Readiness assessment
Share this section

Chapter VI · Powers, Functions and Procedure

Section 27: Powers and Functions of Board

Section 27 is the enforcement gateway: it lists the events that let the Board act, breach intimations, complaints, government and court references, Consent Manager breaches and intermediary non-compliance, and empowers it to order urgent mitigation, inquire, issue binding directions and impose penalties.

Official text
Section 27Powers & functions
Chapter
Chapter VI · Powers, Functions and Procedure
Status
Enacted · phased commencement
Effective
13 May 2027 (s.27(1)(d): 13 Nov 2026)
Applies to
Board · Data Fiduciaries
Official citation
DPDP Act, 2023, s.27
Reading time
7 min
Updated
August 2026

At a glance

Section 27 sets out the powers and functions of the Data Protection Board. Section 27(1) lists five jurisdiction triggers: a personal data breach intimation under Section 8(6), where the Board can also direct urgent remedial or mitigation measures [27(1)(a)]; a Data Principal complaint about a breach, a Data Fiduciary's obligations or the exercise of her rights, or a Central or State Government reference, or a court's directions [27(1)(b)]; a complaint about a Consent Manager's obligations [27(1)(c)]; an intimation that a Consent Manager breached a condition of its registration [27(1)(d)]; and a Central Government reference about an intermediary breaching Section 37(2) [27(1)(e)]. In each case the Board may inquire and impose a penalty as provided in the Act. Section 27(2) lets the Board issue binding directions after a hearing and recorded reasons, and Section 27(3) lets it modify, suspend, withdraw or cancel a direction. Most of Section 27 takes effect on 13 May 2027; Section 27(1)(d) is set to commence earlier, on 13 November 2026.

Applies to DF & Consent ManagersChapter Chapter VIEffective 13 May 2027Read time 7 min

Key takeaways

  • Section 27 is the enforcement gateway: it defines the events that let the Board act and what it can do in each case [27(1)].
  • Five triggers: a Section 8(6) breach intimation [a], a Data Principal complaint or government/court reference [b], a Consent Manager complaint [c], a Consent Manager registration-condition breach [d], and an intermediary Section 37(2) breach [e].
  • Only 27(1)(a) lets the Board order urgent remedial or mitigation measures; the other four triggers give inquiry and penalty powers.
  • 27(2) lets the Board issue binding directions, but only after a hearing and recorded reasons; 27(3) lets it modify, suspend, withdraw or cancel a direction.
  • The Board penalises "as provided in the Act": the amount comes from Section 33 and the Schedule, not from Section 27 itself.
  • Split commencement: most of Section 27 is set for 13 May 2027, but 27(1)(d) (Consent Manager registration breaches) commences earlier, on 13 November 2026.

Who should read this

Read this if you may deal with the Board: it tells you exactly how a DPDP matter reaches the regulator, when it can order urgent action, and when it can issue a binding direction against you.

FoundersLegal / DPOCompliance leadsProduct / engineering

In plain language

Section 27 answers a simple question: how does a DPDP problem reach the Board, and what can it do once it does? There are five routes in: your own breach intimation, a complaint from a person whose data you hold, a government reference, a court direction, or a Consent Manager or intermediary matter.

In most of those cases the Board can inquire and, if the breach is significant, impose a penalty. Only one route, a Section 8(6) breach intimation, lets it also order urgent remedial or mitigation measures straight away, before any full inquiry.

Beyond penalties, the Board can issue a binding direction under 27(2), but only after hearing you and recording reasons; and it can later modify or withdraw that direction under 27(3). A direction is not optional: you must comply, and the appeal route in Section 29 does not automatically pause it.

The text of the law

Section 27: Powers and Functions of Board

27(1) The Board shall exercise the following powers and functions: (a) on a Section 8(6) personal data breach intimation, direct urgent remedial or mitigation measures, inquire into the breach and impose a penalty; (b) on a Data Principal complaint about a breach or a Data Fiduciary's obligations or the exercise of her rights, or a Central or State Government reference, or in compliance with a court's directions, inquire and impose a penalty; (c) on a Data Principal complaint about a Consent Manager's obligations, inquire and impose a penalty; (d) on an intimation of breach of a condition of a Consent Manager's registration, inquire and impose a penalty; and (e) on a Central Government reference about an intermediary's breach of Section 37(2), inquire and impose a penalty.

27(2) The Board may, for the effective discharge of its functions, after giving the person concerned an opportunity of being heard and recording reasons in writing, issue such directions as it considers necessary, and the person is bound to comply.

27(3) The Board may, on a representation by a person affected by a direction, or on a Central Government reference, modify, suspend, withdraw or cancel the direction, imposing such conditions as it deems fit.

Wording summarised from the enacted Act. Always confirm against the official Gazette text for authoritative language.

What this means for you

  • Treat the Board as a real regulator you can reach in five ways: build your breach-intimation, grievance and Board-response processes around those triggers.
  • If you intimate a breach under Section 8(6), expect the Board to be able to order urgent measures immediately: keep a breach-response playbook that can act on a direction within hours.
  • Keep a Board-response evidence pack ready: the complaint or breach record, notices and consent logs, data map, access and audit logs, processor contracts, rights-request records, retention decisions and remediation evidence.
  • Do not treat a proactive breach report as the end of the matter: it opens the formal pathway, and the Board can still inquire and penalise.
  • Comply with a 27(2) direction promptly while preserving your appeal rights; filing a Section 29 appeal does not automatically stay it. Not sure you could withstand a Board inquiry? Take the readiness assessment or find a specialist.

Frequently asked questions

Does every breach intimation lead to a penalty?
No. A Section 8(6) intimation lets the Board direct urgent measures, inquire and potentially penalise, but a penalty needs a Section 33 finding, after inquiry and a hearing, that the breach is significant.
Can the Board order urgent action before a full inquiry?
Yes, but only on a Section 8(6) breach intimation. Section 27(1)(a) is the one trigger that carries an express urgent remedial or mitigation power.
Can a person complain to the Board without using our grievance channel?
Section 13 requires a Data Principal to exhaust the grievance route with the Data Fiduciary or Consent Manager first. A broken grievance process only increases your risk.
Is a Board direction optional while we appeal?
No. A Section 27(2) direction is binding, and Section 29 does not say an appeal automatically suspends it. Comply unless you obtain a stay.
What penalty can the Board impose under Section 27?
Section 27 itself sets no amount; it says the Board may penalise as provided in the Act. The figure comes from Section 33 and the Schedule, up to Rs 250 crore for a security-safeguard breach, down to a Rs 50 crore residual.

Sources

This is an educational explanation, not legal advice. dpdpactindia.in is an independent resource and is not affiliated with the Government of India.

Start readiness assessment