Data Protection and Privacy 2025

INDIA Law and Practice Contributed by: Suvarna Mandal and Rishikaa, Saikrishna & Associates

Cybersecurity Law For non-compliance with the cybersecurity requirements under the CERT-IN Directions, the IT Act prescribes imprisonment for up to one year or a fine of up to INR1 crore (approximately USD116,000), or both. 1.4 Data Protection Fines in Practice Orders pertaining to contravention of the SPDI Rules issued by the AO are infrequent and per - tain to negligence in implementing and maintain - ing reasonable security practices and proce - dures, causing wrongful loss or wrongful gain to any person. According to the publicly available orders, AOs have awarded compensation rang - ing from INR50,000 to INR1.3 crore (approxi - mately USD575 to USD150,000). These cases largely pertained to telecoms service providers, banks and other financial institutions. While there is information about investigations and probes conducted by the CERT-IN, there is no publicly available information regarding any fines imposed by the CERT-IN in case of a cyber - security incident. Once the DPDP Act comes into force and the DPB becomes fully operational, the jurispru - dence in this area will develop further. 1.5 AI Regulation At present, there is no specific law pertaining to the regulation of AI in India. However, the devel - opment, deployment and use of AI technologies are subject to prevailing laws and regulations in other areas of law, such as data protection, intellectual property, intermediary liability, etc. Moreover, any entity deploying AI that qualifies as an intermediary under the IT Act would have to comply with the due diligence requirements provided in the Information Technology (Inter -

• inquire into a personal data breach; • direct urgent remedial or mitigation measures in the event of a personal data breach; • impose penalties for such breaches; and • function as a civil court in respect of: (a) summoning, enforcing the attendance of, and examining any person; (b) receiving evidence; (c) inspecting any data, book, document, etc; and (d) any other matters that may be prescribed through rules. Upon the communication of a personal data breach, a complaint from a Data Principal or a reference made by the government regarding a breach in observing directions made to an intermediary, the DPB will determine if there are sufficient grounds to proceed with the inquiry and record its reasons for its actions during the inquiry. The DPB cannot prevent access nor seize any equipment capable of adversely affecting the daily functioning of a person. The DPB will function as an independent digital office and would adopt the techno-legal meas - ures as may be prescribed in the rules. The Draft DPDP Rules do not specifically propose such measures and simply state that the DPB may adopt techno-legal measures that do not require the physical presence of any individual. This, however, will not affect that power of the DPB to summon and enforce attendance. The DPDP Act prescribes monetary penalties of INR50 crore (approximately USD5.75 million) up to INR250 crore (approximately USD28.5 million) depending on the nature of the contravention of provisions of the DPDP Act.

191 CHAMBERS.COM

Powered by