By: Manisha Kumari
Introduction
The enactment of the Digital Personal Data Protection Act, 2023 (“DPDP Act”) marks a significant shift in India’s data governance framework. While the Act primarily regulates the processing of digital personal data by Data Fiduciaries, its implications extend far beyond operational compliance. Boards of directors can no longer treat data protection as an issue confined to the IT or legal departments. Rather, privacy governance has become an essential component of enterprise risk management and corporate governance.
Although the DPDP Act does not expressly impose personal liability upon directors for every contravention committed by a company, directors continue to owe statutory and fiduciary duties under the Companies Act, 2013 to exercise due care, diligence and independent judgment. Consequently, the board’s oversight of data governance may become an important factor in determining whether directors have discharged these obligations.
This article examines the evolving responsibilities of company boards under the DPDP Act and analyses the legal framework governing director accountability.
The DPDP act: Liability Primarily rests with the Data Fiduciary
Unlike several Indian statutes that specifically create “offences by companies” provisions, the DPDP Act primarily imposes obligations upon the Data Fiduciary. The Act authorises the Data Protection Board of India to impose substantial monetary penalties for non-compliance, including failures relating to implementation of reasonable security safeguards, breach notifications, children’s data processing and fulfilment of data principal rights.
Importantly, the Act does not contain a blanket provision making every director personally liable merely because the company has violated the Act.
However, this should not be interpreted as insulating directors from regulatory scrutiny. Modern corporate governance increasingly evaluates whether boards exercised appropriate oversight over organisational compliance systems.
Reading the DPDP act with the Companies act, 2013
The responsibilities of directors arise not merely from the DPDP Act but also from Section 166 of the Companies Act, 2013.
Section 166 requires directors to:
- act in good faith in promoting the objects of the company;
- exercise due and reasonable care, skill and diligence;
- exercise independent judgment; and
- act in the best interests of the company, its shareholders, employees, customers and the community.
A significant data breach resulting from inadequate governance mechanisms, absence of internal controls or repeated compliance failures may therefore invite questions regarding whether the board discharged these statutory duties.
While monetary penalties under the DPDP Act may be imposed upon the company, shareholders, regulators and even courts may examine whether directors adequately supervised compliance systems.
Data Privacy as an Enterprise Risk
Historically, organisations viewed data privacy as a technical issue managed by information technology teams. The DPDP Act fundamentally changes this approach.
Personal data has become a strategic corporate asset. Consequently, privacy failures now expose organisations to:
- regulatory penalties;
- contractual claims;
- shareholder actions;
- reputational harm;
- operational disruption;
- loss of customer confidence.
Boards therefore need to classify data protection alongside cybersecurity, financial reporting, ESG compliance and anti-corruption frameworks as an enterprise-level risk requiring periodic oversight.
Board Oversight: What does good governance look like?
The board is not expected to manage day-to-day compliance. Rather, its role is one of governance and supervision.
An effective board should ensure that management has established:
- A documented privacy governance framework
The organisation should adopt documented policies governing data collection, processing, retention, deletion and access controls. Clear accountability structures should identify responsible personnel and reporting mechanisms.
- Periodic compliance reporting
Privacy compliance should become a standing agenda item before the board or an appropriate committee. Directors should periodically receive reports concerning:
- ongoing compliance initiatives;
- security incidents;
- audit findings;
- regulatory developments; and
- high-risk processing activities.
Documenting such discussions through board minutes may also assist in demonstrating that directors exercised appropriate oversight.
- Cybersecurity integration
Data protection cannot be separated from cybersecurity. Boards should periodically review whether the organisation maintains reasonable technical safeguards, vulnerability assessments, access controls, encryption standards and incident response capabilities.
- Vendor governance
Most organisations rely extensively upon cloud service providers, payroll processors, HR platforms, software vendors and outsourced service providers. The DPDP Act continues to hold the Data Fiduciary accountable for personal data processed through such third parties. Boards should therefore ensure that vendor agreements incorporate appropriate contractual safeguards, confidentiality obligations, audit rights, breach notification requirements and security standards.
Incident Preparedness: Governance before crisis
One of the most significant indicators of board oversight is preparedness before a breach occurs.
Every organisation should maintain an incident response framework identifying:
- reporting lines;
- internal investigation procedures;
- escalation protocols;
- communication responsibilities;
- regulatory notification mechanisms; and
- business continuity measures.
Regular tabletop exercises and periodic review of incident response plans may significantly strengthen organisational resilience.
Insight from International Corporate Governance
The expectation of board-level oversight of data protection is not unique to India. International data protection and corporate governance frameworks increasingly recognise that privacy and cybersecurity are matters of enterprise risk rather than issues that can be left entirely to IT or compliance teams.
Under the EU GDPR, the principle of accountability requires organisations not only to comply with data protection obligations but also to be able to demonstrate such compliance. This has encouraged organisations to establish documented governance frameworks, appropriate technical and organisational measures, risk assessments and clear allocation of responsibility. For boards, the broader lesson is that privacy compliance should be capable of being demonstrated through effective oversight and documentation.
The United Kingdom follows a similar approach. The Information Commissioner’s Office emphasises leadership and oversight, including the involvement of senior management in data protection governance. The focus is not on making directors automatically liable for every privacy violation, but on ensuring that responsibility for compliance is appropriately allocated and effectively monitored.
In the United States, cybersecurity has increasingly become a corporate governance issue. The U.S. Securities and Exchange Commission requires public companies to disclose information concerning their cybersecurity risk management and the board’s oversight of cybersecurity risks.
These developments do not directly determine the liability of Indian directors. However, they demonstrate a broader international shift towards board-level accountability, documented oversight and active monitoring of material data and cybersecurity risks. For Indian companies, this provides useful context when considering the DPDP Act alongside directors’ duties under the Companies Act, 2013.
Practical Recommendations for Indian Boards
To demonstrate effective oversight, boards should consider:
- conducting periodic data mapping exercises;
- commissioning independent privacy audits;
- reviewing high-risk data processing activities;
- ensuring appropriate contractual protections with vendors;
- providing periodic privacy training for employees and directors;
- maintaining board-level reporting mechanisms; and
- documenting compliance discussions in board minutes.
These measures not only strengthen compliance under the DPDP Act but also support directors in demonstrating that they exercised reasonable care and diligence under the Companies Act.
Conclusion
The DPDP Act should not be viewed merely as another compliance statute. It represents a shift in corporate governance expectations, requiring boards to recognise data protection as a strategic business risk.
Although the Act does not expressly impose automatic personal liability upon directors, board inaction may nevertheless become relevant when assessing whether directors fulfilled their statutory and fiduciary obligations under the Companies Act. Organisations that integrate privacy into board governance, risk management and compliance oversight will be better positioned to navigate the evolving regulatory landscape and strengthen stakeholder trust.