Next due
11 OCTGSTR-1 · Outward supplies · Sep 2026tomorrow 15 OCTPF & ESI · Contributions · Sep 2026in 5 days 20 OCTGSTR-3B · Summary return · Sep 2026in 10 days 21 OCTTax Audit Report · Form 3CA/3CB · AY 2026-27 · extended from 30 Sepin 11 days 30 OCTAOC-4 · Financial statements · FY 2025-26in 20 days 7 NOVTDS / TCS deposit · Deducted in Oct 2026in 28 days 21 NOVITR filing · Audit cases · AY 2026-27 · extended from 31 Octin 42 days 29 NOVMGT-7 / 7A · Annual return · FY 2025-26in 50 days
All due dates

Section 27 of the Digital Personal Data Protection Act, 2023: Powers and functions of the Board

The Board acts on five kinds of input under section 27(1) and, in each, can inquire and impose penalty as provided in the Act. On a breach intimation it can also direct urgent...

Published
Updated
Reading time
7 min
Views
8
Questions
6 answered
  • Expert Reviewed
  • Medium Complexity
Topic
Data Protection
Published
September 30, 2026
Last updated
Oct 7, 2026
Reading time
7 min
0:00
Last updated: October 2026Verified against: Government sources

Section 27 says what the Data Protection Board actually does. Sub-section (1) lists five triggers for action: a breach intimation, a Data Principal's complaint about a fiduciary, a complaint about a Consent Manager, a breach of a Consent Manager's registration condition, and a Central Government reference about intermediaries. Sub-section (2) gives it a direction power and sub-section (3) a power to modify directions. If you face a complaint or a direction, our legal dispute resolution team can assist.

The five functions in section 27(1)

ClauseTriggerWhat the Board does
(a)Intimation of personal data breach under section 8(6)Direct urgent remedial or mitigation measures; inquire into the breach; impose penalty
(b)Complaint by a Data Principal about a personal data breach or a Data Fiduciary's breach of obligations or of her rights; or a reference by the Central or a State Government; or compliance with a court's directionsInquire into the breach and impose penalty
(c)Complaint by a Data Principal about a Consent Manager's breach of its obligations in relation to her personal dataInquire and impose penalty
(d)Intimation of breach of any condition of registration of a Consent ManagerInquire and impose penalty
(e)Reference by the Central Government about breach by an intermediary of section 37(2)Inquire and impose penalty

Clause (a): breach intimations

When a Data Fiduciary intimates a breach to the Board under section 8(6), the Board may direct urgent remedial or mitigation measures, in addition to inquiring and penalising. The clause gives the Board an active role at the moment of a breach, before any inquiry concludes. See section 8(6). The form and manner of intimation is for the Rules. A fiduciary that intimates promptly and cooperates will find section 33(2)(e) on mitigation relevant to penalty. See section 33.

Clause (b): complaints, references and court directions

Three channels feed clause (b).

  1. A Data Principal's complaint about a personal data breach, or a breach by a Data Fiduciary of its obligations regarding her personal data or her rights under the Act.
  2. A reference by the Central Government or a State Government.
  3. A court's directions, in compliance with which the Board inquires.

Section 13(3) says a Data Principal must exhaust the grievance route with the Data Fiduciary or Consent Manager before approaching the Board. So a complaint under clause (b) is, in the ordinary case, a second step. See section 13. Section 15(d) bars a false or frivolous complaint, and section 28(12) lets the Board warn or impose costs.

Clause (c): Consent Managers

A Data Principal may complain about a Consent Manager's breach of obligations regarding her personal data. The Board inquires and penalises. Clause (d) separately covers an intimation of breach of a condition of the Consent Manager's registration. See section 6 Consent Manager. The Act does not say who makes the intimation under clause (d); the manner of registration and conditions are for the Rules (section 40(2)(d)).

Clause (e): intermediaries

The Central Government may refer a breach of section 37(2), the duty of an intermediary to comply with a blocking direction, and the Board inquires and penalises. See section 37. This is the only clause that concerns a person who is not a Data Fiduciary or Consent Manager.

Section 27(2): directions

The Board "may, for the effective discharge of its functions under the provisions of this Act, after giving the person concerned an opportunity of being heard and after recording reasons in writing, issue such directions as it may consider necessary to such person, who shall be bound to comply with the same."

Four features:

  • Hearing first. The person concerned must be given an opportunity of being heard.
  • Written reasons. The Board must record reasons in writing.
  • Wide content. "Such directions as it may consider necessary", limited by the purpose of discharging its functions. The Act does not list types of direction.
  • Binding. The person "shall be bound to comply".

The Act does not say what penalty attaches to non-compliance with a direction. Item 7 of the Schedule covers breach of any other provision of the Act or the Rules, up to fifty crore rupees, and a direction is given "under the provisions of this Act", so non-compliance is at least arguably caught; the text does not say so in terms. Take advice before treating a direction as optional. An appeal lies to the Appellate Tribunal under section 29 within sixty days.

Section 27(3): modifying directions

On a representation made by a person affected by a direction under 27(1) or (2), or on a reference by the Central Government, the Board may "modify, suspend, withdraw or cancel such direction and, while doing so, impose such conditions as it may deem fit, subject to which the modification, suspension, withdrawal or cancellation shall have effect."

This gives the affected person a first-stage remedy before the Board itself, separate from the appeal. The Act does not set a time for the representation and does not say that making a representation pauses the direction or extends the appeal time.

How section 27 fits with sections 28 to 33

StageSection
Triggers and powers27
Procedure and interim orders28
Appeal29
Mediation and voluntary undertaking31 and 32
Penalty33 and the Schedule

The Board's jurisdiction also excludes civil courts: section 39 bars a civil court from entertaining a suit or proceeding on any matter for which the Board is empowered, and bars injunctions in respect of action taken under the Act's powers.

What section 27 does not say

  • It does not allow the Board to award compensation to a Data Principal. The Act provides for penalties, which go to the Consolidated Fund of India under section 34.
  • It does not give the Board suo motu power expressly; the triggers are intimations, complaints, references and court directions. Whether it may act on other information is not stated.
  • It does not say how a person other than a Data Fiduciary or Consent Manager is to be dealt with under clause (b), beyond the listed triggers.

Example

A retailer intimates a breach under section 8(6). The Board directs immediate steps to contain the breach, then inquires. The retailer may make a representation under 27(3) if a direction is unworkable, and appeal a final order to the Appellate Tribunal.

Need help responding to the Board?

Responding to a direction or a complaint within the time and in the form the Board expects decides how the inquiry goes. Our legal dispute resolution team can help you prepare your response, your representation and, if needed, an appeal.

Key takeaways

  • Section 27(1) lists five triggers: breach intimations, Data Principal complaints, Consent Manager complaints, Consent Manager registration breaches and intermediary references.
  • The Board can direct urgent remedial measures on a breach intimation.
  • Directions need a hearing and written reasons, and bind the recipient.
  • The Board can modify, suspend, withdraw or cancel a direction on representation.
  • Appeals go to the Appellate Tribunal.

Read next

Disclaimer: Based on the Digital Personal Data Protection Act, 2023 (official text as enacted, No. 22 of 2023) as on 30 September 2026. The DPDP Rules, 2025 were notified in November 2025 and different provisions commence on different dates; this article does not state rule-level detail. Verify the current position in the Rules and the commencement notifications before acting.

Quick recapKey facts & short answers

Key Facts About Section 27

  • Applies in: All states across India, under the relevant central law.
  • Mode: Mostly online via the official government portal.
  • Typical timeline: Ranges from a few days to a few weeks depending on the case.
  • Non-compliance: May attract penalties, interest or late fees.
  • Expert help: TaxClue completes the entire process end to end for you.

What can the Board do when a breach is reported?

Direct urgent remedial or mitigation measures, inquire into the breach and impose penalty (section 27(1)(a)).

Must the Board hear me before issuing a direction?

Yes. Section 27(2) requires an opportunity of being heard and written reasons.

Paperwork done properly once does not have to be done again under pressure.

— TaxClue Compliance Desk

Section 27: a key compliance topic in Indian tax and corporate law that businesses and individuals must understand to remain compliant.

Related Services & Guides

Was this article helpful?
About the author
13,350 articles
Vikas Sharma Verified expert Tax & Compliance Expert

Experienced in company registration, GST, trademark, and compliance. Helping Indian businesses stay compliant.

Last reviewed: Live

Disclaimer: This article is for general informational purposes only and does not constitute professional tax, legal or financial advice. Laws, rates and due dates change and can vary by individual case — always verify with the relevant government source (e.g. mca.gov.in, incometax.gov.in) or consult a qualified professional before acting. TaxClue accepts no liability for decisions taken based on this content.

People also ask

Questions, answered

Short, direct answers to the 6 questions readers ask most on this topic.

Direct urgent remedial or mitigation measures, inquire into the breach and impose penalty (section 27(1)(a)).

Yes. Section 27(2) requires an opportunity of being heard and written reasons.

Yes. On a representation, the Board may modify, suspend, withdraw or cancel it under section 27(3).

Clause (b) covers inquiry in compliance with the directions of any court.

The Act provides for penalties under section 33; it does not provide for compensation orders in section 27.

A Data Principal, under section 27(1)(c).