top of page

India’s DPDP Enforcement Framework: The Remedy Gap, Mediation Route and Independence of the Data Protection Board


Executive Snapshot


India’s Digital Personal Data Protection Act, 2023 marks a major shift in India’s privacy and digital governance framework. It creates statutory rights for Data Principals, imposes obligations on Data Fiduciaries, and establishes the Data Protection Board of India as the principal enforcement authority.

However, the enforcement model under the DPDP Act raises an important legal and practical question: does the Act provide an effective individual remedy when privacy is breached ?

The answer is nuanced.

The Act empowers the Data Protection Board to inquire into contraventions and impose monetary penalties. However, it does not create a direct statutory compensation remedy for affected Data Principals. Further, a Data Principal must first exhaust the grievance redressal mechanism of the concerned Data Fiduciary or Consent Manager before approaching the Board.

This creates a remedial gap. The law may punish non-compliance, but the affected individual may still have to explore remedies outside the DPDP Act for monetary compensation.

The next phase of Indian data protection litigation is therefore likely to turn on five core issues: grievance exhaustion, compensation, mediation, civil court jurisdiction and the institutional independence of the Data Protection Board.


At a Glance

Issue

Position under DPDP Framework

Practical Impact

Grievance redressal

Data Principal must first approach the Data Fiduciary or Consent Manager.

Access to the regulator is conditional, not immediate.

Compensation

No express statutory compensation remedy for affected Data Principals.

Penalty may be imposed, but the individual may remain uncompensated.

Mediation

Board may refer suitable complaints to mediation.

Useful settlement route, but not a substitute for statutory damages.

Civil court jurisdiction

Civil court jurisdiction is barred for matters within the Board’s powers.

Future litigation may test whether independent tort, consumer or constitutional claims survive.

Board independence

Appointment structure involves significant Central Government role.

Independence concerns may arise, especially in State-linked cases.


1. India’s Shift to a Dedicated Privacy Regime


The DPDP Act, 2023 provides a dedicated framework for processing digital personal data in India. Its object is to balance two interests: the right of individuals to protect their personal data and the legitimate need to process such data for lawful purposes.

The Act must be read in the constitutional background of Justice K.S. Puttaswamy (Retd.) v. Union of India, where the Supreme Court recognised privacy as part of the fundamental right to life and personal liberty under Article 21 of the Constitution of India.

The DPDP Act is therefore not merely a compliance statute. It is part of India’s wider transition towards rights-based digital governance.

At the same time, the statute adopts a regulator-led enforcement model rather than a private compensation model. This distinction is central to understanding the present remedy gap.


2. Enforcement Architecture: Internal Grievance First, Regulator Later


Section 13 of the DPDP Act gives every Data Principal the right to grievance redressal. Every Data Fiduciary and Consent Manager is required to provide readily available means for grievance redressal in respect of acts or omissions relating to personal data obligations or the exercise of statutory rights.

However, Section 13 also requires the Data Principal to exhaust this grievance redressal opportunity before approaching the Data Protection Board.

This model has an administrative rationale. It allows organisations to resolve complaints internally and prevents every data-related grievance from immediately becoming a regulatory proceeding. For routine matters such as correction, updation, erasure, access, consent withdrawal or nomination, an internal mechanism may work efficiently.

The concern arises in serious cases.

Where a complaint concerns a major data breach, unauthorised processing, refusal to erase personal data, repeated non-compliance, misuse of personal information or systemic failure in data security, the Data Principal is still required to first approach the very entity whose conduct is under challenge.

This creates the first enforcement gap: access to the regulator is not immediate; it is conditional upon prior internal grievance exhaustion.


3. The Remedy Gap: Penalty Is Not Compensation


The most significant limitation of the DPDP Act is that it does not create a direct statutory compensation remedy for affected Data Principals.

The Data Protection Board may impose monetary penalties for contraventions of the Act and Rules. However, penalties are credited to the Consolidated Fund of India. They are not paid to the affected individual.

This creates a critical distinction:

A regulatory penalty punishes non-compliance. Compensation repairs individual harm.

The DPDP Act clearly provides for the first. It does not expressly provide for the second.

This is particularly significant because the DPDP Act also provides for omission of Section 43A of the Information Technology Act, 2000, subject to applicable commencement. Section 43A earlier provided a compensation route where a body corporate negligently failed to implement reasonable security practices and procedures, causing wrongful loss or wrongful gain.

Therefore, once the relevant provisions are fully operational, India will move from the earlier statutory compensation mechanism under Section 43A towards a penalty-driven regulatory model under the DPDP Act.

This is the central remedial gap in India’s new data protection framework.


4. Mediation under Section 31: Useful, but Limited


Section 31 of the DPDP Act allows the Data Protection Board to direct parties to attempt mediation where the Board is of the opinion that a complaint may be resolved through mediation.

This is an important practical tool. Mediation can produce outcomes which a penalty order may not directly deliver, including:

  • correction or erasure of personal data;

  • cessation of unauthorised processing;

  • modification of internal data-handling practices;

  • written undertakings;

  • apology or corrective communication;

  • settlement of individual claims;

  • future compliance commitments.

However, mediation is not the same as a statutory compensation mechanism.

It depends on the willingness of parties, the strength of the claim, the bargaining position of the Data Principal, and the procedural approach adopted by the Board. The DPDP Act does not itself create a detailed damages framework through mediation.

The Mediation Act, 2023 may support enforceability of mediated settlement agreements where the process falls within its statutory framework. However, that does not convert the DPDP Act into a compensation statute.

Accordingly, Section 31 is useful as a resolution tool, but it cannot be treated as a substitute for a direct statutory compensation remedy.


5. Civil Court Jurisdiction and Alternative Remedies


Section 39 of the DPDP Act bars civil courts from entertaining suits or proceedings in respect of any matter for which the Data Protection Board is empowered under the Act. It also restricts courts and other authorities from granting injunctions in respect of actions taken or proposed under the Act.

This provision is likely to become one of the most litigated parts of the DPDP framework.

The key question is whether an affected Data Principal can pursue independent remedies outside the DPDP Act, such as claims in tort, consumer law or constitutional law, while using DPDP violations as evidence of breach of duty.

The position is not free from doubt.

On one hand, the Board is the statutory authority for matters falling within its jurisdiction. On the other hand, the DPDP Act does not expressly create a private compensation remedy. If civil claims are also restricted, Data Principals may be left with penalties but no effective individual damages route.

This tension may invite judicial scrutiny.

The principles in Dhulabhai v. State of Madhya Pradesh remain relevant while analysing exclusion of civil court jurisdiction. Where a statute creates a special right and provides a special remedy, civil court jurisdiction may be excluded expressly or by necessary implication. However, exclusion clauses are generally interpreted carefully, particularly where the statutory remedy may not fully address the nature of relief sought.

Future courts may therefore have to examine whether compensation claims arising from privacy harms can survive independently of the DPDP process.


6. Possible Alternative Routes for Data Principals


Although the DPDP Act does not provide a direct compensation mechanism, affected Data Principals may explore other legal routes depending on the facts.


A. Tort Law

A Data Principal may consider claims based on negligence, breach of confidence, misuse of private information or failure to maintain reasonable safeguards.

In such cases, DPDP obligations may be used as evidence of the standard of care expected from a Data Fiduciary. A breach of statutory obligation may not automatically create a damages claim under the DPDP Act, but it may support a broader civil claim where negligence or breach of duty is otherwise established.


B. Consumer Protection Law

Where a Data Principal is also a consumer, remedies under the Consumer Protection Act, 2019 may be considered. In appropriate cases, failure to secure personal data or failure to provide safe digital services may be argued as deficiency in service.

However, this route may face challenges where the service is free or where consideration is contested. Maintainability will therefore depend on the nature of the relationship, the service model and the harm alleged.


C. Constitutional Remedies

Where the breach involves the State, a public authority or State-linked processing of personal data, constitutional remedies may arise under Article 226 or Article 32 of the Constitution of India.

After Justice K.S. Puttaswamy (Retd.) v. Union of India, privacy forms part of Article 21. Serious violations involving State action may therefore invite constitutional scrutiny.

In appropriate cases, constitutional courts have the power to grant public law compensation for violation of fundamental rights. However, such proceedings may face maintainability concerns, particularly where complex disputed facts require evidence.


7. Independence of the Data Protection Board


The Data Protection Board of India is central to the success of the DPDP regime. It is expected to function as the authority for complaints, inquiries, directions, voluntary undertakings, penalties and regulatory enforcement.

The Board has been established under the DPDP Act. The Government has also moved ahead with the appointment process for the Chairperson and Members.

However, the independence of the Board remains a live issue.

The Chairperson and Members are appointed by the Central Government in the prescribed manner. The DPDP Rules provide for Search-cum-Selection Committees with significant executive involvement. This has led to concern over whether the Board will be sufficiently insulated from executive influence, especially in matters involving government departments, public authorities or State-linked Data Fiduciaries.

This issue is not merely institutional. It affects the credibility of the entire enforcement framework.

A regulator deciding privacy complaints against private companies must be efficient. A regulator deciding privacy complaints involving the State must also be demonstrably independent.

The independence question is therefore likely to remain central to future DPDP litigation and policy debate.


8. Pending Constitutional Questions


The DPDP framework is already under constitutional scrutiny before the Supreme Court of India.

Publicly reported challenges concern provisions of the DPDP Act and Rules, including exemptions, the role and independence of the Data Protection Board, and the amendment to Section 8(1)(j) of the Right to Information Act, 2005.

The RTI-related amendment is particularly significant because it raises a larger constitutional question: how should Indian law balance personal data protection with transparency, public accountability and access to information?

The Supreme Court’s eventual approach may shape the future relationship between privacy, transparency, public interest disclosures and regulatory independence in India.


9. Statutory Issue Matrix

Legal Issue

Relevant Provision

Practical Reading

Grievance redressal

Section 13, DPDP Act; Rule 14, DPDP Rules

Data Principals must first use the Data Fiduciary or Consent Manager’s grievance mechanism before approaching the Board.

Response timeline

Rule 14, DPDP Rules

Grievance response framework must operate within a reasonable period not exceeding ninety days.

Board establishment

Sections 18 and 19, DPDP Act

The Data Protection Board is the statutory body for enforcement.

Digital-by-design Board

Section 28, DPDP Act

Board functions are intended to be digital by design, including complaints, hearings and decisions.

Mediation

Section 31, DPDP Act

Board may refer suitable complaints to mediation.

Voluntary undertakings

Section 32, DPDP Act

Board may accept undertakings regarding compliance measures.

Penalties

Section 33, DPDP Act

Board may impose monetary penalties for significant breaches.

Penalty credit

Section 34, DPDP Act

Penalties are credited to the Consolidated Fund of India, not paid to affected Data Principals.

Civil court bar

Section 39, DPDP Act

Civil court jurisdiction is restricted for matters within the Board’s powers.

IT Act amendment

Section 44, DPDP Act

Section 43A of the IT Act is omitted, subject to applicable commencement.

RTI amendment

Section 44, DPDP Act

Section 8(1)(j) of the RTI Act is amended, raising privacy-transparency questions.


10. Business Compliance Takeaways


For businesses, the absence of a direct statutory compensation mechanism should not be misunderstood as weak regulation.

The DPDP Act creates substantial compliance exposure. Data Fiduciaries should assume that the next phase of enforcement will be evidence-driven. Policies alone will not be sufficient. Organisations must be able to demonstrate implementation, audit trails, internal controls and documented accountability.

Every Data Fiduciary should review the following:

  1. privacy notice and consent language;

  2. consent withdrawal mechanism;

  3. grievance redressal system;

  4. response timelines and escalation matrix;

  5. Data Principal rights management process;

  6. personal data breach response protocol;

  7. security safeguards and access controls;

  8. processor and vendor contracts;

  9. retention and erasure policy;

  10. child data processing safeguards;

  11. internal audit and compliance documentation;

  12. evidence preservation for Board proceedings;

  13. mediation and settlement strategy for escalated grievances.

The compliance question is no longer whether an organisation has a privacy policy. The real question is whether it can prove that the policy is operational.


11. TLC View


The DPDP Act is a landmark statute, but its remedial architecture remains incomplete.

It creates rights, but not a direct statutory compensation route. It creates penalties, but penalties are credited to the Consolidated Fund of India. It creates mediation, but mediation depends on the willingness of parties. It establishes a regulator, but the regulator’s independence will be tested in practice and in constitutional litigation.

The next phase of Indian data protection law is likely to develop around five core issues.

First, whether Data Principals can maintain independent tort, consumer or constitutional claims despite Section 39.

Second, whether breach of DPDP obligations can be used as evidence of negligence or breach of duty.

Third, whether mediation under Section 31 can become a meaningful settlement mechanism.

Fourth, whether the Data Protection Board will be perceived as institutionally independent, especially in complaints involving State actors.

Fifth, how courts will balance privacy protection with public interest transparency under the RTI framework.


Conclusion

India has entered a new phase of digital rights enforcement. The DPDP Act gives the country a dedicated privacy statute and creates a specialised regulatory authority. However, meaningful privacy protection requires more than penalties. It requires effective remedies.

For Data Principals, the challenge will be converting statutory rights into practical relief.

For Data Fiduciaries, the challenge will be building compliance systems that are not merely policy-ready, but audit-ready, grievance-ready and breach-ready.

For the Data Protection Board, the challenge will be establishing independence, consistency and institutional trust.

The success of India’s DPDP framework will ultimately depend on whether it can bridge the gap between privacy as a statutory right and privacy as an enforceable remedy.


Resource References
  1. Digital Personal Data Protection Act, 2023.
  2. Digital Personal Data Protection Rules, 2025.
  3. MeitY notification and materials relating to the Data Protection Board of India.
  4. Information Technology Act, 2000, including the earlier Section 43A compensation framework.
  5. Consumer Protection Act, 2019.
  6. Mediation Act, 2023.
  7. Right to Information Act, 2005, particularly Section 8(1)(j).
  8. Constitution of India, Articles 14, 19(1)(a), 21, 32 and 226.
  9. Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1.
  10. Dhulabhai v. State of Madhya Pradesh, AIR 1969 SC 78.
  11. L. Chandra Kumar v. Union of India, (1997) 3 SCC 261.
  12. Nilabati Behera v. State of Orissa, (1993) 2 SCC 746.
  13. Central Public Information Officer, Supreme Court of India v. Subhash Chandra Agarwal, (2020) 5 SCC 481.
  14. Venkatesh Nayak v. Union of India, W.P.(C) No. 177 of 2026, Supreme Court of India, pending.
Disclaimer
This article is intended for general informational purposes only and does not constitute legal advice or a legal opinion. Readers should seek specific professional advice before acting on any issue discussed herein.

The Lord’s ConsultancyTax & Law Practitioners www.tlctaxlaw.com

Comments


bottom of page