Back to Enforcement Architecture

Adjudication Process

Step-by-step guide to the adjudication process under the DPDPA - from complaint filing to Board determination and remedial action.

7 min read

Step 1: Complaint Filing

The adjudication process begins when a Data Principal files a complaint with the Data Protection Board, or when the Board initiates proceedings suo motu based on a reference from the Central or State Government. The complaint must be filed after the internal grievance redressal process with the Data Fiduciary has been exhausted or the prescribed timeline has lapsed. Complaints are submitted digitally through the Board's portal in the prescribed form and manner.

Step 2: Inquiry by the Board

Upon receiving a complaint, the Board conducts an inquiry into the alleged non-compliance. The inquiry follows principles of natural justice - both parties are given an opportunity to be heard. The Board may call for information, examine evidence, and hear witnesses. Under section 26(c) of the Act, the Board may allocate proceedings to a Member or to groups of Members based on the subject matter or volume of cases. Proceedings are conducted digitally using technology-driven processes.

Step 3: Determination and Directions

Upon completing the inquiry, the Board determines whether a breach of the Act has occurred. If non-compliance is established, the Board may: (a) impose financial penalties as prescribed in the Schedule; (b) issue directions for remedial action; (c) direct the Data Fiduciary to cease specific processing activities; and (d) direct the Data Fiduciary to take specific steps to comply with the Act. All orders must be reasoned and are published for public access.

Penalty Determination Factors

Section 33(2) of the Act lists seven factors the Board must have regard to when determining the quantum of penalty: (a) the nature, gravity and duration of the breach; (b) the type and nature of the personal data affected; (c) the repetitive nature of the breach; (d) whether the person realised a gain or avoided a loss as a result of the breach; (e) whether the person took action to mitigate the effects of the breach, and the timeliness and effectiveness of that action; (f) whether the penalty imposed is proportionate and effective, having regard to the need to secure observance of the Act and to deter breach; (g) the likely impact of the penalty on the person. Penalties are civil in nature and are not criminal sanctions. The maximum penalty of Rs 250 crore applies to the most serious breaches.

Enforcement of Board Orders

Board orders are binding and enforceable. Non-compliance with Board directions may result in additional proceedings and penalties. The Board's digital-first approach ensures that orders are communicated promptly and records are maintained electronically. Organisations should establish internal protocols for responding to Board inquiries, including designating responsible persons, preserving relevant evidence, and engaging legal counsel.

Frequently Asked Questions

Disclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.