers:

  • Verify the former official’s last date in office and calculate the one-year window.
  • If the role starts within that window, plan for prior approval from the Central Government.
  • Screen for any past proceedings involving your organisation that were initiated by or heard before the candidate. If present, prepare to support their disclosure.
  • Document your conflict review steps to establish good faith.

What changes in practice

For Central Government and administrative teams:

Use a resignation intake checklist that logs the date of receipt, calculates the earliest effective date, and kicks off the fresh appointment process. Maintain a live tracker of vacancies and proceedings that may be affected by the shift.

For ongoing proceedings:

Pre-plan reassignment paths for cases tied to the outgoing official to avoid idle time. Relying on a three-month expectation is a gamble when the “earliest-of” rule can abruptly shorten the transition.

For regulated entities and the market:

Hiring former Members or the Chairperson is possible, but only with clear compliance steps. You do not onboard first and regularize later. Be careful with roles that place the former official in contact with matters they previously touched. Even if legally cleared, such roles invite intense scrutiny and reputational risk.

Boundaries of interpretation

Section 22 leaves a few deliberate blanks. It does not detail interim arrangements when a seat is vacant. Assume that a proper fresh appointment is required and plan for continuity within existing frameworks.

Because the term employment is undefined, a cautious approach that treats compensated roles of any kind as employment will drastically reduce risk.

Finally, the disclosure requirement attaches to employment with any Data Fiduciary that had proceedings initiated by or before the former official. Maintain precise records of those interactions. If your records of who adjudicated what are sloppy, you will miss a mandatory disclosure.

Illustration of a person holding a magnifying glass over a document, representing DPDPA Section 22.

Execution checklist

Section 22 is straightforward, but execution is where mistakes happen.

For an outgoing Chairperson or Member:

  • Submit written resignation and retain proof of delivery.
  • Track the earliest-of triggers and be ready for an accelerated exit.
  • Create a case and document handover pack.
  • For one year after cessation, do not accept employment without prior Central Government approval.
  • Disclose any accepted role with a Data Fiduciary involved in proceedings initiated by or before you.

For organisations considering a hire:

  • Confirm the cessation date and compute the one-year restriction window.
  • Determine if your entity had proceedings initiated by or before the candidate.
  • Obtain prior approval when the role starts within one year of cessation.
  • Keep an auditable file of approvals, disclosures, and conflict checks.

Ready to simplify compliance?

Missed deadlines, unclear handovers, or rushed hiring decisions turn administrative transitions into reputational risks. Treat these requirements as operational controls that need strict tracking, documentation, and accountability.

If you want a reliable way to operationalize DPDPA Section 22 without dropped balls, explore how Regodit can help. We provide a structured way to coordinate approvals, track cooling-off windows, map proceedings to potential conflicts, and document each step cleanly. Schedule a discussion to see how your team can run this with precision and clear evidence of compliance.

Disclaimer: The views and explanations shared in this blog are based on our team's understanding of the relevant compliance frameworks. While every effort has been made to ensure accuracy, readers are encouraged to refer to the original legal provisions and official notifications for authoritative guidance. Please reach out to us at connect@solsphere.ai.

Keep reading

All blogs →