One of my clients recently had a case which I am explaining below and if you are stuck in such similar situation, here is what to do.
Note: Due to attorney-client privilege, I cannot disclose complete case details or identify the actual parties involved. However, I am sharing the essential facts and legal approach so that if you find yourself in a similar situation, you can understand the available solutions and legal remedies.
Early March 2025. A mid-sized software services firm out of Pune — roughly 60 employees, predominantly B2B clients — reached out after their internal compliance officer had spent several months trying to build a DPDP framework entirely from scratch. The compliance officer, a capable professional, had read the Digital Personal Data Protection Act, 2023 and the draft Rules carefully. But the firm's efforts had stalled. They'd drafted privacy policies and updated vendor contracts. That was it. Their consent mechanisms still defaulted to pre-ticked boxes. Their breach escalation process was informal — basically a WhatsApp message to the CTO. And they had no clarity at all on when "purpose limitation" actually triggered data erasure obligations.
An earlier consultant the company had engaged, experienced in general corporate advisory, had recommended largely documentation-based changes. Reasonable on paper, but incomplete in practice. And here's the thing — the gap between what the Act requires and what a policy document says is wide, and that gap is exactly where regulatory exposure sits.
When the matter came to us, the approach shifted. We mapped data flows operationally, not just on paper. Consent collection interfaces were reviewed against the "free, specific, informed, unambiguous" standard under Section 6 of the DPDP Act. Breach notification timelines were built into internal SOPs with hard escalation deadlines, aligned with what the Data Protection Board framework is expected to demand. Data retention schedules were tied directly to stated processing purposes — not the general "we keep data for 7 years" blanket policies that were so common a few years ago and are now plainly indefensible. The firm came out of the exercise with a defensible, audit-ready compliance posture. Critically, they understood what they were doing and why — not just what documents they had signed.
Advice in Such Cases
Consult with Lawyer: The very basic and important step to start is talk to Lawyer / advocate. You should not hesitate in paying his consultation fee i.e. might be in range of Rs. 10,000 to 50,000 depends case to case. He is helping you in this situation to come out. He is expert in the domain and can help you explain the procedure which you might have never explored. A good lawyer can get the issues resolved much faster than you think.
Don't treat DPDP compliance as a one-time exercise. The Act creates ongoing obligations — consent must be refreshed when processing purposes change, and erasure obligations trigger automatically once the stated purpose is fulfilled. Policies drafted once and forgotten won't hold up to scrutiny.
Involve your technical team early. Most DPDP obligations — breach notification, data erasure, consent logging — require system-level changes, not just contractual language. Lawyers and developers need to work together from the start, not in sequence. Now, before you act, make sure your tech lead is in the room from day one, not brought in after the legal drafting is done.
This area of law sits at the intersection of data architecture, contract drafting, regulatory procedure, and enforcement risk. General corporate practitioners may not be fully familiar with the evidentiary and operational nuances involved. Engaging an advocate who regularly advises on data protection and technology law typically produces faster, more defensible outcomes.
Applicable Sections of Law
The primary statute governing this matter is the Digital Personal Data Protection Act, 2023. Key provisions include:
- Section 4 — Grounds for processing personal data; lawfulness of processing limited to consent and legitimate uses.
- Section 6 — Consent requirements: must be free, specific, informed, unconditional, and unambiguous; expressed through a clear affirmative action.
- Section 8 — Obligations of Data Fiduciaries, including accuracy, completeness, and security of personal data.
- Section 9 — Retention and erasure: personal data must be erased once the purpose for which consent was given is no longer being served.
- Section 66A of the Information Technology Act, 2000 (as read with IT (Amendment) Act, 2008) and the IT (Reasonable Security Practices and Procedures) Rules, 2011 continue to apply to the extent not inconsistent with the DPDP Act, particularly for defining "reasonable security safeguards."
Frankly, companies that treat these provisions as a checklist rather than as operational mandates are setting themselves up for trouble once the Board starts functioning at full capacity.
Jurisdiction — Where to File the Case
Jurisdiction matters. Don't file in the wrong forum and lose six months learning that lesson. Enforcement and adjudication under the DPDP Act, 2023 vest primarily in the Data Protection Board of India, once fully constituted. The Board has the power to inquire into personal data breaches and non-compliance, impose financial penalties, and direct remedial action. Appeals from Board orders lie before the Telecom Disputes Settlement and Appellate Tribunal (TDSAT), and thereafter to the High Court on questions of law. For matters involving civil liability or contractual disputes arising from data processing agreements, territorial jurisdiction follows ordinary CPC principles — the court within whose jurisdiction the defendant resides or the cause of action arises. Filing before the wrong forum can cause costly delays, and that's not a technicality you can talk your way around later.
Limitation Period
The DPDP Act, 2023 does not yet specify a standalone limitation period for complaints before the Data Protection Board. Until Rules provide otherwise, general principles under the Limitation Act, 1963 apply to civil claims arising from data misuse — typically three years from the date the cause of action arises (Article 113, Limitation Act). For contractual disputes involving data processing agreements, the standard three-year limitation under Article 55 applies from the date of breach. Missing limitation is fatal to a claim. Condonation of delay under Section 5 of the Limitation Act is available, but you'll need to demonstrate sufficient cause before the forum — and that's a harder argument than most people expect.
Interim Reliefs Available
Speed can make all the difference here. Where a Data Fiduciary's non-compliance causes ongoing or imminent harm — continued processing after withdrawal of consent, or failure to erase data — a Data Principal may approach the Data Protection Board for urgent directions once it's operational. Before the Board is constituted, civil courts retain jurisdiction to grant injunctions under Order 39 Rules 1 and 2 of the Code of Civil Procedure, 1908 restraining unlawful data processing. Attachment before judgment under Order 38 CPC may apply where pecuniary claims arise from data misuse. Status quo orders are particularly useful in cases where erased or altered data would destroy evidence. Make no mistake, interim relief secured early can significantly shape the eventual outcome — don't wait until the damage compounds.
If You Are the Victim
- Document every instance of data misuse or non-compliance — screenshots, email trails, consent records, or the absence of them — at the earliest possible point.
- Send a formal written notice to the Data Fiduciary demanding compliance, erasure, or breach disclosure, as the case may be. This creates a paper trail and often triggers faster resolution.
- File a complaint with the Data Protection Board of India once it is operational; track the Ministry of Electronics and Information Technology (MeitY) portal for updates on Board constitution.
- If financial harm results from the breach, consider a parallel civil suit for damages under general tort and contract principles before the appropriate civil court.
- Retain counsel early — the procedural interplay between the Board, TDSAT, and civil courts is not straightforward, and procedural missteps can affect admissibility and timing of relief.
Documents You Must Keep Ready
- Identity proof of the Data Principal or authorized representative (Aadhaar, PAN card)
- Copies of consent notices and consent records provided by or to the Data Fiduciary
- Data processing agreements, vendor contracts, or terms of service accepted
- Records of the erasure or correction request sent and any response received
- Breach notification received (or evidence that none was received when one was required)
- Bank statements or financial records showing harm arising from the data breach
- Screenshots or logs showing ongoing or unauthorized data processing
- Correspondence with the Data Fiduciary's grievance officer, if any
What Evidence Is Required?
- Consent records: Proof of what consent was given, when, and for what specific purpose — or proof that no valid consent was obtained at all.
- Processing logs: System-generated records showing what personal data was processed, by whom, and when (primary evidence under the Indian Evidence Act, 1872 / Bharatiya Sakshya Adhiniyam, 2023).
- Breach records: Internal incident reports, server logs, or forensic reports evidencing a data breach event.
- Communications: Emails, notices, tickets, or chat logs between the Data Principal and the Data Fiduciary's grievance mechanism.
- Expert evidence: Cybersecurity expert affidavits on the adequacy (or inadequacy) of security safeguards, particularly relevant when disputing "reasonable security" compliance.
- Comparative standards: ISO 27001 certifications, SOC 2 reports, or CERT-In advisories used as secondary evidence of the applicable security benchmark.
How Courts Typically Approach Such Cases
Data protection litigation in India is still young. Courts have historically relied on decisions like Justice K.S. Puttaswamy (Retd.) v. Union of India, 2017, affirming privacy as a fundamental right, as the constitutional anchor. But regulatory enforcement under the DPDP Act will primarily flow through the Data Protection Board, not civil courts. Courts are likely to take a purposive approach to interpretation, reading consent and erasure obligations broadly in favour of Data Principals. At the same time, courts have consistently required precise pleading and documentary foundation. Vague complaints about "data misuse" without specific evidence of harm are unlikely to attract strong relief — and rightly so.
Timeline of Legal Process
- Step 1 — Internal grievance: File complaint with Data Fiduciary's designated grievance officer. Response expected within the timeline prescribed under Rules (expected to be 30–45 days once notified). Duration: 1–2 months.
- Step 2 — Data Protection Board complaint: File complaint before the Board post constitution. Board to acknowledge and initiate inquiry. Duration: 2–4 months for initial proceedings.
- Step 3 — Board inquiry and hearing: Evidence filed, opportunity to be heard granted to both parties. Duration: 3–6 months depending on complexity.
- Step 4 — Board order: Directions for compliance, penalty imposition, or both. Duration: 6–12 months from filing.
- Step 5 — Appeal before TDSAT: If either party challenges the Board's order. Duration: 6–18 months.
- Step 6 — High Court / Supreme Court: Only on questions of law. Duration: variable.
Understanding the Costs
The total cost of a matter like this varies significantly from one case to the next — it depends on the complexity of the dispute, the forum involved, the number of hearings, and the specific facts of your situation. There is no single fixed figure that applies to everyone.
A professional advocate can give you an accurate estimate only after reviewing all your facts and documents in a consultation.
Can the Matter Be Settled Out of Court?
Yes. And it often should be explored first. Where a Data Fiduciary has failed to erase data or address a consent grievance, a formal legal notice frequently produces resolution without adjudication — companies are acutely sensitive to regulatory exposure and reputational risk once formal proceedings are threatened. Mediation under Section 89 of the Code of Civil Procedure, 1908 is available for civil claims arising from data breaches. Lok Adalats can take up pre-litigation matters involving financial compensation claims. The DPDP Act itself envisages a consent-based resolution pathway before the Board escalates to formal penalty proceedings. Settlement is particularly advisable where the primary goal is data erasure or correction rather than financial penalty — quick resolution protects both parties, and frankly, most companies would rather fix the problem quietly than fight it publicly.
Common Mistakes People Make
- Treating compliance as purely a documentation exercise: Drafting a privacy policy does not, by itself, satisfy DPDP obligations. Consent must be operationally collected, logged, and withdrawable — and that requires technical implementation, not just policy language.
- Using pre-ticked consent boxes or bundled consents: Section 6 of the DPDP Act is unambiguous — consent must be a clear affirmative action. Pre-ticked boxes fail this test and expose Data Fiduciaries to significant penalty risk.
- Ignoring breach notification obligations: Many companies still have no defined internal SOP for breach detection and escalation. Delayed notification — even by a few days — can constitute a separate compliance failure independent of the breach itself.
- Applying blanket data retention periods without purpose linkage: