Disclaimer

This website has been designed only for the purposes of dissemination of basic information on ILRF; information which is otherwise available on the internet, various public platforms and social media. The contents of this website have been collated from external sources believed to be reliable; however, the India Legal Research Foundation expressly disclaims any and all liability for the accuracy, completeness, or veracity of the information contained herein. ILRF is not responsible for any reliance that a reader places on such information and shall not be liable for any loss or damage caused due to any inaccuracy in or exclusion of any information, or its interpretation thereof. Readers are advised to confirm the veracity of the same from independent and expert sources.

This website is not an attempt to advertise or solicit clients, and does not seek to create or invite any lawyer-client relationship. The links provided on this website are to facilitate access to basic information on ILRF, and to share the various thought leadership initiatives undertaken by it. The content herein or on such links should not be construed as a legal reference or legal advice. Readers are advised not to act on any information contained herein or on the links and should refer to legal counsels and experts in their respective jurisdictions for further information and to determine its impact.

ILRF advises against the use of the communication platform provided on this website for exchange of any confidential, business or politically sensitive information. User is requested to use his or her judgment and exchange of any such information shall be solely at the user’s risk.

ILRF uses cookies on its website to improve its usability. This helps us in providing a good user experience and to also help in improving our website. By continuing to use our website without changing your privacy settings, you agree to use our cookies.

ILRF Logo
ILRF Logo
Back to Research

DPDP ACT: Digital Inequality And Exclusions

By Sanjeevini Singh & Sonal Rai

2 Sept 20267 min read
Cover image for DPDP ACT: Digital Inequality And Exclusions

The proliferation of digital services in India has rendered the collection and processing of personal data indispensable to modern life. The Digital Personal Data Protection Act, 2023 (“DPDP Act”) seeks to govern such processing and safeguard the rights of data principals. However, rights without remedies are of little essence, and the present analysis explores the lacunae in the DPDP Act’s remedial framework, particularly with respect to compensation for individuals subjected to unlawful data processing.

A pertinent issue emerges from the very omission of the compensation mechanism under the DPDP Act, especially in light of the repeal of Section 43A of the Information Technology Act, 2000. Although an exorbitant penalty is contemplated against the entities found responsible for causing harm to the data principals, the latter remains deprived of a recourse for claiming compensation for the damage suffered. This provision, as shall be argued herewith, contravenes the principle of ubi jus ibi remedium, particularly when juxtaposed with a similar provision, i.e., Article 82 of the GDPR, which explicitly envisages the right to compensation. Section 15 of the DPDP Act, which criminalises false or malicious complaints, would also be pertinent in this context. This article appraises the aforesaid statutory lacunae from the standpoint of an individual seeking remedies under the DPDP Act and highlights the advantages of the GDPR framework.

I. Section 7: Limits and Scope of Deemed Consent

Under Section 7 of DPDP Act 2023, personal data may be processed without the data principal's knowledge or consent in a limited set of circumstances: where the data is voluntarily shared with a data fiduciary for a particular purpose, without coercion or compulsion; where processing is carried out for employment-related functions, such as providing employee benefits or protecting the organisation from loss or liability; where it is necessary to comply with a legal obligation arising from a court order, decree, or statute; where it is required to respond to a medical, health, or safety emergency; and where the government processes data in the discharge of its functions, such as granting subsidies or permits.

II. Contrasting Remedies: The DPDP Act and the GDPR Model

The most notable difference between the Indian and the EU law is who benefits from the violation. According to the DPDP Act, Section 33, the Data Protection Board of India may impose a financial penalty on the data fiduciary if, after an inquiry, the Board determines that the violation was significant. Section 34 of the DPDP Act notes that all fines collected on the basis of Section 33 must go to the Consolidated Fund of India. Thus, in India, if an organisation violates the data protection regulations and pays the fine, this sum is transferred to the state budget. It has no correlation to the compensation for the affected data principals: the data subject has no right to claim any part of the penalty. By contrast, Section 43A of the Information Technology Act, which came into force in 2000, implies that the data subject could claim compensation for the damage suffered due to the organisation’s negligence, not the state's. Meanwhile, the GDPR liability principle also prioritises the data subject and states in Article 82 that any person who has suffered materially or immaterially from an infringement of his or her rights has the right to claim compensation from the controller or processor. The Court of Justice of the European Union ruled in Case C-529/185 (PJ v European Union Intellectual Property Office, 2022) that even if an organisation demonstrates that it was not at fault in the infringement, the liability for damages is mandatory. However, in terms of evidence, the CJEU noted that for the sake of proportionality, it should be up to the data subject to prove that the processor’s fault caused the damage. Nevertheless, in terms of compensation, the violation of data protection regulations is no less serious than any other damage. As indicated in the C-529/18 ruling, Article 82 does not stipulate any threshold for compensation: it suffices to prove that damage occurred, but there is no specific severity level that should be met.

The difference between the GDPR and the DPDP Act proves that EU law treats the data subject as a rights-holder whose violations can be claimed directly, whereas, in India, the data principal is a complainant against the data fiduciary. Section 33 of the DPDP Act proves that the data subject is not a “civil wrongdoer” as the violation of the processing rules is not a wrong towards the data subject. Even though Section 33(4) stipulates that the payment of the penalty cannot absolve the fiduciary from liability, the data principal will still have to take legal action against the organisation in court to secure compensation.

This process is more resource-intensive than the process proposed by the Data Protection Board of India. The Government of India by introducing the right to a state-budget penalty, the Government of India has established a framework in which the data subject will not have direct recourse to claim damages suffered. Instead, the data principal will have to rely on the data protection authority to bring legal action against the organisation in the data protection court, which has already opted for the online dispute settlement process to make the procedure less time- and resource-consuming. Therefore, compared to the EU model, the Indian data protection rules lack civil liability in terms of compensation for the damage suffered by the data principal due to the data fiduciary’s violation.

III. Reorienting the DPDP Act: Prioritising Victim Rights Over State Enforcement

It is advisable to introduce liability and direct compensation options like GDPR Article 2 for data processing fraud, or Section 43A in the Act, to ensure that those who have been hurt by unlawful processing of data receive compensation instead. To safeguard vulnerable individuals from costly fines, Section 15 should provide safe-harbour protections to differentiate between bad-faith complaints and innocent complaints caused by inadequate knowledge of tools or the law. To prevent government control, establish an independent Data Protection Board with multiple stakeholders and a selection panel to manage appointments and conditions. Limit major government exemptions for security by ensuring courts review them and grant them only when necessary and reasonable.

Puttaswamy Judgment (Justice K.S. Puttaswamy (Retd.) v. Union of India, 2017) quotes: “Employ a 'Legitimate Interest' test and have data fiduciaries conduct 'legitimate interests assessments' to ensure that the processing without consent under Section 7 does not undermine people's rights or expectations. Explain the significance of employment purposes in preventing excessive monitoring and unrelated program data.’’

IV. Conclusion: Access to Justice

The DPDP Act of 2023 acknowledges the existence of the right to grievance redressal, but one must examine if the Act caters to the requirement of a wider understanding of the access to justice available to the underprivileged data principals. The Act may have provided for grievance redressal in Section 13, but it is not made clear that such provisions shall be necessary to enable an economically or digitally poor data principal to advocate for the enforcement of his or her rights. This is unfortunate because this would imply that the data principal is suffering from inadequate legal knowledge, financial ability to obtain legal services as well as having no digital knowledge whatsoever. Furthermore, the Act is directed at regulating the duties of Data Fiduciaries and creating institutions for the enforcement of the duties of Data Fiduciaries, which means that there is no victim-centric approach in the Act directed toward the compensation of the data principals. Although Section 15 requires Data Principals to ensure that the grievance registered is not false or frivolous, this provision appears to pose a challenge for underprivileged Data Principals, as it might prevent them from availing of their remedy. Therefore, the key issue that arises in this background is whether the DPDP Act, 2023 provides adequate access to justice to data principals in terms of availability, accessibility, affordability, and efficacy while balancing the need to deter misuse of the grievance redressal mechanisms. In that regard, it is for the DPDP Act, 2023 to be evaluated if its grievance redressal mechanisms do satisfy the substantive aspects of access to justice for the underprivileged data principals.

India Legal Research

Foundation

ILRF

An independent legal research foundation strengthening access to justice, dispute resolution, and constitutional governance in India.

+91 8377009673
contact@ilrf.in
A-9, Block A, Sector 68, Noida,
Basi Bahuddin Nagar, Uttar Pradesh 201309

Initiatives

Company

ISSN 3139-7107 (Online)

© 2026 Indian Legal Research Foundation.

All rights reserved.