This article is written by Divya Gupta, Vivekananda Institute of Professional Studies (VIPS-TC), GGSIPU. In the article, it is examined whether this act improves the legal regulation of data breach reporting in India or not.

Each month brings at least one data breach case to the headlines in India, whether it is a case of confidential data of a client from the bank going viral or a hospital losing its patients’ data or a commerce website being attacked and many customers’ information getting stolen. Earlier, such incidents were treated as nothing more than a technical glitch but now are viewed as a serious issue of law with severe implications for the corporation but with no proper solution available for the affected individual.
With the emergence of the Digital Personal Data Protection Act (DPDP Act), 2023, which became India’s very first law of data protection, the pace of development of legal regulation in this area has become much faster. When comparing the old IT Act, 2000, and the new DPDP Act, 2023, one is able to see how each of these laws defines the concept of a breach, the process of reporting the event and the penalty for it. This paper analyses the topic of breach definition, the responsibilities, the aftermaths and the drawbacks of both acts.
A data breach is not only a technical problem but it may lead to the victimization of personal information. With the introduction of the Digital Personal Data Protection Act, 2023, India finally receives a dedicated law instead of the bits of regulation of the data protection from the IT Act, 2000. But what does the DPDP Act offer us?
What Counts as a Data “Breach” Legally?
Under the DPDP Act, 2023, a data breach is any unauthorized use, access, loss, sharing, modification, disclosure, alteration, or deletion of personal data which leads to violation of its confidentiality, accuracy, and availability. This is significantly different from what the previous legislation (IT Act) used to call a breach.
According to the previous regulation, for something to be considered a breach, the concerned personal data should be sensitive data (such as banking details, personal health records, biometric information, and passwords), and negligence or breach of contract should have occurred. However, under the new law, there are no such limitations anymore. In other words, as soon as a data breach of any kind happens, it would be qualified as such.
This change affects not only the concept of data breaches itself but also the responsibility that companies have for reporting about those incidents. For instance, under the previous law, negligence or breach of contract needed to be proven to show that a company is liable for the data breach. Thus, as long as there was proof that reasonable precautionary measures have been implemented by the company, it wouldn’t be found liable. Under the new law, however, such defence will not work when it comes to reporting requirements.
Thus, under the new law, reporting is triggered automatically by the occurrence of a data breach. As a result, the question of whether there was negligence becomes completely irrelevant in this respect. Now, instead of asking if the company was negligent in some way, one needs to ask two questions: was a data breach reported and was it reported properly?
The Legal Framework
IT Act, 2000
There are two most important provisions concerning data breaches in India:
Section 43A requires anybody corporate having sensitive personal data to ensure reasonable security practices. In case they fail to do so and it results in wrongful gain or loss; they are required to compensate the aggrieved individual.
Section 72A prohibits disclosing personal data provided under a lawful contract without the consent of the data subject, where it is done in order to cause wrongful loss or gain, punishable with imprisonment up to three years, fine up to ₹5 lakh, or both.
Both provisions remain intact, but these were made before DPDP Act, 2023 and are very much dependent upon proof of negligence or intention – a real evidentiary burden for individuals.
DPDP Act, 2023
Burden of prevention and notification is now squarely on companies (“Data Fiduciaries”) under the DPDP Act:
- Data Fiduciaries should take adequate “reasonable security safeguards” to prevent data breach incidents, although the Act does not provide any technical details about such measures.
- In case of a data breach, Data Fiduciary is supposed to inform the Data Protection Board of India (DPBI) and all the concerned Data Principals in accordance with section 8(6). According to DPDP Rules, 2025 (notification issued on November 13, 2025), this responsibility has been converted to two-step process where initially Data Fiduciary is supposed to notify the DPBI about such incident without further ado and then submit an “integrated report” containing root cause, scope of damage, remedial measures, and summary of notifications made to individuals within 72 hours (calendar hours, not working hours) from such incident. Noteworthy point is that this responsibility falls under the third and last implementation stage of these Rules which will take effect only in May 2027 (eighteen months after notification).
- The definition of data breach provided under the Act does not contain any materiality threshold – if a breach affects ten data records, then it means the same for ten million data records.
Sectoral Overlays
There are sectors that, apart from the DPDP Act, have their own additional obligations to fulfil when reporting a breach of personal data:
For example, the RBI provides such requirements to banks. The bank is responsible for the cybersecurity framework and, according to this framework, has a duty to report any incident within a certain deadline, since the breach can negatively affect the whole financial sector.
Players of the stock exchange market, including listed companies and market intermediaries, are subject to the same requirements by SEBI. In the event of any cyber threat related to the breach of investors’ or trading data, the company should inform SEBI promptly.
CERT-In provides even stricter requirements to companies. The latest CERT-In directions of 2022 oblige organizations to report a great variety of cyber incidents (not only personal data breaches) in just six hours after the identification of an incident. That is probably the strictest deadline in this sphere, and a number of companies oppose this requirement arguing that it is not always possible to comply with it.
In conclusion, one can say that a breach of personal data in a bank is regulated not only by the DPDP Act. A bank is obliged to report an incident to the RBI and to CERT-In, with different deadlines, different regulators, and different ways of making a disclosure. In this regard, the process becomes very different for the company, and one department cannot deal with it independently.
Who must answer for the breach?
Under the DPDP Act, responsibility for a breach doesn’t get diluted just because multiple entities handled the data. The Act draws a clear line: the Data Fiduciary, the entity that decides why and how personal data is processed, is primarily and ultimately responsible for compliance, regardless of any processing carried out by a Data Processor. In plain terms, if you outsource data processing to a vendor and that vendor causes the breach, you, the fiduciary, are still the one the Board comes after.
That said, the Act doesn’t let Data Processors off the hook entirely; it just handles their liability contractually rather than statutorily. The Act requires that Data Fiduciary-Processor contracts include provisions ensuring the processor implements reasonable security safeguards, and in practice, processors typically agree to notify the fiduciary of a breach within a set window, commonly around 24 hours to give the fiduciary enough runway to meet its own 72-hour notification duty to the Board. Any liability the processor bears usually flows through indemnity clauses in that contract, not directly through the Act itself.
So, while the law is aimed squarely at Data Fiduciaries, the practical burden gets pushed down the chain contractually, meaning companies now negotiate detailed data-processing agreements specifically to manage who eats the cost if a processor’s failure causes a fiduciary’s breach.
Liabilities and Penalties
The maximum penalties under the DPDP Act’s Schedule increase with the type of violation. For failing to put into place reasonable security safeguards under Section 8(5), one can incur a penalty up to ₹250 crore, the highest penalty in the Schedule. In addition, for failure to report the data breach under Section 8(6), the company would be penalized up to ₹200 crore. Similarly, any violation of the provisions about children’s data under Section 9 could earn the company a penalty up to ₹200 crore, and failures of Significant Data Fiduciaries under Section 10 to meet their additional obligations are punishable by a penalty of up to ₹150 crore. Since these are different heads of violation, an investigation that results in the finding of a failure to put in security safeguards as well as a failure to notify can lead to a total penalty for both violations.
Following the operational rules of breach notification under the DPDP Rules, 2025, notified in November 2025, there is a two-step process. First, the Data Protection Board needs to be informed without undue delay. The clock for this starts as soon as the company discovers that a breach has taken place, not at the end of the investigation. Second, the affected individuals need to be notified within 72 hours of the breach, and the notice shall include a plain language description of what happened and what data was leaked.
Enforcement of these penalties lies with the Data Protection Board, not with the court directly; the appeal against the order of the Board shall go to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT), and from there to the Supreme Court. It is worth noting that, unlike the DPDP Act, Section 72A of the IT Act provides for imprisonment for persons who are found guilty of disclosing data illegally.
As before, under the new version of Section 8(6), all these massive fines of ₹250 crores or ₹200 crores do not in any way benefit the actual victim of the data leak. This money does not even get to those people; it goes to the enforcement authorities. Thus, individuals still have to rely on Section 43A of the IT Act or consumer forums for a personal remedy.
Case Illustrations
1. Banking Sector: The Bank of Baroda 1TB Leak (July 2026)
In July 2026, TripleX, which is a ransomware group, managed to steal almost 1 Terabyte of confidential information from the government-owned Bank of Baroda through exploiting an employee’s email. The data leak, which was later released into a dark web storage, comprised customer documents like Aadhaar, PAN documents, loan assessment reports, and audit records for branches. Although the bank acted swiftly and confirmed that there were no security issues with the bank’s transactional system, the leak led to an instant regulatory intervention concerning access controls. According to DPDP, failure to safeguard employee emails as a medium for leaking customer information is a serious security lapse that can attract legal sanctions.
2. Financial Technology Sector: The Angel One AWS Exposure (2026)
Mid-2026 witnessed a severe cloud security breach at the retail stockbroker Angel One owing to a misconfigured and unprotected AWS database cloud storage. This unprotected database was accessible to the threat actors and had trading account details, customer communication logs, and transaction history. The security team at Angel One made necessary adjustments in the cloud security permissions as soon as the problem came to light and performed a forensic analysis to understand the extent of the exposure. At present, the regulatory authorities consider an unforced mistake in cloud security as a failure in adhering to the mandate of “reasonable security safeguards” under the DPDP Act.
Shortcomings and Drawbacks
Even though DPDP Act has been enacted, there are some major drawbacks in the Act which still hold good:
- No individual right to sue — there is no provision for private right of action allowing an aggrieved individual to sue for compensation under DPDP Act.
- Non-technical definition of “security” — the term “reasonable security safeguards” is non-technical, making it hard to ascertain what will be considered compliant in case of a breach.
- No materiality criterion — under DPDP Act, the notification obligation applies equally whether the breach concerns a single record or millions of records, providing no way for a more proportionate response.
- Board’s independence and competence — it has been debated how effective the Board will be in investigating and imposing penalties on big corporate organizations.
- Overlapping compliance requirements — organizations operating in regulated sectors such as banks and financial institutions, etc., have to report breaches to the RBI, SEBI, CERT-In, and DPBI on separate timelines.
- Delay in enforcement — the breach notification provisions of the Act itself are not applicable till 2027.
Conclusion
From the negligence-based approach under the IT Act, India’s legal framework for handling data breaches has now evolved into the fiduciary duty-based approach under the DPDP Act. This is definitely a positive change. However, the fact that there is no private right of action means that it is the regulatory response, not the individual’s, which is at the heart of the legislation. Breach preparedness (through incident response plans, notifications, documentation of security measures and coordination amid regulatory compliance) is no longer a best practice; it is now an absolute necessity.
As for the law, it remains to be seen whether the Data Protection Board will have the capacity and mandate to effectively enforce the provisions of the legislation and whether any further amendments will allow individuals to get an independent remedy out of the DPDP Act rather than relying on three separate pieces of legislation to make their case. In any event, it will remain true that while the law is strong on paper, it will still fail to provide adequate compensation to individuals in the context of a data breach. The field of doctrine of DPDP Act is expected to develop very quickly as the enforcement process takes off and the first decisions of the Data Protection Board become available.
References
News Reports
Reuters, “Customer data of India’s Bank of Baroda leaked online, source, researcher say,” Reuters, 27 July 2026, https://www.reuters.com/business/media-telecom/customer-data-indias-bank-baroda-leaked-online-source-researcher-say-2026-07-27/
Anjaly Raj, “BoB data breach: A look at India’s biggest corporate cyberattacks,” Business Standard, 28 July 2026, https://www.business-standard.com/companies/news/bank-of-baroda-data-breach-india-biggest-corporate-cyberattacks-126072800727_1.html
Industry/Analytical Sources
Vijay Mandora, “Recent Cyber Attacks in India (2025–2026): Major Breaches Every Business Should Know,” ECS Infotech, 6 July 2026, https://www.ecsinfotech.com/recent-cyber-attacks-in-india/
“DPDPA Penalties Explained: Rs 50 Crore to Rs 250 Crore Fines,” DPDPA.com, https://www.dpdpa.com/blogs/dpdpa_penalties_explained_50_crore_250_crore_fines.html
“DPDPA Penalties 2026 [Up to Rs 250 Cr] — Full Schedule, Case Studies + FAQ,” Unified Chambers and Associates, https://www.unifiedchambers.com/blog/dpdp-act-penalties-complete-guide
“Penalties & Adjudication Under India’s DPDP Act, 2023,” KS&K, https://ksandk.com/data-protection-and-data-privacy/penalties-adjudication-under-indias-dpdp-act-2023/
“DPDP Act Data Breach Notification Rules for Indian Businesses,” Bachao.AI, https://www.bachao.ai/blog/dpdp-data-breach-notification-rules-india
“DPDP Rules 2025: India’s Complete Compliance Guide,” Seclore, https://www.seclore.com/fundamentals/dpdp-rules-2025-compliance-guide/
“DPDP Breach Notification: 72-Hour Rule & ₹200 Cr Penalty,” Matters.ai, https://www.matters.ai/article/dpdp-breach-notification
“[Analysis] India’s DPDP Act and Rules 2025 – Timeline | Obligations | Enforcement,” Taxmann, https://www.taxmann.com/post/blog/analysis-indias-dpdp-act-and-rules
“Digital Personal Data Protection Rules, 2025 Notified,” Press Information Bureau, Government of India, https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc20251117695301.pdf


