India’s data-protection regime has entered a new era with the Digital Personal Data Protection Act, 2023 (DPDP Act). Yet compliance is only one dimension of data risk. The mishandling, loss or unauthorised disclosure of personal data increasingly gives rise to regulatory action, civil claims and, in appropriate cases, criminal proceedings under the Information Technology Act, 2000 (IT Act). We help organisations build compliant data-protection programmes, respond decisively to data breaches, and — when disputes arise — represent them across regulatory, civil and criminal forums.
Our work spans the full lifecycle of a data-protection matter: from designing consent and governance frameworks, to managing a live breach, to defending the complaints, claims and prosecutions that can follow. The right course of action rarely turns on generic rules — it depends on your operations, your contracts and the facts of the incident.
Our Data Protection Services
- Compliance with the Digital Personal Data Protection Act, 2023
- Data-breach incident response and breach notification
- Engagement with the Data Protection Board and regulators
- Privacy policies, consent frameworks and data-principal rights
- Data-processing and cross-border data-transfer arrangements
- Vendor, processor and data-sharing agreements
- Data-protection disputes, complaints and litigation
- Civil claims, injunctions and interim relief arising from data misuse and unauthorised disclosure
- Defence of criminal complaints and proceedings under the Information Technology Act, 2000
- Regulatory investigations, penalty proceedings and appeals before the Appellate Tribunal
Breach Response and Beyond
A data breach is a legal, technical and reputational event at once. We help you assess the breach, meet notification and regulatory obligations, coordinate with forensic teams, and manage affected individuals and stakeholders — while positioning you to defend the disputes that frequently follow. A single incident can trigger parallel proceedings: regulatory scrutiny from the Data Protection Board, civil claims from affected parties, contractual disputes with vendors or processors, and even criminal complaints. Managing these together, coherently and on the correct timelines, is central to protecting both your liability position and your reputation.
Data-Protection Disputes and Litigation
Data disputes rarely stay in a single forum. We advise and represent organisations across the range of proceedings that can arise from the handling of personal data, and — crucially — co-ordinate strategy where several run in parallel.
Civil litigation and disputes
We act in claims for compensation, injunctions and interim relief arising from data misuse, unauthorised disclosure or loss of personal data, as well as contractual disputes and indemnity claims between data fiduciaries, processors and vendors. We also handle consumer complaints and represent clients in proceedings before the Data Protection Board, with appeals lying to the designated Appellate Tribunal. A recurring complexity is that the DPDP Act itself is directed at regulatory penalties rather than personal compensation — so whether, and how, an affected party can recover often turns on the contractual matrix and other causes of action. Whether a particular claim is viable, and what relief is realistically available, depends closely on the facts. We assess that before any position is taken.
Criminal litigation and disputes
Data breaches and misuse can attract criminal liability under the IT Act — for example, in connection with unauthorised access, identity theft, cheating by personation, and breach of confidentiality or wrongful disclosure of information. These matters frequently involve insiders, third-party actors or compromised vendors, and require careful co-ordination between internal investigation, forensic evidence and law-enforcement engagement. We advise organisations both on pursuing criminal complaints where they are the victims of data theft or misuse, and on defending complaints, FIRs and prosecutions directed at the organisation or its personnel. Whether an offence is actually made out — and, if so, the right strategic response — is highly fact-specific and is best assessed before any statement is made or complaint filed.
Data Protection & Data Breach faq
The Digital Personal Data Protection Act, 2023 is India’s dedicated law governing the processing of digital personal data. It sets out obligations for organisations (data fiduciaries), rights for individuals (data principals), and a regulator in the form of the Data Protection Board. Its practical effect, however, depends significantly on the subordinate rules and on how its obligations interact with the existing IT Act framework — an area where the correct compliance posture is rarely obvious without advice tailored to how your organisation actually handles data.
There is no single checklist that fits every incident. The right response depends on the nature and scale of the breach, the categories of data and individuals affected, and your contractual and regulatory obligations — and it often has to be executed on tight, prescribed timelines. A breach can simultaneously trigger notification duties, regulatory scrutiny, civil claims and, in some cases, criminal exposure. Because early missteps can materially increase liability, engaging legal counsel at the outset is critical to getting the response right for your situation.
It can. Depending on the facts, conduct connected to a data breach — such as unauthorised access, identity theft or wrongful disclosure of information — may attract offences under the Information Technology Act, 2000. Whether liability arises, and for whom, is highly fact-specific and frequently contested, which is exactly why early, considered legal advice matters before positions are taken, statements are given or complaints are filed.
Affected individuals, business counterparties and regulators may each pursue different remedies — ranging from injunctions and compensation to contractual and indemnity claims between fiduciaries, processors and vendors. The available route, forum and prospects vary considerably with the facts and the contracts in place, so a case-specific assessment is important before responding to any claim, notice or demand.
The Data Protection Board is the regulator under the DPDP Act, with appeals lying to the designated Appellate Tribunal, while related civil and criminal proceedings may run in parallel before the courts. Because a single incident can move across several forums at once, coordinated strategy across them is often decisive — something best mapped with counsel early rather than forum by forum.