Directors, Data Privacy and Corporate Governance: Navigating the DPDP Act, 2023

Home     Articles      Directors, Data Privacy and Corporate Governance: Navigating the DPDP Act, 2023

Directors, Data Privacy and Corporate Governance: Navigating the DPDP Act, 2023

September 26, 2026

By: Manisha Kumari

Introduction

The enactment of the Digital Personal Data Protection Act, 2023 (“DPDP Act”) marks a significant shift in India’s data governance framework. While the Act primarily regulates the processing of digital personal data by Data Fiduciaries, its implications extend far beyond operational compliance. Boards of directors can no longer treat data protection as an issue confined to the IT or legal departments. Rather, privacy governance has become an essential component of enterprise risk management and corporate governance.

Although the DPDP Act does not expressly impose personal liability upon directors for every contravention committed by a company, directors continue to owe statutory and fiduciary duties under the Companies Act, 2013 to exercise due care, diligence and independent judgment. Consequently, the board’s oversight of data governance may become an important factor in determining whether directors have discharged these obligations.

This article examines the evolving responsibilities of company boards under the DPDP Act and analyses the legal framework governing director accountability.

The DPDP act: Liability Primarily rests with the Data Fiduciary

Unlike several Indian statutes that specifically create “offences by companies” provisions, the DPDP Act primarily imposes obligations upon the Data Fiduciary. The Act authorises the Data Protection Board of India to impose substantial monetary penalties for non-compliance, including failures relating to implementation of reasonable security safeguards, breach notifications, children’s data processing and fulfilment of data principal rights.

Importantly, the Act does not contain a blanket provision making every director personally liable merely because the company has violated the Act.

However, this should not be interpreted as insulating directors from regulatory scrutiny. Modern corporate governance increasingly evaluates whether boards exercised appropriate oversight over organisational compliance systems.

Reading the DPDP act with the Companies act, 2013

The responsibilities of directors arise not merely from the DPDP Act but also from Section 166 of the Companies Act, 2013.

Section 166 requires directors to:

  • act in good faith in promoting the objects of the company;
  • exercise due and reasonable care, skill and diligence;
  • exercise independent judgment; and
  • act in the best interests of the company, its shareholders, employees, customers and the community.

A significant data breach resulting from inadequate governance mechanisms, absence of internal controls or repeated compliance failures may therefore invite questions regarding whether the board discharged these statutory duties.

While monetary penalties under the DPDP Act may be imposed upon the company, shareholders, regulators and even courts may examine whether directors adequately supervised compliance systems.

Data Privacy as an Enterprise Risk

Historically, organisations viewed data privacy as a technical issue managed by information technology teams. The DPDP Act fundamentally changes this approach.

Personal data has become a strategic corporate asset. Consequently, privacy failures now expose organisations to:

  • regulatory penalties;
  • contractual claims;
  • shareholder actions;
  • reputational harm;
  • operational disruption;
  • loss of customer confidence.

Boards therefore need to classify data protection alongside cybersecurity, financial reporting, ESG compliance and anti-corruption frameworks as an enterprise-level risk requiring periodic oversight.

Board Oversight: What does good governance look like?

The board is not expected to manage day-to-day compliance. Rather, its role is one of governance and supervision.

An effective board should ensure that management has established:

  1. A documented privacy governance framework

The organisation should adopt documented policies governing data collection, processing, retention, deletion and access controls. Clear accountability structures should identify responsible personnel and reporting mechanisms.

  1. Periodic compliance reporting

Privacy compliance should become a standing agenda item before the board or an appropriate committee. Directors should periodically receive reports concerning:

  • ongoing compliance initiatives;
  • security incidents;
  • audit findings;
  • regulatory developments; and
  • high-risk processing activities.

Documenting such discussions through board minutes may also assist in demonstrating that directors exercised appropriate oversight.

  1. Cybersecurity integration

Data protection cannot be separated from cybersecurity. Boards should periodically review whether the organisation maintains reasonable technical safeguards, vulnerability assessments, access controls, encryption standards and incident response capabilities.

  1. Vendor governance

Most organisations rely extensively upon cloud service providers, payroll processors, HR platforms, software vendors and outsourced service providers. The DPDP Act continues to hold the Data Fiduciary accountable for personal data processed through such third parties. Boards should therefore ensure that vendor agreements incorporate appropriate contractual safeguards, confidentiality obligations, audit rights, breach notification requirements and security standards.

Incident Preparedness: Governance before crisis

One of the most significant indicators of board oversight is preparedness before a breach occurs.

Every organisation should maintain an incident response framework identifying:

  • reporting lines;
  • internal investigation procedures;
  • escalation protocols;
  • communication responsibilities;
  • regulatory notification mechanisms; and
  • business continuity measures.

Regular tabletop exercises and periodic review of incident response plans may significantly strengthen organisational resilience.

Insight from International Corporate Governance

The expectation of board-level oversight of data protection is not unique to India. International data protection and corporate governance frameworks increasingly recognise that privacy and cybersecurity are matters of enterprise risk rather than issues that can be left entirely to IT or compliance teams.

Under the EU GDPR, the principle of accountability requires organisations not only to comply with data protection obligations but also to be able to demonstrate such compliance. This has encouraged organisations to establish documented governance frameworks, appropriate technical and organisational measures, risk assessments and clear allocation of responsibility. For boards, the broader lesson is that privacy compliance should be capable of being demonstrated through effective oversight and documentation.

The United Kingdom follows a similar approach. The Information Commissioner’s Office emphasises leadership and oversight, including the involvement of senior management in data protection governance. The focus is not on making directors automatically liable for every privacy violation, but on ensuring that responsibility for compliance is appropriately allocated and effectively monitored.

In the United States, cybersecurity has increasingly become a corporate governance issue. The U.S. Securities and Exchange Commission requires public companies to disclose information concerning their cybersecurity risk management and the board’s oversight of cybersecurity risks.

These developments do not directly determine the liability of Indian directors. However, they demonstrate a broader international shift towards board-level accountability, documented oversight and active monitoring of material data and cybersecurity risks. For Indian companies, this provides useful context when considering the DPDP Act alongside directors’ duties under the Companies Act, 2013.

Practical Recommendations for Indian Boards

To demonstrate effective oversight, boards should consider:

  • conducting periodic data mapping exercises;
  • commissioning independent privacy audits;
  • reviewing high-risk data processing activities;
  • ensuring appropriate contractual protections with vendors;
  • providing periodic privacy training for employees and directors;
  • maintaining board-level reporting mechanisms; and
  • documenting compliance discussions in board minutes.

These measures not only strengthen compliance under the DPDP Act but also support directors in demonstrating that they exercised reasonable care and diligence under the Companies Act.

Conclusion

The DPDP Act should not be viewed merely as another compliance statute. It represents a shift in corporate governance expectations, requiring boards to recognise data protection as a strategic business risk.

Although the Act does not expressly impose automatic personal liability upon directors, board inaction may nevertheless become relevant when assessing whether directors fulfilled their statutory and fiduciary obligations under the Companies Act. Organisations that integrate privacy into board governance, risk management and compliance oversight will be better positioned to navigate the evolving regulatory landscape and strengthen stakeholder trust.

Join Our List To Stay In Touch

Leave your email id to receive regular updates on
corporate law changes that have impact on businesses.

     

    As per The Bar Council of India Rules and The Advocates Act, 1961, an advocate cannot approach his/her client or advertise or promote his profession by way of advertisements or solicitation. Thus the materials on this website are intended for informational purposes only. The materials on this website are neither intended to be, nor should they be interpreted as, legal advice or opinion. The reader should not consider this information to be an invitation to an attorney client relationship, should not rely on information presented here for any purpose, and should always seek the legal advice of counsel in the appropriate jurisdiction. Transmission and receipt of the information in this site and/or communication with the Samisti Legal LLP (“Samisti Legal / Firm”) via e-mail/ chat / blog or any other mode is not intended to solicit or create, and does not create, an attorney-client relationship between Samisti Legal and any person or entity. The information provided under this website is solely available at your request for informational purposes only, should not be interpreted as soliciting or advertisement…

    By accessing and using this site, the user expressly agrees with, and acknowledges, the following:

    • The user wishes to gain more information about Samisti Legal for his/her/its own information and use.
    • The user has not received any unsolicited invitation from Samisti Legal or any of its members or authorized representatives to view this website.
    • There has been no advertisement, personal communication, solicitation, invitation or inducement of any sort whatsoever to the user from Samisti Legal or any of its members or any authorized representative to solicit any work, including through this website.
    • The information about Samisti Legal is provided to the user only on his/her/its specific request, and any information obtained or materials downloaded from this website is completely at the user’s own volition.
    • Samisti Legal assumes no liability for the interpretation and/or use of the information contained or referred to on this website, nor does it offer a warranty of any kind, either expressed or implied.