Skip to content
DPDP Insurance IndiaNoida · DPDP · Cyber · Privacy
Home/DPDP Insurance
Cover 01 of 03

DPDP insurance for the day the Board asks questions

The Digital Personal Data Protection Act put a price on mishandled personal data, and the Rules notified in November 2025 set the clock running. DPDP insurance funds the defence, the representation and the penalties that Indian law allows anyone to insure.

Full compliance deadline

13 May 2027

Eighteen months from the notification of the DPDP Rules, when notices, safeguards, breach reporting and erasure obligations apply in full.

0Days
00Hours
00Mins
00Secs
The Schedule, drawn to scale

What non-compliance is worth, per violation

These are statutory maximums from the Schedule to the DPDP Act, not predictions. The Board weighs the nature of the breach, how many people were affected, your compliance history and what you did to fix it. Penalties stack: one incident can attract several heads at once.

Security safeguard failure
Up to ₹250 crore
Breach notification failure
Up to ₹200 crore
Children's data obligations
Up to ₹200 crore
Significant data fiduciary duties
Up to ₹150 crore
Other breaches of the Act
Up to ₹50 crore

The insurable line. Legal defence and representation costs are squarely insurable and are what these policies deliver first. Civil penalties can be covered where Indian law permits; criminal fines cannot be insured by anyone. Before you buy, ask to see the regulatory section of the wording and the definition of “penalty” in it. We put that clause in front of you unprompted.

What the Rules ask of you

Six duties every data fiduciary carries

Insurance sits on top of this, not instead of it. Underwriters will ask how far along you are on each line, and your answers move both the price and the claim.

01

Notice and consent

Every collection needs a clear, itemised notice and consent that is free, specific, informed and unconditional — in English or any language in the Eighth Schedule, at the data principal's choice.

02

Reasonable security safeguards

Encryption, access control, logging, monitoring and backups, with contractual obligations pushed down to every processor. This is the ₹250 crore line.

03

Breach reporting

Inform the Board without delay, then notify every affected data principal within 72 hours with a plain-language description and the steps they can take.

04

Erasure and retention

Delete personal data once the purpose is served or consent is withdrawn, subject to the retention periods set out in the Rules for specified classes of fiduciary.

05

Data principal rights

Access, correction, erasure, grievance redressal and nomination — with published contact details for the person who answers those requests.

06

Significant data fiduciary duties

If you are notified as an SDF: a DPO based in India reporting to the board, annual data protection impact assessment and independent audit.

What the policy does

Where DPDP insurance steps in

Funded The policy responds

  • Legal costs of responding to a Data Protection Board notice or inquiry
  • Representation through the proceeding, and appeals to the Appellate Tribunal
  • Privacy counsel to assess whether an incident is a reportable breach
  • Preparing and issuing the Board notification and data principal notices
  • Civil regulatory penalties, where the wording and Indian law allow
  • Forensic work needed to establish the scope of personal data affected
  • Crisis communications when the breach becomes public
  • Costs of a mandated remediation programme following the inquiry

Not funded You carry these

  • Criminal fines, which cannot be insured under Indian public policy
  • Building the compliance programme you should already have
  • Consent management tooling, DPO salary, audit fees in the ordinary course
  • Penalties arising from deliberate or fraudulent conduct by management
  • Failures you were already on notice about before the policy incepted
  • Contractual penalties you agreed with a customer without insurer consent
Where the lines fall

How the three covers divide the work

Same incident, three separate bills. Most businesses end up with all three sections on one policy; the useful thing is knowing which section is doing the paying.

DPDP (this page)CyberData privacy
Answers toThe regulatorYour own lossesOther people's claims
Typical triggerA Data Protection Board notice or inquirySystems encrypted, hacked or downA customer, employee or client alleges their data was mishandled
Pays forLegal defence, representation, insurable penaltiesForensics, restoration, downtime, extortionDamages, settlements, notification, credit monitoring
Biggest numberPenalty exposure up to ₹250 croreBusiness interruptionClass-style claims and enterprise contract liability
You need it ifYou are a data fiduciary — which is almost everyoneA day offline hurtsYou hold personal data belonging to people who can sue you
Before you renew

The DPDP readiness questions underwriters will ask

Answer these before you go to market. Every yes is leverage on price; every no is something to fix or disclose.

  1. Do you have a current inventory of the personal data you hold, and where it sits?
  2. Is your consent notice itemised, in plain language, and available in the languages the Rules require?
  3. Can you produce a consent record for any individual on request?
  4. Do your processor contracts pass down security and breach-notification obligations?
  5. Do you have a tested plan for notifying the Board and affected data principals within the clock?
  6. Are your backups immutable, and have you actually restored from them in the last year?
  7. Is MFA enforced on email, VPN and administrative access without exception?
  8. Do you know whether you are likely to be notified as a significant data fiduciary?
  9. Have you set retention periods and can you evidence erasure when consent is withdrawn?
  10. Is there a named person answering data principal requests, published on your website?

Score yourself honestly. Send us the list with your answers and we will tell you which gaps will cost you at underwriting and which are cheap to close before renewal.

FAQ

DPDP Act and insurance, answered

What is DPDP insurance?

It is the regulatory-liability part of a cyber policy, tuned to India's Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. It funds the legal defence of a Data Protection Board inquiry, representation through the proceeding, the cost of preparing breach notifications, and civil regulatory penalties to the extent Indian law and the policy wording permit them to be insured.

When do the DPDP obligations actually bite?

The Rules were notified on 13 November 2025. The Data Protection Board and its procedures came into effect immediately. Rule 4 on consent managers took effect one year later, in November 2026. The substantive obligations most businesses care about — notice, security safeguards, breach reporting, erasure and significant data fiduciary duties — come into force eighteen months from notification, on 13 May 2027.

What are the penalties under the DPDP Act?

The Schedule sets maximums of up to ₹250 crore for failing to take reasonable security safeguards, up to ₹200 crore each for failing to notify a breach and for breaching children's-data obligations, up to ₹150 crore for significant data fiduciary failures, and up to ₹50 crore for other breaches of the Act. Penalties are imposed per violation and one incident can attract more than one head.

Are DPDP penalties insurable in India?

Partly, and the wording decides. Defence and representation costs are insurable and are the core of what these policies deliver. Civil regulatory penalties can be covered where the law permits; criminal fines cannot be insured as a matter of public policy. Any broker who tells you a policy simply pays a ₹250 crore penalty has not read the wording. We mark the line clearly on the comparison sheet.

Who counts as a data fiduciary?

Any person who alone or with others determines the purpose and means of processing digital personal data. That is almost every business with customers, employees or users in India, including foreign companies offering goods or services to people in India. There is no small-business revenue threshold for the core obligations — only the significant data fiduciary tier adds extra duties.

Does insurance replace compliance?

No, and any policy that let it would not be underwritten. Insurers ask what you have built before they price the risk, and a claim gets read against what you declared. Think of insurance as funding the residual risk after the programme, not as a substitute for it. Businesses with a documented consent flow, a data inventory and a tested incident plan both pay less and claim more successfully.

What does the 72-hour rule mean in practice?

On becoming aware of a personal data breach you must inform the Board without delay, and then give affected data principals a plain-language description of the breach, the data involved, the steps they can take to protect themselves, and your contact details. At scale, that notification is an operation with a cost — which is exactly why it is an insured expense.

Get your DPDP exposure priced

We will map your obligations against the Rules, mark where insurance genuinely responds, and take the risk to insurers who write the regulatory section properly.

WhatsApp us Call +91 63070 73633