[Kriti Kabra is a fifth-year student at Gujarat National Law University. In this piece, the author interrogates the lack of compensation provisions under the new Digital Data Protection framework and how the omission has altered the role of the victim from a claimant to a mere complainant. The piece argues that the absence of a statutory compensatory remedy leaves victims without any redressal mechanisms for data breaches and suggests possible solutions to improve the framework.]
- Introduction
With the introduction of the timeline for the Digital Personal Data Protection Act, 2023 (“Act”) and the Digital Personal Data Protection Rules, 2025 (“Rules”), India’s new data privacy framework will soon see the light of day in its entirety. As technology grows rapidly, with it will also come litigation in droves as data breaches are an inevitable event. However, when it comes to remedies, an aggrieved user’s options are rather limited. The creation of a separate data privacy legislation was spearheaded by the Srikrishna Committee in 2018 (“Committee”), which advocated for joint and several liability to pay compensation. This model, drawing from the General Data Protection Regulation (“GDPR”) scheme, places the Data Principals at the forefront, ensuring that they are paid their dues.
The Committee outlined various factors that need to be taken into consideration when deciding compensation to be awarded. These recommendations were later included within Section 64-66 of the Personal Data Protection Bill, 2019. However, when the Bill was later replaced with the DPDP Act, the compensation provision was missing, with penalties taking the centre stage instead. The difference between compensation and penalty lies in the structural difference between the two, wherein the earlier takes a remedial role while the latter serves a punitive role [page 164 and 165]. In practice, money collected through penalties goes to the Consolidated Fund of India, i.e., the government, under Section 34 of the Act, while the user is left penniless in addition to their data being breached.
This piece argues that the Act’s omission of a compensation provision is a structural flaw that leaves Data Principals without any meaningful recourse. Since the consequences of a data breach cannot be undone, any other measure taken by the company only affects future actions. This means that the victim of the present data breach is left with hardly any recourse apart from contractual remedies, if at all available. A compensation provision therefore acts as relief for the victim when hardly any other option is obtainable.
After a brief introduction of the issue at hand, Part II maps out the legislative gap by examining the ambiguity created by the introduction of the Data Protection Board (“Board”) and how the simultaneous application of the Information Technology Act, 2000 (“IT Act”) creates an uneasy overlap when it comes to the realities of granting compensation. Part III turns to the GDPR jurisprudence for comparative guidance on how such a provision can be operationalised by providing general principles that still create room for flexibility in application. Part IV then draws on India’s existing jurisprudence in other areas of law to suggest possible changes that can be incorporated.
- The Legislative Gap
(i) The introduction of the Data Protection Board
As the first standalone statute created specifically to govern the processing of personal data and superseding provisions scattered across the IT Act framework, how the DPDP deals with remedying breaches is rather strange. The Act creates a Board which is empowered to direct urgent remedial or mitigation measures, inquire into the data breaches, issue directions and impose penalties under Section 27. While one could argue that “issue directions” and “urgent remedial measures” could encompass compensation however that is mere speculation, the answer to which we can only know once courts interpret the same. Even if courts were to interpret it in a manner that extends to awarding compensation, it would still remain vague as the scope remains unclear. Due to a lack of any criteria or guidelines, it would be awarded on a case to case basis, making it non-uniform. Additionally, the legislative scheme of most legislations in India that provide for compensation mention the same separately, which is indicative of the direction courts may take on the issue.
Furthermore, the Section 39 of the Act excludes the jurisdiction of civil courts from any subject matter that falls under the jurisdiction of the Board. This brings up the alternative argument that since compensation does not fall under the powers of the Board, litigants can take up the issue before civil courts separately however this defeats the purpose of the Board altogether as parties would have to pursue the same issue before multiple forums, making it significantly more difficult for them to enforce their rights. It may even lead to conflicting proceedings as multiple forums may view the same the issue differently.
(ii) Simultaneous application with the IT Act
The DPDP replaced Section 43A of the IT Act and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 which previously governed the Indian privacy framework. The IT Act has a whole host of provisions that deal with compensation. Section 43A, though now repealed, provided for compensation in case of breach of data by a body corporate and Section 47 details the factors that are to be taken into account by the adjudicating officer when deciding the quantum of compensation. The IT Act also provides for mechanisms to recover the compensation if not paid by the defaulting party (Section 66 of the IT Act), and distinctness of the different punishments imposed under the Act (Section 77 of the IT Act). Section 45 even contains a residuary clause that acts as a catch all for any violations of the Act that haven’t been prescribed a penalty, where the affected party would be given a capped compensation by the defaulting party.
Interestingly despite Section 43A being repealed, all the remaining provisions mentioned above were left intact. There are only two provisions in the IT Act that provide compensation, one being Section 43A and the other being Section 43, which covers scenarios in which “persons” access, damage or download computers, computer systems or computer networks. A bare reading suggests that Section 43 is primarily a cyber-security provision rather than being privacy centric. Though its interaction with DPDP will be observed in the future, it is possible that an incident can trigger both Section 43 and the DPDP, such as breaking into a computer system and then leaking data. So while the former can give compensation, the latter cannot. This creates a murky overlap – apart from being a possible logical consequence of breaking into systems, the effect the data breach will have may be one of the key metrics in quantifying loss under Section 47.
This becomes especially relevant when considering that Section 43A is only set to be repealed at stage 3 as per the enforcement notification dated 13th November, 2025, which means that Section 43A and the DPDP Act will simultaneously apply till the it is repealed. This also presents a procedural issue. The appropriate authority under the IT Act for claims not exceeding 5 crores is the adjudicating officer (Section 46 of the IT Act) and for those exceeding 5 crores, it is the competent court. It explicitly excludes the jurisdiction of civil courts (Section 61 of the IT Act). Similarly, the Board is empowered to entertain matters pertaining to the DPDP Act, barring the jurisdiction of the civil courts (Section 39 of the Act). Both provisions prevent interference from other courts. So for overlapping matters even under Section 43 of the IT Act, litigants are left in a dilemma.
- The GDPR Approach
The problem with data is that it cannot be treated the way other breaches are. Data can be copied infinitely, used in unexpected ways, misused long after the breach has taken place and exploited by unknown actors once released. Due to the expansive nature of its consequences, its very difficult to quantify damage and ascertain liability accordingly. In the age of artificial intelligence, even data not classified as “sensitive” can be used in unforeseen ways, making the causal chain even harder to establish. It is almost impossible to ascertain the possibilities of the repercussions of any breach. Furthermore, the harm is completely asymmetric, with each breach having the capability to affect millions of people simultaneously. The consequences are so drastic that leaving this section unaddressed only creates legal battles down the line for Data Principal, Data Fiduciary and Data Processor rights.
The Indian approach recognises harm but it disconnects enforcement from victim reparation. To tackle the same, inspiration can be taken from foreign legislations. The European Union has one of the leading frameworks in the sector with the GDPR, which recognises compensation as a right of all Data Principals under Article 82. Its structure rests on three conditions as established by UI v. Österreichische Post AG – there must be an infringement of the GDPR, damages must have been suffered by the data subject and there must be a causal link between the infringement and the damage caused [paragraph 36]. The range of compensable damages is quite broad, primarily being classified into material, i.e., financial loss and non-material damages, such as distress, reputational harm and loss of control over one’s data [paragraph 45]. Moreover, in VB v Natsionalna agentsia za prihodite, the court acknowledged that a well-founded fear of future misuse is enough to constitute a compensable harm [paragraphs 75 – 86]. The consideration of this factor is imperative as a breach victim in India almost never knows exactly how their data will be misused. Additionally, with the advent of AI, pictures can be morphed and data can be used in numerous ways beyond what was initially intended at the time of collection.
The CJEU has even clarified that there exists no de minimis threshold, i.e., that there is no minimal amount of damage that needs to happen in order to claim damages under the provision [paragraphs 45 – 49]. Even being put in a position of uncertainty may amount to a non-material damage [paragraph 197], however purely hypothetical and speculative claimsdo not give rise to compensation [paragraph 192]. This framework is incredibly beneficial as it covers a wide range of damages that can be incurred by any user, and it lifts the burden off of the users to prove negligence or fault on behalf of the data controller or processor, instead shifting the burden on them. Despite this classification, even the GDPR has not managed to arrive at a conclusive model that can be uniformly applied to cases, with interpretation being left to member states to be decided on a case to case basis and as per Regulations adopted by each Member State under Recital 146. This has led to divergence in the award of non-material damages as different Member States take different factors into account such as the difference in dealing with the loss of control. Despite its imperfections, the GDPR framework does not shy away from providing compensation even if it is difficult to quantify.
What is India’s Takeaway?
Indian law is not alien to the concept of awarding compensation. One of the best parallels that can be made is to environmental law as it has similar considerations involved. A singular event can lead to unfathomable consequences and may materialise many years down the line. Such harms are difficult to quantify as the extent is unknown at the time of the event and may cause illnesses along with pollution of the surrounding environment. Each victim cannot practically prove individual causation. In such cases, courts have ordered both compensation and penalty, one as a reparation and the other to punish the polluter. Even if harms were caused by private parties, judicial interpretation permits enforcement of remedies and compensation against them when the act leads to gross violations of fundamental rights such as the right to life and clean environment under Article 21. The same logic can be extended to the right to privacy under the same constitutional provisions as recognised by K.S. Puttaswamy (Privacy-9J.) v. Union of India’s judgement as a right without a remedy is no right at all.
Previously, Section 43A of the IT Act used to follow a model similar to the Article 82 GDPR model. Apart from environmental law, various other types of laws have dealt with compensation as well. Quantification of reputation loss and mental agony have been tackled by defamation law. Medical law also awards compensation for reduced probability of survival, the logic for which can be carried forward to calculating the increased probability of future harm caused by data breaches. Furthermore, imposition of penalty requires weighing multiple elements which are common considerations for levying compensation as well. Therefore, difficulty in quantification cannot be the sole reason for avoiding compensation.
There are several improvements that must be made to the DPDP in this regard, the first one being the inclusion of an explicit provision providing for compensation in cases of breach. While having a clean cut method that can directly be applied is desirable, till the same is arrived upon, the provision could list various factors that courts must take into consideration for quantification. For this, factors from Section 33(2) of the Act and the Srikrishna Committee Report such as nature and sensitivity of the data breached and repetitiveness can be used as these factors have already been accepted by the Parliament as relevant considerations in data protection disputes, which makes their extension a logical step. The need to tackle this legislatively is imperative, as leaving the compensation model to be developed solely by the judiciary through precedents could lead to the same interpretation issue the current GDPR framework has. In order to accommodate compensation, the scope of the Board would need to be expanded in order to empower them with the authority to award compensation in a manner that is accessible for Data Principals without requiring them to bear disproportionate litigation costs.
Conclusion
The DPDP Act’s silence on individual compensation is legislative oversight – rather it is a structural flaw that undermines the very purpose of data protection law. The existing framework leaves Data Principals without a direct remedy as the Board’s powers remain ambiguous on compensation, civil courts are ousted from jurisdiction and penalties flow to the State instead of the victim. The partial survival of the IT Act’s compensation provisions only deepens the confusion, creating overlapping forums and conflicting proceedings for what may be the same underlying harm. Meanwhile, the GDPR’s experience demonstrates that compensation is achievable, however leaving it up to judicial interpretation would cause divergence, unpredictability and uneven outcomes, a step India can avoid.
Ultimately, the question of data compensation is inseparable from the broader question of what data protection law is for. The current framework treats the harm suffered by Data Principals as a means of improvement as penalties deter, remedial measures improve the systems in place, while the victim receives nothing. Data is uniquely personal and its breach carries harms that are simultaneous, asymmetric, and often invisible until long after the breach has taken place. Just as Indian law has evolved to recognise victim-centric remedies in environmental harm, the same logic must also extend to its privacy framework. The foundation is there, only the gaps need to be filled.