One of my clients recently had a case which I am explaining below and if you are stuck in such similar situation, here is what to do.
Note: Due to attorney-client privilege, I cannot disclose complete case details or identify the actual parties involved. However, I am sharing the essential facts and legal approach so that if you find yourself in a similar situation, you can understand the available solutions and legal remedies.
A young professional from Indore, whom we'll call Rohan Gupta, had recently purchased a new prepaid SIM from a Reliance Jio retail outlet in the Vijay Nagar locality around 8 February 2025. When he tried logging into Zomato using his newly activated number, the app opened directly into a complete stranger's existing account — full delivery address, saved contact details, and an order history going back months, all sitting right there on his screen.
Rohan was alarmed. And frankly, he had every reason to be. Not only could he read a stranger's personal information, he realised that if the previous account holder ever tried logging in again, they could potentially access his own saved data too. He contacted Zomato's customer support twice over the next three days. Both times, templated responses. No concrete resolution. A local advocate he consulted initially sent a routine complaint letter that Zomato's team simply ignored.
Then Rohan approached Advocate Sudhir Rao. The matter was handled with a focused strategy — a formal legal notice invoking specific provisions of the Information Technology Act, 2000 and the Consumer Protection Act, 2019, combined with a complaint to the relevant authorities. Zomato responded within ten days of the legal notice, immediately delinked the number, deleted the exposed data, and confirmed remediation steps in writing. Rohan also received a formal written apology acknowledging the breach. The structured, domain-specific approach made a clear difference where earlier attempts had not.
Advice in Such Cases
Consult with Lawyer: The very basic and important step to start is talk to Lawyer / advocate. You should not hesitate in paying his consultation fee i.e. might be in range of Rs. 10,000 to 50,000 depends case to case. He is helping you in this situation to come out. He is expert in the domain and can help you explain the procedure which you might have never explored. A good lawyer can get the issues resolved much faster than you think.
Document everything immediately: Take timestamped screenshots of the exposed account data, the app screen, and all customer support conversations. Don't log out yet — your screenshots are your primary evidence. Store them on a secure cloud backup right away.
Send a formal legal notice: A well-drafted legal notice to the platform's registered office citing specific statutory provisions tends to produce far faster results than repeated support tickets. Platforms have legal and compliance teams that treat formal notices very differently from consumer helpline complaints. And here's the thing — even one properly worded notice to the right desk can move a case forward in days when weeks of helpline calls achieved nothing.
File a complaint with CERT-In and the Data Protection authority: India's Computer Emergency Response Team (CERT-In) handles data breach complaints. You can also lodge a complaint under the Digital Personal Data Protection Act, 2023 framework as it operationalises. These parallel tracks increase pressure on the platform.
Cases involving digital data breaches and platform liability sit at the intersection of IT law, consumer law, and constitutional privacy rights. This is a specialised area — procedural nuances around evidence preservation, notice requirements, and the specific forums available are often unfamiliar to general practitioners. Engaging an advocate who regularly handles cyber and consumer matters typically leads to faster resolution and stronger outcomes.
Applicable Sections of Law
This matter is primarily civil and regulatory in nature, with consumer law and IT law as the dominant frameworks. The following provisions are directly applicable:
- Section 43A, Information Technology Act, 2000: Imposes liability on a body corporate that negligently handles sensitive personal data, entitling the affected person to claim compensation.
- Section 72A, Information Technology Act, 2000: Penalises disclosure of personal information in breach of a lawful contract or without consent, with imprisonment up to three years or fine up to Rs. 5 lakh, or both.
- Section 2(1)(g) read with Section 35, Consumer Protection Act, 2019: A platform's failure to protect a consumer's personal data constitutes a deficiency in service, giving grounds for complaint before the District Consumer Disputes Redressal Commission.
- Digital Personal Data Protection Act, 2023 (Sections 8 and 17): Places obligations on data fiduciaries (such as food delivery platforms) to ensure accuracy, security, and proper deletion of personal data, and grants data principals the right to seek correction and erasure.
Now, before you act, understand that these aren't overlapping provisions that cancel each other out. They can be invoked simultaneously across different forums, and a good lawyer will tell you exactly which combination works best for your facts.
Jurisdiction — Where to File the Case
Getting jurisdiction right matters. For a consumer complaint under the Consumer Protection Act, 2019, the District Consumer Disputes Redressal Commission has jurisdiction where the complainant ordinarily resides or carries on business, or where the service was availed — making your home district the appropriate forum in most cases. Pecuniary jurisdiction for claims up to Rs. 50 lakh lies with the District Commission. For IT Act compensation claims under Section 43A, a civil suit in the District Court of the complainant's jurisdiction is maintainable. A complaint to CERT-In can be filed online regardless of location. A filing in the wrong forum can lead to dismissal on technical grounds and lost time — don't let that happen over something avoidable.
Limitation Period
Don't delay. Under the Limitation Act, 1963, a consumer complaint must ordinarily be filed within two years from the date on which the cause of action arose — in this case, the date you discovered the data exposure. Under Section 69 of the Consumer Protection Act, 2019, the Commission may condone delay if sufficient cause is shown, but relying on condonation is risky. For civil suits under the IT Act, the standard three-year limitation period under Article 113 of the Limitation Act applies. The clock starts from the date of discovery of the breach. Evidence degrades, platform data gets overwritten, and limitation defences become harder to defeat as time passes.
Interim Reliefs Available
Interim reliefs can be critical in data privacy matters. Under Order 39 Rule 1 of the Code of Civil Procedure, 1908, a court may grant a temporary injunction directing the platform to immediately delink the number and freeze any further processing of the exposed data. Where there's a risk of dissemination of the data to third parties, an urgent status quo order can be sought. Under the Specific Relief Act, 1963, a mandatory injunction can be sought compelling the platform to delete the wrongfully retained data. Make no mistake, these interim orders carry immediate practical effect and often bring the opposite party to the negotiating table long before a full hearing on merits takes place.
If You Are the Victim
- Screenshot everything first: Capture all visible personal data, order history screens, and the app's account settings page with date and time visible. Do this before the platform resolves or removes anything.
- File a formal written complaint with the platform's Grievance Officer: Under Rule 4 of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, significant platforms are required to appoint a Grievance Officer. Escalate directly to them in writing — email or registered post.
- File a complaint with CERT-In: Report the incident at incident@cert-in.org.in. Keep the acknowledgement number.
- Consider a consumer complaint: If the platform fails to respond within 30 days of your grievance, you have strong grounds to approach the District Consumer Disputes Redressal Commission.
- Consult a specialised advocate promptly: A lawyer familiar with IT Act and consumer law can structure your case across multiple forums simultaneously for maximum effect.
Documents You Must Keep Ready
- Aadhaar card and PAN card (identity proof)
- Copy of SIM purchase receipt or activation confirmation message from the telecom operator
- Timestamped screenshots of the exposed Zomato account, showing name, address, and order history
- All customer support chat transcripts and email exchanges with the platform
- Screen recording (if possible) of the unauthorised account access
- Written complaint copy sent to the platform's Grievance Officer with proof of delivery
- CERT-In complaint acknowledgement
- Any response or lack of response from the platform within the statutory period
What Evidence Is Required?
- Screenshots with metadata: Primary evidence of the data exposure — ensure timestamps are visible and screenshots are stored in original format, not compressed.
- Screen recording: Stronger than static screenshots as it demonstrates live access to the account.
- Telecom operator's records: Confirmation that the mobile number was freshly allocated to you and was not previously active in your name — obtainable from Reliance Jio, Airtel, Vi, or BSNL customer records.
- Platform's privacy policy: A downloaded copy of Zomato's published privacy policy is secondary evidence establishing the platform's own stated data protection obligations.
- Email communication trail: All correspondence with the platform's support and Grievance Officer, showing dates and failure to act.
- Expert certificate under Section 79A, IT Act: In formal proceedings, a certificate from an empanelled examiner of electronic evidence may be needed to authenticate digital evidence.
How Courts Typically Approach Such Cases
Consumer Commissions across India have taken an increasingly firm view on data negligence by digital platforms, particularly after the Supreme Court's recognition of privacy as a fundamental right in Justice K.S. Puttaswamy (Retd.) v. Union of India, 2017. Courts look at whether the platform had adequate technical and organisational safeguards, whether it acted promptly upon notice, and what the nature of the exposed data was. A failure to delink a mobile number upon reallocation is typically treated as a systemic deficiency rather than an isolated error, which tends to attract heavier scrutiny. Compensation awards in such cases range from nominal to substantial depending on the sensitivity of exposed data and the platform's conduct after being notified.
Timeline of Legal Process
- Week 1-2: Gather evidence, send formal legal notice to platform's Grievance Officer and registered office — many platforms resolve at this stage.
- Week 3-4: If no resolution, file consumer complaint before District Consumer Disputes Redressal Commission or civil suit in District Court.
- Month 1-2: Commission issues notice to platform; platform files written response (typically 30-45 days allowed).
- Month 2-4: Evidence stage — both sides submit documents; interim relief applications heard if filed.
- Month 4-8: Arguments before the Commission or Court.
- Month 8-14: Order / judgment pronounced.
- If appealed: State Consumer Disputes Redressal Commission hears appeals — add 6-12 months.
- Execution: If platform fails to comply with the order, execution proceedings may be initiated.
Understanding the Costs
The total cost of a matter like this varies significantly from one case to the next — it depends on the complexity of the dispute, the forum involved, the number of hearings, and the specific facts of your situation. There is no single fixed figure that applies to everyone.
A professional advocate can give you an accurate estimate only after reviewing all your facts and documents in a consultation.
Can the Matter Be Settled Out of Court?
Yes. And in many cases, that's the preferred route. Platforms like large food delivery aggregators have legal and compliance teams that respond quickly once formal legal proceedings are initiated. Mediation and conciliation are available under Section 37 of the Consumer Protection Act, 2019, and the Commission may refer the matter to mediation before proceeding to adjudication. A negotiated settlement can include immediate data deletion, a formal written apology, and monetary compensation — often within weeks. Lok Adalat is also available for pre-litigation settlement of consumer disputes under the Legal Services Authorities Act, 1987, and awards passed by Lok Adalat are final and non-appealable. Settlement is advisable where the primary goal is quick remediation rather than a precedent-setting judgment.
Common Mistakes People Make
- Logging out of the exposed account immediately: This destroys your primary evidence. Always capture all visible data first before taking any action on the app.
- Relying only on support tickets: Customer helplines aren't designed to handle legal violations. Sending a legally sound notice to the Grievance Officer or registered office is a fundamentally different step that platforms treat far more seriously.
- Posting screenshots on social media: Sharing another person's private data publicly — even to highlight a platform's negligence — can itself attract liability under Section 72A of the IT Act and constitute a privacy violation of the third party whose data was exposed.
- Waiting too long before acting: Platforms regularly purge logs, overwrite data, and update systems. Evidence that exists today may be irretrievable in four weeks.
- Engaging an advocate without relevant domain experience: Data privacy and consumer-tech disputes involve specific procedural steps — evidence preservation protocols, Grievance Officer escalations, CERT-In filings, and the interplay between IT Act and