CYBER CRIME AND THE DPDP ACT
CYBER CRIME AND THE DPDP ACT A Step Toward Your Security
Data theft, ransomware, and cyber fraud are rising. The DPDP Act provides a strong legal framework for your protection. Know your rights and security measures.
YOUR DIGITAL SECURITY
“How secure is my data? — Cyber crime and the DPDP Act”
Cyber crime is rising rapidly in India. In 2024, the average cost of a data breach for Indian companies was ₹19.5 crore — 39% higher than in 2020 . The estimated total loss due to cyber crime in 2025 is ₹20,000 crore, with the banking sector accounting for ₹8,200 crore and e-commerce for ₹5,800 crore .
To address this challenge, the Government of India enacted the Digital Personal Data Protection (DPDP) Act, 2023 . This Act provides a comprehensive legal framework for the protection and processing of personal data . This guide covers cyber crime prevention, your rights under the DPDP Act, and the legal remedies available for your digital security .
The Supreme Court’s Landmark Judgment
In the historic case of Justice K.S. Puttaswamy v. Union of India (2017), the Supreme Court declared Privacy a fundamental right . The Court held that informational privacy is an integral part of the Right to Life under Article 21 of the Constitution and directed the government to create a robust legal framework for data protection. The DPDP Act, 2023 is the legislative response to this landmark judgment .
1. Cyber Crime: The Current Landscape
The Growing Threat of Cyber Crime
Cyber Crime Statistics in India:
▸ 10.29 lakh cyber crime incidents were recorded in 2022, rising to 22.68 lakh in 2024 — a 120% increase .
▸ Estimated total loss from cyber crime in 2025 is ₹20,000 crore, with banking at ₹8,200 crore and e-commerce at ₹5,800 crore .
▸ Costliest cyber crimes: Business Email Compromise (₹21.5 crore per breach), Social Engineering (₹21.3 crore), and Phishing (₹20.9 crore) .
Common Forms of Cyber Crime
Ransomware: Encrypting data and demanding ransom — mandatory reporting to CERT-In .
Phishing & Social Engineering: Stealing passwords, OTPs, or banking details through fake emails or messages .
Data Breach: Theft of personal information from company databases — mandatory reporting under DPDP Act .
Identity Theft: Misuse of stolen Aadhaar, PAN, or passport details .
AI-Based Fraud: Deepfakes and AI-generated messages for deception .
2. DPDP Act, 2023: Your Security Shield
What Is the DPDP Act?
The Digital Personal Data Protection Act, 2023 was enacted on 11 August 2023 . Its objective is to ensure the protection of digital personal data, while allowing data processing for lawful purposes. The DPDP Rules, 2025 draft has been released for public consultation and will provide detailed guidelines for implementation .
Key Features of the Act
Data Principal: The individual whose personal data is being processed — that is YOU .
Data Fiduciary: The entity (Amazon, Flipkart, banks, etc.) that collects and processes your data .
Consent: Your free, specific, informed, and unambiguous consent is required for data processing .
Penalties: Heavy fines for non-compliance :
▸ Up to ₹250 crore for failure to implement security measures
▸ Up to ₹200 crore for failure to notify a breach
▸ Up to ₹200 crore for violations related to children’s data
▸ Up to ₹50 crore for other violations
3. Your Rights Under the DPDP Act
Rights of the Data Principal
1. Right to Access: You can know what data is being processed, for what purpose, and by which entity .
2. Right to Correction & Erasure: You can request correction, updation, or erasure of your data .
3. Right to Withdraw Consent: You can withdraw your consent at any time .
4. Right to Grievance Redressal: Every Data Fiduciary must provide a grievance redressal mechanism .
5. Right to Nominate: You can nominate another person to exercise your rights in case of death or incapacity .
6. Right to Data Portability: You can transfer your data from one Data Fiduciary to another .
4. Data Breach — Now Mandatory Notification
What to Do in Case of a Data Breach?
Under Section 8(6) of the DPDP Act, in case of a data breach, the Data Fiduciary must notify both the Data Protection Board (DPB) and the affected Data Principals . Under the DPDP Rules, 2025, breach notification must be made “without undue delay” — effectively immediately .
New Breach Notification Rules
Dual Notification:
▸ To the Data Protection Board (DPB): Detailed report of the breach, including cause, affected systems, data volume, and remedial measures .
▸ To affected Data Principals: Nature of the breach, categories of affected data, potential consequences, and security measures .
Report to CERT-In: Cyber security incidents must be reported to CERT-In within 6 hours .
What to Include:
▸ Description and cause of the breach
▸ Categories and volume of affected data
▸ Number of affected individuals
▸ Steps taken and corrective measures
▸ Plan for future prevention
No “Materiality Threshold”: Every personal data breach, regardless of its impact, must be reported .
5. CERT-In: India’s National Cyber Security Agency
Indian Computer Emergency Response Team
CERT-In is the national cyber security nodal agency established under Section 70B of the Information Technology Act, 2000 .
Key Functions:
▸ Collection, analysis, and dissemination of information on cyber incidents
▸ Forecasting and alerts for cyber security incidents
▸ Emergency measures for managing cyber incidents
▸ 24×7 helpline
▸ Issuing cyber security guidelines and advisories
Government Initiatives:
▸ National Cyber Coordination Centre (NCCC): Detecting cyber threats
▸ Cyber Swachhta Kendra (CSK): Detecting and removing botnets and malware
▸ NCIIPC: Protecting critical information infrastructure
▸ I4C (Indian Cyber Crime Coordination Centre): Combating cyber crime
6. Data Protection Board — Your Grievance Authority
Data Protection Board of India (DPB)
The DPDP Act provides for the establishment of a Data Protection Board . The Board will be fully digital and will perform the following functions :
Key Powers:
▸ Inquire into data breaches and impose penalties
▸ Direct urgent remedial measures
▸ Inquire into complaints by Data Principals
▸ Maintain registration of Consent Managers
▸ Powers of a civil court (summons, document production, etc.)
Appellate Process:
▸ First Appeal: Against DPB decisions — to TDSAT (Telecom Disputes Settlement and Appellate Tribunal)
▸ Second Appeal: Against TDSAT orders — to the Supreme Court
7. Cyber Insurance — The DPDP Act’s Impact
The DPDP Act has increased the importance of cyber insurance . A data breach is now not just an IT failure, but a regulatory event that can attract heavy fines and legal costs .
What Cyber Insurance Covers:
▸ Regulatory fines and penalties (where permitted by law)
▸ Cyber incident management and crisis management costs
▸ Notification costs and credit monitoring
▸ Data restoration/recovery
▸ Third-party liability and defence costs
Challenge for MSMEs: Small and medium businesses (SMEs/MSMEs) are the most vulnerable — they lack robust security controls, dedicated compliance teams, or the financial reserves to absorb a penalty. One small incident can shut down a business .
Frequently Asked Questions
Q: When was the DPDP Act enacted?
The DPDP Act received Presidential assent on 11 August 2023. The DPDP Rules, 2025 draft has been released for public consultation and is yet to be notified .
Q: What should I do if my data is breached?
If you suspect your data has been leaked: (1) immediately change your passwords, (2) notify your bank, (3) use the Data Fiduciary’s grievance redressal mechanism, (4) file an online complaint with the Data Protection Board, and (5) report to cybercrime.gov.in or call 1930 .
Q: Which companies does the DPDP Act apply to?
The Act applies to all Data Fiduciaries — any entity operating in India that processes personal digital data. This includes foreign companies if they offer services to Data Principals in India .
Q: Can I directly approach the Data Protection Board?
Yes, but you must first use the Data Fiduciary’s grievance redressal mechanism. If the issue is not resolved, you can then approach the Data Protection Board .
The Golden Rule for Digital Security
“Always use strong and unique passwords. Enable two-factor authentication (2FA). Never click on unknown links or emails. Never share your OTP or password with anyone. Keep your banking apps updated. Check permissions before granting any unknown mobile app access to your data. And remember — your data is your identity. The DPDP Act is with you, but your most powerful security is your own caution.”
Conclusion
Amid the growing threats of cyber crime and data theft, the DPDP Act, 2023 is a milestone in India’s data protection journey. This law gives individuals control over their personal data and holds Data Fiduciaries accountable through strict security measures, breach notification requirements, and heavy penalties .
Key Takeaways:
▸ DPDP Act is India’s comprehensive law for digital personal data protection
▸ Your rights: Access, correction, erasure, consent withdrawal, grievance redressal, nomination
▸ Data breach: Dual notification to Data Protection Board and affected Data Principals — and to CERT-In within 6 hours
▸ Penalties: Up to ₹250 crore for security failures, ₹200 crore for breach notification failures
▸ Your vigilance and awareness are your first line of defence
Stay alert, know your legal rights, and take immediate action on any violation.
Victim of Cyber Crime or Data Theft? Get Legal Help Now
If your data has been leaked, or you’ve been a victim of phishing or cyber fraud, seek legal help immediately. Taking the right steps can protect your rights and help you file a complaint with the Data Protection Board.
Senior Cyber & Data Protection Law Advocate
Ahmed Jamal Siddiqui
High Court Advocate | Cyber & Data Protection Law
