By Adv. K J Muhammed Aslam · Advocate, Ernakulam (Bar Council of Kerala)
A message that your phone number, Aadhaar, email or health record held by a company was accessed without authority — or the discovery that it is circulating — is the victim side of the same breach the company must report within hours. Indian law after the Digital Personal Data Protection Act, 2023 as phased by the DPDP Rules, 2025 (G.S.R. 846(E) 13 Nov 2025, phased to 13 May 2027) gives you three parallel tracks that must be started in the right order: (1) grievance and access before the fiduciary → (2) complaint to the Data Protection Board with Board penalty and directions; and (3) compensation claims under Section 43A IT Act and the Consumer Protection Act where service deficiency is made out, with civil damages as the common base.
What three tracks does the victim actually have?
| Track | Where you go | What it gives | Legal basis |
|---|---|---|---|
| 1. Fiduciary → Board | Grievance officer of the company → Data Protection Board of India | Inquiry, directions to the fiduciary, penalties up to 250 crore (safeguards) / 200 crore (breach/children) that establish breach for your other claims | DPDP Sections 11-14, 13, 27-28, 33 plus Rule 7 (breach intimation) and Rule 14 (rights/grievance) |
| 2. Compensation tribunal / adjudication | Adjudicating Officer for Section 43A IT Act (negligent handling of sensitive personal data) | Compensation to the victim for wrongful loss caused by failure to implement reasonable security (AO jurisdiction is up to five crore rupees under Section 46(1A) IT Act; larger claims lie before the competent court) | IT Act Sections 43A and 46(1A) (adjudication), read with SPDI Rules 2011 reasonable security (Section 43A repeal not yet in force) |
| 3. Consumer / civil court | Consumer Commission (CPA 2019) or civil court | Consumer compensation where data handling was part of a service and was deficient; civil damages for breach of duty/contract | CPA 2019; Contract Act; general law of damages |
Under the DPDP framework, track 1 is the procedural gateway — Section 13 requires you to first invoke the fiduciary’s published grievance mechanism before the Board entertains the complaint. A Board filing that skips the grievance record is premature.
What rights can you exercise before the fiduciary?
Under DPDP Sections 11-14 read with Rule 14, a Data Principal (Section 2(j)) may:
- Section 11 — Right to access: Obtain a summary of the personal data being processed and the identities of the other Data Fiduciaries and Data Processors with whom the personal data has been shared by the fiduciary, with a description of the data so shared — Section 11(1)(b). This is subject to the Section 11(2) exception for sharing with another Data Fiduciary authorised by law to obtain the data, where made on a written request for prevention, detection or investigation of offences or cyber incidents, or for prosecution or punishment of offences.
- Section 12 — Correction and erasure: Request correction of inaccurate or incomplete data and erasure where the specified purpose is spent or consent withdrawn (subject to legal retention).
- Section 13 — Grievance redressal: Approach the fiduciary’s published grievance mechanism (contact, timelines) for any grievance on breach of the Act/Rules or on exercise of rights. Rule 14 requires the fiduciary to publish how to exercise rights and to respond within 90 days with a reasoned decision; unresolved grievances may be taken to the Board. The Board’s digital office and e-filing will be the channel once operational.
- Section 14 — Nomination: Nominate another person to exercise rights on death or incapacity.
- Rule 7 — Breach intimation to you: Where your data was part of a breach, the fiduciary must intimate you without delay with nature, extent, mitigation and contact — if you received no intimation, note that omission explicitly in your grievance (it is a separate penalty head under Section 33).
Deliver the grievance in writing by email + registered post, attach the breach evidence, set a 90-day clock (per Rule 14), and keep delivery proof. Where the fiduciary’s breach concerned children’s data, the same Section 9 + Rule 10 context from the children’s data guide strengthens the penalty case.
What compensation routes survive the DPDP transition?
| Route | When it fits | What to file | Ceiling and proof |
|---|---|---|---|
| IT Act Section 43A (repeal by DPDP Section 44(2)(a) not yet in force) | The company handled sensitive personal data (SPDI Rules 2011 categories: password, financial, health, sexual orientation, medical, biometrics) without reasonable security (IS/ISO 27001 or other prescribed/code-notified standard) causing wrongful loss | Application before the Adjudicating Officer (State IT Secretary) under Section 46(1A) IT Act | AO jurisdiction is up to five crore rupees; claims exceeding that lie before the competent court; proof of negligence + causation + loss |
| Consumer Protection Act, 2019 | The data handling was part of a consumer service (telecom, banking, edtech, health app, e-commerce) and the breach is a deficiency in service | Consumer complaint before District/State Commission | Compensation for loss, mental agony where made out; no PMLA-style penalty, but respondent must answer service-deficiency standard |
| Civil damages | Contract or tort where duty and loss are made out independent of sector | Civil suit | General damages; limitation 3 years from cause |
| DPDP Board consequence | Establishes breach, penalty and directions that support the compensation case — but the Act’s text does not itself award direct compensation to the victim | — | Board penalties go to the Consolidated Fund; victim’s monetary remedy is via the routes above |
Transition note: The DPDP Act omits IT Act Section 43A, but the omission — DPDP Section 44(2)(a) — is not yet in force. Under DPDP Sections 38(1) and 38(2), the Act is in addition to other laws and prevails only to the extent of any conflict, so the Section 43A and consumer routes continue alongside a Board complaint.
In Kerala, Section 43A adjudication has been the most direct compensation forum for SPDI — e.g., hospital or NBFC leaks — while CPA 2019 has been used where the data breach flows from a paid service. A Board complaint strengthens both, because a Section 33 penalty finding is strong evidence of safeguard failure.
How does DPDP’s complaint to the Board actually work?
- File the Section 11/13 package first. Access request (Section 11) + grievance (Section 13) with the breach intimation (Rule 7) and your timeline. Request: confirmation of breach scope, recipients under Section 11(1)(b) (subject to the Section 11(2) exception), and erasure under Section 12 where the purpose is spent.
- Wait the published response period (up to 90 days) or until an inadequate reply. Rule 14 requires the fiduciary to publish timelines and respond with reasons. Preserve the reply — or the absence of reply after 90 days — as the Board’s threshold evidence.
- Complain to the Board under Sections 27-28 with: grievance record, breach evidence, the access request and reply, and a prayer for inquiry, directions and penalty under Section 33. The Board inquires (digital office, e-hearing), may impose penalty per the Schedule, and may direct the fiduciary to remediate, notify affected principals (Rule 7), and strengthen safeguards (Rule 6). Appeal lies to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) under Section 29 within 60 days.
- Parallel compensation. File the Section 43A / CPA track without waiting for the Board’s final order — the claims are not mutually exclusive, but a filed Board complaint makes the safeguard-failure record harder for the respondent to contest.
Heads-up: DPDP Rules 1,2,17-21 were in force from Gazette publication (Nov 2025); substantive fiduciary duties and penalties under Rules 3,5-16,22,23 phase to 18 months from notification (≈ 13 May 2027, displayed as 14 May 2027 on this site). The Board as an adjudicatory body is therefore in a transition year — early victim actions should not wait, but should recognise that first disposals will set procedure.
What proof should you preserve today?
- The breach intimation from the company (or proof you received none — Rule 7’s without-delay intimation is itself an obligation).
- Your grievance email with timestamp and postal acknowledgement, and any access request under Section 11 and its reply.
- The misuse evidence: phishing/SIM-swap/FI activity, bank statement, and — for device/account proof — hash-preserved originals under Section 63 BSA, not forwarded screenshots.
Primary sources
- DPDP Act, 2023 — Sections 2(j), 3, 11-14, 13, 27-29, 33 and Schedule; Rules 6,7,14; DPDP Rules, 2025 (G.S.R. 846(E) 13 Nov 2025); PIB 17 Nov 2025 backgrounder
- IT Act, 2000 — Sections 43, 43A, 46(1A); SPDI Rules, 2011 (reasonable security)
- Consumer Protection Act, 2019
- BSA, 2023 — Section 63; Cybercrime.gov.in / 1930
FAQ
