---
title: "Personal Data Leaked by a Company: Your DPDP Act Rights"
description: "Company leaked your Aadhaar, phone or health data? DPDP Sections 11-14 rights, Board complaint, IT Act 43A compensation, consumer and civil remedies."
url: "https://advaslam.com/writing/data-breach-victim-rights-dpdp-compensation/"
image: "https://advaslam.com/og/writing/data-breach-victim-rights-dpdp-compensation.png"
---

[Data protection & DPDP compliance](https://advaslam.com/practice/data-protection/)

# Your Personal Data Was Leaked by a Company: What You Can Do Under the DPDP Act

By [**Adv. K J Muhammed Aslam**](https://advaslam.com/profile/) · Advocate, Ernakulam (Bar Council of Kerala)

Published 6 September 2026

A message that your phone number, Aadhaar, email or health record held by a company was accessed without authority — or the discovery that it is circulating — is the victim side of the same breach the company must report within hours. Indian law after the **[Digital Personal Data Protection Act, 2023](https://indiacode.gov.in/handle/123456789/496508)** as phased by the **DPDP Rules, 2025 (G.S.R. 846(E) 13 Nov 2025, phased to 13 May 2027)** gives you **three parallel tracks** that must be started in the right order: **(1) grievance and access before the fiduciary → (2) complaint to the Data Protection Board with Board penalty and directions; and (3) compensation claims under Section 43A IT Act and the Consumer Protection Act where service deficiency is made out**, with civil damages as the common base.

## What three tracks does the victim actually have?

| Track | Where you go | What it gives | Legal basis |
| --- | --- | --- | --- |
| **1\\. Fiduciary → Board** | Grievance officer of the company → Data Protection Board of India | Inquiry, directions to the fiduciary, **penalties up to 250 crore** (safeguards) / 200 crore (breach/children) that establish breach for your other claims | DPDP Sections 11-14, 13, 27-28, 33 plus Rule 7 (breach intimation) and Rule 14 (rights/grievance) |
| **2\\. Compensation tribunal / adjudication** | Adjudicating Officer for **Section 43A IT Act** (negligent handling of sensitive personal data) | **Compensation** to the victim for wrongful loss caused by failure to implement reasonable security (AO jurisdiction is up to **five crore rupees** under Section 46(1A) IT Act; larger claims lie before the competent court) | IT Act Sections 43A and 46(1A) (adjudication), read with SPDI Rules 2011 reasonable security (Section 43A repeal not yet in force) |
| **3\\. Consumer / civil court** | Consumer Commission (CPA 2019) or civil court | **Consumer compensation** where data handling was part of a service and was deficient; **civil damages** for breach of duty/contract | CPA 2019; Contract Act; general law of damages |

Under the DPDP framework, **track 1 is the procedural gateway** — Section 13 requires you to first invoke the fiduciary’s published grievance mechanism before the Board entertains the complaint. A Board filing that skips the grievance record is premature.

## What rights can you exercise before the fiduciary?

Under **DPDP Sections 11-14 read with Rule 14**, a Data Principal (Section 2(j)) may:

-   **Section 11 — Right to access:** Obtain a summary of the personal data being processed and the identities of the other Data Fiduciaries and Data Processors with whom the personal data has been shared by the fiduciary, with a description of the data so shared — Section 11(1)(b). This is subject to the Section 11(2) exception for sharing with another Data Fiduciary authorised by law to obtain the data, where made on a written request for prevention, detection or investigation of offences or cyber incidents, or for prosecution or punishment of offences.
-   **Section 12 — Correction and erasure:** Request correction of inaccurate or incomplete data and erasure where the specified purpose is spent or consent withdrawn (subject to legal retention).
-   **Section 13 — Grievance redressal:** Approach the fiduciary’s **published grievance mechanism** (contact, timelines) for any grievance on breach of the Act/Rules or on exercise of rights. **Rule 14 requires the fiduciary to publish how to exercise rights and to respond within 90 days** with a reasoned decision; unresolved grievances may be taken to the Board. The Board’s digital office and e-filing will be the channel once operational.
-   **Section 14 — Nomination:** Nominate another person to exercise rights on death or incapacity.
-   **Rule 7 — Breach intimation to you:** Where your data was part of a breach, the fiduciary must intimate you **without delay** with nature, extent, mitigation and contact — if you received no intimation, note that omission explicitly in your grievance (it is a separate penalty head under Section 33).

**Deliver the grievance in writing by email + registered post**, attach the breach evidence, set a **90-day** clock (per Rule 14), and keep delivery proof. Where the fiduciary’s breach concerned **children’s data**, the same Section 9 + Rule 10 context from the [children’s data guide](https://advaslam.com/writing/dpdp-children-data-parental-consent-guide/) strengthens the penalty case.

## What compensation routes survive the DPDP transition?

| Route | When it fits | What to file | Ceiling and proof |
| --- | --- | --- | --- |
| **IT Act Section 43A (repeal by DPDP Section 44(2)(a) not yet in force)** | The company handled **sensitive personal data** (SPDI Rules 2011 categories: password, financial, health, sexual orientation, medical, biometrics) without **reasonable security** (IS/ISO 27001 or other prescribed/code-notified standard) causing **wrongful loss** | Application before the **Adjudicating Officer (State IT Secretary)** under **Section 46(1A) IT Act** | AO jurisdiction is **up to five crore rupees**; claims exceeding that lie before the competent court; proof of negligence + causation + loss |
| **Consumer Protection Act, 2019** | The data handling was part of a **consumer service** (telecom, banking, edtech, health app, e-commerce) and the breach is a **deficiency in service** | Consumer complaint before District/State Commission | Compensation for loss, mental agony where made out; no PMLA-style penalty, but respondent must answer service-deficiency standard |
| **Civil damages** | Contract or tort where duty and loss are made out independent of sector | Civil suit | General damages; limitation **3 years** from cause |
| **DPDP Board consequence** | Establishes breach, penalty and directions that **support** the compensation case — but the Act’s text does not itself award direct compensation to the victim | —   | Board penalties go to the Consolidated Fund; victim’s monetary remedy is via the routes above |

**Transition note:** The DPDP Act omits IT Act Section 43A, but the omission — DPDP Section 44(2)(a) — is not yet in force. Under DPDP Sections 38(1) and 38(2), the Act is in addition to other laws and prevails only to the extent of any conflict, so the Section 43A and consumer routes continue alongside a Board complaint.

In Kerala, Section 43A adjudication has been the most direct compensation forum for SPDI — e.g., hospital or NBFC leaks — while CPA 2019 has been used where the data breach flows from a paid service. A Board complaint strengthens both, because a **Section 33 penalty finding** is strong evidence of safeguard failure.

## How does DPDP’s complaint to the Board actually work?

1.  **File the Section 11/13 package first.** Access request (Section 11) + grievance (Section 13) with the breach intimation (Rule 7) and your timeline. Request: confirmation of breach scope, recipients under Section 11(1)(b) (subject to the Section 11(2) exception), and erasure under Section 12 where the purpose is spent.
2.  **Wait the published response period (up to 90 days) or until an inadequate reply.** Rule 14 requires the fiduciary to publish timelines and respond with reasons. Preserve the reply — or the absence of reply after 90 days — as the Board’s threshold evidence.
3.  **Complain to the Board under Sections 27-28** with: grievance record, breach evidence, the access request and reply, and a prayer for inquiry, directions and penalty under Section 33. The Board inquires (digital office, e-hearing), may impose penalty per the Schedule, and may direct the fiduciary to remediate, notify affected principals (Rule 7), and strengthen safeguards (Rule 6). **Appeal** lies to the **Telecom Disputes Settlement and Appellate Tribunal (TDSAT)** under **Section 29** within **60 days**.
4.  **Parallel compensation.** File the Section 43A / CPA track **without waiting** for the Board’s final order — the claims are not mutually exclusive, but a filed Board complaint makes the safeguard-failure record harder for the respondent to contest.

**Heads-up:** DPDP Rules 1,2,17-21 were in force from Gazette publication (Nov 2025); substantive fiduciary duties and penalties under Rules 3,5-16,22,23 phase to **18 months from notification (≈ 13 May 2027, displayed as 14 May 2027 on this site)**. The Board as an adjudicatory body is therefore in a **transition year** — early victim actions should not wait, but should recognise that first disposals will set procedure.

## What proof should you preserve today?

-   The **breach intimation** from the company (or proof you received none — Rule 7’s without-delay intimation is itself an obligation).
-   Your **grievance email with timestamp and postal acknowledgement**, and any **access request** under Section 11 and its reply.
-   The **misuse evidence**: phishing/SIM-swap/FI activity, bank statement, and — for device/account proof — **hash-preserved originals** under [Section 63 BSA](https://advaslam.com/writing/electronic-evidence-bsa-section-63-certificate-guide/), not forwarded screenshots.

## Primary sources

-   [DPDP Act, 2023 — Sections 2(j), 3, 11-14, 13, 27-29, 33 and Schedule; Rules 6,7,14](https://indiacode.gov.in/handle/123456789/496508); [DPDP Rules, 2025 (G.S.R. 846(E) 13 Nov 2025)](https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf); [PIB 17 Nov 2025 backgrounder](https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc20251117695301.pdf)
-   [IT Act, 2000 — Sections 43, 43A, 46(1A)](https://indiacode.gov.in/handle/123456789/496511); [SPDI Rules, 2011](https://indiacode.gov.in/handle/123456789/510187) (reasonable security)
-   [Consumer Protection Act, 2019](https://indiacode.gov.in/handle/123456789/496115)
-   [BSA, 2023 — Section 63](https://indiacode.gov.in/handle/123456789/496549); [Cybercrime.gov.in / 1930](https://cybercrime.gov.in)

FAQ

## Common questions

**What rights do I have if a company leaked my personal data in India?**

Under DPDP Sections 11-14 you have rights to access the personal data and the identities of recipients it was shared with, to correction and erasure, to grievance redressal, and to nominate another person on death or incapacity. Under Section 13 you must first use the fiduciary's published grievance mechanism; if unresolved, you may complain to the Data Protection Board, which can inquire and impose penalties under Section 33 and issue directions. Separately, you may have a claim for compensation under Section 43A IT Act for negligent handling of sensitive personal data (the repeal of Section 43A — DPDP Section 44(2)(a) — is not yet in force), and under the Consumer Protection Act 2019 where the data handling was a service deficiency.

**Can I get compensation if my data was leaked?**

Compensation is not yet fully codified under DPDP — Section 33 provides penalties to the State and Board directions, not direct monetary compensation to the victim in the Act's text. Victim compensation today runs primarily through Section 43A IT Act (compensation for failure to protect sensitive personal data), civil suit for damages, and the Consumer Protection Act 2019 (service deficiency) where personal data handling was part of a consumer service. The Board's penalty and direction do support your compensation case by establishing breach.

**How do I complain to the Data Protection Board under DPDP?**

First, file a grievance with the fiduciary's published grievance officer (required under Section 13 DPDP and Rule 14). Preserve delivery proof. If not satisfactorily answered, you may complain to the Board with the grievance record, the Section 11 access request where relevant, and the breach evidence. The Board inquires under Sections 27-28 and may impose penalties under Section 33 (up to 250 crore for safeguard failure, 200 crore for children's/breach duties) and issue directions. Appeals lie to the TDSAT under Section 29 within 60 days.

**Does the DPDP Act help if old leaked data was non-digital?**

DPDP applies to digital personal data — data in digital form or digitised later where the Act applies (Section 3). A purely paper handling with no digital processing is outside DPDP, but may still be actionable under IT Act 43A where the data was sensitive personal data handled without reasonable security, and under consumer or contract law. Check whether the data entered a digital system at any stage (CRM, app, server) — most modern leaks are digital.

**What proof should I keep after a data breach notification?**

The breach intimation the company sent (Rule 7 requires it without delay with nature, extent, mitigation and contact), your Section 11 access request and its reply, the grievance filing with timestamp, the bank's or platform's statement showing misuse (phishing, SIM swap, fraud), and any dark-web or haveibeenpwned evidence. Keep hash-preserved originals for Section 63 BSA — forwarded screenshots degrade proof.

**A note on this article.** It is general legal information, not legal advice. The law may have changed since the date shown; before acting on anything here, take advice on your specific situation from an advocate of your choice.

Keep reading

Data protection & DPDP compliance

### DPDP Compliance Guide for Kerala Businesses to May 2027

DPDP readiness for Kerala SMEs: phased timeline to May 2027, notices, safeguards, breach response, rights, children, SDF, transfer, contracts, penalties.

25 Sept 2026

[DPDP Compliance Guide for Kerala Businesses to May 2027](https://advaslam.com/writing/dpdp-compliance-guide-kerala-businesses/)

Data protection & DPDP compliance

### CERT-In 6-Hour vs DPDP 72-Hour Breach Reporting: Which Clock Applies to Your Business?

India has two breach clocks that both apply: CERT-In's 6 hours and DPDP Rule 7's 72 hours. Who reports to whom, when each starts, and one playbook for both.

1 Sept 2026

[CERT-In 6-Hour vs DPDP 72-Hour Breach Reporting: Which Clock Applies to Your Business?](https://advaslam.com/writing/cert-in-6-hour-vs-dpdp-72-hour-breach-reporting/)

Contact

[WhatsApp](https://wa.me/919497240215?text=Hello%2C%20I%20found%20advaslam.com%20and%20would%20like%20to%20discuss%20a%20matter.) [contact@advaslam.com](mailto:contact@advaslam.com) [+91 94972 40215](tel:+919497240215)

3rd Floor, Lalan Towers (KGL Builders), Vanchi Square, High Court Junction, Ernakulam, Kerala 682031 · Monday – Saturday, 10:00 – 18:30 (by appointment)

```json
{"@context":"https://schema.org","@graph":[{"@type":"WebSite","@id":"https://advaslam.com/#website","url":"https://advaslam.com","name":"Adv. K J Muhammed Aslam","alternateName":"advaslam.com","publisher":{"@id":"https://advaslam.com/#person"},"inLanguage":"en-IN"},{"@type":"Person","@id":"https://advaslam.com/#person","name":"K J Muhammed Aslam","alternateName":["Adv. K J Muhammed Aslam","Advocate K J Muhammed Aslam","Muhammed Aslam K J","Adv. Aslam"],"honorificPrefix":"Adv.","jobTitle":"Advocate","description":"Advocate enrolled with the Bar Council of Kerala, practising from High Court Junction, Ernakulam: cyber and technology law, data protection (DPDP), business, banking and IPR, and litigation before the High Court of Kerala and the courts at Ernakulam.","url":"https://advaslam.com/profile/","image":"https://advaslam.com/og.png","telephone":"+919497240215","email":"contact@advaslam.com","address":{"@type":"PostalAddress","streetAddress":"3rd Floor, Lalan Towers (KGL Builders), Vanchi Square, High Court Junction","addressLocality":"Ernakulam","addressRegion":"Kerala","postalCode":"682031","addressCountry":"IN"},"alumniOf":{"@type":"CollegeOrUniversity","name":"Bharata Mata School of Legal Studies"},"memberOf":[{"@type":"Organization","name":"Bar Council of Kerala","url":"https://barcouncilkerala.org/lawyer-registry-list"},{"@type":"Organization","name":"Kerala High Court Advocates' Association","url":"https://khcaa.com/"}],"identifier":[{"@type":"PropertyValue","propertyID":"Bar Council of Kerala Enrolment No.","value":"K/001823/2026"},{"@type":"PropertyValue","propertyID":"KHCAA Membership No.","value":"OAJ 358"}],"knowsAbout":["Information Technology Act 2000","Cyber crime law","Technology law and technology contracts","Digital Personal Data Protection Act 2023","DPDP compliance","Data protection and privacy law","Business and commercial law","Contract drafting and negotiation","Banking and finance law","Negotiable Instruments Act cheque dishonour","SARFAESI Act","Intellectual property law","Copyright and trademark law","Patent infringement","GST and income-tax law","Blockchain and cryptocurrency technology","Web3 wallets and NFTs","Drone regulation and DigitalSky framework","Writ petitions under Article 226","Criminal law","Civil and consumer litigation","Family and succession law","Service and labour law","Legal drafting","Mediation and dispute resolution"],"knowsLanguage":["en","ml"],"workLocation":{"@id":"https://advaslam.com/#practice"},"hasCredential":[{"@type":"EducationalOccupationalCredential","credentialCategory":"Enrolment as an advocate","identifier":"K/001823/2026","recognizedBy":{"@type":"Organization","name":"Bar Council of Kerala"},"description":"Enrolled as an advocate with the Bar Council of Kerala (K/001823/2026), 2026"},{"@type":"EducationalOccupationalCredential","credentialCategory":"degree","educationalLevel":"Bachelor","recognizedBy":{"@type":"CollegeOrUniversity","name":"Bharata Mata School of Legal Studies"},"description":"BBA LLB (Hons.), Bharata Mata School of Legal Studies (2025)"},{"@type":"EducationalOccupationalCredential","credentialCategory":"Remote Pilot Certificate","recognizedBy":{"@type":"Organization","name":"Directorate General of Civil Aviation, India"},"description":"DGCA Remote Pilot Certificate, issued 2022"}],"subjectOf":[{"@type":"CreativeWork","name":"Govind Babu v. State of Kerala (Crl.M.C. No. 5640 of 2026, 2026:KER:69496)","url":"https://indiankanoon.org/doc/151180872/","datePublished":"2026-09-10","publisher":{"@type":"Organization","name":"High Court of Kerala"}},{"@type":"CreativeWork","name":"Viji Sagar v. State of Kerala (Crl.M.C. No. 1603 of 2026, 2026:KER:20803)","url":"https://indiankanoon.org/doc/193042273/","datePublished":"2026-03-09","publisher":{"@type":"Organization","name":"High Court of Kerala"}},{"@type":"CreativeWork","name":"Anjana v. Manoharan A.P. (C.R.P. No. 442 of 2025, 2026:KER:10054)","url":"https://indiankanoon.org/doc/68585852/","datePublished":"2026-02-05","publisher":{"@type":"Organization","name":"High Court of Kerala"}}],"sameAs":["https://www.linkedin.com/in/azlubro","https://portal.khcaa.com/advocate?id=10480","https://lexosys.com"]},{"@type":"LegalService","@id":"https://advaslam.com/#practice","name":"Adv. K J Muhammed Aslam — Advocate, Ernakulam","url":"https://advaslam.com","image":"https://advaslam.com/og.png","telephone":"+919497240215","email":"contact@advaslam.com","address":{"@type":"PostalAddress","streetAddress":"3rd Floor, Lalan Towers (KGL Builders), Vanchi Square, High Court Junction","addressLocality":"Ernakulam","addressRegion":"Kerala","postalCode":"682031","addressCountry":"IN"},"geo":{"@type":"GeoCoordinates","latitude":9.9889,"longitude":76.2748},"hasMap":"https://www.google.com/maps/search/?api=1&query=Lalan+Towers+High+Court+Junction+Ernakulam","areaServed":[{"@type":"City","name":"Ernakulam"},{"@type":"City","name":"Kochi"},{"@type":"State","name":"Kerala"},{"@type":"Country","name":"India"}],"openingHoursSpecification":{"@type":"OpeningHoursSpecification","dayOfWeek":["Monday","Tuesday","Wednesday","Thursday","Friday","Saturday"],"opens":"10:00","closes":"18:30"},"founder":{"@id":"https://advaslam.com/#person"},"knowsAbout":["Cyber crime and IT Act matters","Data protection and DPDP Act compliance","Business, banking, intellectual property and tax","Legal drafting","Criminal law: bail, quash and appeals","Writ petitions before the High Court of Kerala","Civil, property and consumer matters","Family and succession matters","Service and labour matters"]},{"@type":"BlogPosting","@id":"https://advaslam.com/writing/data-breach-victim-rights-dpdp-compensation/#article","isPartOf":{"@id":"https://advaslam.com/#website"},"headline":"Your Personal Data Was Leaked by a Company: What You Can Do Under the DPDP Act","description":"Company leaked your Aadhaar, phone or health data? DPDP Sections 11-14 rights, Board complaint, IT Act 43A compensation, consumer and civil remedies.","url":"https://advaslam.com/writing/data-breach-victim-rights-dpdp-compensation/","mainEntityOfPage":"https://advaslam.com/writing/data-breach-victim-rights-dpdp-compensation/","datePublished":"2026-09-06T00:00:00.000Z","dateModified":"2026-09-06T00:00:00.000Z","keywords":"my data leaked company what to do India, DPDP Act data principal rights, data breach victim compensation India, IT Act 43A data breach compensation, DPDP Board complaint data breach","inLanguage":"en-IN","author":{"@id":"https://advaslam.com/#person"},"publisher":{"@id":"https://advaslam.com/#person"},"image":"https://advaslam.com/og/writing/data-breach-victim-rights-dpdp-compensation.png","about":{"@type":"Service","@id":"https://advaslam.com/practice/data-protection/#service","name":"Data protection & DPDP compliance","url":"https://advaslam.com/practice/data-protection/","provider":{"@id":"https://advaslam.com/#practice"}}},{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://advaslam.com/"},{"@type":"ListItem","position":2,"name":"Articles","item":"https://advaslam.com/writing/"},{"@type":"ListItem","position":3,"name":"Your Personal Data Was Leaked by a Company: What You Can Do Under the DPDP Act","item":"https://advaslam.com/writing/data-breach-victim-rights-dpdp-compensation/"}]},{"@type":"FAQPage","mainEntity":[{"@type":"Question","name":"What rights do I have if a company leaked my personal data in India?","acceptedAnswer":{"@type":"Answer","text":"Under DPDP Sections 11-14 you have rights to access the personal data and the identities of recipients it was shared with, to correction and erasure, to grievance redressal, and to nominate another person on death or incapacity. Under Section 13 you must first use the fiduciary's published grievance mechanism; if unresolved, you may complain to the Data Protection Board, which can inquire and impose penalties under Section 33 and issue directions. Separately, you may have a claim for compensation under Section 43A IT Act for negligent handling of sensitive personal data (the repeal of Section 43A — DPDP Section 44(2)(a) — is not yet in force), and under the Consumer Protection Act 2019 where the data handling was a service deficiency."}},{"@type":"Question","name":"Can I get compensation if my data was leaked?","acceptedAnswer":{"@type":"Answer","text":"Compensation is not yet fully codified under DPDP — Section 33 provides penalties to the State and Board directions, not direct monetary compensation to the victim in the Act's text. Victim compensation today runs primarily through Section 43A IT Act (compensation for failure to protect sensitive personal data), civil suit for damages, and the Consumer Protection Act 2019 (service deficiency) where personal data handling was part of a consumer service. The Board's penalty and direction do support your compensation case by establishing breach."}},{"@type":"Question","name":"How do I complain to the Data Protection Board under DPDP?","acceptedAnswer":{"@type":"Answer","text":"First, file a grievance with the fiduciary's published grievance officer (required under Section 13 DPDP and Rule 14). Preserve delivery proof. If not satisfactorily answered, you may complain to the Board with the grievance record, the Section 11 access request where relevant, and the breach evidence. The Board inquires under Sections 27-28 and may impose penalties under Section 33 (up to 250 crore for safeguard failure, 200 crore for children's/breach duties) and issue directions. Appeals lie to the TDSAT under Section 29 within 60 days."}},{"@type":"Question","name":"Does the DPDP Act help if old leaked data was non-digital?","acceptedAnswer":{"@type":"Answer","text":"DPDP applies to digital personal data — data in digital form or digitised later where the Act applies (Section 3). A purely paper handling with no digital processing is outside DPDP, but may still be actionable under IT Act 43A where the data was sensitive personal data handled without reasonable security, and under consumer or contract law. Check whether the data entered a digital system at any stage (CRM, app, server) — most modern leaks are digital."}},{"@type":"Question","name":"What proof should I keep after a data breach notification?","acceptedAnswer":{"@type":"Answer","text":"The breach intimation the company sent (Rule 7 requires it without delay with nature, extent, mitigation and contact), your Section 11 access request and its reply, the grievance filing with timestamp, the bank's or platform's statement showing misuse (phishing, SIM swap, fraud), and any dark-web or haveibeenpwned evidence. Keep hash-preserved originals for Section 63 BSA — forwarded screenshots degrade proof."}}]}]}
```
