CYBER CRIMES AND THE DPDP ACT 

Cyber Crimes and the DPDP Act: A Complete Guide to Your Digital Rights
Cyber Security and Data Protection Symbol

CYBER CRIMES AND THE DPDP ACT A Complete Guide to Your Digital Rights & Protection in India

In the digital age, your data is your identity. Learn how to protect your personal information and understand your legal rights.

UNDERSTANDING YOUR DIGITAL RIGHTS

“Is my data safe? — A Complete Guide to Cyber Crimes and the DPDP Act”

In the digital age, every step we take — online shopping, banking, social media — leaves a data trail. This data is our identity, but for cybercriminals, it is a goldmine. Your data can be stolen, misused, or fall into the wrong hands. Addressing these concerns, the Government of India enacted the Digital Personal Data Protection (DPDP) Act, 2023.

This Act provides a robust legal framework for the protection of your personal digital information. It dictates how companies (Data Fiduciaries) can collect your data, when your consent is mandatory, and what legal actions can be taken if your data is leaked. This guide gives you complete information on preventing cyber crimes and your rights under the DPDP Act.

Key Laws DPDP Act, 2023 | IT Act, 2000
Key Institutions Data Protection Board of India | TDSAT (Appellate Tribunal)

The Supreme Court’s Landmark Ruling

In the historic Justice K.S. Puttaswamy v. Union of India (2017) judgment, the Supreme Court declared Privacy a Fundamental Right. The Court stated that informational privacy is an integral part of Article 21 (Right to Life) and directed the government to create a robust legal framework for data protection. The DPDP Act, 2023, was born from the foundation of this very judgment.

1. Cyber Crimes: Common Threats

Major Forms of Cyber Crime

Phishing: Stealing your banking details, passwords, or OTPs through fake emails or messages.

Identity Theft: Stealing your identity (Aadhaar, PAN, Passport) and misusing it.

Ransomware: Encrypting your data and demanding a ransom to release it.

Data Breach: The theft of your personal information from a company’s database.

Social Engineering: Manipulating you psychologically into revealing confidential information.

Online Fraud: Scamming money through fake websites, fake apps, or fraudulent offers.

Cyberbullying and Harassment: Threats, defamation, or sexual harassment on social media.

2. The DPDP Act, 2023: Your Shield of Protection

What is the DPDP Act?

The Digital Personal Data Protection Act, 2023 (DPDP Act) is India’s first comprehensive data protection law. Passed by Parliament on August 11, 2023, its objective is to ensure the protection of digital personal data while allowing data processing for legitimate purposes. The Act is based on a SARAL (Simple, Accessible, Reasonable, Actionable, and Lawful) approach.

Key Features of the Act

Applicability: The Act applies to personal data processed digitally or digitized later. It also applies to data processed outside India if it relates to offering goods or services to Data Principals in India.

Basis of Data Processing: Personal data can only be processed for a lawful purpose. This is either through the consent of the Data Principal or under Certain Legitimate Uses (e.g., government services, medical emergencies, legal obligations, employment).

Consent: Consent must be free, specific, informed, unconditional, and unambiguous. It must be given through a clear affirmative action (e.g., ticking a box). The Data Fiduciary must provide a notice detailing the purpose, data collected, and grievance redressal mechanism.

Data Protection Board: The Data Protection Board of India (DPB) has been established to monitor compliance. It is a fully digital body, allowing citizens to file and track grievances online.

Penalties: Non-compliance can result in heavy penalties for Data Fiduciaries:
▸ Failure to take security safeguards: Up to ₹250 Crore
▸ Failure to notify a data breach: Up to ₹200 Crore
▸ Violations involving children’s data: Up to ₹200 Crore
▸ Other violations: Up to ₹50 Crore

3. Who is Who: Key Terms of the Act

Important Definitions

Data Principal: The individual to whom the personal data relates. In simple terms, you.

Data Fiduciary: The entity or person who determines the purpose and means of processing personal data. Examples: Amazon, Flipkart, banks, government departments.

Data Processor: The entity that processes data on behalf of the Data Fiduciary.

Significant Data Fiduciary (SDF): Large tech companies that will have additional responsibilities, such as appointing a DPO, conducting data audits, and performing Data Protection Impact Assessments.

Consent Manager: A platform that makes it easy for the Data Principal to give, manage, and withdraw consent from a single place. It must be an Indian company.

Data Protection Officer (DPO): The person appointed by an SDF who is responsible for data security.

4. Your Rights Under the DPDP Act

Rights of the Data Principal

1. Right to Information: You can know what data of yours is being processed, for what purpose, and by which entity.

2. Right to Withdraw Consent: You can withdraw your consent at any time.

3. Right to Correction and Erasure: You can request the correction, updating, or erasure of your data.

4. Right to Grievance Redressal: Every Data Fiduciary must provide a grievance redressal mechanism. You must first complain to them, and then to the Data Protection Board if unresolved.

5. Right to Nominate: You can nominate another person to exercise your rights in the event of your death or incapacity.

6. Right to Access Data: You can know which Data Fiduciaries and Processors your data has been shared with.

5. Data Breach: What to Do?

Steps to Take in Case of a Data Breach

Under the DPDP rules, in the event of a data breach, the Data Fiduciary must immediately notify all affected individuals in plain language. This notice must include the nature of the breach, potential impact, steps taken, and contact details for assistance.

Actions to Take After a Breach

1. Change Passwords Immediately: Change the password of the breached platform. If you use the same password elsewhere, change those too.

2. Notify Your Bank/Card Provider: If your financial details (credit/debit cards, bank accounts) were leaked, inform your bank immediately and block the cards.

3. Use the Company’s Grievance Mechanism: First, file a complaint with the Data Fiduciary’s grievance redressal system.

4. File a Complaint with the Data Protection Board: If the company does not provide a satisfactory resolution, file an online complaint with the Data Protection Board (DPB). The DPB is fully digital.

5. Report to the Cyber Crime Portal: If a cyber crime has occurred, file an online complaint at cybercrime.gov.in or call the cyber helpline at 1930.

6. DPDP Act Implementation Timeline

The DPDP Act and its rules are being implemented in phases to give entities adequate time to comply:

Phase 1: Procedural provisions — Definitions, establishment of the DPB, and administrative provisions.

Phase 2: Provisions related to Consent Managers — Registration with the DPB, obligations, and breach investigations.

Phase 3: All core provisions — Basis of data processing, consent, notice, children’s data, cross-border transfer, security safeguards, and Data Principal rights.

What applies in the meantime: Until Phase 3 is fully effective, Section 43A of the Information Technology Act, 2000 and the SPDI Rules, 2011 will continue to apply.

Frequently Asked Questions

Q: Can I get compensation under the DPDP Act?

The DPDP Act focuses on imposing heavy penalties on Data Fiduciaries for non-compliance rather than direct compensation to individuals. However, you can still seek civil remedies for damages under other applicable laws.

Q: Do foreign companies fall under the DPDP Act?

Yes. If a foreign company offers goods or services to Data Principals residing in India, it must comply with the DPDP Act.

Q: Can I get my data completely deleted?

Yes, you can request the erasure of your data if you have withdrawn consent or the purpose has been fulfilled. However, if the law mandates the retention of data (e.g., for tax or legal purposes), it cannot be deleted.

Q: Where should I complain if a company is misusing my data?

First, file a complaint with the company’s grievance redressal mechanism. If unresolved, file an online complaint with the Data Protection Board of India (DPB). The appellate authority for the DPB is TDSAT.

The Golden Rule for Digital Safety

“Always create strong, unique passwords. Use Two-Factor Authentication (2FA). Never click on unknown links or emails. Never share your OTP or password with anyone. Keep your banking apps updated. Always check permissions before granting any unknown mobile app access to your data. And remember — your data is your identity. The DPDP Act is on your side, but your own vigilance is your strongest defense.”

Conclusion

In the digital age, your personal information is your most valuable asset. Cyber crimes are constantly evolving, but the DPDP Act, 2023 provides you with a robust legal shield.

Key Takeaways:
▸ The DPDP Act is a comprehensive law for the protection of digital personal data.
▸ Your Rights: Information, correction, erasure, withdrawal of consent, and grievance redressal.
▸ Data Fiduciaries are responsible for implementing security measures, notifying breaches, and paying penalties.
▸ The Data Protection Board is a fully digital grievance redressal platform.
▸ Awareness and vigilance are your first line of defense.

Stay alert to protect your data, know your legal rights, and take immediate action against any violation.

Victim of Cyber Crime or Data Theft?

If your data has been leaked, or you have fallen victim to phishing or cyber fraud, seek legal advice immediately. Taking the right steps can help you protect your rights and file a complaint with the Data Protection Board.

Senior Cyber & Data Protection Law Advocate

Ahmed Jamal Siddiqui

High Court Advocate | Cyber Law, IT Act & Digital Rights

Disclaimer: This information is for general guidance only and does not constitute legal advice. Given the complexity of cyber crime and DPDP Act matters, always consult a qualified cyber and data protection lawyer for advice tailored to your specific situation.

Leave a Comment