Why this is now a board-level risk
Data protection has moved from a compliance footnote to a governance issue. Under India's Digital Personal Data Protection Act (DPDP Act), penalties for serious failures run into hundreds of crores — up to ₹250 crore for a failure to maintain reasonable security safeguards — and that is before the reputational and commercial cost of losing customer trust. With the DPDP Rules, 2025 setting a compliance deadline of 13 May 2027, the risk is neither theoretical nor distant.
A board does not need to understand every technical control. But it is responsible for oversight, and good oversight comes down to asking the right questions and recognising a good answer. Here are seven.
1. Do we know what personal data we hold — and why?
Everything in data protection begins with visibility. If management cannot produce a clear record of the personal data the organisation holds — what it is, where it lives, why it is held, and where it flows — then no assurance about protecting it can be trusted. A good answer points to a maintained Record of Processing Activities (RoPA), not a promise to “look into it.”
2. What is our single biggest data protection exposure right now?
A programme that treats every risk as equal has no priorities. The board should expect management to name the organisation's most significant exposures — a high-risk data set, an over-collecting product, a weak vendor — and explain what is being done about them. Blanket reassurance that “we're compliant” is a warning sign, not an answer.
3. Are we on track for the DPDP deadline — and who owns getting us there?
Accountability cannot be diffuse. The board should know who is responsible for data protection — a Data Protection Officer, a named executive, or an external DPO-as-a-service arrangement — and whether the readiness plan will land before 13 May 2027. Given that a full programme typically takes nine to twelve months, “we'll start soon” is already behind.
4. If we suffered a data breach tomorrow, what would happen in the first 72 hours?
Under the DPDP Rules, a breach triggers a demanding notification process — the Data Protection Board must be informed without delay, affected individuals must be told, and a detailed report is due to the Board within 72 hours. The board should be confident that a tested incident response plan exists, with named roles and drafted notifications. If the honest answer is “we'd work it out,” the organisation is not ready.
5. Can we actually honour the rights our customers and employees now have?
The Act gives individuals real rights — to access, correct, and erase their data, and to seek redress. A right without a process behind it is a liability. The board should ask whether the organisation can receive, verify, and act on such requests within time, and whether grievances are being resolved or quietly accumulating.
6. What data protection risk are our vendors and partners creating for us?
An organisation's obligations extend to the third parties that process personal data on its behalf. A failure at a vendor becomes the organisation's problem — legally and reputationally. The board should expect assurance that contracts, due diligence, and oversight of processors reflect the Act's requirements, not just internal systems.
7. How do we know this is working — not just documented?
This is the most important question, and the easiest to fudge. Policies, certificates, and completed checklists are evidence of intent, not of effectiveness. The board should look for signs of a living programme — testing, monitoring, internal audit, incidents surfaced and closed — rather than a binder that looks impressive and describes a reality that has moved on.
The quality of your oversight is the quality of your questions
A board's oversight is only as strong as the questions it asks. A board that puts these seven to management — and presses for real answers rather than reassurance — will surface the gaps in its data protection posture while there is still time to close them. That, ultimately, is what oversight is for.
This article is for general information and does not constitute legal advice. For guidance on your organisation's specific obligations under the DPDP Act and the DPDP Rules, 2025, speak with a data protection lawyer.

