Skip to content
DPDP Insurance IndiaNoida · DPDP · Cyber · Privacy
Noida · India-wide · DPDP specialists

DPDP, cyber and data privacy insurance, built for Indian businesses

The DPDP Rules made data a balance-sheet risk with a number attached to it. We do one thing: place the three policies that fund that risk under Indian law, explain exactly where each one stops, and stay on the call when a breach turns into a claim.

Same-day response on enquiries 24×7 claims line Deadline: 13 May 2027

Exposure meter

Live estimate
₹10L ₹100Cr
₹0

Indicative cost of one breach

Suggested sum insured
₹5 Cr
Indicative premium
₹3.7 L*

*A planning number, not a quote. It uses published per-record response costs and standard rates on line. Your actual premium depends on controls, claims history, sector and the insurer's underwriting. Send us the numbers and we will come back with a real one.

Ransomware — production halted, ransom demanded, data leakedBusiness email compromise — vendor payment diverted mid-invoiceCloud misconfiguration — S3 bucket left open, records scrapedInsider exfiltration — departing employee copies the CRMDPDP Board inquiry — notice served after a reported breachThird-party processor breach — your data, your vendor's failureCredential stuffing — customer accounts drained overnightRegulatory penalty — up to ₹250 crore for safeguard failuresRansomware — production halted, ransom demanded, data leakedBusiness email compromise — vendor payment diverted mid-invoiceCloud misconfiguration — S3 bucket left open, records scrapedInsider exfiltration — departing employee copies the CRMDPDP Board inquiry — notice served after a reported breachThird-party processor breach — your data, your vendor's failureCredential stuffing — customer accounts drained overnightRegulatory penalty — up to ₹250 crore for safeguard failures
The three covers

One incident. Three very different bills.

A breach costs you money three ways at once, and each one is answered by a different section of cover. Buy them together and the seams disappear. Buy one alone and you will find the seam at the worst moment.

DPDP Insurance

The regulatory cover. Defence costs for a Data Protection Board inquiry, representation, breach-notification expense and the penalties that are insurable under Indian law.

See what it covers

Cyber Insurance

The incident cover. Ransomware, system damage, business interruption, extortion handling, forensics and restoration — the money that gets your operation back on its feet.

See what it covers

Data Privacy Insurance

The liability cover. Third-party claims from customers, employees and partners whose personal data you held, plus notification, credit monitoring and PR at scale.

See what it covers
What the law now says

The numbers you are underwriting against

These are not marketing figures. They come from the Digital Personal Data Protection Act, 2023 and the DPDP Rules notified on 13 November 2025.

₹250 CrMaximum penalty for failing to keep reasonable security safeguards
₹200 CrMaximum penalty for not reporting a personal data breach properly
72 hrsTo notify affected data principals after notifying the Board
13 May 2027When the substantive obligations bite in full for every data fiduciary

Penalties are set out in the Schedule to the DPDP Act and are imposed per violation, so a single incident can attract more than one head of penalty. Sources: DPDP Act, 2023 and the Digital Personal Data Protection Rules, 2025.

Where the money goes

What a breach actually costs, line by line

Companies budget for the ransom and are blindsided by the other four lines. In most Indian claims the ransom is not even the biggest number.

Downtime

Every hour your systems are down is revenue you do not bill and orders you do not ship. Business interruption is usually the largest line in an Indian cyber claim.

Forensics and legal

You cannot notify the Board accurately until you know what left the building. Incident response firms and privacy counsel are billed by the hour, from hour one.

Notification at scale

The Rules require a plain-language notice to every affected data principal within 72 hours of the Board notification. At 200,000 users that is a project, not an email.

Penalties and claims

Up to ₹250 crore for a failure of reasonable security safeguards, and separately, whatever your customers and enterprise clients decide to claim from you.

How we work

Four steps, and the fourth is the one that counts

Step 01

We map what you actually hold

A 30-minute call and a short data inventory. What personal data, whose, where it sits, which processors touch it, what your enterprise contracts already promise. Most gaps show up here, before any insurer is involved.

Step 02

We build the submission insurers say yes to

Underwriters price the story you give them. We write the risk narrative, evidence your controls — MFA, backups, logging, vendor contracts — and take it to the Indian cyber market together, so you get comparable terms instead of one take-it-or-leave-it quote.

Step 03

You choose from a plain comparison

Limits, sub-limits, retention, waiting period for business interruption, whether the regulatory section responds to a DPDP inquiry. Side by side, in English, with the exclusions marked in red rather than buried on page 14.

Step 04

We answer the phone at 2am

Cover is only worth what it pays. When something happens, you call one number, we trigger the insurer's incident response panel, help you meet the 72-hour notification clock, and run the claim to settlement.

The honest version

What these policies pay for — and what they never will

Every broker will show you the left column. Read the right one before you sign; it is where claims are lost.

Covered Typically inside the policy

  • Forensic investigation and incident response
  • Ransomware negotiation, and ransom where lawfully payable
  • Data and system restoration
  • Business interruption and extra expense
  • Breach notification to data principals and the Board
  • Legal defence and regulatory representation
  • Third-party privacy liability and settlements
  • Crisis PR and customer credit monitoring
  • Funds-transfer fraud and social engineering (sub-limited)

Excluded Typically outside it

  • Upgrading systems you should already have patched
  • Loss of value in your own intellectual property
  • Criminal fines, and penalties the law will not let anyone insure
  • Bodily injury and physical property damage
  • Anything you knew about before the policy started
  • War and state-backed attack, subject to the wording
  • Contractual penalties you agreed to without cover
  • Failure to maintain the controls you declared at proposal

Read this bit. Sub-limits are where cover quietly shrinks. A ₹10 crore policy can carry a ₹50 lakh sub-limit on social engineering and a 12-hour waiting period before business interruption starts counting. We list every sub-limit on one page before you buy.

Questions we get every week

Cyber and DPDP insurance, answered

Is DPDP insurance mandatory in India?

No Indian law makes DPDP or cyber insurance compulsory. What is now compulsory is the duty under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 to protect personal data, report breaches and face penalties of up to ₹250 crore if you fail. Insurance is how businesses fund that exposure, and enterprise customers increasingly write it into contracts.

What is the difference between DPDP insurance and cyber insurance?

Cyber insurance pays for the incident: forensics, restoration, ransom handling, downtime and extortion. DPDP insurance responds to the consequence in law: defence costs for a Data Protection Board inquiry, representation, and the penalties that are legally insurable. Most Indian businesses buy them as one policy with both sections switched on.

How much cyber insurance cover does a business in India need?

The working answer is the cost of your worst plausible breach, plus room for legal defence. For a company holding 50,000 customer records, response and liability costs typically land in the ₹1–5 crore band before any penalty. Use the exposure meter on this page for a starting number, then let us stress-test it against your actual data volumes and contracts.

Can DPDP penalties actually be insured?

Insurability of fines and penalties depends on the wording and on Indian public policy, which generally does not allow criminal fines to be insured. Indian cyber wordings do cover the legal and defence costs of a regulatory inquiry, and cover civil regulatory penalties where the law permits. We read the wording with you and mark plainly which part is funded and which part is not.

How fast can a policy be placed?

For a straightforward risk with a completed proposal form, quotes usually come back in two to four working days and cover can be bound the same day you accept. Larger limits, regulated sectors or a prior claim will add an underwriting call.

Do you help when a claim happens?

That is the part that matters. You get a named person, a call to the insurer's incident response panel within the hour, help drafting the Data Protection Board notification and the data principal notice, and we push the claim through to settlement rather than handing you a claim form.

Insights

Plain-English notes on India's data risk

Find out what one breach would cost you

Send us your data volumes and your enterprise contracts. We will come back with a real quote, the sub-limits marked, and an honest view of whether you need all three covers or two.

WhatsApp us Call +91 63070 73633