On January 5, 2025, almost two years after the promulgation of the Digital Personal Data Protection Act, 2023 (DPDPA), the Ministry of Electronics and Information Technology (MeitY) published a draft of the Digital Personal Data Protection Rules (DPDPR). The Ministry is inviting public comments/feedback until March 5, 2025.
While the DPDPR aims to clarify and strengthen the DPDPA, concerns persist regarding its enforcement mechanisms, the independence of the Data Protection Board (DPB), and its ability to uphold user rights. This blog post will specifically delve into irregularities afflicting the establishment of the DPB and compare the DPDPR with the European Union’s General Data Protection Regulation (GDPR), which is widely regarded as the gold standard for data protection.
The DPB has been one of the most awaited innovations of the DPDPA. With the accumulation of data assuming increasing importance, the capability of its misuse rises with every passing day. In this context, the establishment of the DPB cements the enforcement of a much-needed data protection law. However, what the DPDPA (and the DPDPR) presents to us is a body that cannot independently conduct regulatory oversight and can lead to more harm being caused to users’ rights than before.
One of the most significant flaws in the DPDPA is the structure of the DPB, the regulatory body responsible for its enforcement. Unlike the GDPR’s independent Data Protection Authorities (DPAs), a requirement that is explicitly mentioned under Article 52, the DPB is a Central Government-appointed and controlled body. DPAs may have their flaws, but they are financially and institutionally independent and retain the ability to penalise both private companies and government entities. For instance, the Dutch DPA imposed a fine of 30.5 million euros on Clearview AI for building an illegal database that has billions of photos of faces. In a separate case, the Irish DPA fined Meta a whopping 251 million euros following an investigation into a data breach.
In contrast, Rule 16 of the DPDPR requires the Central Government to constitute a Search-cum-Selection Committee, with the Cabinet Secretary at its helm, along with Secretaries to the Government of India in charge of the Department of Legal Affairs, and the Ministry of Electronics and Information Technology, in addition to two experts of repute having special knowledge or practical experience in the relevant field. Rule 16(4), in particular, shields the decisions of the Search-cum-Selection by stipulating that it cannot be called into question on grounds such as vacancies, absences, or defects in its constitution. The provision remains vague on whether situations exist for which the said Committee can be scrutinised.
Moreover, an indication of immense power in the hands of the Central Government over the functioning of the DPB can be found in Rule 20 of the DPDPR. This rule states that the Central Government holds the power to “specify, appoint such officers and employees as it may deem necessary for the efficient discharge of its functions under the provisions of Act”. This influence speaks volumes about the ability of the DPB to act impartially and independently.
Coupled with organisational issues, other issues afflict the DPB as well and find their place, or lack thereof, in the DPDPA or DPDPR. These include the inability of the DPB to act upon complaints and conduct independent audits of companies and government agencies. Further, though the DPB is empowered to impose fines, the enforcement mechanisms remain unclear due to a lack of clarity pertaining to, amongst other things, situations which involve non-compliance on the part of entities. Further, unlike the DPAs under GDPR, they cannot suspend data processing activities if violations pose a risk to fundamental rights.

