Corporate Liability for Data Breaches : Emerging responsibilities of Indian companies: Author:Arjuman Lodhi
The rapid growth of digital services in India has made personal data an important corporate asset. It has also increased the risk of data breaches. The Digital Personal Data Protection Act 2023 has introduced stronger responsibilities for companies that collect & use personal data. This article explains what a data breach is and how the DPDP Act changes the responsibilities of Indian companies.
ARTICLE


Abstract
The rapid growth of digital services in India has made personal data an important corporate asset. It has also increased the risk of data breaches. The Digital Personal Data Protection Act 2023 has introduced stronger responsibilities for companies that collect & use personal data. This article explains what a data breach is and how the DPDP Act changes the responsibilities of Indian companies.
Keywords
Data Breach, Data Protection, Data Fiduciary, DPDP Act 2023, Corporate Liability and Privacy.
What is a Data Breach?
A personal data breach happens when personal data is accessed or handled without permission. It can also happen when data is accidentally shared, changed, destroyed or lost. A data breach can affect the security and privacy of personal data.
A data breach does not always happen because of a complex cyberattack. It can happen through phishing, a wrong email, an exposed database, a stolen laptop, a hacked employee account or careless handling of data by a third party.
A cybersecurity incident and a personal data breach are not always the same. A system failure may not involve personal data. However, if a database containing personal data is stolen then it can be both a cybersecurity incident and a personal data breach.
This difference is important because different laws and rules may apply to different incidents.
Introduction
Earlier data protection in India was mainly governed by the Information Technology Act 2000. The Supreme Court’s decision in Justice K.S. Puttaswamy v. Union of India recognised privacy as a fundamental right under Article 21. The Digital Personal Data Protection Act 2023 further strengthened the legal framework for protecting personal data in India.
What is the DPDP Act & How Does It Change Everything?
The Digital Personal Data Protection Act 2023 is India’s law for protecting digital personal data. It sets rules for how companies & organisations can collect and use personal data. It also gives people more control over their personal information.
Under the Act companies that decide why & how personal data is used are called Data Fiduciaries. They must protect personal data & take reasonable security measures. They must also follow the rules when collecting & using personal data.
The Act gives people certain rights over their personal data. They can ask about how their data is being used. They can also withdraw their consent when consent is the basis for using their data.
The Act also changes how companies deal with data breaches. Companies must take steps to prevent data breaches. They must also report breaches as required by the law & rules. This means that data protection is not only an IT responsibility. It is also a legal responsibility.
The Act also provides for the Data Protection Board of India. The Board can deal with complaints & take action when companies fail to follow the law. Companies can also face financial penalties for failing to meet their duties.
In simple words the DPDP Act changes the way companies handle personal data. They must collect & use data responsibly. They must protect it from misuse & breaches. They must also respect the rights of the people whose data they hold.
Corporate Responsibilities
Companies that collect & use personal data are called Data Fiduciaries under the DPDP Act. They must take reasonable security measures to protect personal data. They must also take steps to prevent data breaches & inform the authorities and affected individuals when required.
Companies can also be held responsible when they use third party vendors or cloud service providers to process personal data. They must make sure that proper data protection measures are followed. A data breach can happen through phishing, hacking, an exposed database, a stolen device or careless handling of data. Companies must therefore have proper security systems & a clear plan to respond to such incidents.
Important Case Law
In Justice K.S. Puttaswamy v. Union of India the Supreme Court recognised privacy as a fundamental right under Article 21. This decision became an important foundation for privacy & data protection in India.
Earlier cases such as M.P. Sharma v. Satish Chandra and Kharak Singh v. State of Uttar Pradesh had taken a narrower approach to privacy. The Puttaswamy judgment changed the legal position & strengthened privacy protection.
Conclusion
Corporate responsibility for data protection in India is becoming stronger. Companies can no longer treat cybersecurity as only an IT issue. Data protection is now an important part of corporate governance. Companies should use strong security measures, conduct regular audits & have proper procedures for dealing with data breaches.
The DPDP Act has made it clear that companies have a legal responsibility to protect personal data. As businesses become more dependent on digital information, responsible data handling will become an important part of corporate compliance.
Sources & References
1. Justice K.S. Puttaswamy v. Union of India
2. M.P. Sharma v. Satish Chandra
3. Kharak Singh v. State of Uttar Pradesh
4. Ministry of Electronics and Information Technology reports on data protection
5. Legal commentaries on data protection & the DPDP Act
6. Digital Personal Data Protection Act 2023
7. Information Technology Act 2000
