Skip to content
DPDP Insurance IndiaNoida · DPDP · Cyber · Privacy
Home/ Insights/Explainer
Explainer

DPDP, cyber or data privacy cover: which one does your business need?

Published 17 June 2026 · 6 min read · DPDP Insurance India

Ask three brokers what "cyber insurance" covers and you will get three answers, because the market uses cyber, DPDP and data privacy cover as near-synonyms in marketing and as distinct sections in the wording. The distinction matters when you are choosing limits, and it matters enormously at claim time.

Three names, one incident

The clean way to hold them apart is to ask who is asking you for money.

  • Cyber insurance answers your own losses. Nobody is suing you yet; your systems are down and rebuilding them costs money.
  • DPDP insurance answers the regulator. The Data Protection Board has questions, and answering them takes counsel, time and possibly a penalty.
  • Data privacy insurance answers everyone else. Customers, employees and the enterprise client whose data you processed under an indemnity you signed two years ago.

One ransomware event can trigger all three, in that order, over about nine months.

Side by side

DPDPCyberData privacy
Who claimsThe BoardYouIndividuals and clients
Typical triggerNotice or inquirySystems encrypted or downLegal claim or contractual indemnity
Largest lineDefence costs, then penaltiesBusiness interruptionSettlements and notification
TimingWeeks to monthsDaysMonths to years
Skip it if…You process no personal data at allDowntime genuinely costs you nothingNobody's personal data sits with you

Notice how implausible the last row gets after the first column. For almost every business with customers or employees in India, the honest answer is that all three sections should be switched on. The real question is how much limit sits behind each.

A decision path

  1. Does a day of downtime cost you real money? If yes, the cyber section carries your largest limit, and negotiate the business interruption waiting period hard.
  2. Do you hold personal data of people in India? Then you are a data fiduciary and the regulatory section is not optional. Check that it names the DPDP Act and the Board specifically, rather than referring vaguely to "applicable privacy regulation".
  3. Do you sign enterprise contracts with data-breach indemnities? If yes, read the cap. If the indemnity sits outside the general liability cap, size privacy liability against your client's potential loss, not your contract value.
  4. Do processors hold your data? Payroll, CRM, cloud, analytics. If yes, the wording must follow data into their systems, or your most likely breach is uninsured.
  5. How many records? Multiply by an indicative per-record response cost and you have the floor for the privacy section. Our exposure meter does this arithmetic.

Three expensive mistakes

Buying a limit that sounds round. ₹1 crore is chosen because it is a nice number, not because anyone modelled a breach. Size it against records and contracts.

Assuming "cyber" includes the regulator. Some wordings answer a Board inquiry properly, some gesture at it. Ask to see the regulatory clause before you sign, not after.

Ignoring the sub-limits. The headline limit is not what pays. Funds-transfer fraud, social engineering and notification costs routinely carry sub-limits at a fraction of the main limit, and that fraction is where most real claims land.

If you want this applied to your own numbers rather than in the abstract, send us your record count and your largest customer contract. That is usually enough to size all three sections in a single call.

Questions people ask

Can we buy just DPDP insurance without cyber cover?

In the Indian market these are almost always sections of a single cyber policy rather than standalone products. You can weight the limits toward the regulatory section, but buying the regulatory piece alone is rarely available and rarely sensible, since the same incident triggers both.

Which cover do enterprise customers usually require in contracts?

Most enterprise MSAs specify a cyber liability limit and require that privacy liability is included and extends to sub-processors. Send us the clause and we will confirm whether your current policy satisfies it.

Want this applied to your business? Send us your record count and your largest customer contract. We will come back with a sized limit and a market quote. Call +91 63070 73633 or use the enquiry form.

Keep reading

More insights

WhatsApp us Call +91 63070 73633