Skip to Content

The DPDP Act Just Got Real: What the DPBI Appointment Notice Means for Your Business

The DPDP Act Just Got Real: What the DPBI Appointment Notice Means for Your Business

On May 6, 2026, MeitY formally invited applications for the statutory leadership of the Data Protection Board of India  the independent adjudicatory authority established under Section 18 of the Digital Personal Data Protection Act, 2023 (DPDP Act).

The board will consist of:

  • 1 Chairperson (equivalent to Additional Secretary rank or above, salary: Rs. 4,50,000/month)
  • 4 Members (equivalent to Joint Secretary rank or above, salary: Rs. 4,00,000/month)

This is not a policy committee. This is not an advisory panel.

The DPBI is a body corporate with real enforcement powers the authority to inquire into personal data breaches, issue remediation directions and impose monetary penalties as defined under the DPDP Act and the DPDP Rules 2025.

The minimum age for applicants is 55 years, the tenure is up to 2 years or age 65, and candidates must carry at least 5 years of domain experience in data governance, ICT, law or techno-regulation. At least one Member must be a legal expert. These are senior, experienced professionals being brought in specifically to adjudicate. Not rubber-stamp. Adjudicate.

The application window closes 30 days from the date the advertisement appears in the Employment News. After that, the Search-cum-Selection Committee evaluates, recommends and the government appoints. Once the Chairperson and Members are in place, the DPBI becomes fully operational.

That timeline is months away. Your compliance remediation may need longer than that.


Why This Moment Matters More Than Any Previous DPDP Update

The DPDP Act was notified in August 2023. The DPDP Rules were finalised in early 2025. And yet, for many organisations, compliance remained on the "we'll get to it" list because there was no active enforcement body.

That excuse is now expiring.

Think of it this way. A traffic law without traffic police is uncomfortable but survivable. The moment the police take position, the same road becomes a different experience entirely.

MeitY has now formally begun positioning the traffic police for India's data economy. The DPBI's appointment signals that the government is moving from legislation to enforcement. Organisations that have been waiting for "absolute clarity" before acting are out of time.

Here's what makes this particularly sharp for Indian businesses: the DPDP Act applies to virtually every entity that processes digital personal data of Indian residents, whether the processing happens inside India or outside it. E-commerce platforms, fintech companies, healthcare providers, HR departments, edtech platforms, SaaS businesses the scope is broad and deliberate.


The Compliance Gap: Where Most Organisations Stand Today

Let's be direct about what DPDP compliance actually requires. It is not simply a privacy policy update. It involves:

1. Identifying and mapping all personal data Most organisations do not have a comprehensive inventory of what personal data they collect, where it lives, who can access it and how long it is retained. The DPDP Act requires this clarity as a foundation.

2. Establishing a lawful basis for processing The Act rests heavily on the concept of "consent" clear, informed, specific and revocable consent. If your current consent mechanisms were designed around old terms and conditions, they almost certainly do not meet the standard.

3. Appointing a Data Protection Officer (where applicable) Significant Data Fiduciaries a category MeitY will notify will be required to appoint a DPO. Identifying whether your organisation falls in this category and appointing one is not a quick exercise.

4. Building grievance redressal mechanisms Data Principals (the individuals whose data you hold) have the right to raise complaints. Organisations must have an internal mechanism to receive, log and resolve these complaints before they escalate to the DPBI.

5. Preparing for breach notification obligations Under the Act, personal data breaches must be notified to both the DPBI and the affected Data Principals. This requires breach detection capability, a clear internal escalation process and pre-drafted communication templates.

Each of these workstreams takes time. Legal review. Technology implementation. Policy drafting. Training. And often, vendor audits.

With the DPBI leadership about to be appointed, that time is shrinking faster than most compliance teams realise.


What the DPBI Will Actually Do Once Constituted

Understanding the DPBI's mandate helps organisations understand exactly what they are exposed to if they fall short.

The Board is designed as a digital-by-design institution a phrase MeitY used deliberately in the appointment notice. It will likely operate with online complaint filing, digital hearings and electronic orders. This is not a slow-moving bureaucratic tribunal. The intent is speed and accessibility.

The DPBI is empowered to:

  • Inquire into personal data breaches and instances of non-compliance
  • Issue directions for mitigation and remediation
  • Impose monetary penalties as defined in the Schedule to the DPDP Act

The penalty structure under the DPDP Act is significant. Non-fulfilment of obligations related to children's data can attract up to Rs. 200 crore. Failure to implement adequate security safeguards for a breach can attract up to Rs. 250 crore

These are not symbolic amounts. For mid-sized organisations, a single enforcement action at this scale is an existential event.


The One-Year Post-Tenure Restriction: A Signal About Independence

A detail in the appointment notice that deserves attention: Board members are barred from accepting employment for one year after leaving office without prior Central Government approval.

This cooling-off period signals that the government is building the DPBI as a genuinely independent adjudicatory body not a revolving door. Members will have strong incentive to decide cases on their merits. Organisations that assume enforcement will be lenient because India's regulatory bodies "aren't really that strict" are misreading the architecture of this institution.


What Your Organisation Should Do Right Now

The DPBI appointment process will likely conclude within 3 to 6 months. Here is a prioritised action plan for the window that remains:

Immediate (0 to 30 days) Conduct a data mapping exercise. Know what personal data you hold, why you hold it and who has access.

Short-term (30 to 90 days) Audit your consent mechanisms. Update your privacy notices. Identify whether your organisation qualifies as a Significant Data Fiduciary under the Act's criteria.

Medium-term (90 to 180 days) Build your grievance redressal mechanism. Draft your breach response protocol. Train customer-facing and data-handling teams on their obligations.

Before the DPBI is fully operational Conduct a mock audit. Stress-test your processes. Identify the gaps a regulator would find before the regulator finds them.

This is not about achieving perfect compliance in one leap. It is about demonstrating good faith, building defensible processes and reducing your organisation's exposure to the penalties the DPBI is authorised to impose.


The Line

The DPBI appointment notice is not a bureaucratic update. It is a starting gun.

For three years, the DPDP Act existed as law without a standing enforcement body. That period is ending. The government is now recruiting the Chairperson and Members who will hear complaints, investigate breaches and impose penalties that can run into hundreds of crores.

India's data economy is maturing. The rules are no longer aspirational they are actionable. And the authority to act on them is being formally constituted.

Your compliance programme cannot wait for the next update, the next circular or the next extension. The window to get your house in order is open right now. The question is whether your organisation will use it.


📎 Attachments (1)

📄
DPBI
927 KB · 168 downloads
🔗 Share this post: https://llmadvocates.com/blog/dpdp-compliance-deadline-dpbi-appointment-2026

About LLM Advocates

LLM Advocates is a specialized law firm registered with the Punjab & Haryana High Court, focusing on cyber law, AI governance, data privacy, and technology-related legal services. Our advocates hold LLM degrees in Cyber Law and are ISO 42001:2023 Certified Lead Auditors.

Meet Our Advocates →
Bot Avatar

LLMbot

Online