Tuesday, July 28


Varun Singh, founder, Foresight Law Offices

Up until recently, Indian companies have been content to relegate data privacy to the back office, leaving it in the hands of their IT staff, compliance officers, or outside counsel. The 2023 Digital Personal Data Protection (DPDP) Act has put an end to that way of doing things. But one cannot view this change in a vacuum; its origins are constitutional. You can trace them back to the Supreme Court’s 2017 ruling in K.S. Puttaswamy (Retd.) v. Union of India. The landmark judgement made it clear that privacy is a fundamental right under Article 21. What the DPDP Act does is give effect to that principle, turning what was once a legal abstraction into something the boardroom has to answer for.

Delegating Data Protection: No longer an option?

One could say the DPDP Act’s defining characteristic is putting the onus of accountability squarely on the Data Fiduciary, the party that decides how and why personal data is to be processed. In that respect, it is in line with global regulations. Take Article 24 of the EU’s Data Regulations, for instance, which makes data controllers answerable squarely, whether or not they outsource.

The provisions of the DPDP Act are quite stringent, too. If you do not put in place reasonable security measures, Section 33 of the DPDP Act (along with its Schedule) will see you face fines as high as Rs 250 crore. Then there is the matter of corporate governance. This dovetails with what Section 166 of the Companies Act, 2013 requires of directors in terms of due care and the protection of the interests of the company and its stakeholders.

Real Risks: Beyond Monetary Penalties

The Rs 250 crore fine often found its way into headlines, but it is not where regulatory matters usually conclude. A look at global regulators and the Data Safety provisions shows that the damage to one’s reputation can be far more onerous than the financial sanction. British Airways and Marriott International are cases in point: their data breaches have led to protracted litigation, a loss of customers, and lingering scrutiny from investors. Then there are the disclosure issues for India’s listed firms.

Under the 2015 LODR Regulations put in place by the SEBI, an enforcement action has to be considered if a breach stands to have a material impact on the company’s finances or standing. And in the realm of M&A, due diligence now routinely covers data governance. If privacy controls are found wanting, it can put a dent in transaction valuations and complicate everything from indemnity discussions to representations and warranties, with deal completion timelines no exception.

Data Fiduciary: Significant Strategic Challenge

There is no provision in the DPDP Act more strategically vital than Section 10, which authorises the Government to designate entities as Significant Data Fiduciaries (SDFs). In making that call, they will consider a number of factors: the scale and sensitivity of the personal data being handled, any risk to individuals’ rights, and the implications for national interests. Once designated, an SDF must meet certain obligations, including appointing Data Protection Officers and conducting independent audits and Data Protection Impact Assessments. It is a risk-based approach to governance, not unlike the GDPR or other well-established privacy frameworks.

For some organisations, the temptation might be to put off building their governance infrastructure until the formal designation comes through. But that could put them under considerable operational strain. If you look at the regulatory track record in any sector, you will see that a compliance programme is much better served by being implemented proactively.

Navigating Cross-Border Data Responsibilities

With India’s digital economy ever more enmeshed in global operations, cross-border data governance has become a boardroom matter. The DPDP Act is clear on allowing international transfers, barring those to certain restricted jurisdictions, but that is not the only consideration. Organisations must also contend with the sectoral demands of regulators such as the RBI, the IRDAI, and the National Digital Health Mission framework.

For Global Capability Centres (GCCs), the situation is especially tricky. The same GCC can be a Data Fiduciary for the operational and employee data it holds in India and, at the same time, a processor for its parent company abroad. You need to design your governance with care in such a dual capacity, since legal liability is not always a function of reporting lines. The RBI made much of this in 2018 with its Payment System Data Storage Directions, underscoring the need for accountability and control over key data assets and putting the spotlight on issues of localisation and sovereignty.

Defensibility Is the New Compliance

The DPDP Act repeatedly refers to “reasonable security safeguards” but avoids prescribing an exhaustive checklist. You will find this approach consistent with an old adage of Indian law: that an organisation is expected to take reasonable measures to manage risk, commensurate with its size and the responsibilities it bears. The Supreme Court was clear in the case of its ruling in the Puttaswamy case: privacy protection is not a matter of mere legal compliance but demands robust safeguards within the organisation. So, one can expect regulators to be less concerned with a company’s good intentions and more with what it can put forward as evidence of its actions. Should there be a data breach, they will want to see whether risks were properly appraised, whether staff have been trained, whether vendors have been vetted, whether consent records are kept, and whether policies on data retention or deletion are in place. It is only to be expected, given Section 134(5) of the Companies Act, 2013, which places the onus on directors to have effective internal controls in place. In a regulatory investigation, documentation often becomes the strongest defence. If an action was not documented, it becomes significantly harder to demonstrate that it occurred.

What Boards Should Be Doing Today?

It is incumbent on boards to view DPDP compliance as an ongoing matter of governance, not some one-off legal exercise. That is the way it should be done, in keeping with the corporate governance tenets set out in the Companies Act, 2013 and the SEBI framework. To that end, a thorough data-mapping exercise ought to be put at the top of the agenda so that one can analyse what personal data is being gathered, where it sits, how it flows through your systems, and who among third parties can access it. One would do well to re-examine vendor governance for any regulatory exposure or contractual liability. And if your data footprint indicates you are likely to be classed as a Significant Data Fiduciary down the line, put the money into proper accountability and audit readiness now. Do not wait. As regulators around the world have shown, it is far cheaper to be prepared than to put things right after the fact.

Conclusion: A Boardroom Issue, Not an IT Issue

It is time for boards to view DPDP compliance as a matter of continuous governance, not some one-off legal or IT formality. Firms can begin by getting a handle on their data landscape: where does the personal data go, how does it flow between systems, what is being collected, and who from the third party has access? Then have a look at vendors to make sure accountability and contracts are aligned with the real regulatory risks. And if the data footprint is such that they may be deemed a Significant Data Fiduciary, do not wait for an official notification to implement the necessary internal controls and audit readiness. The world over, regulations make it clear that it is much cheaper to build out compliance capabilities in advance than to put out fires after a breach or some kind of regulatory action.

(Views are personal)

  • Published On Jul 28, 2026 at 12:26 PM IST

Join the community of 2M+ industry professionals.

Subscribe to Newsletter to get latest insights & analysis in your inbox.

All about ETLegalWorld industry right on your smartphone!




Source link

Share.
Leave A Reply

Exit mobile version