DPDP Rules status: compliance window active. Read the update

Skip to content
Data Privacy · Enforcement status

Is the Data Protection Board of India operational yet?

No. It was constituted in law on 13 November 2025, but members are not yet appointed and it is not receiving or hearing complaints.

Educational only · not legal adviceLast reviewed: 17 August 2026Reviewed by Sandesh Kokate, Editor

Short answer

No. The Board's enabling provisions came into force on 13 November 2025, so it exists as a legal body — but it has no appointed members and no live complaints channel, so nothing is being adjudicated today.

The detail

"Constituted" and "operational" are different things. Sections 18–26 of the DPDP Act create the Data Protection Board and set its composition. These sections commenced on 13 November 2025 alongside the DPDP Rules 2025. That gave the Board a legal existence. It also gave the government the machinery to appoint a Chairperson and Members.

The Board was legally established on 13 November 2025, and will consist of a Chairperson and four Members (G.S.R. 845(E), 13 November 2025). MeitY began the appointment process on 6 May 2026, writing to all Union Ministries and Departments and all State and UT Chief Secretaries seeking nominations, and advertised one Chairperson post and four Member posts. A further notification followed on 6 June 2026. As at 4 Sep 2026, no appointment has been notified. Until the Board is staffed there is no active regulator to adjudicate complaints, register Consent Managers, or issue the standards the Rules assume it will issue.

You will sometimes see the Board described as operational, or as already investigating companies. That is not correct. Until members are appointed, there is no body hearing DPDP matters, and no penalties are being imposed under the Act.

The complaint route is also not live. Under the Act, a Data Principal must first go to the Data Fiduciary's own grievance-redressal process. Only then can she approach the Board. That second step has nowhere to go yet.

The duties a complaint would be about include notice, consent, security, breach reporting, and rights. None of these are enforceable until 13 May 2027. That is also when section 33 and the Schedule of penalties take effect.

Where the Board sits in the timeline

13 Nov 2025Board provisions in force

Sections 18–26 commenced, along with the definitions and rule-making powers (Rules 1, 2, 17–21). The Board exists in law; no members appointed, no complaints accepted.

13 Nov 2026Consent Manager registration opens

Section 6(9), section 27(1)(d) and Rule 4 commence, giving the Board its first live registration function.

13 May 2027Core obligations and penalties enforceable

Notice, consent, security, breach reporting, retention, children's data, Significant Data Fiduciary duties, rights, cross-border transfers and section 33 penalties all take effect — the point from which the Board can adjudicate and fine.

What this means for you

Founders

No regulator is knocking today, but your own grievance-redressal process must exist and work by 13 May 2027 — it is the first step every complaint runs through.

Freelancers

Clients asking you to prove "Board compliance" are asking for something that does not exist yet; build to the Act's duties instead.

Creators

If a platform mishandles your data now, the DPDP complaint route is not available — existing IT Act and consumer channels are what you have.

Status

In ForceSections 18–26 in force since 13 November 2025 — no Chairperson or Members had been appointed as at 4 Sep 2026; the Board is not receiving or hearing complaints. Penalties enforceable from 13 May 2027.

Read next

Primary sources

Source
MeitY — DPDP Act (Gazette PDF)

Gazette of India, Extraordinary, Part II, Section 1, 11 August 2023 (Act 22 of 2023) — sections 18–26 establish the Board.

Status unverified — no status check recorded

Source
MeitY — Appointment to the post of Chairperson and Other Members, DPBI (6 May 2026)

Board appointment process — nominations invited from Ministries, Departments and States, 6 May 2026.

Status unverified — no status check recorded

Source
MeitY — DPDP Rules, 2025 (Gazette PDF)

G.S.R. 846(E), 13 November 2025 (Gazette publication ID CG-DL-E-14112025-267650, published 14 November 2025) — sets the phased commencement dates; Rule 4 (Consent Manager registration, the Board's first live function) commences 13 November 2026.

Status unverified — no status check recorded

Companion notifications issued the same day (13 November 2025)

  • G.S.R. 843(E), 13 November 2025 — Phased commencement of the DPDP Act's sections.
  • G.S.R. 844(E), 13 November 2025 — Statutory functions and powers of the Data Protection Board.
  • G.S.R. 845(E), 13 November 2025 — Constitutes the Data Protection Board of India with four Members.

Cited by notification number and date. Individual Gazette PDFs for these three have not been sourced. PDF pending

Citation

Kokate, S. (2026). Is the Data Protection Board of India operational yet? India AI Rulebook. Retrieved from https://indiaairulebook.com/learn/data-privacy/is-the-data-protection-board-operational. Educational content, not legal advice.

The Rules are dated 13 November 2025 and were published in the Gazette on 14 November 2025. Some sources therefore give 14 May 2027. We use 13 May 2027; see Methodology.