Data breach by a company — your rights and remediesThe Digital Personal Data Protection Act, 2023 was notified in August 2023 but its substantive obligations remain partly in transition — the Board has not yet been constituted operationally, the Draft Digital Personal Data Protection Rules, 2025 were published for consultation in January 2025, and Section 43A of the IT Act 2000 with the SPDI Rules 2011 continues to govern compensation for breaches until the DPDP repeal takes full effect. This piece sets out what the DPDP fram Two regimes, one breach, a tribunal in TDSATand a Board not yet operational
[ Everyday Law ]

Data breach by a company — your rights and remedies

The Digital Personal Data Protection Act, 2023 was notified in August 2023 but its substantive obligations remain partly in transition. The Data Protection Board of India has not been operationally constituted, the Draft Digital Personal Data Protection Rules, 2025 were published for consultation by MeitY in January 2025, and Section 43A of the Information Technology Act, 2000 read with the SPDI Rules, 2011 continues to govern compensation for breach of sensitive personal data until the DPDP repeal under Section 44(2) takes full effect. This piece sets out what the DPDP framework will deliver, what the IT Act overlay still does, and where the consumer-protection and constitutional remedies sit.

A personal-data breach by a company — the leak of customer KYC documents from a fintech, the exposure of patient records from a hospital, the theft of an e-commerce database from a cloud account, the publication of insurance-claim files on a paste-bin — engages a layered Indian regime in 2026 that has neither fully transitioned to the new statutory architecture nor entirely shed the old. The Digital Personal Data Protection Act, 2023, the country's first horizontal data-protection statute, received Presidential assent on 11 August 2023 and was published in the Gazette the following day; but the substantive Sections — including the obligations of Data Fiduciaries under Section 8, the rights of Data Principals under Sections 11–14, the breach-notification duty in Section 8(6), and the penalty framework in Section 33 read with the Schedule — are conditioned on the constitution and operationalisation of the Data Protection Board of India under Sections 18–26 and on the notification of subordinate rules. The Draft Digital Personal Data Protection Rules, 2025 were published by the Ministry of Electronics and Information Technology for public consultation in January 2025; the final rules are awaited. Until the DPDP Act fully repeals and replaces the earlier regime — Section 44(2) of the DPDP Act expressly omits Section 43A of the Information Technology Act, 2000 from the IT Act on a date to be notified — the Section 43A regime, read with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, continues to govern compensation. The constitutional anchor for both regimes is the informational-privacy doctrine of Justice K S Puttaswamy v Union of India, (2017) 10 SCC 1.

Section 2(t) DPDP — what counts as a "personal data breach"

Section 2(t) of the DPDP Act, 2023 defines a personal data breach as any unauthorised processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises the confidentiality, integrity or availability of personal data. The definition is broad on three axes — it captures both deliberate and accidental events, it captures both confidentiality-and-integrity failures and availability failures, and it does not require an external attacker. A misconfigured cloud bucket exposing customer records is a Section 2(t) event; so is the ransomware-driven loss of access; so is the inadvertent disclosure by a careless employee. The breadth of Section 2(t) carries over to the Section 8(6) notification duty — every Section 2(t) event is in principle notifiable, and the Draft Rules of 2025 propose to refine the notification thresholds and timelines.

The Section 2(t) definition departs from the narrower Section 43A IT Act idea, which is anchored in "sensitive personal data or information" as defined by Rule 3 of the SPDI Rules, 2011 — passwords, financial information, health condition, sexual orientation, medical records, biometric information, and similar categories. The DPDP Act's "personal data" is defined in Section 2(t) read with Section 2(u) to mean any data about an individual who is identifiable by or in relation to such data — a wider category that does not turn on a closed list of sensitive items. The DPDP framework does not retain the sensitive/non-sensitive distinction of the SPDI Rules; in its place, Section 9 of the DPDP Act introduces additional obligations for "Significant Data Fiduciaries" notified by the Central Government, and Section 9(2) requires Data Protection Impact Assessments and the appointment of a Data Protection Officer.

Section 8 DPDP — the Data Fiduciary's obligations and the breach-notification duty

Section 8 of the DPDP Act sets out the general obligations of a Data Fiduciary. Section 8(1) imposes the umbrella obligation to comply with the Act in respect of any processing undertaken; Section 8(2) requires the Data Fiduciary to ensure the completeness, accuracy and consistency of personal data; Section 8(3) requires the implementation of appropriate technical and organisational measures to ensure effective observance of the Act; Section 8(4) requires the implementation of "reasonable security safeguards" to prevent personal data breach. Section 8(5) requires the Data Fiduciary, in the event of a personal data breach, to give intimation of the breach to the Data Protection Board and to each affected Data Principal, in such form and manner as may be prescribed. Section 8(6) makes the intimation duty unconditional — every Section 2(t) breach engages the notification obligation, with the form, manner and timeline to be specified in the Rules.

The Draft Digital Personal Data Protection Rules, 2025, in their January 2025 consultation form, propose a two-tier notification scheme — an initial intimation to the Board "without delay" upon becoming aware of the breach, and a fuller report within seventy-two hours that includes the nature of the breach, the categories of personal data affected, the approximate number of Data Principals affected, the likely consequences, and the mitigation measures taken or proposed. The intimation to affected Data Principals is, in the Draft Rules, to be made by a means reasonably likely to reach them, with content prescribed by a schedule to the Rules — the nature and approximate scale of the breach, the description of likely consequences, the safeguards available to the Data Principal, the contact details of the Data Protection Officer or the equivalent contact. The Draft Rules, until finalised and notified, are consultative; they signal direction but do not yet bind.

The breach-notification duty under Section 8(6) is the single most material new obligation for Indian businesses. Under the Section 43A IT Act regime, there is no statutory breach-notification duty; the CERT-In Directions of April 2022 require reporting of cyber incidents within six hours but engage cyber-security incidents rather than personal-data-breach events, and the SPDI Rules require security-practice disclosures but not breach notifications. The DPDP framework, once fully operational, will impose for the first time in Indian law a horizontal personal-data-breach-notification regime comparable in design to the GDPR's Article 33.

Sections 11–14 DPDP — the rights of the Data Principal

The Data Principal's rights are set out in Sections 11–14 of the DPDP Act. Section 11 confers the right to access — the right to obtain from the Data Fiduciary a summary of the personal data being processed, the processing activities undertaken, the identities of the Data Fiduciaries and Data Processors with whom the personal data has been shared, and any other information relating to the personal data and its processing. Section 12 confers the right to correction, completion, updating and erasure of personal data — the Data Fiduciary must, on the Data Principal's request, correct inaccurate or misleading personal data, complete incomplete data, update data, and erase personal data that is no longer necessary for the specified purpose unless retention is required by law. Section 13 confers the right of grievance redressal — the Data Fiduciary must provide a readily accessible mechanism for the Data Principal to grieve, and must respond within such period as may be prescribed; the Draft Rules of 2025 propose a thirty-day default. Section 14 confers the right to nominate — the Data Principal may nominate another individual who may, in the event of death or incapacity, exercise the Data Principal's rights.

The exercise of the Sections 11–14 rights is the procedural predicate for the Data Principal's complaint to the Data Protection Board under Section 27. The Section 13 grievance-redressal route must be exhausted first — Section 27 read with the Draft Rules contemplates that a Data Principal aggrieved by the Data Fiduciary's response (or by the absence of one) may complain to the Board, which then proceeds under Section 28 to inquire into the matter. The Section 13 exhaustion requirement is not absolute — the Board has discretion to entertain a complaint where the Data Principal demonstrates that the grievance route is unavailable or has been exhausted in substance — but the disciplined complainant follows the sequence.

Sections 18–26 DPDP — the Data Protection Board of India

The Data Protection Board of India is the central regulatory and adjudicatory authority under the DPDP Act. Sections 18–26 set out the Board's composition, qualifications, powers, term, salary, and procedural framework. Section 18 establishes the Board with a Chairperson and such number of other Members as the Central Government may notify; Section 19 prescribes the qualifications; Section 20 specifies that the Chairperson and Members hold office for two years and are eligible for re-appointment; Sections 21–23 cover resignation, removal, and the conditions of service; Sections 24–26 deal with the meetings of the Board, the conditions of service of officers and employees, and other administrative matters.

Section 27 of the DPDP Act sets out the Board's functions — to determine non-compliance and to impose monetary penalties under Section 33, to receive and act on complaints of personal data breach, and to issue directions for remedial measures. Section 28 prescribes the inquiry procedure — the Board may inquire suo motu or on a complaint, summon witnesses, require the production of documents, examine on oath, and pass orders in the manner prescribed. Section 28(7) provides that the Board's proceedings are deemed to be judicial proceedings under Sections 193 and 228 of the Indian Penal Code (now Sections 230 and 267 of the Bharatiya Nyaya Sanhita, 2023). Section 28(8) confers contempt-related powers.

The Board has not been operationally constituted as of the date of writing. The Government has indicated, in the Draft Rules of 2025 and in the related Press Notes, that the Board will be notified shortly after the Rules are finalised. The transition state means that complaints of personal data breach that, on a substantive reading, would attract Section 8 of the DPDP Act and Section 33 penalties cannot at present be filed before the Board — the substantive provisions of the Act are in force in a notional sense but the adjudicatory machinery is not. The practical consequence is set out in the next two sections.

Section 29 DPDP — the appeal to TDSAT

Section 29 of the DPDP Act prescribes the appeal from the Board's order. Any person aggrieved by an order or direction of the Board may, within sixty days from the date of receipt of the order, prefer an appeal to the Appellate Tribunal — and the Appellate Tribunal, for the purposes of the DPDP Act, is the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) established under Section 14 of the Telecom Regulatory Authority of India Act, 1997. The architecture mirrors the IT Act's appellate structure: Section 48 of the IT Act, as amended by the Finance Act, 2017, also designates TDSAT as the Appellate Tribunal for the IT Act's adjudicatory framework under Sections 46 and 57. The same tribunal now hears appeals from both the IT Act Adjudicating Officer's compensation orders under Section 43A and (when the Board becomes operational) from the Data Protection Board's penalty orders under Section 33.

Section 29(2) of the DPDP Act provides that the Tribunal may, after giving the parties an opportunity of being heard, confirm, modify or set aside the order appealed against. Section 29(3) sets the timeline — the Tribunal shall endeavour to dispose of the appeal within six months of filing. Section 29(4) provides that an appeal from the Tribunal's order lies to the Supreme Court within ninety days.

Section 33 DPDP — penalties up to Rs 250 crore

Section 33 of the DPDP Act, read with the Schedule, prescribes the monetary penalties for non-compliance. The Schedule lists the contraventions and the maximum penalties: failure of the Data Fiduciary to take reasonable security safeguards to prevent personal data breach attracts a penalty up to Rs 250 crore; failure to give intimation of a personal data breach to the Board or to affected Data Principals attracts a penalty up to Rs 200 crore; non-fulfilment of additional obligations relating to children attracts a penalty up to Rs 200 crore; non-fulfilment of additional obligations of a Significant Data Fiduciary attracts a penalty up to Rs 150 crore; breach of the Data Principal's duties attracts a penalty up to Rs 10,000; and a residual category of "breach of any other provision of this Act or rules made thereunder" attracts a penalty up to Rs 50 crore.

The Rs 250 crore ceiling for security-safeguard failure is the headline number, but the structure of Section 33 is more important than the maximum. Section 33(1) requires the Board, in determining the penalty, to have regard to the nature, gravity and duration of the breach, the type and nature of personal data affected, the recurrent nature of the breach, the gain or loss avoided as a result of the breach, whether the person took any steps to mitigate, and the impact on Data Principals. The framework is calibrative, not punitive at the maximum. The early Board decisions, once they begin to issue, will set the trajectory.

It is important to note what Section 33 does and does not do for the Data Principal. Section 33 imposes a monetary penalty payable to the consolidated fund of India; it is not a compensation route for the Data Principal. The DPDP Act, in its enacted form, does not include a private right of compensation comparable to Section 43A of the IT Act. This is a structural design choice — and a contested one. The Data Principal who suffers loss from a personal data breach is, under the DPDP framework, principally an enforcement complainant whose role is to bring the breach to the Board's attention; the Board's penalty does not flow to her. The compensation route, until the Section 43A repeal takes full effect, runs through the IT Act.

The Section 43A IT Act overlay — what continues to operate during transition

Section 43A of the IT Act, 2000 — inserted by the 2008 amendment — provides that where a body corporate, possessing, dealing with or handling any sensitive personal data or information in a computer resource which it owns, controls or operates, is negligent in implementing and maintaining reasonable security practices and procedures, and thereby causes wrongful loss or wrongful gain to any person, the body corporate is liable to pay damages by way of compensation, not exceeding five crore rupees, to the person so affected. The "reasonable security practices and procedures" are those specified in the SPDI Rules, 2011, including the ISO/IEC 27001 standard or an equivalent code approved by the Central Government and notified in the Gazette.

Section 43A is operative until expressly omitted by notification under Section 44(2) of the DPDP Act. As of the date of writing, that omission has not been notified; Section 43A continues to operate. The compensation route under Section 43A runs through the Adjudicating Officer under Section 46 of the IT Act — an officer of the Central Government, not below the rank of Director, designated for the purpose. The Adjudicating Officer's order under Section 46 read with Section 43A is appealable to TDSAT under Section 57 within forty-five days, with the further safeguard under Section 64 that an unpaid award is recoverable as an arrear of land revenue.

The IT Act's broader compensation framework — Section 43 (compensation for damage to computer, computer system or computer network), Section 66 (computer-related offences with imprisonment up to three years), Section 72 (breach of confidentiality and privacy by a person who has secured access to information under the Act), Section 72A (disclosure of information in breach of a lawful contract) — continues to operate in parallel and is not displaced by the DPDP Act. Section 72A in particular catches the disclosure-of-personal-information-by-service-provider-in-breach-of-contract scenario that is common in employee-leak and insider-attack cases, with imprisonment up to three years or fine up to five lakh rupees or both. Where the breach has a criminal-law character — a deliberate exfiltration, an extortion attempt, the sale of breached data on dark-web marketplaces — the FIR route under Section 173 of the Bharatiya Nagarik Suraksha Sanhita, 2023 runs in parallel to the civil/regulatory route, invoking Sections 66 and 72 of the IT Act and the cognate provisions of the Bharatiya Nyaya Sanhita, 2023 (Sections 303, 315 and 318 on theft, dishonest misappropriation and cheating).

The consumer-protection route — deficiency in service under the CPA 2019

An independent route — sometimes faster, sometimes the only effective route during the DPDP transition — runs through the Consumer Protection Act, 2019. Where the breached entity provided a service to the Data Principal — a bank, an insurer, an e-commerce platform, a fintech, a hospital, a telecommunications service provider, an OTT service — the personal-data breach is, on settled consumer-forum reasoning, a deficiency in service within the meaning of Section 2(11) of the CPA 2019. A complaint under Section 35 of the CPA 2019 lies before the District, State or National Commission depending on the pecuniary jurisdiction set under Sections 34, 47 and 58.

The consumer route's advantages are procedural — the consumer complainant pays a low filing fee, may appear in person, is not constrained by the Section 46/57 IT Act framework, and may seek both compensation and consequential reliefs (correction of records, deletion, future-conduct directions). Its limitations are jurisdictional — it engages only the "consumer" category and not, for example, a Data Principal whose personal data was processed without any service relationship. For the typical breach case — a customer's KYC files leaked from a bank or fintech, an insured's claim records exposed by an insurer — the CPA 2019 route is in practice the most accessible.

The constitutional anchor — Puttaswamy and Article 21

The constitutional doctrine that sits above the statutory architecture is Justice K S Puttaswamy v Union of India, (2017) 10 SCC 1, the nine-judge ruling that recognised privacy as a fundamental right under Article 21 of the Constitution and explicitly extended the protection to informational privacy. The Puttaswamy doctrine has two consequences for the data-breach context. First, it supplies a horizontal-rights anchor that informs the construction of the statutory framework — both the DPDP Act and the residual IT Act provisions are to be read in a manner that gives effect to the informational-privacy guarantee. Second, it opens a writ remedy under Article 226 of the Constitution where State authorities or instrumentalities are implicated in the breach — a Section 226 writ petition lies in the High Court against a State-owned bank, a public-sector insurer, a State-owned hospital, or an instrumentality, with the doctrinal anchor running through the proportionality framework most authoritatively articulated in Internet & Mobile Association of India v Reserve Bank of India, (2020) 10 SCC 274.

The intermediary-liability framework in Shreya Singhal v Union of India, (2015) 5 SCC 1, retains its independent force in the breach context. Where the breached data has been redistributed on intermediary platforms — published on file-sharing sites, paste-bins or forums — the Section 79 IT Act safe-harbour architecture and the Rule 3 takedown framework of the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 supply the removal route, with the DPDP Section 8 obligations of the original Data Fiduciary running in parallel.

The breach-response roadmap for a Data Principal

The Data Principal who learns that her personal data has been breached by a company faces a sequencing problem — the DPDP machinery is not yet operational, the Section 43A regime is, and the consumer- and constitutional-law routes sit on either side. The disciplined sequence is the following.

Step 1 — Evidence preservation and breach scoping. Obtain and preserve all materials evidencing the breach — the company's breach-notification email, the news reports, the dark-web post or paste-bin URL where the data has surfaced, the screenshots of the company's website or app showing the relevant disclosures. Establish the categories of personal data affected, the date or window of the breach, and the date of the company's notification (where given). Preserve the underlying contract or terms-of-service that governed the data relationship.

Step 2 — Issue a Section 11–13 DPDP rights notice. Send a written notice to the company invoking the rights under Sections 11, 12 and 13 of the DPDP Act — access to a summary of the personal data processed, correction or erasure as appropriate, and grievance redressal of the breach-specific complaint. The Draft Rules of 2025 contemplate a thirty-day response period; treat thirty days as the operating timeline. The Section 13 grievance-redressal route is the procedural predicate for the later complaint to the Board.

Step 3 — File the Section 43A IT Act compensation claim before the Adjudicating Officer. Where the breached data falls within the SPDI Rules 2011 sensitive-personal-data categories — passwords, financial information, health condition, biometric information, sexual-orientation data — file a compensation claim before the Adjudicating Officer of the IT Act in the relevant State under Section 46 read with Section 43A. The claim may seek damages up to Rs 5 crore. The Adjudicating Officer's powers under Section 46(2) include summoning, examining on oath, and ordering compensation; the procedure mirrors the civil-court framework. An order under Section 43A is appealable to TDSAT under Section 57 within forty-five days, and TDSAT's order is itself appealable to the High Court under Section 62 within sixty days.

Step 4 — File a CPA 2019 consumer complaint where the relationship is one of service. Where the breached entity supplied a service to the Data Principal — bank, insurer, e-commerce, fintech, hospital, OTT — file a consumer complaint under Section 35 of the CPA 2019 before the District, State or National Commission with appropriate pecuniary jurisdiction, alleging deficiency in service in the implementation of reasonable security safeguards. The consumer route may seek both compensation and consequential reliefs.

Step 5 — File an FIR under Section 173 BNSS where the breach has a criminal-law character. Where the breach was the result of a deliberate exfiltration, an insider attack, a sale on a dark-web marketplace, or an extortion attempt, file an FIR with the local cybercrime cell invoking Sections 43, 66, 72 and 72A of the IT Act and the cognate provisions of the Bharatiya Nyaya Sanhita, 2023 (Sections 303, 315 and 318). The investigation must be by an Inspector or above per Section 78 of the IT Act.

Step 6 — Reserve the writ remedy for State-instrumentality breaches. Where the breached entity is a State-owned bank, a public-sector insurer, a State-owned hospital, or an instrumentality, an Article 226 writ petition before the jurisdictional High Court is available, invoking Justice K S Puttaswamy v Union of India, (2017) 10 SCC 1, and the proportionality framework of Internet & Mobile Association of India v Reserve Bank of India, (2020) 10 SCC 274. The writ is an additional, not a substitute, remedy.

Step 7 — File a complaint with the Data Protection Board once operational. Once the Board is constituted and the Section 28 inquiry framework is in force, file a complaint with the Board under Section 27 alleging non-compliance by the Data Fiduciary with Sections 8(4) (reasonable security safeguards) and 8(5)–(6) (breach-intimation duty). The Board may, after inquiry, impose a Section 33 penalty up to Rs 250 crore. The order is appealable to TDSAT under Section 29 within sixty days.

What is unresolved — and what the Data Principal should be alert to

Four matters remain unresolved in 2026.

The first is the timeline for full operationalisation of the DPDP Act. The Act has been on the statute book since August 2023; the substantive provisions — Sections 8, 11–14, 27, 28, 33 — are in force in a notional sense but conditioned on the constitution of the Board and the notification of the Rules. The Draft Rules of 2025 were published in January 2025 for consultation; final notification has not occurred. The Government has indicated that operationalisation will follow promptly after the Rules are finalised, but no firm date has been published. Until operationalisation, the Section 43A IT Act regime continues as the principal compensation route.

The second is the design choice on private compensation. The DPDP Act, in its enacted form, does not include a private right of compensation analogous to Section 43A of the IT Act. The Joint Parliamentary Committee Report on the earlier 2019 Bill had recommended a private right; the 2023 Act dropped it. When the Section 43A repeal takes effect under Section 44(2), the only compensation routes for a Data Principal will be the consumer-forum route under the CPA 2019 and the residual civil suit. The doctrinal coherence of this design — a horizontal data-protection regime with no private compensation route — is genuinely contested.

The third is the interaction between the DPDP framework and sector-specific regulators. The Reserve Bank of India's cybersecurity and data-protection directions for banks and NBFCs, the Insurance Regulatory and Development Authority's directions for insurers, the Securities and Exchange Board of India's directions for listed entities, and the CERT-In Directions of April 2022 will continue to operate alongside the DPDP framework. Section 38 of the DPDP Act addresses the relationship — the DPDP Act has an overriding effect in respect of personal data but does not displace sector-specific obligations. The boundary will be tested in litigation.

The fourth is the cross-border-transfer regime. Section 16 of the DPDP Act empowers the Central Government to notify by order the countries outside India to which a Data Fiduciary may transfer personal data; the design departs from the GDPR's adequacy-decision framework. The Draft Rules of 2025 do not, on their face, resolve the cross-border-transfer architecture for the breach-disclosure context, where the breached data may have been redistributed across foreign-hosted platforms.

For the Data Principal, the working 2026 framework is the IT Act compensation route under Section 43A and the consumer-forum deficiency-in-service route under the CPA 2019, with the DPDP rights-notice (Sections 11–13) preserved against the eventual Board complaint, the criminal-law route under Sections 66, 72 and 72A of the IT Act held in reserve for deliberate-breach cases, and the writ remedy available for State-instrumentality breaches. The DPDP Act's full operationalisation — when it comes — will add the Section 33 penalty enforcement and the Board's regulatory direction power, but will not, on present design, displace the Section 43A or CPA 2019 compensation routes. The transition state is genuinely a state, not a milestone — and the Data Principal who wishes to be effectively protected must use the layered architecture as it stands.