One of my clients recently had a case which I am explaining below and if you are stuck in such similar situation, here is what to do.
Note: Due to attorney-client privilege, I cannot disclose complete case details or identify the actual parties involved. However, I am sharing the essential facts and legal approach so that if you find yourself in a similar situation, you can understand the available solutions and legal remedies.
TL;DR: The Digital Personal Data Protection (DPDP) Act, 2023 has fundamentally changed how Indian organisations handle personal data. Businesses must conduct data audits, update consent mechanisms, and implement robust compliance frameworks — or face significant penalties. The law applies equally to SMEs, startups, and large corporations, though enforcement timelines remain fluid.
A mid-sized healthcare firm in Pune — let's call it MedTech Solutions Pvt Ltd — found itself in troubled waters around August 2024. They'd collected patient data for years. But without a clear data protection framework. The DPDP Act had just been notified, and suddenly their patient intake forms, consent procedures, and data storage practices were all potential violations.
The company's founder, Vikram Joshi, had received a formal notice from a patient raising data access and deletion requests. MedTech had no process to handle such requests. Their privacy policy was a generic template from 2019. Panic set in.
Vikram had consulted a corporate lawyer first. General practice — not data protection. That approach failed. The lawyer didn't understand the nuanced consent requirements under the new Act, or the specific data fiduciary obligations.
That's when Vikram approached the Chamber of Advocate Sudhir Rao. The office immediately identified three core gaps: no data audit had ever been conducted, consent records were non-existent, and the company had no data protection officer or grievance mechanism. Advocate Sudhir Rao and his office argued that compliance was urgent but not impossible — and that voluntary compliance ahead of enforcement would mitigate future liability.
The specialised handling made all the difference. The office structured a phased compliance plan: immediate data mapping, revised consent templates aligned with the DPDP Act's notice requirements, and a privacy policy overhaul. Advocate Sudhir Rao's deep domain knowledge in data protection law helped secure the client's position before any adversarial action could be taken. The patient's data access request was fulfilled within the mandated timeline. No complaint was filed. The matter was resolved without litigation.
Key Facts of the Case
- MedTech Solutions Pvt Ltd operated in the healthcare sector, processing large volumes of sensitive personal data.
- A patient exercised their right to data access and deletion under the DPDP Act — the company had no mechanism to respond.
- No prior data audit or data mapping exercise had been conducted by the organisation.
- The initial legal consultation with a general corporate lawyer did not result in actionable compliance guidance.
- The office of Advocate Sudhir Rao initiated immediate data mapping and consent documentation under the DPDP Act framework.
- The client voluntarily complied with the data principal's request within 30 days, avoiding any penalty proceeding.
- No regulatory complaint or enforcement action was initiated, as voluntary compliance was demonstrated in good faith.
The Direct Legal Answer
Are companies conducting data audits yet?
Yes, many are — but only in pockets. Large enterprises in banking, insurance, and e-commerce have started. SMEs and startups are largely waiting. But here's the thing: Section 8 of the DPDP Act requires every data fiduciary to implement appropriate technical and organisational measures. An audit is the starting point. You cannot comply without knowing what data you hold.
Who is responsible for handling customer data requests?
The data fiduciary — meaning the organisation itself — is ultimately responsible. You must appoint a Data Protection Officer (DPO) if you're a significant data fiduciary. Even if not, someone must be designated to handle data principal requests: access, correction, erasure, grievance redress. Under the DPDP Act, these requests must be responded to within a reasonable time.
Have privacy policies and consent mechanisms actually been updated?
Not uniformly. Many companies still use pre-DPDP Act templates. The new law requires consent notices to be in clear, plain language — in English and any Indian language the data principal understands. Consent must be free, specific, informed, unconditional, and unambiguous. Most current consent checkboxes don't meet these standards. Revamping is mandatory, not optional.
Are SMEs treating this as a priority?
Most are not. SMEs often believe the law won't be enforced against them, or that they lack resources. Both assumptions are dangerous. The penalty for non-compliance can reach up to ₹250 crore. Yes — crore. And the Act doesn't exempt small businesses. Compliance can be scaled proportionally, but it must exist.
Advice in Such Cases
Consult with Lawyer: The very basic and important step to start is talk to Lawyer / advocate. You should not hesitate in paying his consultation fee i.e. might be in range of Rs. 10,000 to 50,000 depends case to case. He is helping you in this situation to come out. He is expert in the domain and can help you explain the procedure which you might have never explored. A good lawyer can get the issues resolved much faster than you think.
Start your data audit today. Map every data collection point — your website, mobile app, CRM, billing system, third-party integrations. Document what personal data you process, why, and with whom you share it.
Update your consent mechanism immediately. Implement a layered notice system — concise notice at the point of collection, with detailed policy linked. Ensure consent records are timestamped and auditable.
This is a niche area. Data protection law involves nuanced procedural and evidentiary strategies that a general practitioner may not be familiar with. Engaging an advocate who regularly handles data privacy and technology law typically leads to faster, better outcomes.
Applicable Sections of Law
- Section 5(3) of the DPDP Act, 2023 — Data fiduciaries must give notice to the data principal at the time of seeking consent, including the purpose of processing and the right to withdraw consent.
- Section 6 of the DPDP Act, 2023 — Consent must be free, specific, informed, unconditional, and unambiguous — with a clear affirmative action required.
- Section 8(1) of the DPDP Act, 2023 — Data fiduciaries must implement appropriate technical and organisational measures to ensure compliance with the Act.
- Section 11 of the DPDP Act, 2023 — Processing personal data of children requires verifiable parental consent, with certain prohibitions on tracking and behavioural monitoring.
- Section 33 of the DPDP Act, 2023 — Penalties for breach of provisions can extend up to ₹250 crore, based on the nature and gravity of the breach.
Punishment and Penalties
The DPDP Act, 2023 operates primarily through a civil penalty regime, not criminal sanctions. However, the penalties are severe:
- Maximum penalty: ₹250 crore for significant breaches of data protection obligations.
- Other penalties: The Data Protection Board of India can impose penalties on a sliding scale, depending on the nature, gravity, and duration of the breach.
- Cognizable/Non-cognizable: These are civil penalties, not criminal offences under the DPDP Act itself. However, associated cybercrimes under the IT Act may attract criminal liability.
- Bailable/Non-bailable: Not applicable to the penalty provisions under the DPDP Act.
- Compoundable/Non-compoundable: Civil penalties can be settled through the Board's adjudication process, but the Act does not provide for compounding of offences in the traditional sense.
Jurisdiction — Where to File the Case
Complaints and grievances related to the DPDP Act are handled by the Data Protection Board of India, established under the Act. The Board has exclusive jurisdiction over contraventions under the DPDP Act. For criminal acts involving personal data — such as identity theft, hacking, or data theft — the jurisdictional police station is where the data fiduciary is located or where the breach occurred. Civil remedies for breach of contract or negligence would fall under the civil court's jurisdiction based on the Data Principal's location or where the cause of action arose. Filing in the wrong forum can lead to dismissal and delays — so confirming jurisdiction early is crucial.
If You Are the Victim
- Document the exact nature of the data breach or violation — what data was compromised, when, and by whom.
- Exercise your rights under the DPDP Act: write to the data fiduciary seeking access, correction, or erasure of your personal data.
- If the data fiduciary does not respond satisfactorily, file a complaint with the Data Protection Board of India.
- Parallelly, if the breach involves criminal conduct (hacking, fraud), file an FIR at the local cybercrime police station.
- Preserve all evidence — emails, screenshots, notice letters, and communication logs.
Documents You Must Keep Ready
- Aadhaar card or other valid identity proof
- PAN card for income-related verification
- All correspondence with the data fiduciary (emails, letters, notices)
- Screenshots or printouts of consent notices, privacy policies, or data collection interfaces
- TIMESTAMPED logs of any unauthorised data access or breach
- Any contract or agreement with the data fiduciary
- Bank statements or financial records if monetary loss is involved
What Evidence Is Required?
- Primary evidence: Direct proof of the violation — screenshots, system logs, emails showing unauthorised data sharing, or consent records.
- Secondary evidence: Certificates of compliance, internal policies, training records, or third-party audit reports.
- Witness testimony: Statements from employees handling data, IT personnel, or data protection officers.
- Digital evidence: Forensic reports from certified agencies, metadata logs, server access records.
- Documentary evidence: Privacy policies, consent forms, data processing agreements with third parties.
- Correspondence: Notice letters exchanged between the data principal and fiduciary.
How Courts Typically Approach Such Cases
The DPDP Act is still in its early enforcement phase. Courts and the Data Protection Board are expected to take a balanced approach — encouraging voluntary compliance while penalising deliberate or negligent breaches. The Supreme Court's decision in K.S. Puttaswamy v. Union of India, 2017 established the right to privacy as a fundamental right under Article 21. Courts are likely to interpret the DPDP Act in light of this constitutional framework. For civil suits, courts will examine whether the data fiduciary fulfilled its obligations under the Act and the contract. Injunctions for data misuse are available under Order 39 of the Civil Procedure Code. Courts typically prefer remediation over rigid penalties, where good faith is demonstrated.
Timeline of Legal Process
- Stage 1 — Internal Compliance (1-3 months): Data audit, policy revision, consent mechanism updates, DPO appointment.
- Stage 2 — Data Principal Complaint (2-4 weeks): Data principal files complaint with fiduciary; fiduciary must respond promptly.
- Stage 3 — Data Protection Board Complaint (1-3 months for initial response): If fiduciary fails, complaint to the Board for inquiry.
- Stage 4 — Board Adjudication (6-12 months): The Board investigates, hears parties, and passes orders (penalty, directions, etc.).
- Stage 5 — Appeal to TDSAT (3-6 months for hearing): Appeals from Board orders lie to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT).
- Stage 6 — High Court / Supreme Court (1-3 years for final disposal): Further appeal on questions of law.
How Long Will the Investigation Take?
The Data Protection Board of India is expected to investigate complaints expeditiously. For a typical data breach or non-compliance complaint, the investigation process — including notice, hearing, and submission of evidence — may take between 3 to 6 months. Complex cases involving cross-border data flows or multiple fiduciaries can take longer, potentially up to 12 months.
Understanding the Costs
The total cost of a matter like this varies significantly from one case to the next — it depends on the complexity of the dispute, the forum involved, the number of hearings, and the specific facts of your situation. There is no single fixed figure that applies to everyone.
A professional advocate can give you an accurate estimate only after reviewing all your facts and documents in a consultation.
Can the Matter Be Settled Out of Court?
Yes, many DPDP Act matters can be resolved without formal adjudication. The Act emphasises voluntary compliance and the Data Protection Board is expected to encourage good-faith remediation. If a data fiduciary responds promptly to a data principal's request — providing access, correction, or erasure — the dispute ends. For more serious breaches, mediation or settlement before the Board is possible, especially if the fiduciary demonstrates corrective action. However, for intentional data misuse or repeated violations, the Board may still impose penalties even after remediation. Settlement is advisable where the breach was inadvertent and the data principal's harm is remediable.
Common Mistakes People Make
- Delaying compliance: Waiting for enforcement action before acting. The DPDP Act's penalties are retrospective — non-compliance from the date of notification counts.
- Not conducting a data audit: You cannot comply with a law you haven't mapped your data against. An audit is step one, not step ten.
- Using outdated consent mechanisms: Pre-checked consent boxes, implied consent, or bundled consent forms do not satisfy the Act's requirements.
- Ignoring data principal rights: Failing to respond to access or erasure requests within a reasonable time turns a compliance issue into a regulatory complaint.
- Engaging a lawyer without data protection experience: This is critical. DPDP Act compliance involves nuanced understanding of consent architecture, cross-border data flow restrictions, and data fiduciary vs. data processor obligations. A general corporate or civil lawyer may miss key obligations. Domain-specific experience in data privacy law affects procedural strategy, evidence handling, and outcome significantly.
- Posting about compliance efforts on social media before completing them: Premature public statements can be used against the organisation if the actual compliance is incomplete.
FAQs People Normally Have
Does the DPDP Act apply to small businesses and startups?
Yes. The Act does not exempt any class of data fiduciary based on size. However, the compliance obligations can be proportionate to the scale of operations. Significant data fiduciaries have additional duties, but all fiduciaries must comply with core obligations like consent and data principal rights.
What happens if I don't comply before enforcement begins?
The Data Protection Board can impose penalties of up to ₹250 crore for breaches. Non-compliance discovered after enforcement action can attract substantial penalties. Voluntary compliance before enforcement is strongly recommended to mitigate risk.
Do I need to appoint a Data Protection Officer?
Only if you are classified as a 'significant data fiduciary' under Section 10 of the Act. The central government will notify classes of fiduciaries considered significant based on volume, sensitivity, and risk. For others, it's good practice but not mandatory.
Can I transfer personal data outside India?
Yes, but subject to restrictions. The Act permits cross-border data transfers to notified countries, unless specifically restricted. The government has not yet issued the list of approved countries. Meanwhile, maintain existing safeguards.
What rights do data principals have under the DPDP Act?
Data principals (individuals whose data is processed) have the right to: access their data, seek correction and erasure, grievance redress, and nominate a representative to exercise these rights after their death or incapacity.
This article is general legal information, not legal advice. Consult a qualified advocate about your specific situation.
Advocate Sudhir Rao, Supreme Court of India