Rights Without Courts: India’s Troubling DPDPA Model

[Adarsh Philip Roy is a LLM student at West Bengal National University of Juridical Sciences (WBNUJS), Kolkata.]

The Digital Personal Data Protection Act, 2023 (DPDPA) establishes a framework for the collection, storage, processing, and ultimately the protection of personal data. On closer examination, however, this seemingly progressive law carries a controversial twist. Unlike other global data protection laws, the DPDPA pointedly shuts the courthouse doors to individuals seeking monetary redress for data harms. Section 39 of the Act bars civil courts from exercising jurisdiction over matters entrusted to the board. The law funnels all grievances through an administrative pipeline, first to the offending company itself and then to a government-appointed Data Protection Board, with no other recourse. 

Therefore, when a data principal has her data privacy rights violated, she has to approach the board as the sole forum for enforcement.  To compound this limitation of litigation burden, even if the board finds the company at fault, it cannot award her compensation or damages; it can only levy fines on the data fiduciaries, which are to be paid into the government coffers. 

The result of this system is what I would call ‘rights without courts’, meaning an enforcement framework where the individual suffers a legal injury, but the law provides no mechanism to remedy the harm. To understand the contours of this debate, we must examine closely what the law states.

The Two-Step Redressal Path under the DPDPA

The DPDPA creates a two-step grievance redressal process for Data Principals.

  1. Complain to the Data Fiduciary: If you, as a data principal, have a complaint about how your personal data was handled, say, your data was leaked, or your rights under the Act were denied, the first stop is the Data Fiduciary’s internal grievance mechanism. The “Data Fiduciary” is the entity or company handling your data. Every data fiduciary must provide readily available means to address user grievances. You lodge your complaint with the data fiduciary itself (or its designated grievance officer/“Consent Manager”), and the data fiduciary or such other entity must respond within a prescribed period. The idea is to allow the data fiduciary to resolve the issue directly. The data principal is also obliged to exhaust the remedy of contacting the data fiduciary before escalating it to the board. 
  2. Escalate to the Data Protection Board of India: If the fiduciary’s response is unsatisfactory or ignores your grievance, your only next recourse is to file a complaint with the Data Protection Board of India. You cannot file a lawsuit in any civil court or consumer forum for data privacy violations. The Board is established as an independent adjudicatory authority under the Act and is empowered to receive and investigate these complaints.  This means that all data protection disputes must be resolved exclusively by the Board, with no parallel civil lawsuits permitted. 

To better understand this predicament, we can construct a hypothetical situation. Aarav is a 12-year-old boy already struggling with long-standing mental health issues. Without his parents knowing, he downloads a popular online gaming app that collects his personal data and exposes him to highly immersive, dark content. This dark content included glorifying violence or self-harm. According to Section 9 of the DPDP Act, data fiduciaries must obtain verifiable consent from a parent or guardian to process personal data of children. The company, in violation of the DPDPA, never obtained the verified consent of his parents. 

As Aarav played the game more, its design and content fed into his vulnerabilities. One day, the app introduced a “challenge” which essentially included a challenge to inflict self-harm upon himself and upload it as a video in an online community of gamers. Aarav complied, being a naive 12-year-old. The video was subsequently leaked and went viral online. In the leaked videos, his face was clearly visible. Overnight, Aarav was left exposed, humiliated, and emotionally devastated.  His parents eventually found out about their son through social media, and the incident left profound and lasting scars on both him and his family.

Yet when his parents turn to Indian data privacy law for justice, they find the doors of the courts firmly shut. The DPDPA forces them to complain first to the very company whose negligence endangered their child’s well-being, and then, if unsatisfied, to the Data Protection Board of India. Even if the board takes cognisance of the violation and fines the company for failing to obtain parental consent, the penalty is paid only to the government. This fine is meant to punish the company and deter future violations, but Aarav and his family will not see a paisa of it. 

To understand just how extraordinary, and frankly regressive, this move is, one must recognise that the legislature has not merely failed to strengthen existing remedies but has actively rolled back the only statutory compensation mechanism individuals previously had, making the post-DPDPA landscape significantly worse. Section 43A of the Information Technology Act, 2000, which held companies handling sensitive personal data liable to pay compensation if they were negligent in maintaining reasonable security practices and, as a result, negligence caused wrongful loss or gain, was completely omitted by virtue of Section 44(2) of the DPDPA. This now-defunct provision gave individuals the right to sue for damages when their sensitive data was mishandled, with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, defining what constitutes sensitive data and reasonable security standards. By dismantling this liability regime without supplying any equivalent private law remedy, the DPDPA engineers a rights framework without consequences, effectively insulating private corporations from monetary accountability for violations of individual privacy.

This shift represents a significant regression in India’s data protection framework, where the state completely forecloses a right without proper justification. The state essentially receives the benefits of a private individual’s data privacy sufferings.

The Constitutional Dilemma: Testing Section 39

By ousting the jurisdiction of civil courts, the statute effectively severs the link between a legal injury and its judicial remedy, thus rendering the right to privacy illusory. I would therefore argue that Section 39 is constitutionally suspect on three distinct but interrelated grounds. 

Firstly, the Supreme Court of India has long maintained that the existence of a right is inseparable from the existence of an effective forum for its enforcement. In Anita Kushwaha v. Pushap Sudan, the Court elevated access to justice as an integral facet of the right to life and personal liberty under Article 21 of the Constitution. The court explicitly stated that a meaningful life is impossible if a person cannot effectively approach courts or other adjudicatory mechanisms to enforce rights. 

By funnelling all grievances into an administrative body while simultaneously barring the jurisdiction of civil courts, Section 39 effectively undermines the principles laid down in this judgment and raises serious concerns regarding its constitutional validity.

Secondly, the current model overlooks the State’s positive obligation to provide compensatory justice, as the Justice K.S. Puttaswamy v. Union of India judgement firmly located privacy within Article 21 and therefore any breach of this right must trigger a meaningful remedy. The Supreme Court in Nilabati Behera v. State of Orissa was categorical in holding that monetary compensation is the appropriate remedy in public law for the violation of fundamental rights, while in  Rudul Sah v. State of Bihar, 1983, the Supreme Court warned that Article 21 would be “stripped of its significant content” if confined to declaratory relief, and therefore affirmed monetary compensation as an ancillary remedy. When the DPDPA mandates that penalties are paid into state coffers while denying victims any compensatory remedy, it reduces the constitutional guarantee of effective redress to a hollow formality and finds itself in violation of these laws laid down by the Supreme Court. 

Thirdly, the Act runs afoul of the doctrine of non-retrogression, as consistently articulated by the Supreme Court in a line of authoritative decisions. In Navtej Singh Johar v. Union of India, the State is prohibited from taking regressive steps that curtail protections already enjoyed by citizens. By omitting Section 43A of the IT Act, which allowed for compensation, without providing an equivalent private law recourse, the legislature has taken a step backward. 

These structural deficiencies render the statutory framework a failure of the constitutional promises and therefore, I would argue that, in multiple respects, Section 39 fails the test of constitutionality. 

Executive Control and Independence Issues 

Critics argue that the Board’s structural independence is not assured as its composition and tenure are tightly controlled by the Executive. All adjudication happens within this executive-controlled framework by removing courts from the equation. This concentration of power could be worrisome if, for example, a data breach involves a politically connected entity. A reasonable question arises as to whether an executive-dependent board feels the same liberty to enforce the law as an independent court, where judicial officers are appointed and maintained independently. Any perceptions (or reality) of bias, selective enforcement, or inefficiency at the board level could erode trust in the redress system. There is a reason constitutional democracies maintain a separation between the executive and the judiciary. The executive is meant to administer the law, while the judiciary exists to adjudicate disputes and protect rights independently. By concentrating adjudicatory powers within an executive-controlled framework, the DPDPA risks undermining the institutional independence necessary for effective rights enforcement and impartial decision-making. 

Global Position on Judicial Remedies for Data Privacy Violations

To truly gauge how unusual the DPDPA’s no-courts approach is, we can examine data privacy laws worldwide. Under the European Union’s GDPR, individuals enjoy multiple avenues for redress. Under Article 79 (Right to an effective judicial remedy against a controller or processor), data subjects have the right to bring a private action against the errant data controller or processor in court. Article 82 (Right to compensation and liability) states that any person who has suffered material or non-material damage due to an infringement of the right conferred by the GDPR has the right to receive compensation from the controller or processor responsible. The GDPR’s approach recognises that regulatory enforcement and private lawsuits are complementary. 

Though limited, Section 1798.150 of the California Consumer Privacy Act (CCPA) gives consumers the right to sue companies for certain data breaches. In the UK (which mirrored the EU approach in its Data Protection Act 2018), individuals can claim compensation for data misuse, including for emotional distress, by virtue of section 168 of the Act.

Regulators deter and punish violations in the public interest on a large scale, while private actions ensure that individuals are made whole for their personal injuries. One does not negate the other. In fact, the possibility of civil liability under GDPR raises the stakes for companies beyond worrying about an administrative fine. Organisations must also consider potential class-action lawsuits or individual damage claims that could be enormous financial burdens in the long run. This dual pressure leads to greater accountability from private entities that vie for personal data for monetary gain. 

When enforcement is limited solely to administrative fines, major corporations often internalise these penalties as routine compliance costs rather than meaningful deterrents. For companies with deep financial reserves, such fines become an investment in risk rather than a consequence for violating rights. For example, Google’s publicly announced investment of approximately ₹1.25 lakh crore in India, along with its establishment of one of its largest data centre infrastructures outside the United States, illustrates this imbalance. Against commitments of that scale, a proposed ₹250 crore penalty would be relatively negligible. 

Potential Counterarguments to the “No Courts” Model and Their Limitations

Supporters of the DPDPA’s court-exclusion framework may argue that the statute is not entirely devoid of remedial mechanisms and that alternative avenues of redress continue to exist outside traditional civil litigation. However, upon closer examination, these remedies appear fragmented. 

One possible defence of the framework may be drawn from Section 31 of the DPDP Act, which permits mediation. Proponents may contend that this provision allows affected individuals and data fiduciaries to arrive at negotiated settlements, including compensation for harms suffered, thereby reducing the need for adversarial litigation. Such an approach may also be defended as being faster, less expensive, and procedurally simpler than conventional court proceedings.

Yet this argument is ultimately unpersuasive. Mediation is fundamentally consensual in nature and depends heavily on the willingness of the data fiduciary to participate meaningfully. In practice, individual data principals often stand in profoundly unequal bargaining positions when negotiating against large corporations possessing superior financial resources and legal expertise. The provision merely enables settlement if both parties voluntarily agree. Consequently, mediation cannot substitute a guaranteed judicial remedy grounded in enforceable legal rights. A constitutional or statutory right loses much of its substantive value if the injured party must rely upon the goodwill of the violating entity itself in order to obtain relief.

A second counterargument may be based on the constitutional remedy available under Article 226 of the Constitution of India. It may be argued that individuals remain free to approach High Courts seeking compensation or constitutional remedies in cases involving grave privacy violations, particularly where large-scale harm, systemic negligence, or violations affecting multiple persons are involved.

However, this argument also suffers from significant limitations. Writ jurisdiction under Article 226 is extraordinary and discretionary; it is not designed to serve as a routine compensatory forum for ordinary data protection disputes. High Courts traditionally exercise restraint in entertaining fact-intensive private disputes requiring detailed evidentiary examination. The High Courts are fundamentally not fact-finding courts.  PIL jurisdiction, while important, is similarly limited to exceptional circumstances involving broader public injury and cannot realistically replace a comprehensive statutory framework for individual compensation claims. 

A further defence may arise from the Consumer Protection Act, 2019.  A data privacy violation involving unauthorised disclosure of confidential consumer information constitutes an unfair trade practice under Section 2(47)(ix) of the Act. Further, where there is a failure to maintain reasonable standards of confidentiality or data protection in the rendering of services, such conduct may also amount to a deficiency in service under Section 2(11). A consumer may therefore file a complaint under Section 35 and seek relief under Section 39, including compensation for loss or injury suffered, discontinuation of the unfair trade practice, litigation costs, and, in appropriate cases, punitive damages.

Nevertheless, the Consumer Law cannot adequately fill the remedial vacuum created by the DPDPA.  Even if compensation may be awarded for certain data privacy violations, not every data principal would necessarily qualify as a “consumer”, particularly when digital services are provided without direct monetary consideration or when the relationship falls outside conventional consumer-service paradigms.

Taken together, these counterarguments demonstrate that, while certain peripheral remedies may exist in theory, none provides a framework capable of meaningfully replacing judicial remedies expressly excluded under the DPDPA.

Conclusion

In conclusion, if India is to uphold its constitutional promise of effective redress and align itself with global standards recognising the indispensable role of independent courts, the Parliament must urgently reconsider the DPDPA’s existing no-courts remedial framework.

Author

More From Author

Where Does AI Training Infringe, and Do Model Weights Count? Lessons emerging from Getty Images v. Stability AI

India’s Soft Law Approach: Strategic Choice or Potential Oversight?