/The Act · Chapter V · Data Protection Board of India
Section 22: Resignation by Members and filling of vacancy
DPDP Act, 2023 (No. 22 of 2023). In force since 13 November 2025.
- Provision
- Section 22 of The Digital Personal Data Protection Act, 2023
- Status
- In force since 13 November 2025 (phase 1) G.S.R. 843(E)
- Rules made under it
- None identified
- Source
- Ministry of Law and Justice (Legislative Department) · 11 August 2023 · Official PDF
The Chairperson or any other Member may give notice in writing to the Central Government of resigning from her office, and such resignation shall be effective from the date on which the Central Government permits her to relinquish office, or upon expiry of a period of three months from the date of receipt of such notice, or upon a duly appointed successor entering upon her office, or upon the expiry of the term of her office, whichever is earliest.
A vacancy caused by the resignation or removal or death of the Chairperson or any other Member, or otherwise, shall be filled by fresh appointment in accordance with the provisions of this Act.
The Chairperson and any other Member shall not, for a period of one year from the date on which they cease to hold such office, except with the previous approval of the Central Government, accept any employment, and shall also disclose to the Central Government any subsequent acceptance of employment with any Data Fiduciary against whom proceedings were initiated by or before such Chairperson or other Member.
Section 22 explains how the Chairperson or a Member of the Board can resign and what happens when their seat becomes empty. To resign, the member must send a written notice to the Central Government. The resignation does not happen immediately. It takes effect on the earliest of four dates: when the government allows them to step down, three months after the government receives the notice, when a newly appointed successor takes over, or when their official term naturally ends. If a seat becomes vacant because a member resigns, is removed, dies, or leaves for any other reason, the Central Government must fill the vacancy by making a fresh appointment according to the Act. The law also restricts what the Chairperson and Members can do after they leave the Board. For one year after their term ends, they cannot accept any employment without getting prior approval from the Central Government. Additionally, they must disclose to the government if they ever accept a job with a Data Fiduciary (an entity that determines how and why personal data is processed) if that specific Data Fiduciary faced proceedings initiated by or before that member.
Key points
- The Chairperson or any Member may resign by giving written notice to the Central Government (1).
- A resignation takes effect on the earliest of four specific events, such as three months after the notice is received or when a successor enters office (1).
- Any vacancy caused by resignation, removal, or death must be filled by a fresh appointment (2).
- Former members cannot accept any employment for one year after leaving office without prior approval from the Central Government (3).
- Former members must disclose to the Central Government if they later accept employment with a Data Fiduciary that was involved in proceedings before them (3).
Common misreadings
- People might think a resignation takes effect the moment the notice is sent, but it actually takes effect on the earliest of four specific dates, such as three months after receipt or when the government permits it.
- People might assume former members are permanently banned from working for a Data Fiduciary they investigated, but the law only requires them to disclose this employment to the Central Government (and get approval for any job within the first year).
Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.
/MYND · DPDP practice
Putting this into practice?
MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.