A company leaked my personal data in a breach, can I claim compensation?

An app or company I used had a data breach and my personal information including phone number and address is now circulating online. I have been reading conflicting things online and I would like to understand what Indian law actually says about this, which Act and Section applies, what the realistic timelines and costs are, and what I should be doing right now to protect my position. If the matter can be resolved without litigation I would prefer that route, but I want to know what my rights are before I agree to anything or sign any document.

A company leaked my personal data in a breach, can I claim compensation? is governed in India primarily by Digital Personal Data Protection Act, 2023 – Section 8, Information Technology Act, 2000 – Section 43A and Digital Personal Data Protection Act, 2023 – Section 33. The short answer is set out below, followed by the practical steps most people in this situation need to take. Read it alongside the specific provisions named, because the exact relief available to you turns on the facts you can prove on paper.

Section 43A of the IT Act makes a body corporate liable to pay compensation if it fails to implement reasonable security practices while handling sensitive personal data and this causes wrongful loss to you.

Under the DPDP Act, 2023, data fiduciaries must implement 'reasonable security safeguards' (Section 8(5)) and report personal data breaches to the Data Protection Board and affected individuals without delay (Section 8(6)).

The Data Protection Board of India, once fully operational, can impose penalties up to Rs 250 crore on the company under Section 33 for failure to prevent a data breach, though this penalty goes to the government, not to you directly.

You retain the separate civil right to sue for compensation under Section 43A of the IT Act before the adjudicating officer (usually the state IT Secretary) if you can show quantifiable loss, without needing to file a full civil suit.

Also file a complaint at cybercrime.gov.in so that any onward misuse of your leaked data (like fraud calls) is tracked and linked to the original breach.

What to do next: 1) Ask the company in writing for details of the breach and what data was exposed; 2) File a complaint with the Data Protection Board once your grievance to the company is unresolved; 3) Approach the adjudicating officer under Section 43A IT Act for compensation; 4) Monitor your accounts and report any resulting fraud separately at cybercrime.gov.in.

If the other side has already issued a notice, filed a case or set a deadline, treat the matter as time-sensitive — most remedies under Digital Personal Data Protection Act, 2023 – Section 8 carry limitation periods, and a delay you cannot explain weakens an otherwise strong case. You can post the details on the MyVakeel forum for a practising advocate to review, or book a paid consultation with a Bar Council verified lawyer in this practice area.

Disclaimer: This information is for general awareness and does not constitute legal advice. Statutes and their interpretation change, and outcomes depend on the facts of your case. Please consult a qualified advocate before acting on it.