Scam Awareness
Got a Call From the Data Protection Board of India?
A call from the Data Protection Board of India in 2026 is fake. No Members are appointed and DPDP penalties start in 2027. How to verify it and report it.
A call from the Data Protection Board of India is fake. The Board was legally established in November 2025, but as of August 2026 it has no Chairperson and no Members appointed, and DPDP penalties do not commence until May 2027. The Board is a digital office and does not phone anyone. Hang up, transfer nothing, and report it on the national cyber crime helpline 1930 or at cybercrime.gov.in.
Under Rule 20 of the DPDP Rules 2025 the Board conducts proceedings through techno-legal measures that do not require anyone’s physical presence. There is no cold-call channel, no Board helpline, and no public complaints portal. So a phone call, a WhatsApp message, or a video call claiming to be a Data Protection Board officer is an impersonation, every time.
Who this guide is for
Anyone in India who has just been called, messaged, or emailed by someone claiming to be from the Data Protection Board of India. You do not need to run a company to be targeted: the same script is run on salaried professionals, retirees, and small business owners.
It also applies to founders and CTOs running AI-first and API-first SaaS startups who have started preparing for DPDP compliance and would take a notice that looks legitimate seriously.
Why am I getting a call from the Data Protection Board of India?
The DPDP Rules 2025 were notified on November 13, 2025 via MeitY Gazette Notification G.S.R. 846(E). Within weeks of that notification, scammers had already started impersonating the Data Protection Board.
One of the first publicly reported cases: a 64-year-old businessman in Naupada, Thane lost INR 1.25 crore (INR 1,25,50,280) between November 11 and December 3, 2025 to a caller posing as an officer of the Data Protection Board of India. The caller claimed a SIM had been illegally issued in the victim’s name, then handed off to fake Nashik police who invoked the National Security Act and money laundering charges. Over roughly three weeks the victim transferred funds across multiple accounts. Naupada police registered a case under Sections 318(4) and 319(2) of the Bharatiya Nyaya Sanhita plus IT Act provisions. (The Tribune coverage, The420.in coverage)
The script combines two things scammers know work in India:
- A new regulator that most people barely understand. DPDP is real, the headlines are everywhere, but the actual enforcement structure and timeline are rarely communicated outside of legal newsletters.
- The same digital arrest playbook that has been run at scale in India: the target is kept on a video call, threatened with the National Security Act or money laundering charges, and isolated from family and legal counsel. Ministry of Home Affairs figures from the Indian Cyber Crime Coordination Centre record 1,23,672 digital arrest cases and INR 1,918 crore lost in 2024, falling to 17,264 cases and INR 644 crore in 2025 after national awareness campaigns (I4C figures reported by ThePrint). The volume dropped. The script did not, and DPDP is the newest label pasted on it.
For a SaaS founder who has spent the last 12 months preparing for DPDP compliance, a Data Protection Board notice arriving by call or email feels plausible. That is exactly what the scammers are counting on.
Is the Data Protection Board of India enforcing DPDP in 2026?
Rule 1 of the DPDP Rules 2025 sets a three-phase commencement schedule, summarised by PIB and tracked publicly by leading law firms (Shardul Amarchand Mangaldas summary).
| Phase | When | What goes live |
|---|---|---|
| Phase 1 | On publication, November 2025 | Rules 1, 2 and 17 to 21, with Sections 18 to 26 of the Act: the Data Protection Board is legally established |
| Phase 2 | One year after publication, November 2026 | Rule 4: consent manager registration and obligations |
| Phase 3 | Eighteen months after publication, May 2027 | Rules 3, 5 to 16, 22 and 23: substantive Data Fiduciary obligations and the penalty regime |
The Rules tie each phase to the date of publication in the Official Gazette rather than to a fixed calendar date, and published trackers differ on whether that clock starts on November 13 or November 14, 2025. Treat the deadlines as mid-November 2026 and mid-May 2027.
As of August 2026, only Phase 1 has taken effect. The Board exists on paper. Three things follow from this:
- The Chairperson and Members are still not appointed. MeitY issued notifications on May 6 and June 6, 2026 inviting applications and nominations, and the search-cum-selection committee for the Chairperson is chaired by the Cabinet Secretary, but no appointment has been announced (LiveLaw, August 2026, Mondaq summary on Board status). A communication citing a named Board officer today is fake by definition, because there are no Board officers.
- Penalties cannot be levied. The Schedule to the DPDP Act 2023, read with Section 33, sets a maximum of INR 250 crore for failing to take reasonable security safeguards under Section 8(5). Both Section 8 and Section 33 sit in the Phase 3 bucket.
- The Board operates as a digital office. Rule 20 of the DPDP Rules 2025 states that the Board shall function as a digital office and may adopt techno-legal measures to conduct proceedings in a manner that does not require the physical presence of any individual. There is no cold-call channel, and no public Board complaints portal has been launched.
In short: nobody can legally fine you under DPDP today. And when the penalty provisions do commence in 2027, they will not arrive via a phone call.
How does the Data Protection Board of India fake call scam work?
The Thane case follows the standard template. The pattern repeats across reports tracked by industry watchers (VARINDIA advisory, N-Pav advisory).
Step by step:
- The cold call. A caller introduces themselves as an officer of the Data Protection Board of India, often with a name that sounds official. They cite a fake reason: a SIM in your name was used for illegal activity, your Aadhaar was used to send vulgar content, your company’s data handling has been flagged.
- The handoff. Once the victim engages, the call is transferred to a second person posing as Mumbai or Nashik police, sometimes a third posing as ED or CBI. The story escalates: NSA, money laundering, drug trafficking.
- The isolation. In the standard version of this script the victim is kept on a continuous video call. They are told not to consult lawyers, not to inform family, not to leave the room. The room becomes a digital arrest.
- The drain. Money is requested in tranches as verification deposits or settlement fees to specific accounts. The Thane victim transferred funds over roughly three weeks. The amounts grow as the victim becomes psychologically committed.
- The vanish. When the victim runs out of funds or finally consults someone, the scammers stop responding. The accounts that received the money are mule accounts, already drained by the time anyone can act.
What makes this scam especially dangerous for SaaS founders: it weaponizes a real concern (DPDP compliance) to bypass the usual skepticism a founder might apply to a generic phishing call.
How do I check if a Data Protection Board call or notice is real?
If you receive any communication claiming to be from the Data Protection Board, run through these checks before doing anything else.
1. Is this arriving by phone, WhatsApp, or video call?
If yes, it is fake. Rule 20 puts Board proceedings in a digital office format, conducted through techno-legal measures rather than in person or over the phone. A genuine Board process would run through official written and digital channels, and right now the Board has no appointed Members to run one at all.
2. Does the sender domain match an official Government of India address?
Real Government of India email addresses end in .gov.in or .nic.in. They do not end in dataprotectionboard.in, dpbi.org, protect-data.in, or any lookalike domain. They never come from Gmail, Yahoo, Outlook, or any consumer email service.
3. Does the notice cite a section the Act actually contains?
The DPDP Act 2023 has 44 sections across 9 chapters. If a notice cites Section 89 or Section 102, it does not exist. If a notice claims an arrest warrant under DPDP, that does not exist either. The Act carries a penalty Schedule enforced under Section 33, and even then the maximums are crore-level civil penalties imposed by the Board after an inquiry, not arrest powers and not on-the-spot demands.
4. Are the Chairperson and Members named on official sites?
As of August 2026 there are no appointed Members of the Board and no appointed Chairperson. If a notice or call cites a specific officer name, cross-check it against PIB releases and MeitY’s official page before responding. If the name does not appear in any official appointment notification, the caller is impersonating the Board.
5. What is the demand?
The DPDP Act does not allow officers to demand immediate cash transfers, demand cryptocurrency, freeze your bank account by verbal instruction, or arrest you over a phone call. If the communication ends in transfer this amount in 30 minutes or you will be arrested, it is a scam regardless of how official the rest of it sounded.
The Data Protection Board of India called me: what do I do?
- Hang up immediately. Do not engage. The longer the call lasts, the more control scammers have.
- Do not transfer money. Even a small verification deposit confirms you as a viable target and triggers escalation.
- Save evidence. Caller number, time of call, any WhatsApp messages, screenshots of email threads. Save the caller ID screenshot and any voicemail.
- Report to cybercrime.gov.in or call the national cyber crime helpline at 1930. Banks can sometimes freeze recipient accounts within hours if reported fast enough.
- Notify your team. If the call came on a corporate line, alert your Data Protection Officer, finance team, and security lead. Scammers often try the same number again with a different angle.
- If you already paid: report to your bank within minutes, file a complaint at 1930 the same day, and reach out to your local cyber crime cell. Speed of reporting is the single biggest factor in fund recovery.
Got a Data Protection Board call or notice? We verify it free
If you received a call, email, WhatsApp message, or letter claiming to be from the Data Protection Board of India and want a sanity check before you respond, send it to us privately.
WhatsApp / Call: +91 99644 43350
Send a screenshot, audio recording, sender number, or whatever details you have. We tell you whether it is a real DPDP communication or a scam, and what to do next.
What we do:
- Cross-check the sender domain against known Government of India address patterns
- Check the named officer (if any) against PIB and MeitY appointment records
- Look for the standard scam-script tells: NSA invocation, urgent transfer demand, video-call coercion, account-freeze threat
- Tell you whether it is real or fake, in plain language
What we do not do:
- Charge you for the verification
- Ask for your bank details, OTPs, or UPI PIN
- Pretend to be the Data Protection Board ourselves
Verification is free.
We also publish a related guide on digital arrest scams and police impersonation for the broader audience these scammers target.
Report it, and how to check something first
Report to the official channels first. They are the only ones who can freeze an account or open an investigation:
- 1930: the National Cyber Crime Helpline, 24/7. Reporting speed is the single biggest factor in getting money back, because banks can sometimes freeze a mule account within hours.
- cybercrime.gov.in: file the formal complaint.
- sancharsaathi.gov.in: report the number or sender (Chakshu).
- 112: police emergency.
Not sure yet whether it is a scam? Send it to ScamNextStep and we will tell you what it is, free:
- WhatsApp: +91 99644 43350
- Email: scamnextstep@gmail.com
What we do is check the open record and tell you what it shows: when a domain was registered, who really publishes an app, whether a company exists, where a photo came from. We are not police: we cannot compel anyone, freeze an account, or recover money that has already gone. We will never ask you for money, OTPs, documents or remote access. If money has already moved, call 1930 first, a bank freeze is faster than we are.
Frequently asked questions
- Is the Data Protection Board of India calling me in 2026?
- No. As of August 2026 the Data Protection Board of India has no Chairperson and no Members appointed, and the DPDP Act penalty provisions do not commence until Phase 3 in May 2027. Any caller claiming to be a Data Protection Board officer today is impersonating the Board.
- How do I verify a real DPDP notice?
- Under Rule 20 of the DPDP Rules 2025 the Board functions as a digital office and conducts proceedings without requiring the physical presence of any individual. It does not cold call citizens or demand payment by phone, WhatsApp, or email. The Board has no appointed Members and no public complaints portal yet, so cross-check anything claiming to be a Board notice against MeitY and PIB announcements before you respond.
- Are DPDP penalties enforceable now?
- No. The penalty regime, including the INR 250 crore maximum in the Schedule to the Act for failing to take reasonable security safeguards under Section 8(5), commences in Phase 3, eighteen months after the DPDP Rules 2025 were published, which falls in May 2027. Phase 1 in November 2025 only established the Board. Phase 2, one year after publication in November 2026, brings consent manager registration into force.
- What should I do if I get a fake DPDP call?
- Hang up. Do not transfer money. Save the caller's number, take screenshots of any messages, and report to cybercrime.gov.in or call the national 1930 cyber crime helpline. If your company received the call on a corporate line, also notify your Data Protection Officer and security team.
- Can the Data Protection Board call me on WhatsApp?
- No. Rule 20 of the DPDP Rules 2025 makes the Board a digital office that conducts proceedings through techno-legal measures rather than in person, and it has no appointed Members yet. Phone calls, WhatsApp messages, and Skype video calls claiming to be from the Board are scams.
- How do I report a fake Data Protection Board of India call?
- Call the national cyber crime helpline on 1930 or file a complaint at cybercrime.gov.in. Report the same day, because banks can sometimes freeze the recipient account within hours if the transfer is flagged fast enough. Keep the caller number, the time of the call, and screenshots of any messages, and if money has already left your account tell your bank immediately.
- Does the Data Protection Board of India have a helpline number?
- No. The Board has not launched a public helpline or a public complaints portal, and it has no appointed Chairperson or Members as of August 2026. Any number presented as a Data Protection Board helpline is not one. For fraud, the number to use is the national cyber crime helpline 1930.
- DPDP Act
- scam awareness
- phishing
- founders
- data protection board
- fraud India