Section 27 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Section 27 says what the Data Protection Board actually does. Sub-section (1) lists five triggers for action: a breach intimation, a Data Principal's complaint about a fiduciary, a complaint about a Consent Manager, a breach of a Consent Manager's registration condition, and a Central Government reference about intermediaries. Sub-section (2) gives it a direction power and sub-section (3) a power to modify directions. If you face a complaint or a direction, our legal dispute resolution team can assist.
The Board acts on five kinds of input under section 27(1) and, in each, can inquire and impose penalty as provided in the Act. On a breach intimation it can also direct urgent remedial or mitigation measures. Under section 27(2) it may issue directions after giving the person an opportunity of being heard and recording reasons in writing, and the person shall be bound to comply. Under 27(3) it may modify, suspend, withdraw or cancel a direction on a representation or a Government reference.
The five functions in section 27(1)
| Clause | Trigger | What the Board does |
|---|---|---|
| (a) | Intimation of personal data breach under section 8(6) | Direct urgent remedial or mitigation measures; inquire into the breach; impose penalty |
| (b) | Complaint by a Data Principal about a personal data breach or a Data Fiduciary's breach of obligations or of her rights; or a reference by the Central or a State Government; or compliance with a court's directions | Inquire into the breach and impose penalty |
| (c) | Complaint by a Data Principal about a Consent Manager's breach of its obligations in relation to her personal data | Inquire and impose penalty |
| (d) | Intimation of breach of any condition of registration of a Consent Manager | Inquire and impose penalty |
| (e) | Reference by the Central Government about breach by an intermediary of section 37(2) | Inquire and impose penalty |
Clause (a): breach intimations
When a Data Fiduciary intimates a breach to the Board under section 8(6), the Board may direct urgent remedial or mitigation measures, in addition to inquiring and penalising. The clause gives the Board an active role at the moment of a breach, before any inquiry concludes. See section 8(6). The form and manner of intimation is for the Rules. A fiduciary that intimates promptly and cooperates will find section 33(2)(e) on mitigation relevant to penalty. See section 33.
Clause (b): complaints, references and court directions
Three channels feed clause (b).
- A Data Principal's complaint about a personal data breach, or a breach by a Data Fiduciary of its obligations regarding her personal data or her rights under the Act.
- A reference by the Central Government or a State Government.
- A court's directions, in compliance with which the Board inquires.
Section 13(3) says a Data Principal must exhaust the grievance route with the Data Fiduciary or Consent Manager before approaching the Board. So a complaint under clause (b) is, in the ordinary case, a second step. See section 13. Section 15(d) bars a false or frivolous complaint, and section 28(12) lets the Board warn or impose costs.
Clause (c): Consent Managers
A Data Principal may complain about a Consent Manager's breach of obligations regarding her personal data. The Board inquires and penalises. Clause (d) separately covers an intimation of breach of a condition of the Consent Manager's registration. See section 6 Consent Manager. The Act does not say who makes the intimation under clause (d); the manner of registration and conditions are for the Rules (section 40(2)(d)).
Clause (e): intermediaries
The Central Government may refer a breach of section 37(2), the duty of an intermediary to comply with a blocking direction, and the Board inquires and penalises. See section 37. This is the only clause that concerns a person who is not a Data Fiduciary or Consent Manager.
Section 27(2): directions
The Board "may, for the effective discharge of its functions under the provisions of this Act, after giving the person concerned an opportunity of being heard and after recording reasons in writing, issue such directions as it may consider necessary to such person, who shall be bound to comply with the same."
Four features:
- Hearing first. The person concerned must be given an opportunity of being heard.
- Written reasons. The Board must record reasons in writing.
- Wide content. "Such directions as it may consider necessary", limited by the purpose of discharging its functions. The Act does not list types of direction.
- Binding. The person "shall be bound to comply".
The Act does not say what penalty attaches to non-compliance with a direction. Item 7 of the Schedule covers breach of any other provision of the Act or the Rules, up to fifty crore rupees, and a direction is given "under the provisions of this Act", so non-compliance is at least arguably caught; the text does not say so in terms. Take advice before treating a direction as optional. An appeal lies to the Appellate Tribunal under section 29 within sixty days.
Section 27(3): modifying directions
On a representation made by a person affected by a direction under 27(1) or (2), or on a reference by the Central Government, the Board may "modify, suspend, withdraw or cancel such direction and, while doing so, impose such conditions as it may deem fit, subject to which the modification, suspension, withdrawal or cancellation shall have effect."
This gives the affected person a first-stage remedy before the Board itself, separate from the appeal. The Act does not set a time for the representation and does not say that making a representation pauses the direction or extends the appeal time.
How section 27 fits with sections 28 to 33
| Stage | Section |
|---|---|
| Triggers and powers | 27 |
| Procedure and interim orders | 28 |
| Appeal | 29 |
| Mediation and voluntary undertaking | 31 and 32 |
| Penalty | 33 and the Schedule |
The Board's jurisdiction also excludes civil courts: section 39 bars a civil court from entertaining a suit or proceeding on any matter for which the Board is empowered, and bars injunctions in respect of action taken under the Act's powers.
What section 27 does not say
- It does not allow the Board to award compensation to a Data Principal. The Act provides for penalties, which go to the Consolidated Fund of India under section 34.
- It does not give the Board suo motu power expressly; the triggers are intimations, complaints, references and court directions. Whether it may act on other information is not stated.
- It does not say how a person other than a Data Fiduciary or Consent Manager is to be dealt with under clause (b), beyond the listed triggers.
Example
A retailer intimates a breach under section 8(6). The Board directs immediate steps to contain the breach, then inquires. The retailer may make a representation under 27(3) if a direction is unworkable, and appeal a final order to the Appellate Tribunal.
Need help responding to the Board?
Responding to a direction or a complaint within the time and in the form the Board expects decides how the inquiry goes. Our legal dispute resolution team can help you prepare your response, your representation and, if needed, an appeal.
Key takeaways
- Section 27(1) lists five triggers: breach intimations, Data Principal complaints, Consent Manager complaints, Consent Manager registration breaches and intermediary references.
- The Board can direct urgent remedial measures on a breach intimation.
- Directions need a hearing and written reasons, and bind the recipient.
- The Board can modify, suspend, withdraw or cancel a direction on representation.
- Appeals go to the Appellate Tribunal.
Read next
- Section 28 of the DPDP Act, 2023: inquiry procedure of the Board
- Section 33 of the DPDP Act, 2023: monetary penalty and factors
- Section 18: establishment of the Data Protection Board of India
- Data breach notification obligation under the DPDP Act
Disclaimer: Based on the Digital Personal Data Protection Act, 2023 (official text as enacted, No. 22 of 2023) as on 30 September 2026. The DPDP Rules, 2025 were notified in November 2025 and different provisions commence on different dates; this article does not state rule-level detail. Verify the current position in the Rules and the commencement notifications before acting.
