Corporate Criminal Liability For Data Breaches Under The Digital Personal Data Protection Act, 2023: A Critical Analysis
- IJLLR Journal
- Aug 7
- 2 min read
Aisha Tanvir, United University (LLM in Criminal and Forensic Law)
ABSTRACT
The exponential growth of the digital economy has transformed personal data into a valuable corporate asset, making organizations increasingly vulnerable to data breaches that threaten individual privacy, financial security, and public trust. In India, the recognition of privacy as a fundamental right in Justice K.S. Puttaswamy (Retd.) v. Union of India prompted the enactment of the Digital Personal Data Protection Act, 2023 (DPDP Act), which establishes a comprehensive legal framework for regulating the collection, processing, and protection of personal data. While the Act imposes extensive obligations on Data Fiduciaries and prescribes substantial monetary penalties for non-compliance, it does not expressly recognize corporate criminal liability for data breaches. This raises a significant legal question as to whether a predominantly regulatory and civil penalty regime is sufficient to ensure corporate accountability in cases involving serious negligence, reckless data management, or intentional misuse of personal data.
This paper critically examines the concept of corporate criminal liability in the context of data breaches under the DPDP Act, 2023. It analyses the statutory framework alongside the Information Technology Act, 2000 to evaluate the extent to which the existing legal regime addresses corporate misconduct involving personal data. Adopting a doctrinal research methodology, the study relies on statutory provisions, judicial precedents, government reports, and scholarly literature to assess the adequacy of the current framework. The paper argues that although the DPDP Act marks a significant advancement in India's data protection landscape by introducing stronger compliance obligations and enforcement mechanisms, its reliance on administrative penalties leaves important gaps in addressing grave corporate misconduct. It concludes that a more coherent legal framework, supported by effective enforcement, clearer standards of corporate accountability, and appropriate liability mechanisms, is essential to strengthen data governance and protect the constitutional right to informational privacy in India's rapidly evolving digital ecosystem.
Keywords: Corporate Criminal Liability; Data Breaches; Digital Personal Data Protection Act, 2023; Right to Privacy; Information Technology Act, 2000
