India DPDP Rules 2026: Data Protection Board Appointments Explained

India DPDP Rules 2026 data protection board explained Photo via Unsplash (photo-1563986768609-322da13575f3); free to use under the Unsplash License. Illustrative only.

India DPDP Rules 2026 enforcement finally has a concrete next step: the Ministry of Electronics and Information Technology (MeitY) issued a notification on May 6, 2026 inviting applications for the Chairperson and four Members of the Data Protection Board of India (DPBI). The DPBI is the independent adjudicatory body created under Section 18 of the Digital Personal Data Protection Act, 2023, and its functioning was operationalised only after the government notified the Digital Personal Data Protection Rules, 2025 on November 13, 2025. Until leadership is in place, India’s flagship data protection law has no functioning enforcement arm. This explainer breaks down who is eligible for the top posts, how the selection process works, what powers the board will eventually wield, and why the appointment timeline matters for businesses, government departments, and ordinary citizens whose personal data is at stake.

What Is the Data Protection Board of India?

The DPBI is a body corporate established under the DPDP Act, 2023, which received Presidential assent in August 2023. It is designed to function as a \”digital-by-design institution\” — meaning most of its proceedings, filings, and hearings are meant to happen online rather than through physical courtrooms. Its core mandate is to act as a quasi-judicial authority that investigates personal data breaches, adjudicates complaints of non-compliance filed by data principals (ordinary users) against data fiduciaries (companies, apps, and government bodies that process personal data), and imposes monetary penalties of up to ₹250 crore per violation depending on the nature and severity of the breach. Unlike sectoral regulators such as the RBI or SEBI, the DPBI’s jurisdiction cuts across every sector that touches personal data, making its eventual composition and independence a matter of wide interest to industry and privacy advocates alike.

Why the Appointment Notification Matters Now

Since the DPDP Act received assent in 2023, the Board has existed only on paper. The turning point came when the DPDP Rules, 2025 were notified on November 13, 2025, which finally activated the Seventh Schedule provisions governing the search-and-selection process, salary structure, and terms of service for the Chairperson and Members. Legal commentary published as late as April 2026 noted that the DPBI was \”the enforcer that isn’t there yet,\” since no Chairperson or Member had actually been appointed and taken office. MeitY’s May 6, 2026 notification — released through Employment News and the ministry’s website — is the first concrete administrative step toward changing that, inviting a fresh panel of candidates to be shortlisted by a Search-cum-Selection Committee (SCSC) before final appointments are cleared by the Central Government.

Key Details of the DPBI Vacancy Notification

PositionEligibility RankMinimum AgeTenureMonthly Salary
Chairperson (1 post)Additional Secretary to Government of India or equivalent55 yearsUp to 2 years or till age 65, whichever is earlier₹4,50,000 (consolidated)
Member (4 posts)Joint Secretary to Government of India or equivalent55 yearsUp to 2 years or till age 65, whichever is earlier₹4,00,000 (consolidated)

Eligibility, Selection Process and Restrictions

Applicants need at least a bachelor’s degree and a minimum of five years of special knowledge or professional experience relevant to data governance, consumer protection law, dispute resolution, information and communication technology, the digital economy, or regulation and techno-regulation. Of the four Member posts, at least one must go to a candidate with expertise in law. The Search-cum-Selection Committee constituted under the DPDP Rules, 2025 will screen applications and prepare a panel of names for the Central Government’s final approval. Serving government officials must route applications through their cadre-controlling authority, though an advance copy may be sent directly. Selected appointees will face a one-year cooling-off period before taking up any other employment connected to matters they handled at the Board, and — notably — will not receive official housing or car facilities despite the seniority of the posts, a detail that has drawn some commentary about how the roles compare with equivalent tribunal positions.

Advertisement

What the Board Will Actually Do Once Constituted

Once appointed, the Chairperson and Members will handle complaints from data principals about mishandled consent, delayed breach notifications, or unauthorised data sharing, as well as suo motu inquiries into significant data breaches reported by companies. The Board can direct data fiduciaries to adopt remedial measures, refer matters for further investigation, and levy penalties scaled to the severity, duration, and repetition of a violation, along with the type and volume of personal data involved. Proceedings are intended to be paperless and largely conducted online, reducing the need for parties to travel to a physical bench. Any party aggrieved by a Board order retains a right of appeal to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT), which has been designated as the appellate authority under the DPDP Act framework, giving the enforcement structure a two-tier check.

Limitations and Open Questions

Several questions remain unresolved even after the vacancy notification. Critics point out that the Search-cum-Selection Committee is dominated by government nominees, raising independence concerns for a body meant to adjudicate against the state as well as private companies. It is also unclear how quickly the SCSC will finalise its panel, how many regional benches (if any) the Board will eventually operate, and how case backlogs will be managed once large volumes of complaints start arriving. Overlap with sectoral regulators such as the RBI, SEBI, and TRAI on data-related matters has not been fully clarified either. Separately, rules covering significant data fiduciaries, cross-border data transfer restrictions, and children’s data safeguards under the DPDP Rules, 2025 are being phased in on their own timelines, meaning the Board’s full docket of responsibilities will expand gradually rather than all at once.

Frequently Asked Questions

When will the Data Protection Board actually start hearing cases?

Only after the Search-cum-Selection Committee finalises its panel and the Central Government formally notifies the Chairperson and Members. Given the 30-day application window from the May 6, 2026 notification and the time needed for screening, the Board is unlikely to become operational before the second half of 2026.

Who is eligible to apply for Chairperson or Member?

Indian citizens at least 55 years old with a bachelor’s degree and five years of relevant experience in data governance, law, ICT, consumer protection, or the digital economy. The Chairperson needs experience equivalent to Additional Secretary rank, while Members need Joint Secretary-equivalent standing.

Advertisement

What penalties can the DPBI impose?

Monetary penalties of up to ₹250 crore per violation under the DPDP Act, 2023, with the exact amount determined by factors such as the nature and severity of the breach, repeated non-compliance, and the volume of personal data affected.

Can a DPBI order be appealed?

Yes. Orders of the Data Protection Board can be appealed before the Telecom Disputes Settlement and Appellate Tribunal (TDSAT), which acts as the designated appellate authority under the DPDP framework.

Bottom Line

The May 2026 vacancy notification is a genuine milestone, but it is a starting gun, not a finish line — the Data Protection Board of India will not be functional until a Chairperson and Members are actually appointed and take charge. Businesses and government bodies should not treat this as a reason to delay DPDP compliance work such as consent management, breach notification protocols, and data fiduciary obligations, since those requirements are already in force independent of whether the enforcement machinery is fully staffed. The coming months, particularly the SCSC’s shortlisting process and the eventual notification of names, will be the real signal of how quickly India’s data protection regime moves from law on paper to law in practice.

Primary sources

Related Topic Express coverage

Featured image: Photo via Unsplash (photo-1563986768609-322da13575f3); free to use under the Unsplash License. Illustrative only.

Loading

Written and fact-checked by

Topic Express

Topic Express is an independent newsroom in India covering breaking news, politics, business, technology, and science. We publish sourced explainers that focus on what is confirmed, what remains unclear, and why a story matters. Editorial contact: topicexpressblog@gmail.com.

Last reviewed July 31, 2026

Advertisement