Compensation for Data Breach Victims in India Under the DPDP Act, 2023: The Missing Remedy

Compensation for data breach victims in India is a question the Digital Personal Data Protection Act, 2023 leaves largely unanswered — and that gap is the subject of this analysis. India’s Digital Personal Data Protection Bill was introduced in 2022 and became the Digital Personal Data Protection Act, 2023 (herein referred to as the ‘DPDP Act’) after being approved by both houses of Parliament and receiving the President’s assent in August 2023, though it is yet to be implemented. The Act applies to personal data collected in digital form or data that is later converted into digital form. Its primary aim is to protect the personal information of individuals and hold organizations accountable for managing large amounts of such data, especially those with online operations and mobile apps.
This post is written for data breach victims, privacy lawyers, policy researchers, and compliance professionals who want to understand data breach victim rights under Indian law. You will learn how the DPDP Act’s penalty regime works, why Section 34 routes penalty money away from victims, how this differs from the earlier IT Act framework, and why a victim-centered compensation mechanism is urgently needed.
Prior to the DPDP Act and at present, the only legal framework addressing digital data privacy issues is the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (herein referred to as the ‘IT Act and Rules’). The DPDP Act tends to replace Section 43A of the IT Act and Rules.
Section 43A of the IT Act, along with the related rules, provides for compensation to individuals affected by the negligence of a company in handling sensitive personal data. It stated that if a company, which owns, controls, or operates a computer resource containing sensitive personal data, failed to maintain reasonable security measures and caused a breach, it would be liable to pay compensation to the affected person. However, the DPDP Act does not include such provisions for compensation. Instead, it imposes penalties for non-compliance with the DPDP Act.
This paper advocates for the introduction of provisions compensating individuals affected by data breaches. Before addressing the issue of victims being left without remedies, it is important to first understand what a data breach is.
What Is a Data Breach? A Brief Overview
Data is crucial for organizations as it helps them understand customers better and make informed decisions. However, as data becomes more valuable to businesses, it also becomes a target for cybercriminals who want to exploit it for malicious purposes.
A data breach occurs when information is stolen or accessed without the owner’s consent. This can involve sensitive data, such as credit card details, customer information, trade secrets, or national security matters. A breach exposes confidential data to unauthorized individuals, who may view or share it without consent.
Anyone, from individuals to large organizations and governments, can be affected by a data breach. Inadequate protection can also put others at risk.
While breaches can result from innocent mistakes, significant harm can occur if the stolen data, such as Personally Identifiable Information (PII) or corporate secrets, is sold or misused for financial gain or harm. Cybercriminals often plan their attacks by identifying vulnerabilities in a system, such as outdated software or security flaws. (For how organizations are expected to respond once a breach occurs, see our guide to the data breach response plan and notification duties under the DPDP Act.)
Penalty vs. Compensation: The Key Issue for Data Breach Victims
The primary issue in this situation is that individuals who are victims of a data breach will continue to face the negative consequences of having their personal information exposed or misused. This could include financial loss, identity theft, or other privacy-related harm. However, these victims are not entitled to any direct compensation for their suffering or losses. While the DPDP Act does impose penalties on the organization responsible for the breach — such as fines up to 250 crores — it does not include provisions for compensating the individuals affected. As a result, those who are affected by the breach may have no remedy other than filing a separate suit to recover the damages they have suffered.
Furthermore, the lack of a clear compensation mechanism in the DPDP Act creates a gap in protecting individuals. The Act provides for the responsibility of organizations to protect personal data, but it fails to consider the direct impact on individuals who are victims of data breaches. This leaves victims in a weaker position, as they may be left to deal with the consequences of the data breach without any compensation from the company at fault. In essence, while companies may face penalties for mishandling data, the affected parties are left without a clear mechanism to recover their losses. These situations bring forward the issue of accountability of the defaulters towards victims.
How Are Penalties Determined Under the DPDP Act, 2023?
Chapter 8 of the DPDP Act, titled ‘Penalties and Adjudication’, lays down the procedures to be followed by the Data Protection Board (herein referred to as the ‘Board’) when addressing data breaches. The chapter gives the Board the power to inquire into incidents of non-compliance with the DPDP Act and its rules, including any data breaches, and to impose fines on organizations found to be in violation of the same. Before imposing any penalty, the Board must conduct a thorough inquiry into the breach, offering the concerned party an opportunity of being heard. If the breach is found to be substantial, the Board is empowered to impose fines, with the specific penalty amounts mentioned in the Schedule of the DPDP Act. (For a business-facing breakdown of these amounts, see our post on data breach penalties under the DPDP Act.)
In determining the size of the penalty, the Board is required to take several key factors into account. These include the gravity of the breach, the scale of its impact, and its duration. The type of personal data affected is also a critical consideration, as certain types of data such as PII may attract more severe penalties. The Board will also look at whether the breach was a repeated offense, whether the organization involved gained financially or avoided losses as a result of the breach, and the actions taken to mitigate the effects of the breach. Specifically, the Board will evaluate the effectiveness and timeliness of the response to the incident, as well as the measures implemented to prevent similar breaches in the future.
Moreover, the Board has the responsibility to ensure that any penalty imposed serves both as a fair and effective measure against future violations and encourages compliance with the DPDP Act. The penalty must also be proportionate to the nature and scale of the breach, considering the potential impact on the organization involved. In its decision-making process, the Board has the responsibility to balance the need for accountability with the need to promote compliance by others, ultimately ensuring that penalties serve their purpose without unduly harming the organization’s operations or future business prospects.
Section 34 of the DPDP Act: A Deterrent Approach That Bypasses Victims
Section 34 of the DPDP Act provides that all sums realized by way of penalties imposed by the Board are credited to the Consolidated Fund of India. The major concern is that the penalty fund recovered under the DPDP Act may compromise remedies available to victims, which is a significant issue that needs closer scrutiny. While the penalties collected by the Board are intended to serve as a deterrent to prevent future breaches and to promote organizational compliance, these funds may not adequately address the harms suffered by the individuals whose data was subjected to breach. Under the current framework, the penalties are collected into a consolidated fund, but there is no direct provision for compensating the victims of the breach. This raises the concern that individuals who suffer from identity theft, financial loss, or other personal harms due to data breaches may not receive adequate relief under the IT Act as well, as the penalties imposed are not reserved specifically for victim compensation.
This situation could potentially shift the focus from helping victims get compensation to achieving regulatory goals. While imposing penalties on organizations is a necessary step in holding them accountable, it is also crucial to ensure that victims’ rights are protected in the process. There is an urgent need for mechanisms that would allow for a more direct form of remedies for individuals, such as creating a designated fund or a system through which victims can seek compensation from the penalties imposed on companies. Without such mechanisms, the purpose of the penalties could unintentionally be weakened, as organizations may view penalties as a cost of doing business, while the individuals whose rights have been violated may not get any substantive benefit from the penalties.
Conclusion
Concluding on the same lines as stated earlier, the DPDP Act provides a comprehensive framework for handling data breaches and imposing penalties on organizations responsible for mishandling digital personal data. However, the current mechanism of the Act raises significant concerns, especially in relation to the lack of compensation for victims of data breaches. While the penalties collected from organizations serve as a preventive measure and a way to enforce compliance, they do not directly address the loss suffered by individuals whose personal information is exposed or misused. As a result, victims of data breaches are left without a clear mechanism of recovering the damages they incur, such as financial loss, identity theft, or privacy violations.
To ensure that the DPDP Act completely protects individuals and holds organizations accountable, there is a need for a more victim-centered approach along with regulatory goals. This could involve establishing a system through which victims can seek compensation from the penalties imposed on organizations. Without such provisions, the Act may unintentionally shift focus away from the individuals affected by data breaches and prioritize regulatory goals. A clear mechanism for victim compensation would not only enhance fairness but also reinforce the purpose of data protection laws, ensuring that both organizations and individuals are protected from the threats arising from data breaches.
Frequently Asked Questions
Can data breach victims get compensation under the DPDP Act in India?
No — the DPDP Act, 2023 does not include provisions for directly compensating individuals affected by data breaches. It imposes penalties on the organization responsible (fines up to 250 crores), but those sums go to the Consolidated Fund of India. Victims may have no remedy other than filing a separate suit to recover their damages.
What did Section 43A of the IT Act provide for breach victims?
Section 43A of the IT Act, 2000, along with the related 2011 Rules, provided for compensation to individuals affected by a company’s negligence in handling sensitive personal data. If a company operating a computer resource containing sensitive personal data failed to maintain reasonable security and caused a breach, it was liable to pay compensation to the affected person. The DPDP Act tends to replace this provision — without carrying over the compensation mechanism.
What is Section 34 of the DPDP Act?
Section 34 provides that all sums realized by way of penalties imposed by the Data Protection Board are credited to the Consolidated Fund of India. This means penalty money serves as a deterrent and compliance tool, but none of it is reserved for compensating the victims of the breach.
What factors does the Data Protection Board consider when imposing penalties?
The Board considers the gravity, scale of impact, and duration of the breach; the type of personal data affected (PII may attract more severe penalties); whether it was a repeated offense; whether the organization gained financially; and the effectiveness and timeliness of the mitigation response. Penalties must be proportionate and must be preceded by a thorough inquiry with an opportunity of being heard.
What is the maximum penalty for a data breach under the DPDP Act?
The DPDP Act empowers the Board to impose fines up to 250 crores on organizations responsible for breaches, with specific penalty amounts set out in the Schedule of the Act. However, these fines are penalties payable to the state, not compensation payable to victims.
Key Takeaways
- The DPDP Act, 2023 imposes penalties (up to 250 crores) on organizations for data breaches but provides no direct compensation to the individuals harmed.
- Section 43A of the IT Act — which did give breach victims a compensation remedy for corporate negligence — is effectively replaced by the DPDP Act without an equivalent provision.
- Under Section 34, all penalty sums are credited to the Consolidated Fund of India, leaving victims of identity theft, financial loss, or privacy harm without a share of the recovery.
- Victims’ only current route to damages is filing a separate suit against the defaulting organization.
- The Data Protection Board must weigh gravity, impact, duration, data type, repetition, financial gain, and mitigation efforts when setting penalties.
- A victim-centered mechanism — such as a designated compensation fund drawn from penalties — is needed to make India’s data protection regime genuinely protective of individuals.