Customer and user claims
Individuals whose personal data was exposed, acting alone or in numbers. Defence costs, settlements and the cost of running the response.
The regulator is not the only one with a case against you. The people whose data you held have rights, and the enterprise client whose records you processed has an indemnity clause. This is the cover that answers them.
Incident contained. Cyber section pays the response.
Board notified, data principals notified. Privacy section funds the notification.
Enterprise client invokes the indemnity in the MSA.
Individual claims and grievances land. Defence costs run for years.
Individuals whose personal data was exposed, acting alone or in numbers. Defence costs, settlements and the cost of running the response.
The indemnity you signed in an MSA or data processing agreement. Frequently uncapped for data breach, and frequently the largest claim you will ever see.
Your payroll provider, CRM or cloud host loses data you are responsible for. The claim still lands on you, so the cover has to follow the data.
HR records, payroll, health and background-check data. Same statutory rights, systems that are often less hardened than the customer database.
Identifying who was affected, notifying them within the clock, staffing the questions that follow, and funding credit or identity monitoring.
Defamation, IP infringement and privacy breaches arising from your own digital content and marketing. Usually bundled in this section.
The Rules require a plain-language notice to every affected data principal within 72 hours of notifying the Board. Here is roughly what that costs before anyone files a claim.
| Records affected | Indicative notification cost | What the money buys |
|---|---|---|
| 10,000 | ₹8 – 20 lakh | Email notice, small support load, limited monitoring |
| 1 lakh | ₹45 lakh – ₹1.2 crore | Verified contact data, drafted notice, temporary call handling |
| 10 lakh | ₹3 – 8 crore | Call centre, monitoring offers, sustained legal and PR support |
| 1 crore | ₹15 crore and upward | Multi-month programme, regulator scrutiny, contractual claims in parallel |
Planning ranges based on published breach-response cost benchmarks and Indian vendor pricing. Your number depends on data quality, sector and whether monitoring is offered.
Same incident, three separate bills. Most businesses end up with all three sections on one policy; the useful thing is knowing which section is doing the paying.
| DPDP | Cyber | Data privacy (this page) | |
|---|---|---|---|
| Answers to | The regulator | Your own losses | Other people's claims |
| Typical trigger | A Data Protection Board notice or inquiry | Systems encrypted, hacked or down | A customer, employee or client alleges their data was mishandled |
| Pays for | Legal defence, representation, insurable penalties | Forensics, restoration, downtime, extortion | Damages, settlements, notification, credit monitoring |
| Biggest number | Penalty exposure up to ₹250 crore | Business interruption | Class-style claims and enterprise contract liability |
| You need it if | You are a data fiduciary — which is almost everyone | A day offline hurts | You hold personal data belonging to people who can sue you |
Before buying a limit, read the indemnity you have already signed. Four clauses decide how much cover you actually need.
Send us the clause. Paste the insurance and indemnity sections of your largest customer contract into an email. We will tell you within a day whether your current policy satisfies it.
It is the third-party liability half of a cyber programme. Where cyber insurance pays your own losses and DPDP insurance answers the regulator, data privacy insurance answers the people whose personal data you held — customers, employees, patients, users and the enterprise clients whose data you processed. It funds defence, settlements and the notification machinery that follows a breach.
Individuals now have a statutory grievance route to you and then to the Data Protection Board. Separately, your enterprise customers can sue on the indemnity in your MSA or DPA, which is often uncapped for data breach — and that contractual route is usually the larger number. If you process data for overseas clients, GDPR-style claims and contractual damages can reach you too.
It scales with your record count and it is rarely just an email. Identifying affected individuals, verifying contact details, drafting a notice that meets the Rules, running a call centre for the questions that follow, and offering credit or identity monitoring where it is warranted. At a million records this is a seven-figure project before a single claim is filed.
Usually a certificate showing a named limit, that privacy liability is included rather than excluded, that the cover extends to data held by your sub-processors, and sometimes that the client is an additional insured. We read the MSA clause and place cover that actually satisfies it rather than one that looks close.
It should. Vicarious liability for processors is one of the clauses we check first, because most Indian businesses now run payroll, CRM and infrastructure through third parties. If the wording only covers data on your own systems, it will not respond to the most likely breach you face.
Yes under most wordings, and it matters more than people expect. HR files, payroll, background checks and health information sit in systems that are often less protected than customer databases, and employees are data principals with the same rights.
Privacy liability is the section most often bought too small. Let us size it against your record count and the indemnities you have already signed.