As a company, what is our liability if we negligently expose customer data?

Our company's database was left unsecured and customer personal data was exposed online due to an internal error, not a hack. I have been reading conflicting things online and I would like to understand what Indian law actually says about this, which Act and Section applies, what the realistic timelines and costs are, and what I should be doing right now to protect my position. If the matter can be resolved without litigation I would prefer that route, but I want to know what my rights are before I agree to anything or sign any document.

As a company, what is our liability if we negligently expose customer data? is governed in India primarily by Information Technology Act, 2000 – Section 43A, Digital Personal Data Protection Act, 2023 – Section 8 and Digital Personal Data Protection Act, 2023 – Section 33. The short answer is set out below, followed by the practical steps most people in this situation need to take. Read it alongside the specific provisions named, because the exact relief available to you turns on the facts you can prove on paper.

Section 43A of the IT Act holds a body corporate liable to compensate affected persons if it is negligent in implementing and maintaining reasonable security practices for sensitive personal data, resulting in wrongful loss or gain.

'Reasonable security practices' are typically interpreted with reference to internationally accepted standards like ISO/IEC 27001; failure to have and follow a documented security policy weighs heavily against the company in any claim.

Under the DPDP Act's Section 8, the breach must be reported to the Data Protection Board 'without delay' and to affected data principals in the prescribed manner, and delayed/non-reporting itself invites penalties under Section 33 (up to Rs 250 crore).

There is no statutory cap on Section 43A compensation, and multiple affected individuals could each claim damages, making swift containment and voluntary disclosure a mitigating factor in any regulatory proceeding.

Engage legal counsel and a forensic auditor immediately to document the root cause, remediation steps taken, and to prepare compliant breach notifications before any regulator or affected party files a complaint.

What to do next: 1) Immediately secure the exposed database and stop further data leakage; 2) Notify the Data Protection Board and affected individuals without delay; 3) Document remediation steps and engage a forensic auditor; 4) Prepare for potential Section 43A compensation claims by consulting counsel proactively.

If the other side has already issued a notice, filed a case or set a deadline, treat the matter as time-sensitive — most remedies under Information Technology Act, 2000 – Section 43A carry limitation periods, and a delay you cannot explain weakens an otherwise strong case. You can post the details on the MyVakeel forum for a practising advocate to review, or book a paid consultation with a Bar Council verified lawyer in this practice area.

Disclaimer: This information is for general awareness and does not constitute legal advice. Statutes and their interpretation change, and outcomes depend on the facts of your case. Please consult a qualified advocate before acting on it.