DPDP Insurance
The regulatory cover. Defence costs for a Data Protection Board inquiry, representation, breach-notification expense and the penalties that are insurable under Indian law.
See what it coversThe DPDP Rules made data a balance-sheet risk with a number attached to it. We do one thing: place the three policies that fund that risk under Indian law, explain exactly where each one stops, and stay on the call when a breach turns into a claim.
Indicative cost of one breach
*A planning number, not a quote. It uses published per-record response costs and standard rates on line. Your actual premium depends on controls, claims history, sector and the insurer's underwriting. Send us the numbers and we will come back with a real one.
A breach costs you money three ways at once, and each one is answered by a different section of cover. Buy them together and the seams disappear. Buy one alone and you will find the seam at the worst moment.
The regulatory cover. Defence costs for a Data Protection Board inquiry, representation, breach-notification expense and the penalties that are insurable under Indian law.
See what it coversThe incident cover. Ransomware, system damage, business interruption, extortion handling, forensics and restoration — the money that gets your operation back on its feet.
See what it coversThe liability cover. Third-party claims from customers, employees and partners whose personal data you held, plus notification, credit monitoring and PR at scale.
See what it coversThese are not marketing figures. They come from the Digital Personal Data Protection Act, 2023 and the DPDP Rules notified on 13 November 2025.
Penalties are set out in the Schedule to the DPDP Act and are imposed per violation, so a single incident can attract more than one head of penalty. Sources: DPDP Act, 2023 and the Digital Personal Data Protection Rules, 2025.
Companies budget for the ransom and are blindsided by the other four lines. In most Indian claims the ransom is not even the biggest number.
Every hour your systems are down is revenue you do not bill and orders you do not ship. Business interruption is usually the largest line in an Indian cyber claim.
You cannot notify the Board accurately until you know what left the building. Incident response firms and privacy counsel are billed by the hour, from hour one.
The Rules require a plain-language notice to every affected data principal within 72 hours of the Board notification. At 200,000 users that is a project, not an email.
Up to ₹250 crore for a failure of reasonable security safeguards, and separately, whatever your customers and enterprise clients decide to claim from you.
A 30-minute call and a short data inventory. What personal data, whose, where it sits, which processors touch it, what your enterprise contracts already promise. Most gaps show up here, before any insurer is involved.
Underwriters price the story you give them. We write the risk narrative, evidence your controls — MFA, backups, logging, vendor contracts — and take it to the Indian cyber market together, so you get comparable terms instead of one take-it-or-leave-it quote.
Limits, sub-limits, retention, waiting period for business interruption, whether the regulatory section responds to a DPDP inquiry. Side by side, in English, with the exclusions marked in red rather than buried on page 14.
Cover is only worth what it pays. When something happens, you call one number, we trigger the insurer's incident response panel, help you meet the 72-hour notification clock, and run the claim to settlement.
Every broker will show you the left column. Read the right one before you sign; it is where claims are lost.
Read this bit. Sub-limits are where cover quietly shrinks. A ₹10 crore policy can carry a ₹50 lakh sub-limit on social engineering and a 12-hour waiting period before business interruption starts counting. We list every sub-limit on one page before you buy.
No Indian law makes DPDP or cyber insurance compulsory. What is now compulsory is the duty under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 to protect personal data, report breaches and face penalties of up to ₹250 crore if you fail. Insurance is how businesses fund that exposure, and enterprise customers increasingly write it into contracts.
Cyber insurance pays for the incident: forensics, restoration, ransom handling, downtime and extortion. DPDP insurance responds to the consequence in law: defence costs for a Data Protection Board inquiry, representation, and the penalties that are legally insurable. Most Indian businesses buy them as one policy with both sections switched on.
The working answer is the cost of your worst plausible breach, plus room for legal defence. For a company holding 50,000 customer records, response and liability costs typically land in the ₹1–5 crore band before any penalty. Use the exposure meter on this page for a starting number, then let us stress-test it against your actual data volumes and contracts.
Insurability of fines and penalties depends on the wording and on Indian public policy, which generally does not allow criminal fines to be insured. Indian cyber wordings do cover the legal and defence costs of a regulatory inquiry, and cover civil regulatory penalties where the law permits. We read the wording with you and mark plainly which part is funded and which part is not.
For a straightforward risk with a completed proposal form, quotes usually come back in two to four working days and cover can be bound the same day you accept. Larger limits, regulated sectors or a prior claim will add an underwriting call.
That is the part that matters. You get a named person, a call to the insurer's incident response panel within the hour, help drafting the Data Protection Board notification and the data principal notice, and we push the claim through to settlement rather than handing you a claim form.
The headline number gets quoted everywhere and understood almost nowhere. Here is how the Schedule is structured, what the Board weighs, and where insurance actually helps.
Premium is a function of six things, and you control four of them. A walk through how Indian underwriters price cyber risk, with the ranges we see in the market.
A composite of the pattern we see repeatedly: nine quiet days, one loud morning, and a loss run where the ransom is the fourth-largest line.
Send us your data volumes and your enterprise contracts. We will come back with a real quote, the sub-limits marked, and an honest view of whether you need all three covers or two.