DPDP ACT: Digital Inequality And Exclusions
By Sanjeevini Singh & Sonal Rai

The proliferation of digital services in India has rendered the collection and processing of personal data indispensable to modern life. The Digital Personal Data Protection Act, 2023 (“DPDP Act”) seeks to govern such processing and safeguard the rights of data principals. However, rights without remedies are of little essence, and the present analysis explores the lacunae in the DPDP Act’s remedial framework, particularly with respect to compensation for individuals subjected to unlawful data processing.
A pertinent issue emerges from the very omission of the compensation mechanism under the DPDP Act, especially in light of the repeal of Section 43A of the Information Technology Act, 2000. Although an exorbitant penalty is contemplated against the entities found responsible for causing harm to the data principals, the latter remains deprived of a recourse for claiming compensation for the damage suffered. This provision, as shall be argued herewith, contravenes the principle of ubi jus ibi remedium, particularly when juxtaposed with a similar provision, i.e., Article 82 of the GDPR, which explicitly envisages the right to compensation. Section 15 of the DPDP Act, which criminalises false or malicious complaints, would also be pertinent in this context. This article appraises the aforesaid statutory lacunae from the standpoint of an individual seeking remedies under the DPDP Act and highlights the advantages of the GDPR framework.
I. Section 7: Limits and Scope of Deemed Consent
Under Section 7 of DPDP Act 2023, personal data may be processed without the data principal's knowledge or consent in a limited set of circumstances: where the data is voluntarily shared with a data fiduciary for a particular purpose, without coercion or compulsion; where processing is carried out for employment-related functions, such as providing employee benefits or protecting the organisation from loss or liability; where it is necessary to comply with a legal obligation arising from a court order, decree, or statute; where it is required to respond to a medical, health, or safety emergency; and where the government processes data in the discharge of its functions, such as granting subsidies or permits.
II. Contrasting Remedies: The DPDP Act and the GDPR Model
The most notable difference between the Indian and the EU law is who benefits from the violation. According to the DPDP Act, Section 33, the Data Protection Board of India may impose a financial penalty on the data fiduciary if, after an inquiry, the Board determines that the violation was significant. Section 34 of the DPDP Act notes that all fines collected on the basis of Section 33 must go to the Consolidated Fund of India. Thus, in India, if an organisation violates the data protection regulations and pays the fine, this sum is transferred to the state budget. It has no correlation to the compensation for the affected data principals: the data subject has no right to claim any part of the penalty. By contrast, Section 43A of the Information Technology Act, which came into force in 2000, implies that the data subject could claim compensation for the damage suffered due to the organisation’s negligence, not the state's. Meanwhile, the GDPR liability principle also prioritises the data subject and states in Article 82 that any person who has suffered materially or immaterially from an infringement of his or her rights has the right to claim compensation from the controller or processor. The Court of Justice of the European Union ruled in Case C-529/185 (PJ v European Union Intellectual Property Office, 2022) that even if an organisation demonstrates that it was not at fault in the infringement, the liability for damages is mandatory. However, in terms of evidence, the CJEU noted that for the sake of proportionality, it should be up to the data subject to prove that the processor’s fault caused the damage. Nevertheless, in terms of compensation, the violation of data protection regulations is no less serious than any other damage. As indicated in the C-529/18 ruling, Article 82 does not stipulate any threshold for compensation: it suffices to prove that damage occurred, but there is no specific severity level that should be met.
The difference between the GDPR and the DPDP Act proves that EU law treats the data subject as a rights-holder whose violations can be claimed directly, whereas, in India, the data principal is a complainant against the data fiduciary. Section 33 of the DPDP Act proves that the data subject is not a “civil wrongdoer” as the violation of the processing rules is not a wrong towards the data subject. Even though Section 33(4) stipulates that the payment of the penalty cannot absolve the fiduciary from liability, the data principal will still have to take legal action against the organisation in court to secure compensation.
This process is more resource-intensive than the process proposed by the Data Protection Board of India. The Government of India by introducing the right to a state-budget penalty, the Government of India has established a framework in which the data subject will not have direct recourse to claim damages suffered. Instead, the data principal will have to rely on the data protection authority to bring legal action against the organisation in the data protection court, which has already opted for the online dispute settlement process to make the procedure less time- and resource-consuming. Therefore, compared to the EU model, the Indian data protection rules lack civil liability in terms of compensation for the damage suffered by the data principal due to the data fiduciary’s violation.
III. Reorienting the DPDP Act: Prioritising Victim Rights Over State Enforcement
It is advisable to introduce liability and direct compensation options like GDPR Article 2 for data processing fraud, or Section 43A in the Act, to ensure that those who have been hurt by unlawful processing of data receive compensation instead. To safeguard vulnerable individuals from costly fines, Section 15 should provide safe-harbour protections to differentiate between bad-faith complaints and innocent complaints caused by inadequate knowledge of tools or the law. To prevent government control, establish an independent Data Protection Board with multiple stakeholders and a selection panel to manage appointments and conditions. Limit major government exemptions for security by ensuring courts review them and grant them only when necessary and reasonable.
Puttaswamy Judgment (Justice K.S. Puttaswamy (Retd.) v. Union of India, 2017) quotes: “Employ a 'Legitimate Interest' test and have data fiduciaries conduct 'legitimate interests assessments' to ensure that the processing without consent under Section 7 does not undermine people's rights or expectations. Explain the significance of employment purposes in preventing excessive monitoring and unrelated program data.’’
IV. Conclusion: Access to Justice
The DPDP Act of 2023 acknowledges the existence of the right to grievance redressal, but one must examine if the Act caters to the requirement of a wider understanding of the access to justice available to the underprivileged data principals. The Act may have provided for grievance redressal in Section 13, but it is not made clear that such provisions shall be necessary to enable an economically or digitally poor data principal to advocate for the enforcement of his or her rights. This is unfortunate because this would imply that the data principal is suffering from inadequate legal knowledge, financial ability to obtain legal services as well as having no digital knowledge whatsoever. Furthermore, the Act is directed at regulating the duties of Data Fiduciaries and creating institutions for the enforcement of the duties of Data Fiduciaries, which means that there is no victim-centric approach in the Act directed toward the compensation of the data principals. Although Section 15 requires Data Principals to ensure that the grievance registered is not false or frivolous, this provision appears to pose a challenge for underprivileged Data Principals, as it might prevent them from availing of their remedy. Therefore, the key issue that arises in this background is whether the DPDP Act, 2023 provides adequate access to justice to data principals in terms of availability, accessibility, affordability, and efficacy while balancing the need to deter misuse of the grievance redressal mechanisms. In that regard, it is for the DPDP Act, 2023 to be evaluated if its grievance redressal mechanisms do satisfy the substantive aspects of access to justice for the underprivileged data principals.
