What can I do if my personal data is found leaked on the dark web?

I discovered that my Aadhaar number, phone number, and bank details are being sold on a dark web forum. What legal remedy do I have? I have been reading conflicting things online and I would like to understand what Indian law actually says about this, which Act and Section applies, what the realistic timelines and costs are, and what I should be doing right now to protect my position. If the matter can be resolved without litigation I would prefer that route, but I want to know what my rights are before I agree to anything or sign any document.

What can I do if my personal data is found leaked on the dark web? is governed in India primarily by Digital Personal Data Protection Act 2023, Section 8, Information Technology Act 2000, Section 43A, Information Technology Act 2000, Section 72A and CERT-In Directions 2022, Direction 3. The short answer is set out below, followed by the practical steps most people in this situation need to take. Read it alongside the specific provisions named, because the exact relief available to you turns on the facts you can prove on paper.

The entity that originally collected your data, called the data fiduciary, is obliged under Section 8 of the Digital Personal Data Protection Act 2023 to implement reasonable security safeguards and prevent such leaks.

A body corporate that is negligent in maintaining reasonable security practices and thereby causes wrongful loss is liable to pay compensation under Section 43A of the Information Technology Act 2000.

A person who discloses personal information obtained under a lawful contract without consent, with intent to cause wrongful loss, is punishable under Section 72A of the Information Technology Act 2000.

Under Direction 3 of the CERT-In Directions 2022, the affected organisation must report the data breach to CERT-In within six hours of noticing it, and you can seek confirmation of this from them.

You should also be alert to identity theft using the leaked data, which is separately punishable under Section 66C of the Information Technology Act 2000.

What to do next: 1) Change passwords and enable two-factor authentication on all linked accounts immediately; 2) Report the leak to cybercrime.gov.in and file a complaint against the entity that lost your data; 3) Send a written notice to the data fiduciary demanding details of the breach and remedial steps taken; 4) Monitor your credit report and bank statements for unauthorised activity.

If the other side has already issued a notice, filed a case or set a deadline, treat the matter as time-sensitive — most remedies under Digital Personal Data Protection Act 2023, Section 8 carry limitation periods, and a delay you cannot explain weakens an otherwise strong case. You can post the details on the MyVakeel forum for a practising advocate to review, or book a paid consultation with a Bar Council verified lawyer in this practice area.

Disclaimer: This information is for general awareness and does not constitute legal advice. Statutes and their interpretation change, and outcomes depend on the facts of your case. Please consult a qualified advocate before acting on it.