All articles
News & Analysis 8 min read 9 September 2026 Primitra

India's Data Protection Board Is Being Assembled: What SMEs Should Fix Before It Starts Hearing Cases

India's Data Protection Board is being staffed in 2026, and the soft-enforcement phase is expected to end around November. Here are the four gaps Indian SMEs should close before the Board starts hearing cases.

India's Data Protection Board Is Being Assembled: What SMEs Should Fix Before It Starts Hearing Cases

For most of 2026, the Data Protection Board of India existed mainly on paper. That is changing. In May, the Ministry of Electronics and Information Technology (MeitY) invited applications for the Board's Chairperson and four Members, the recruitment that turns a statutory body into a working regulator. As of late summer, the seats were still being filled, but the direction is set: the office that will actually decide breach cases and hand out penalties under the DPDP Act is being built right now. If you run a small or mid-sized business in India, this is the moment to close the obvious gaps, because the window where nobody is enforcing anything is closing.

The Data Protection Board of India matters to your business in a very concrete way. It is the adjudicatory body that inquires into personal data breaches, examines complaints from people whose data you hold, issues directions, and imposes monetary penalties. Under the DPDP Act, 2023, those penalties run up to ₹250 crore for failing to keep reasonable security safeguards when a breach occurs, and up to ₹200 crore for failing to report a breach on time. Those are ceilings, not automatic fines, but they signal how seriously the law treats sloppy handling of personal data.

Why the timing is not academic

The DPDP Rules, 2025 were notified in November 2025, and the period since has been widely read as a soft-enforcement phase: awareness, guidance, and preparation rather than aggressive supervision. November 2026 marks one year from that notification, and most observers expect the Board to shift from hand-holding toward active enforcement around then. Pair that with the Consent Manager registration framework becoming operational, and the machinery for people to review and withdraw consent, and for the regulator to act, starts working at roughly the same time.

The practical read for an SME is simple. The Board being staffed now means the first real inquiries are months away, not years. You do not want to be discovering your compliance gaps at the same time a data-principal complaint lands.

Four things worth fixing before the Board is live

Know exactly what personal data you hold, and why. Most breach penalties trace back to data a company forgot it even had: an old export sitting in someone's inbox, a marketing list nobody deleted, customer records duplicated across three tools. You cannot protect what you have not mapped. A basic data inventory, who has access, where it lives, how long you keep it, is the foundation everything else sits on. A privacy impact assessment is the structured way to do this for higher-risk processing.

Have a breach response you could actually run at 9pm on a Saturday. The Act expects prompt intimation to affected individuals and the Board, and the working expectation discussed across the industry is notification within about 72 hours of becoming aware. Seventy-two hours sounds generous until a breach happens on a long weekend and nobody knows who decides, who drafts the notice, or where the contact details are. Write the runbook now: who gets called, what gets logged, what the notice says. Failing to report carries penalties of up to ₹200 crore, and a missed notification is one of the easiest failures for a regulator to spot after the fact.

Get your security safeguards to "reasonable." The single largest penalty in the Act attaches to breaches that happen because safeguards were inadequate. Nobody expects a 30-person company to run a bank's security stack, but encryption of sensitive data, access controls, logging, and a patching routine are now the baseline a regulator will look for. If a breach reaches the Board, the question will be whether you took reasonable measures, and "we meant to get to it" is not an answer that helps you.

Fix consent and notice at the point of collection. The Board hears complaints from individuals, and the easiest complaint to make is that you collected data without clear, specific consent or a proper notice explaining what you would do with it. Blanket "accept all" flows and vague privacy policies are exactly the pattern the law was written to end.

What happens if the Data Protection Board of India rules against you

An inquiry does not go straight to a maximum fine. The Board weighs the nature of the failure, the volume and sensitivity of the data involved, whether you tried to mitigate the harm, and whether the problem was repeated. A business that mapped its data, reported the breach quickly, and could show it had real safeguards is in a very different position from one that did none of that. And if you disagree with the Board's order, you are not stuck: an aggrieved party can appeal to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) under Section 29, generally within 60 days. Enforcement is coming, but it comes with process.

There is a wider signal here too. In the EU, full enforcement of the AI Act for high-risk systems began in August 2026, and regulators there have started citing data-protection and AI rules together in a single action. Indian SMEs that use AI tools on customer data should treat that as a preview: the direction of travel everywhere is toward regulators asking harder questions about how personal data feeds automated systems.

A sensible next step

You do not need to solve all of this at once. Start with the inventory, then the breach runbook, then consent and security. If you want a structured way through it, our DPDP Act compliance work and advisory services are built around exactly this sequence for smaller teams. The goal is to be the business that has its house in order before the Board starts knocking, not the one scrambling after a complaint.

This article is general guidance for Indian businesses and is not legal advice; your obligations depend on your specific circumstances. For a practical starting point, run through our DPDP readiness checklist or get in touch to talk through where your gaps are.

Get help implementing this

Turn this reading into a compliance plan.

Book a free 30-minute consultation. We'll map your DPDP Act exposure and give you a prioritized 90-day action list — no obligation.

Book a free 30-minute consultation