Data protection & DPDP compliance

Your Personal Data Was Leaked by a Company: What You Can Do Under the DPDP Act

By Adv. K J Muhammed Aslam · Advocate, Ernakulam (Bar Council of Kerala)

Published 6 September 2026

A message that your phone number, Aadhaar, email or health record held by a company was accessed without authority — or the discovery that it is circulating — is the victim side of the same breach the company must report within hours. Indian law after the Digital Personal Data Protection Act, 2023 as phased by the DPDP Rules, 2025 (G.S.R. 846(E) 13 Nov 2025, phased to 13 May 2027) gives you three parallel tracks that must be started in the right order: (1) grievance and access before the fiduciary → (2) complaint to the Data Protection Board with Board penalty and directions; and (3) compensation claims under Section 43A IT Act and the Consumer Protection Act where service deficiency is made out, with civil damages as the common base.

What three tracks does the victim actually have?

Track Where you go What it gives Legal basis
1. Fiduciary → Board Grievance officer of the company → Data Protection Board of India Inquiry, directions to the fiduciary, penalties up to 250 crore (safeguards) / 200 crore (breach/children) that establish breach for your other claims DPDP Sections 11-14, 13, 27-28, 33 plus Rule 7 (breach intimation) and Rule 14 (rights/grievance)
2. Compensation tribunal / adjudication Adjudicating Officer for Section 43A IT Act (negligent handling of sensitive personal data) Compensation to the victim for wrongful loss caused by failure to implement reasonable security (AO jurisdiction is up to five crore rupees under Section 46(1A) IT Act; larger claims lie before the competent court) IT Act Sections 43A and 46(1A) (adjudication), read with SPDI Rules 2011 reasonable security (Section 43A repeal not yet in force)
3. Consumer / civil court Consumer Commission (CPA 2019) or civil court Consumer compensation where data handling was part of a service and was deficient; civil damages for breach of duty/contract CPA 2019; Contract Act; general law of damages

Under the DPDP framework, track 1 is the procedural gateway — Section 13 requires you to first invoke the fiduciary’s published grievance mechanism before the Board entertains the complaint. A Board filing that skips the grievance record is premature.

What rights can you exercise before the fiduciary?

Under DPDP Sections 11-14 read with Rule 14, a Data Principal (Section 2(j)) may:

  • Section 11 — Right to access: Obtain a summary of the personal data being processed and the identities of the other Data Fiduciaries and Data Processors with whom the personal data has been shared by the fiduciary, with a description of the data so shared — Section 11(1)(b). This is subject to the Section 11(2) exception for sharing with another Data Fiduciary authorised by law to obtain the data, where made on a written request for prevention, detection or investigation of offences or cyber incidents, or for prosecution or punishment of offences.
  • Section 12 — Correction and erasure: Request correction of inaccurate or incomplete data and erasure where the specified purpose is spent or consent withdrawn (subject to legal retention).
  • Section 13 — Grievance redressal: Approach the fiduciary’s published grievance mechanism (contact, timelines) for any grievance on breach of the Act/Rules or on exercise of rights. Rule 14 requires the fiduciary to publish how to exercise rights and to respond within 90 days with a reasoned decision; unresolved grievances may be taken to the Board. The Board’s digital office and e-filing will be the channel once operational.
  • Section 14 — Nomination: Nominate another person to exercise rights on death or incapacity.
  • Rule 7 — Breach intimation to you: Where your data was part of a breach, the fiduciary must intimate you without delay with nature, extent, mitigation and contact — if you received no intimation, note that omission explicitly in your grievance (it is a separate penalty head under Section 33).

Deliver the grievance in writing by email + registered post, attach the breach evidence, set a 90-day clock (per Rule 14), and keep delivery proof. Where the fiduciary’s breach concerned children’s data, the same Section 9 + Rule 10 context from the children’s data guide strengthens the penalty case.

What compensation routes survive the DPDP transition?

Route When it fits What to file Ceiling and proof
IT Act Section 43A (repeal by DPDP Section 44(2)(a) not yet in force) The company handled sensitive personal data (SPDI Rules 2011 categories: password, financial, health, sexual orientation, medical, biometrics) without reasonable security (IS/ISO 27001 or other prescribed/code-notified standard) causing wrongful loss Application before the Adjudicating Officer (State IT Secretary) under Section 46(1A) IT Act AO jurisdiction is up to five crore rupees; claims exceeding that lie before the competent court; proof of negligence + causation + loss
Consumer Protection Act, 2019 The data handling was part of a consumer service (telecom, banking, edtech, health app, e-commerce) and the breach is a deficiency in service Consumer complaint before District/State Commission Compensation for loss, mental agony where made out; no PMLA-style penalty, but respondent must answer service-deficiency standard
Civil damages Contract or tort where duty and loss are made out independent of sector Civil suit General damages; limitation 3 years from cause
DPDP Board consequence Establishes breach, penalty and directions that support the compensation case — but the Act’s text does not itself award direct compensation to the victim — Board penalties go to the Consolidated Fund; victim’s monetary remedy is via the routes above

Transition note: The DPDP Act omits IT Act Section 43A, but the omission — DPDP Section 44(2)(a) — is not yet in force. Under DPDP Sections 38(1) and 38(2), the Act is in addition to other laws and prevails only to the extent of any conflict, so the Section 43A and consumer routes continue alongside a Board complaint.

In Kerala, Section 43A adjudication has been the most direct compensation forum for SPDI — e.g., hospital or NBFC leaks — while CPA 2019 has been used where the data breach flows from a paid service. A Board complaint strengthens both, because a Section 33 penalty finding is strong evidence of safeguard failure.

How does DPDP’s complaint to the Board actually work?

  1. File the Section 11/13 package first. Access request (Section 11) + grievance (Section 13) with the breach intimation (Rule 7) and your timeline. Request: confirmation of breach scope, recipients under Section 11(1)(b) (subject to the Section 11(2) exception), and erasure under Section 12 where the purpose is spent.
  2. Wait the published response period (up to 90 days) or until an inadequate reply. Rule 14 requires the fiduciary to publish timelines and respond with reasons. Preserve the reply — or the absence of reply after 90 days — as the Board’s threshold evidence.
  3. Complain to the Board under Sections 27-28 with: grievance record, breach evidence, the access request and reply, and a prayer for inquiry, directions and penalty under Section 33. The Board inquires (digital office, e-hearing), may impose penalty per the Schedule, and may direct the fiduciary to remediate, notify affected principals (Rule 7), and strengthen safeguards (Rule 6). Appeal lies to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) under Section 29 within 60 days.
  4. Parallel compensation. File the Section 43A / CPA track without waiting for the Board’s final order — the claims are not mutually exclusive, but a filed Board complaint makes the safeguard-failure record harder for the respondent to contest.

Heads-up: DPDP Rules 1,2,17-21 were in force from Gazette publication (Nov 2025); substantive fiduciary duties and penalties under Rules 3,5-16,22,23 phase to 18 months from notification (≈ 13 May 2027, displayed as 14 May 2027 on this site). The Board as an adjudicatory body is therefore in a transition year — early victim actions should not wait, but should recognise that first disposals will set procedure.

What proof should you preserve today?

  • The breach intimation from the company (or proof you received none — Rule 7’s without-delay intimation is itself an obligation).
  • Your grievance email with timestamp and postal acknowledgement, and any access request under Section 11 and its reply.
  • The misuse evidence: phishing/SIM-swap/FI activity, bank statement, and — for device/account proof — hash-preserved originals under Section 63 BSA, not forwarded screenshots.

Primary sources

FAQ

Common questions

What rights do I have if a company leaked my personal data in India?
Under DPDP Sections 11-14 you have rights to access the personal data and the identities of recipients it was shared with, to correction and erasure, to grievance redressal, and to nominate another person on death or incapacity. Under Section 13 you must first use the fiduciary's published grievance mechanism; if unresolved, you may complain to the Data Protection Board, which can inquire and impose penalties under Section 33 and issue directions. Separately, you may have a claim for compensation under Section 43A IT Act for negligent handling of sensitive personal data (the repeal of Section 43A — DPDP Section 44(2)(a) — is not yet in force), and under the Consumer Protection Act 2019 where the data handling was a service deficiency.
Can I get compensation if my data was leaked?
Compensation is not yet fully codified under DPDP — Section 33 provides penalties to the State and Board directions, not direct monetary compensation to the victim in the Act's text. Victim compensation today runs primarily through Section 43A IT Act (compensation for failure to protect sensitive personal data), civil suit for damages, and the Consumer Protection Act 2019 (service deficiency) where personal data handling was part of a consumer service. The Board's penalty and direction do support your compensation case by establishing breach.
How do I complain to the Data Protection Board under DPDP?
First, file a grievance with the fiduciary's published grievance officer (required under Section 13 DPDP and Rule 14). Preserve delivery proof. If not satisfactorily answered, you may complain to the Board with the grievance record, the Section 11 access request where relevant, and the breach evidence. The Board inquires under Sections 27-28 and may impose penalties under Section 33 (up to 250 crore for safeguard failure, 200 crore for children's/breach duties) and issue directions. Appeals lie to the TDSAT under Section 29 within 60 days.
Does the DPDP Act help if old leaked data was non-digital?
DPDP applies to digital personal data — data in digital form or digitised later where the Act applies (Section 3). A purely paper handling with no digital processing is outside DPDP, but may still be actionable under IT Act 43A where the data was sensitive personal data handled without reasonable security, and under consumer or contract law. Check whether the data entered a digital system at any stage (CRM, app, server) — most modern leaks are digital.
What proof should I keep after a data breach notification?
The breach intimation the company sent (Rule 7 requires it without delay with nature, extent, mitigation and contact), your Section 11 access request and its reply, the grievance filing with timestamp, the bank's or platform's statement showing misuse (phishing, SIM swap, fraud), and any dark-web or haveibeenpwned evidence. Keep hash-preserved originals for Section 63 BSA — forwarded screenshots degrade proof.

Contact

3rd Floor, Lalan Towers (KGL Builders), Vanchi Square, High Court Junction, Ernakulam, Kerala 682031 · Monday – Saturday, 10:00 – 18:30 (by appointment)

A note before you read on. In keeping with the Bar Council of India Rules, this website provides information about Adv. K J Muhammed Aslam, and general legal information, only to those who seek it of their own accord. It is not an advertisement or solicitation, and nothing here is legal advice. By continuing, you acknowledge you are visiting voluntarily. Full disclaimer.