4 min

DPDP Act Shields Directors from Personal Liability but Exposes Companies to INR 250 Crore Fines

A legal analysis clarifies that the DPDP Act 2023 holds the Data Fiduciary entity strictly liable for data breaches, omitting personal financial or criminal liability for corporate directors.

Written byVipul Abhishek· Former Advocate, Supreme Court of India

Last updated:

What happened

A legal analysis published by Mondaq confirms the Digital Personal Data Protection Act, 2023 restricts data breach liability exclusively to the Data Fiduciary. Directors face no personal liability. The Act contains no provision deeming key managerial personnel personally responsible for a company default. Monetary penalties for failing to take reasonable security safeguards reach INR 250 crore under Section 33 and the Schedule. The legislation creates no criminal offences. This design deliberately contrasts with older statutes like Section 85 of the Information Technology Act, which assign vicarious liability to company leadership.

Does the DPDP Act apply here?

The liability framework applies directly to any enterprise processing digital personal data within India under Section 3. For a large healthtech platform or hospital network, patient intake forms and diagnostic histories fall squarely under this scope. The law treats the corporate entity as the Data Fiduciary accountable for this information. Processing outside India also falls under the Act if connected to offering goods or services to Data Principals in India. Whether the data originates in a digital format or is digitised subsequently, the company bears the entire compliance burden.

Legal implications under DPDP

Consent is the primary basis for processing, except where Section 7 legitimate uses apply. When an incident occurs, the DPDP Rules, 2025 require the Data Fiduciary to submit a detailed breach report to the Data Protection Board within 72 hours. The corporate entity must simultaneously issue an intimation to affected Data Principals without delay. Directors face no personal financial risk from the regulator. The company itself absorbs the full impact of an inquiry. A failure to produce a valid consent artefact or proof of reasonable security safeguards exposes the balance sheet directly to the INR 250 crore penalty ceiling.

Could this happen to you

A misconfigured cloud bucket or a compromised physician portal can expose thousands of health records overnight. The medical director will not go to jail, but the compliance head must answer to the board when the Data Protection Board of India initiates an inquiry. The regulator will ask for your Record of Processing Activities and evidence of vendor oversight. If your team relies on generic banking compliance software or manual spreadsheets, generating that evidence pack in 72 hours is impossible. A credible solution maps patient data flows continuously so the control owner can produce a regulator-ready audit trail on demand.

What companies should do in the next 30 days

1. Present the precise liability limits to your board, quantifying the INR 250 crore corporate risk against the absence of personal liability. 2. Assign a control owner to map all patient data flows and establish an automated Record of Processing Activities. 3. Draft and simulate a 72-hour breach response workflow that meets the reporting mechanics detailed in the Rules, 2025. 4. Audit sub-processor contracts to confirm vendors carry financial indemnity for data incidents they cause.

What to watch

The Central Government will soon operationalise the Data Protection Board of India under Section 18. Early enforcement will likely target organisations that fail to produce verifiable data trails during breach inquiries. Significant Data Fiduciary candidates in the healthcare sector should expect high scrutiny on their risk assessment protocols. Exactly 221 days remain until the 13 May 2027 hard compliance deadline. Assess your current gap and evaluate your automated evidence capabilities at https://www.complydp.com/audit-preview before the regulatory body begins active enforcement.

Sources

Frequently asked questions

Are directors personally liable for data breaches under the DPDP Act?

The DPDP Act 2023 places liability strictly on the Data Fiduciary as a corporate entity. The Act omits personal or vicarious liability for directors and prescribes no criminal offences or imprisonment.

What is the maximum penalty for a data breach under the Act?

The Data Protection Board of India can impose monetary penalties up to INR 250 crore for failing to take reasonable security safeguards. This penalty applies directly to the corporate entity.

How much time does a company have to report a data breach?

Under the DPDP Rules 2025, a Data Fiduciary must submit a detailed breach report to the Data Protection Board within 72 hours. Affected Data Principals must also receive an intimation without delay.

Does this apply to healthtech companies processing patient data?

Yes. Any enterprise processing digital personal data within India must comply with the DPDP Act. Healthtech platforms act as Data Fiduciaries and face the exact same INR 250 crore penalty risk for security failures.

When is the final deadline for DPDP Act compliance?

Companies have exactly 221 days remaining until the 13 May 2027 hard compliance deadline. Organisations must implement verifiable data controls and audit trails before this date.