Assessing Compensation and Penalties under the Indian Data Protection Regime [pre-publication] - Global Privacy Law Review View Assessing Compensation and Penalties under the Indian Data Protection Regime [pre-publication] by - Global Privacy Law Review Assessing Compensation and Penalties under the Indian Data Protection Regime [pre-publication] 7 2 [pre-publication]

Various laws, including the European Union’s (EU’s) General Data Protection Regulation (GDPR) and Singapore’s Personal Data Protection Act, provide legal mechanisms for claiming compensation for breaches of personal data. Curiously, however, the right to claim compensation was omitted from India’s Digital Personal Data Protection (DPDP) Act, 2023. Further, the recently released DPDP Rules, 2025 also do not provide any mechanism for seeking compensation. At the same time, although the Act prescribes penalties for non-compliance, certain provisions appear problematic, particularly because they impose disproportionately high fines on data principals, among other concerns highlighted in this article.

Certain sector-specific laws in India contain provisions relating to compensation and penalties for breaches of personal data or sensitive personal data. However, most of these laws fail to clarify the procedure through which an individual or body corporate may claim compensation for such breaches. Similarly, the provisions remain unclear regarding the imposition and enforcement of penalties in such cases. This article recommends specific amendments to the DPDP Act to ensure that data principals can effectively exercise a right to compensation and that penalties are enforced in a more balanced and effective manner within India’s data protection regime.

Global Privacy Law Review