top of page

Corporate Criminal Liability For Data Breaches Under The Digital Personal Data Protection Act, 2023: A Critical Analysis




Aisha Tanvir, United University (LLM in Criminal and Forensic Law)


ABSTRACT


The exponential growth of the digital economy has transformed personal data into a valuable corporate asset, making organizations increasingly vulnerable to data breaches that threaten individual privacy, financial security, and public trust. In India, the recognition of privacy as a fundamental right in Justice K.S. Puttaswamy (Retd.) v. Union of India prompted the enactment of the Digital Personal Data Protection Act, 2023 (DPDP Act), which establishes a comprehensive legal framework for regulating the collection, processing, and protection of personal data. While the Act imposes extensive obligations on Data Fiduciaries and prescribes substantial monetary penalties for non-compliance, it does not expressly recognize corporate criminal liability for data breaches. This raises a significant legal question as to whether a predominantly regulatory and civil penalty regime is sufficient to ensure corporate accountability in cases involving serious negligence, reckless data management, or intentional misuse of personal data.


This paper critically examines the concept of corporate criminal liability in the context of data breaches under the DPDP Act, 2023. It analyses the statutory framework alongside the Information Technology Act, 2000 to evaluate the extent to which the existing legal regime addresses corporate misconduct involving personal data. Adopting a doctrinal research methodology, the study relies on statutory provisions, judicial precedents, government reports, and scholarly literature to assess the adequacy of the current framework. The paper argues that although the DPDP Act marks a significant advancement in India's data protection landscape by introducing stronger compliance obligations and enforcement mechanisms, its reliance on administrative penalties leaves important gaps in addressing grave corporate misconduct. It concludes that a more coherent legal framework, supported by effective enforcement, clearer standards of corporate accountability, and appropriate liability mechanisms, is essential to strengthen data governance and protect the constitutional right to informational privacy in India's rapidly evolving digital ecosystem.


Keywords: Corporate Criminal Liability; Data Breaches; Digital Personal Data Protection Act, 2023; Right to Privacy; Information Technology Act, 2000



Indian Journal of Law and Legal Research

Abbreviation: IJLLR

ISSN: 2582-8878

Website: www.ijllr.com

Accessibility: Open Access

License: Creative Commons 4.0

Submit Manuscript: Click here

Licensing: 

 

All research articles published in The Indian Journal of Law and Legal Research are fully open access. i.e. immediately freely available to read, download and share. Articles are published under the terms of a Creative Commons license which permits use, distribution and reproduction in any medium, provided the original work is properly cited.

 

Disclaimer:

The opinions expressed in this publication are those of the authors. They do not purport to reflect the opinions or views of the IJLLR or its members. The designations employed in this publication and the presentation of material therein do not imply the expression of any opinion whatsoever on the part of the IJLLR.

bottom of page