---
title: "Section 27: Powers and functions of Board"
url: https://dpdp.myndsolution.com/wiki/act/section-27-powers-and-functions-of-board/
description: "Section 27 of the Digital Personal Data Protection Act, 2023 (Powers and functions of Board). Official text verbatim, comes into force on 13 november 2026…"
kind: act-section
updated: 2026-09-09
official_source: https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf
text_type: official-text-plus-interpretation
publisher: MYND Integrated Solutions
license: Official Government of India texts are reproduced verbatim (public domain / open government data). Interpretation is CC BY 4.0, MYND Integrated Solutions.
disclaimer: Not legal advice. Official text prevails over any interpretation.
html_version: https://dpdp.myndsolution.com/wiki/act/section-27-powers-and-functions-of-board/
---
# Section 27: Powers and functions of Board

*The Digital Personal Data Protection Act, 2023 (No. 22 of 2023), Chapter VI: POWERS, FUNCTIONS AND PROCEDURE TO BE FOLLOWED BY BOARD. Comes into force on 13 November 2026.*

## Official text

- **(1)** The Board shall exercise and perform the following powers and functions, namely:—
  - **(a)** on receipt of an intimation of personal data breach under sub-section (6) of section 8, to direct any urgent remedial or mitigation measures in the event of a personal data breach, and to inquire into such personal data breach and impose penalty as provided in this Act;
  - **(b)** on a complaint made by a Data Principal in respect of a personal data breach or a breach in observance by a Data Fiduciary of its obligations in relation to her personal data or the exercise of her rights under the provisions of this Act, or on a reference made to it by the Central Government or a State Government, or in compliance of the directions of any court, to inquire into such breach and impose penalty as provided in this Act;
  - **(c)** on a complaint made by a Data Principal in respect of a breach in observance by a Consent Manager of its obligations in relation to her personal data, to inquire into such breach and impose penalty as provided in this Act;
  - **(d)** on receipt of an intimation of breach of any condition of registration of a Consent Manager, to inquire into such breach and impose penalty as provided in this Act; and
  - **(e)** on a reference made by the Central Government in respect of the breach in observance of the provisions of sub-section (2) of section 37 by an intermediary, to inquire into such breach and impose penalty as provided in this Act.

- **(2)** The Board may, for the effective discharge of its functions under the provisions of this Act, after giving the person concerned an opportunity of being heard and after recording reasons in writing, issue such directions as it may consider necessary to such person, who shall be bound to comply with the same.

- **(3)** The Board may, on a representation made to it by a person affected by a direction issued under sub-section (1) or sub-section (2), or on a reference made by the Central Government, modify, suspend, withdraw or cancel such direction and, while doing so, impose such conditions as it may deem fit, subject to which the modification, suspension, withdrawal or cancellation shall have effect.


## Rules made under this section

- [Rule 19: Procedure for meetings of Board and authentication of its orders, directions and instruments](https://dpdp.myndsolution.com/wiki/rules/rule-19-procedure-for-meetings-of-board-and-authentication-of-its/)

## Interpretation in plain English (not legal advice)

> This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation.

Section 27 outlines the powers and functions of the Board. The Board has the authority to look into personal data breaches and failures to follow the law. When a Data Fiduciary (the entity deciding the purpose and means of processing data) reports a data breach, the Board can order urgent steps to fix or limit the damage, investigate the breach, and impose penalties.\n\nThe Board can also investigate and impose penalties based on complaints or references. It can act on a complaint from a Data Principal (the individual to whom the data relates) if a Data Fiduciary or a Consent Manager (an entity that manages consent on behalf of the Data Principal) fails to meet their obligations or violates the individual's rights. The Board can also act on references from the Central Government, a State Government, or a court order. Additionally, it can investigate breaches of a Consent Manager's registration conditions or an intermediary's obligations when referred by the Central Government.\n\nTo carry out its duties, the Board can issue binding directions to any person. Before issuing a direction, the Board must give the person a chance to be heard and must write down the reasons for its decision. If a person affected by a direction makes a representation, or if the Central Government makes a reference, the Board can change, suspend, withdraw, or cancel the direction, and may add conditions when doing so.

### Key points

- The Board can direct urgent remedial measures, investigate, and impose penalties when notified of a personal data breach (1)(a).
- The Board can investigate and penalize a Data Fiduciary based on a Data Principal's complaint, government reference, or court direction (1)(b).
- The Board can investigate and penalize a Consent Manager for failing its obligations or breaching its registration conditions (1)(c), (1)(d).
- The Board can issue binding directions to any person, provided it gives them a chance to be heard and records its reasons in writing (2).
- The Board can modify, suspend, or cancel its directions based on a representation from an affected person or a reference from the Central Government (3).

### Common misreadings

- People might think the Board can issue directions without warning, but the law requires the Board to give the person an opportunity to be heard and record reasons in writing first.
- People might assume a Board direction is final and unchangeable, but the Board has the power to modify or cancel its own directions if an affected person makes a representation.

*Interpretation prepared 2026-09-09 from the official text only; the official text prevails.*

---
Cite as: Digital Personal Data Protection Act, 2023, s. 27. Official source: https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf
