DPDPA Section 24: Officers and Employees of Board

DPDPA Section 24: Officers and Employees of Board

Ensure your organization meets DPDP Act compliance requirements. Discover actionable steps for data fiduciaries to protect privacy and avoid penalties.

Priyanka Choudhury

Written by

Priyanka Choudhury

Date

Read time

6 min

A regulatory notice is never just a piece of paper. It is a demand, signed by a human being, backed by the threat of state power. But before that human can demand your database logs or inspect your infrastructure, they need the legal authority to ask.

That is what DPDPA Section 24 is for. It answers a simple but critical question: who actually works for the Board, who gives them their power, and under what rules do they operate? It has direct consequences for how the regulator functions,and how your organization will be forced to interact with it.

What Section 24 Actually Says

The law gives the Board the discretion to hire the staff it needs to enforce the DPDPA, but it does not give them a blank check.

  • The Board may appoint officers and employees as it deems necessary to discharge its functions.
  • Every single appointment requires the previous approval of the Central Government.
  • The terms and conditions of appointment and service are strictly prescribed by rules.
  • The applicable rule is DPDP Rule 20, which governs the day-to-day realities of Board personnel.

In plain terms: the Board decides what kind of operational muscle it needs, but the Central Government holds the veto power. There are no ad hoc sheriffs here. Detailed service conditions are fixed by formal rules, not left to internal improvisation.

Scope and Boundaries

This provision is entirely about the internal plumbing of the regulator.

  • The Scope: It covers the officers and employees who actually execute the Board’s statutory functions,the people conducting inquiries, running proceedings, and drafting enforcement orders.
  • The Boundaries: It does not invent new obligations for data fiduciaries. It does not magically expand the Board’s substantive powers. It simply ensures that the people wielding those powers are legally allowed to be in the room.

Why This Matters in Practice

Institutions don’t send emails. People do. Every notice, inquiry, inspection, or penalty under the DPDPA will come through an individual. Section 24 is the legal footing for that individual’s authority. Valid appointments and clear service rules drastically reduce the risk of procedural challenges.

Illustration of a person sending an email, representing the human element in DPDPA Section 24.

For organizations, this translates to a few hard realities:

  • You will interact with designated officers whose authority is documented, not implied.
  • Their conduct, duties, and accountability are governed by standardized employment terms under Rule 20.
  • Because the Central Government must approve staffing, the Board’s capacity, speed, and operational bandwidth are directly tied to bureaucratic oversight.

Let’s strip the legalese from the statute to see how it actually operates.

“With previous approval of the Central Government”

This is a control point, not a post-facto rubber stamp. The Board cannot hire first and ask for forgiveness later. This friction will dictate the pace at which the regulator scales its enforcement teams.

“As it may deem necessary”

The Board dictates its own operational strategy and caseload requirements. The discretion is real, but it is entirely checked by the government approval above.

“For the efficient discharge of its functions under the provisions of this Act”

Staffing must be fit for purpose. These roles exist to execute the statutory functions of the Act, not to freelance on unrelated administrative crusades.

“On such terms and conditions of appointment and service as may be prescribed”

Enter Rule 20. Prescribed terms limit inconsistent, off-the-books arrangements and ensure every officer operates under a unified standard.

Rule 20: What to Expect

While Section 24 creates the roles, DPDP Rule 20 dictates how those roles are governed. It sets the baseline for how Board personnel are appointed, how they serve, and how they are held accountable.

For regulated entities, the takeaway is simple: your interactions with the Board are grounded in formal administrative law. That structure supports predictable processes. Ambiguity about who can do what is a liability, and Rule 20 is designed to remove it.

Implications for Enforcement and Procedure

Section 24 is the bedrock of the Data Protection Board of India authority. If the foundation is cracked, the enforcement action is vulnerable. When the regulator knocks, expect the following:

  • Authorised signatories: Notices and directions shouldn’t be signed by a faceless “Board.” They should carry the names, designations, and references of specific, empowered employees.
  • Delegation clarity: Any demand for your data must have a clear legal basis, tied back to the Act, the Board’s regulations, or an internal delegation aligned with a valid appointment.
  • Record verifiability: The legal validity of a regulatory order can hinge on whether the issuing officer was duly appointed under Section 24 and Rule 20. Proper credentials should be available on request.

What Changes for Operators and Compliance Teams

How does this change Tuesday morning for a compliance team?

  • Verification becomes a reflex: Treat the officer’s designation as a standard checkpoint. Verify signatory identity, the basis of their appointment, and the exact scope of their request before you start pulling logs.
  • Process readiness: Build a workflow for regulatory intake. Authenticity checks, legal review, data scoping, and approval need to happen in a straight line.
  • Evidence hygiene: Keep immaculate records of all communications,headers, letterheads, seals, timestamps, and case references. If you ever need to challenge the scope or timing of an inquiry, this is your ammunition.
  • Pragmatic timelines: Government staffing approvals take time, which can influence the Board’s capacity. Be pragmatic, but do not mistake a slow bureaucracy for a lenient one. Prepare to meet your directed deadlines.
  • A single source of truth: Maintain a central registry of regulatory interactions so legal, security, and engineering aren’t playing telephone during a crisis.
A compliance team reviews a regulatory request, verifying the officer’s identity and scope.

Risk and Governance Considerations

  • Procedural challenges: If you ever consider contesting a notice or order, the validity of the officer’s appointment is a primary angle of attack. Section 24 and Rule 20 set the criteria for that analysis. It shouldn’t be your first resort, but it belongs in your due diligence.
  • Confidentiality of disclosures: You are handing sensitive data to human beings. Board officers operate under prescribed service terms that dictate how they handle information under the Act. Know who is receiving your data.
  • Escalation paths: Use the defined channels. Address submissions exactly as instructed to the named officer. Do not spread sensitive material across multiple inboxes hoping for a faster response.

Practical Starting Points

Don’t wait for the first notice to figure out your routing rules.

  1. Create a regulator-response SOP that explicitly includes identity verification of Board officers and a strict checklist for data minimization.
  2. Train frontline teams to route Board communications to legal and privacy leads within hours, not days.
  3. Build a lean, auditable response pack template containing your legal basis analysis, data maps, logs, and approvals.
  4. Map your points of contact. Maintain a current list of official addresses or portals used by the Board, sourced strictly from formal communications.

The Bottom Line

DPDPA Section 24 is a reminder that regulatory machinery is made of people. The Board can staff up, but only with the Central Government’s prior approval, and only on the terms fixed by Rule 20. For your organization, this means every interaction with the regulator is a formal proceeding with an authorized officer.

Treat it like one. Build the internal muscle to respond with speed, precision, and verifiable evidence.

Executing against regulatory obligations is straightforward on paper and chaotic in practice. Teams need absolute clarity on authority, channels, and scope before handing over a single byte of data or taking corrective steps. At Regodit, we built a structured way to manage these workflows, align your stakeholders, and maintain a defensible record,without slowing the business down.

If operationalizing DPDPA requirements is on your plate, schedule a discussion to see how we can streamline your compliance execution.

Disclaimer: The views and explanations shared in this blog are based on our team's understanding of the relevant compliance frameworks. While every effort has been made to ensure accuracy, readers are encouraged to refer to the original legal provisions and official notifications for authoritative guidance. Please reach out to us at connect@solsphere.ai.

Keep reading

All blogs →