INSTITUTIONAL EFFICACY OF THE DATA PROTECTION BOARD OF INDIA UNDER THE DPDP FRAMEWORK: A HUMAN RIGHTS ANALYSIS

Authors

  • Vinod Kumar
  • Abhishek Roy

DOI:

https://doi.org/10.37591/jhrlp.v9i2.2190

Keywords:

Data Protection Board of India; DPDP Act 2023; DPDP Rules 2025; regulatory independence; institutional design; informational privacy; tribunalisation; right to an effective remedy; Paris Principles; UN Guiding Principles on Business and Human Rights; ICCPR Article 17.

Abstract

The Digital Personal Data Protection Act, 2023, read with the Digital Personal Data Protection Rules, 2025, is the legislative response to informational privacy as a fundamental right recognised in Justice K.S. Puttaswamy (Retd.) v. Union of India, and to India's obligation under Article 17 of the International Covenant on Civil and Political Rights, 1966. Academic focus has centred on the content of that response how consent is obtained, which governmental activities are exempted, and the amendment of the Right to Information Act, 2005. This article shifts the focus from substance to structure, and assesses the Data Protection Board of India against human rights benchmarks for oversight institutions rather than against data protection benchmarks alone. It argues that the Board has been constituted as an adjudicatory office and not as a regulatory authority, and that this formative choice regardless of any inadequacy in the rights conferred is the primary threat to the efficacy of the Indian regime. The analysis follows several vectors: want of structural independence, arising from appointment through executive-constituted committees, two-year renewable terms, and service conditions drawn from the Central Civil Services (Classification, Control and Appeal) Rules, 1965; the absence of power to make subordinate legislation, codes or binding guidance; the remedial void created by crediting penalties to the Consolidated Fund of India and omitting section 43A of the Information Technology Act, 2000 without replacement; the bar on civil courts; a procedural framework inconsistent with tribunalisation jurisprudence; and an asymmetric relationship with an executive that appoints, funds, staffs, disciplines and may exempt itself. Each defect is mapped onto an established human rights standard: the Principles relating to the Status of National Institutions, 1993 (Paris Principles) on composition, tenure and funding; Article 8 of the Universal Declaration and Article 2(3) of the ICCPR on the right to an effective remedy, with the public law compensation jurisprudence from Rudul Sah and Nilabati Behera; the legality and proportionality standards governing state interference with privacy; and the access-to-remedy pillar of the United Nations Guiding Principles on Business and Human Rights, 2011, whose effectiveness criteria for non-judicial grievance mechanisms the Board largely fails to satisfy. Drawing on the GDPR supervisory-authority model, the reconstituted United Kingdom regulator, the Singaporean Commission and the conversion of Brazil's ANPD into an autonomous authority, the article proposes reforms calibrated to the transition period closing in May 2027. Its conclusion is that a right recognised as both constitutional and internationally guaranteed has been paired with an institution structurally incapable of vindicating it.

References

1. AIR 2017 SC 4161.

2. AIR 1997 SC 3011.

3. Ahmed, Samreen, and Mohammad Nasir. "Digital Personal Data Protection Act, 2023: A Critical Analysis." INDIAN STUDIES REVIEW 1.

4. Roberts, Alasdair. "A great and revolutionary law? The first four years of India’s Right to Information Act." Public Administration Review 70, no. 6 (2010): 925-933.

5. Triponel, Anna. "Guiding Principle 31: Effectiveness Criteria for Non-Judicial Grievance Mechanisms." In The UN Guiding Principles on Business and Human Rights, pp. 239-248. Edward Elgar Publishing, 2023.

6. Pohjolainen, Anna-Elina. The Evolution of National Human Rights Institutions-The Role of the Unites Nations. Vol. 318, no. 165. 1991.

7. Dixon, Pam. "A Failure to “Do No Harm”--India’s Aadhaar biometric ID program and its inability to protect privacy in relation to measures in Europe and the US." Health and technology 7, no. 4 (2017): 539-567.

8. Schütz, Philip. "Data protection authorities under the EU General Data Protection Regulation-a new global benchmark." In Handbook of Regulatory Authorities, pp. 128-145. Edward Elgar Publishing, 2022.

9. AIR 2020 SC 1308

10. Sky, Nova. "Systematic Review of Regulatory Sandboxes: Implications for the European Union's Artificial Intelligence Act." (2024).

11. AIR 1983 SC 1086.

12. AIR 1993 SC 1960.

13. Arun, P. "Beyond Citizen Oversight." Economic & Political Weekly 60, no. 20 (2025): 13.

14. Schroeder, Ralph. "Aadhaar and the social credit system: personal data governance in India and China." International journal of communication 16 (2022).

15. AIR 1997 SC 568.

16. Hajduk, Pawel. "The Powers of the Supervisory Body in the GDPR as a Basis for Shaping the Practices of Personal Data Processing." Rev. Eur. & Comp. L. 45 (2021): 57.

17. Erdos, David. "Towards Effective Supervisory Oversight? Analysing UK Regulatory Enforcement of Data Protection and Electronic Privacy Rights and the Government’s Statutory Reform Plans." Analysing UK Regulatory Enforcement of Data Protection and Electronic Privacy Rights and the Government’s Statutory Reform Plans (November 28, 2022). University of Cambridge Faculty of Law Research Paper 16 (2022).

18. Kharisma, Dona Budi, and Alvalerie Diakanza. "Patient personal data protection: comparing the health-care regulations in Indonesia, Singapore and the European Union." International Journal of Human Rights in Healthcare 17, no. 2 (2024): 157-169.

19. Akkaya, Fethiye Nur Baştürk. "Governing Personal Data Beyond The GDPR: A Comparative Analysis Of Independent Data Protection Authorities In Türkiye And Brazil." İdare Hukuku ve İlimleri Dergisi 24 (2025): 56-66.

Published

2026-09-20

How to Cite

INSTITUTIONAL EFFICACY OF THE DATA PROTECTION BOARD OF INDIA UNDER THE DPDP FRAMEWORK: A HUMAN RIGHTS ANALYSIS. (2026). Journal of Human Rights Law and Practice, 9(2). https://doi.org/10.37591/jhrlp.v9i2.2190