Tsaaro got CERT-IN Empanelled | MeitY has published the DPDP Rules, 2023.
Tsaaro got CERT-IN Empanelled | MeitY has published the DPDP Rules, 2023.
Tsaaro got CERT-IN Empanelled | MeitY has published the DPDP Rules, 2023.
Tsaaro got CERT-IN Empanelled | MeitY has published the DPDP Rules, 2023.
Back To Home
Privacy

Introduction
The Data Protection Board of India (DPB) is expected to play an important role in adjudicating privacy disputes, as the Act establishes the Board as the statutory authority responsible for examining personal data breaches, investigating non-compliance, and imposing financial penalties.
The consequences of a privacy incident may extend beyond regulatory compliance. Such incidents may give rise to disputes involving contractual obligations, liability, insurance claims, and corporate governance. Different stakeholders may seek remedies before different legal forums depending on the nature of the dispute. As a result, issues arising from a single privacy incident may involve both statutory obligations under the DPDP Act and contractual rights between the parties.
As a result, a single privacy incident may lead to multiple legal proceedings before different forums. Each forum applies different legal principles and considers different issues. In practice, such incidents may give rise to a new category of commercial disputes. These disputes are also unlikely to remain limited to the jurisdiction of the Data Protection Board alone.
Dispute Settlement Mechanism under the DPDP Act
The DPB is empowered to direct mitigation and remedial measures, inquire into personal data breaches, and impose penalties. The DPB can take up cases in the following situations: (i) upon receiving an intimation of a personal data breach; (ii) on a complaint by a Data Principal; (iii) on a reference made by the Central or State Government; (iv) on the directions of a court; and (v) where an intermediary fails to comply with the directions of the Central Government.
The DPDP Act establishes a three-tier dispute resolution mechanism. Proceedings are first initiated before the Data Protection Board. The detailed procedure to be adopted by the board is as follows:
Initiating Proceedings: Section 27 of the Act authorises the board to initiate proceedings in specific situations such as on receiving an intimation of a personal data breach, a complaint from a Data Principal, a complaint or intimation relating to a Consent Manager, a reference from the Central or State Government, directions from a court, or a reference regarding an intermediary's failure to comply with the Act.
Power to Issue Directions: Moreover, the Board may issue directions necessary for the discharge of its functions and must also provide the concerned person with an opportunity to be heard and record the reasons for its decision in writing.
Power to Refer Matters for Mediation: Section 31 further empowers the Board to refer a complaint for mediation where it considers that the dispute may be resolved through mutual settlement.
Factors for Imposing Monetary Penalties: While determining the amount of a monetary penalty, the Board must consider factors such as the nature, gravity, and duration of the breach, the type of personal data affected, whether the breach is repetitive, any gain or loss arising from the breach, the steps taken to mitigate its impact, whether the penalty is proportionate and effective in ensuring compliance, and its likely impact on the person concerned.
Any person aggrieved by an order or direction of the Board may file an appeal before the appellate tribunal. Section 29(1) of the DPDP Act provides for this appellate remedy and designates Telecom Disputes Settlement and Appellate Tribunal (TDSAT) as the Appellate Tribunal for the purposes of the DPDP Act.
Section 18 of the TRAI Act further provides that any person aggrieved by an order of the Telecom Disputes Settlement and Appellate Tribunal (TDSAT), may file an appeal before the Supreme Court.
Understanding Data Processing Agreements
Data fiduciaries remain responsible to data principals even when a data breach is attributable to a data processor. To manage this responsibility, data fiduciaries enter into Data Processing Agreements (DPAs) with data processors. Section 8 of the Act provides that a Data Fiduciary may engage, appoint, use, or otherwise involve a Data Processor to process personal data on its behalf for any activity relating to the provision of goods or services to Data Principals only through a valid contract.
These agreements generally include confidentiality obligations, indemnity clauses, and dispute resolution provisions. The structure of a Data Processing Agreement can be understood through four main elements as discussed below:
Parties: The data fiduciary determines the purpose and manner of processing personal data, while the data processor processes it on the fiduciary's behalf. These agreements allow fiduciaries to outsource data processing while ensuring compliance with privacy laws.
Obligations: DPAs define the scope of the services by identifying the types of personal data involved, such as biometric or financial data, the permitted purposes of processing, such as storage or analytics, and any geographical limits on processing. They also require appropriate technical and organisational security measures, including encryption, access controls, and regular audits to protect personal data.
Risk Allocation: DPAs contain confidentiality obligations, indemnity clauses, and liability provisions that determine how responsibility will be shared if a data breach occurs. These clauses generally require the data processor to compensate the data fiduciary where the breach results from the processor's negligence or failure to comply with its contractual obligations.
Dispute Resolution: Most DPAs contain broadly drafted clauses to resolve disputes arising from contractual breaches, such as unauthorised sharing of personal data, failure to maintain agreed security standards, or failure to comply with data deletion obligations.
A well-drafted and appropriately tailored Data Processing Agreement (DPA) serves as important documentary evidence of an organisation's data governance practices. It demonstrates that the organisation has established contractual safeguards, defined the responsibilities of the parties, and exercised reasonable oversight over the processing of personal data.
To manage contractual risks, organisations often include indemnity clauses that allocate financial responsibility for losses arising from a data processor's breach of its contractual obligations. Depending on the commercial arrangement, these clauses may cover regulatory penalties where legally permissible, litigation costs, investigation expenses, and data recovery costs resulting from the processor's negligence or non-compliance. Such provisions help allocate financial risk between the parties, although they do not relieve the data fiduciary of its statutory obligations under the DPDP Act.
Arbitration as a mode of Dispute Resolution
Whether a data privacy dispute can be resolved through arbitration depends on the nature of the dispute. Disputes arising from contractual obligations between private parties are generally capable of being referred to arbitration. These include disputes relating to Data Processing Agreements, confidentiality obligations, data-sharing arrangements, and other contractual commitments concerning the processing of personal data.
Arbitration offers several advantages for resolving such disputes. It ensures confidentiality, protects commercially sensitive information, allows parties to appoint arbitrators with technical expertise, and generally provides a faster and more flexible dispute resolution process than traditional litigation. These features make arbitration particularly suitable for disputes involving technology, data protection, and commercial relationships.
As organisations increasingly rely on third-party service providers for processing personal data, contractual disputes concerning data protection obligations are likely to become more common. In such cases, arbitration can serve as an effective mechanism for resolving disputes arising from contractual breaches while preserving business relationships and protecting confidential information. It also offers greater flexibility and helps parties avoid the delays and reputational risks associated with court proceedings. These features make arbitration a suitable mechanism for resolving disputes involving contractual obligations and commercial interests.
Conclusion
The DPDP Act, 2023 establishes a statutory framework for addressing personal data breaches through the Data Protection Board. However, the legal consequences of a data breach are not confined to regulatory proceedings. Where contractual obligations exist between data fiduciaries and data processors, the same incident may also give rise to commercial disputes relating to liability, indemnification, or breach of contractual obligations.
Consequently, organisations should not only strengthen their regulatory compliance under the DPDP Act but also ensure that their contractual arrangements clearly allocate responsibilities for data processors to manage future privacy-related dispute risks.
Want to stay ahead?
Reach out to the experts at tsaaro.com today.
Talk to a Privacy Expert
Get a free 1:1 session on AI compliance, DPDPA readiness, or incident response planning.
Related articles












