
DPDPA Section 27: Powers and Functions of the Data Protection Board
Ensure your organization meets DPDP Act compliance requirements. Discover the key obligations for data fiduciaries and protect user privacy effectively.
Written by
Priyanka Choudhury
Date
Read time
6 min

Most compliance laws read like abstract suggestions until you reach the enforcement chapter. DPDPA Section 27 is that chapter.
It outlines the Data Protection Board India powers,detailing exactly what the Board can do, when it can act, and how its directions operate. It gives the Board teeth to respond to personal data breaches, act on complaints, and enforce compliance with the Act. But it also creates procedural checks that matter deeply when you are on the receiving end of a notice.
What Section 27 Authorizes
Section 27(1) lists five specific triggers that invite the Board into your operations. These are not theoretical scenarios; they are operational tripwires:
- Breach intimation under section 8(6): When you notify the Board of a breach, you aren’t just filing paperwork. The Board can direct urgent remedial or mitigation measures, conduct an inquiry into the breach, and impose penalties.
- Complaints or references: Whether a complaint comes from a Data Principal, or a reference arrives from the Central Government, State Government, or a court, the Board can inquire into a breach by a Data Fiduciary related to personal data or rights under the Act, and impose penalties.
- Complaints about a Consent Manager: The Board can inquire into breaches of obligations by a Consent Manager and impose penalties.
- Breach of a Consent Manager’s registration conditions: On receipt of such intimation, the Board can inquire and impose penalties.
- Breach by an intermediary of section 37(2): On a reference from the Central Government, the Board can inquire and impose penalties.
Section 27(2) gives the Board the authority to issue directions necessary for the effective discharge of its functions, and the recipient must comply. But there is a procedural check: the Board can only do this after giving the concerned person an opportunity of being heard and recording reasons in writing.
Section 27(3) offers an escape valve. On a representation by a person affected by a direction under sub-sections (1) or (2), or on a Central Government reference, the Board is permitted to modify, suspend, withdraw, or cancel that direction. The Board may also attach conditions to any such change.
And take note of the applicable rule: under Rule 19, the Board functions as a digital office.
Scope and Triggers in Plain Terms
Here is what those triggers mean in practice.

You must notify breaches under section 8(6). But that notification is not a passive filing,it can immediately trigger urgent directions, an inquiry, and penalties.
A Data Principal can complain about breaches or rights violations. Government or court directions can also force an inquiry.
Consent Managers face continuous oversight for both day-to-day obligation breaches and violations of their registration conditions. Meanwhile, intermediaries can face proceedings for breaches of section 37(2), but only where the Central Government makes a direct reference to the Board.
Across all these triggers, the Board’s remedial and penal powers remain consistent. Every path leads to an inquiry, and every inquiry carries the potential for sanctions.
Due Process and Direction Management
Section 27 builds in two critical procedural guardrails.
First, before issuing directions, the Board must provide a hearing and record its reasons in writing. This sets a standard you can hold the process to. It also means your submissions cannot be vague promises,they need to be comprehensive, timely, and backed by hard evidence.
Second, if a direction harms you or is operationally impractical, you can file a representation asking the Board to modify, suspend, withdraw, or cancel it. The Board can revise its own orders and can set conditions on any change. Use this route with a clear remediation plan and measurable milestones, not just objections.
What This Means for Operators
- Breach response is operational, not theoretical. Expect the Board to issue urgent directions. Prepare playbooks that translate likely directives into concrete actions: containment, mitigation, notifications, and evidence preservation. A playbook that hasn’t been tested is just a well-written lie.
- Complaint handling must be defensible. Maintain traceable records of consent, notices, rights handling, security controls, and vendor oversight. If a Data Principal complains, your audit trail is your first line of defense.
- Consent Managers are regulated entities. Track your registration conditions, maintain compliance evidence, and log breach reporting protocols specific to your role.
- Intermediaries need a map. Map any obligations under section 37(2) to controls and escalation paths, and prepare for inquiries when referred by the Central Government.
Functions Highlighted by the Provided Interpretation
The provided interpretation of Section 27 outlines additional contours of how the Board may operate. These go beyond the bare text but are included in the input:
- Investigative tools: This doesn’t just mean sending emails. The Board may summon witnesses, seek documents, and conduct on-site inspections to gather evidence related to breaches.
- Advisory functions: The Board doesn’t just punish; it may provide guidance and develop best practice frameworks on data management and security.
- Enforcement levers: The Board may impose penalties and mandate corrective actions proportionate to violations.
- Policy development: The Board may participate in shaping and updating data protection policies and guidelines.
- Public awareness: The Board may conduct campaigns and publish educational materials to raise awareness of rights and obligations.
- Monitoring and audits: A direction is not the end of the process. The Board may review the implementation of directives and monitor ongoing compliance.
These points align with a regulator that both enforces the law and steers industry practice. Treat them as a practical preview of how supervision will actually play out.
Interpretation Boundaries You Should Note
The explicit statutory powers in Section 27 are clear: the ability to inquire, issue urgent and other directions after a hearing with reasons, and impose penalties across specified triggers. The ability to revise directions is also explicit.
The broader functions listed above are interpretive and included in the provided material. While consistent with a modern regulator, they are not all spelled out word-for-word in Section 27.
However, Rule 19 is cited as making the Board a digital office. Expect digital filings, digital orders, and digital communications. Plan for authenticated submissions, digital evidence management, and tight response windows. Keeping these lines clear will help you argue scope and process when needed.
Enforcement and Case Handling in Practice
From the input’s illustrations, a typical enforcement case follows a distinct operational arc:

- Intake: Complaints or breach intimations reach the Board.
- Inquiry: The Board requests documentation, conducts hearings, and assesses your actual security and privacy controls against your stated obligations.
- Direction and penalty: The Board orders corrective actions with strict timelines. It may impose penalties. It can also require steps that reduce risk and force transparency.
- Follow-up: The Board can monitor compliance and schedule reviews. You may seek modification or suspension of directions if justified and supported by concrete action plans.
If you are seeking guidance rather than facing an inquiry, the interpretation indicates the Board can assess your current posture and recommend controls like encryption, security audits, or training programs, with periodic reviews.
How to Prepare Now
- Map triggers to actions: Define internal owners and timelines for breach intimation, complaint response, and Board engagement.
- Build the record: Maintain versioned policies, DPIAs where relevant, consent logs, access logs, security configurations, and vendor contracts. You cannot protect what you cannot prove.
- Direction readiness: Create a template for receiving and actioning Board directions, with fields for hearing prep, factual chronology, root cause, remedial plan, and evidence of completion.
- Consent Manager specifics: Track registration conditions, audits, and SLA-backed oversight of data flows tied to consents and withdrawals.
- Intermediary posture: If applicable, document how you meet obligations under section 37(2) and keep a response kit for government-referred matters.
- Governance: Establish a review process to file representations where directions need modification, armed with measurable proposals instead of objections alone.
Real execution will test your incident response maturity, documentation integrity, and ability to convert regulatory directions into completed work. Section 27 rewards timely action and clear evidence. It punishes delay, poor records, and vague commitments.
Operationalizing this consistently is hard without structure. That is why Regodit gives teams a single method to capture obligations, turn them into tasks, track evidence, and be ready for hearings and follow-ups. Compliance isn’t about hoping the Board never calls; it’s about having the exact answers ready when they do.
Disclaimer: The views and explanations shared in this blog are based on our team's understanding of the relevant compliance frameworks. While every effort has been made to ensure accuracy, readers are encouraged to refer to the original legal provisions and official notifications for authoritative guidance. Please reach out to us at connect@solsphere.ai.
Keep reading
All blogs →DPDPA Rule 23: Government Requests for Information from Data Fiduciaries and Intermediaries
Handling a notice under DPDP Act Rule 23 requires strict confidentiality. Discover how to respond to government data requests and ensure full compliance.
DPDPA Rule 22: Appeals to the Appellate Tribunal
Lost at the Data Protection Board? DPDPA Rule 22 governs the digital-first appeals process. Read our complete guide to filing an appeal with the Tribunal.
DPDPA Rule 21: The Machinery Behind the Data Protection Board of India
Ensure your business meets DPDP Act compliance requirements. Discover key obligations for data fiduciaries, penalty risks, and steps to protect user privacy.
