Share 💬 💼
DPDP

Director's Personal Liability Under DPDPA: What Every CEO, CTO & Board Member Must Know

📅 Mar 25, 2026
👤 Adv. Deepak Kumar
⏱️ 15 min read
📂 DPDP
Director's Personal Liability Under DPDPA: What Every CEO, CTO & Board Member Must Know
DPDPA doesn't imprison directors — but the IT Act 2000 does. Every director "in charge" of a company that commits a data offence is deemed personally guilty under Section 85. This guide explains exactly which CXOs are at risk, when the corporate veil fails, and the 10 steps every director must take to protect themselves.
DPDP Act 2023 — Board & CXO Accountability

Most company directors believe that DPDPA compliance is an IT or legal team problem. It is not. Under the DPDP Act 2023, directors, CEOs, CFOs, CTOs, and senior officers can face direct personal financial liability for data protection failures — separate from and cumulative with the company's own penalty. This guide explains exactly how, when, and why individual officers are exposed — and what they must do to protect themselves.

⚠️ Key Facts — Director Liability Under DPDPA
  • DPDPA does not create criminal liability — penalties are civil and financial
  • The IT Act 2000 (Sections 66, 72, 72A) does create criminal liability for officers
  • Personal penalties on individual officers can reach ₹5 crore or more under related laws
  • Directors can be held liable for violations they did not personally carry out — constructive knowledge applies
  • A documented board-level data protection governance programme is the primary defence
  • The DPO (for SDFs) reports to the Board of Directors — making data protection a board obligation
📋 What This Guide Covers
  1. Does DPDPA create direct personal liability for directors?
  2. Where personal liability actually comes from — the full legal picture
  3. IT Act criminal liability for data breaches — what directors must know
  4. Constructive knowledge — "I didn't know" is not a defence
  5. Which C-suite roles carry the highest exposure
  6. How personal liability arises — real-world scenarios
  7. The board's affirmative duty under DPDPA
  8. How DPO accountability flows to the board
  9. The corporate veil — when it protects and when it doesn't
  10. How directors protect themselves — 10 practical steps
  11. What to put on the board agenda now

1. Does DPDPA Create Direct Personal Liability for Directors?

This is the first question every director asks — and the answer requires nuance rather than a simple yes or no.

Under the DPDPA 2023 itself: The Act does not create criminal liability for directors or individual officers. This was a deliberate policy choice — the government specifically designed the DPDPA as a civil penalty regime to avoid the chilling effect on India's digital economy that criminal exposure would create.

However — and this is critical — the DPDPA is not the only law that applies.

The real picture: Every data breach or data protection failure by your company triggers obligations under multiple Indian laws simultaneously — the DPDPA, the IT Act 2000, the Bharatiya Nyaya Sanhita 2023, and sector-specific regulations. Some of these carry criminal penalties. Some create direct personal liability on individual officers. The combination is far more dangerous than the DPDPA alone.

2. Where Personal Liability Actually Comes From — The Full Legal Picture

A director's personal exposure under data protection law comes from four distinct legal sources that operate simultaneously:

Source 1 — DPDPA 2023: Company Penalty + Board Governance Duty

Civil only

The DPDPA penalises the company — not the individual director — with fines up to ₹250 crore. However, for Significant Data Fiduciaries, the DPO is required to report directly to the Board of Directors, creating a formal governance obligation at board level. Failure to establish this oversight structure and act on DPO reports can support claims of board negligence in subsequent legal proceedings.

Individual exposure: Indirect — through reputational damage, shareholder liability, and contribution to conditions that enabled the violation

Source 2 — IT Act 2000: Criminal Liability for Officers

Criminal — imprisonment possible

The Information Technology Act 2000 continues to apply alongside DPDPA and creates direct personal liability on company officers:

Section 43A — Negligent data protection
Body corporate that negligently handles sensitive personal data causing wrongful gain/loss must pay damages to the affected person. No fixed cap — courts determine the amount. Officers responsible can face contribution claims.
Section 66 — Computer-related offences by companies
Where an offence under the IT Act is committed by a company, every person "in charge of and responsible to the company" at the time is deemed guilty. Punishment: imprisonment up to 3 years and/or fine up to ₹5 lakh. Directors and officers who were "in charge" face personal prosecution.
Section 72A — Unlawful disclosure of personal information
Disclosing personal data obtained under a service contract without consent: imprisonment up to 3 years or fine up to ₹5 lakh or both. This applies to individual officers who authorise or knowingly permit such disclosure.

Source 3 — Companies Act 2013: Director Duty of Care

Civil + regulatory

Section 166 of the Companies Act requires every director to act with due care, skill, and diligence. With data now a core business asset, failure to ensure DPDPA compliance can constitute a breach of a director's statutory duty of care — opening the door to shareholder derivative actions, NCLT proceedings, and personal disqualification.

Emerging standard: Just as directors are expected to oversee financial controls, they are increasingly expected to oversee data protection governance. A data breach caused by board-level neglect is analogous to a financial loss caused by negligent oversight.

Source 4 — Bharatiya Nyaya Sanhita 2023 (BNS): Data Theft

Criminal — imprisonment

India's new criminal code creates liability for theft of data and misuse of information. Officers who knowingly permit, authorise, or fail to prevent data theft can face personal prosecution under BNS provisions on cheating, breach of trust, and theft. This is particularly relevant where a data breach involved insider threats that were foreseeable but not prevented.

3. IT Act Criminal Liability — What Directors Must Know

The IT Act 2000's "deemed guilty" provision under Section 85 is the most significant personal liability risk for directors in India's data protection landscape. It states:

"Where a contravention of any of the provisions of this Act or of any rule, direction or order made thereunder has been committed by a company, every person who, at the time the contravention was committed, was in charge of, and was responsible to the company for the conduct of the business of the company, as well as the company, shall be deemed to be guilty of the contravention..."

Translation: If your company commits a data-related offence under the IT Act, every director and senior officer who was "in charge" at that time is automatically deemed to have committed the same offence — unless they can prove they had no knowledge and exercised due diligence.

The "Due Diligence" Defence

An officer can escape personal liability under the IT Act Section 85 only by proving both:

  • The contravention was committed without their knowledge, AND
  • They exercised all due diligence to prevent the contravention

This means passive ignorance is not enough. An officer must demonstrate active oversight — that they took reasonable steps to understand data protection risks and put controls in place. A director who simply said "that's the IT team's job" has no defence.

4. Constructive Knowledge — "I Didn't Know" Is Not a Defence

One of the most important and least understood aspects of officer liability in data protection law is the concept of constructive knowledge — you are treated as knowing something even if you did not actually know it, if you should have known it given your role and responsibilities.

👔
Managing Director / CEO
Deemed to know about consent violations if ordinary due diligence on customer account opening would have revealed them. Cannot claim ignorance of how the company's core product collects and processes customer data.
💻
Chief Technology Officer
Deemed to know about data breach risks if industry-standard security audits would have identified them. Failure to conduct or act on security assessments is itself a form of constructive knowledge of the risks.
📊
Chief Information Officer
Deemed to know about security configuration lapses if adequate audit procedures should have revealed them. Overseeing the IT infrastructure that processes personal data creates constructive knowledge of its security state.
⚖️
Chief Legal Officer / GC
Deemed to know about compliance gaps when they oversee legal and regulatory affairs. Failure to advise the board of DPDPA obligations can itself constitute a breach of professional duty.
💰
Chief Financial Officer
Exposure through financial controls — if budget was allocated to data protection but controls were not implemented, or if compliance costs were cut against advice, the CFO's decision-making is part of the compliance failure chain.
🏦
Non-Executive Directors
Not exempt — constructive knowledge can apply to NEDs who failed to discharge oversight duties, particularly in audit committee roles or where data protection was a board agenda item that was inadequately addressed.

5. How Personal Liability Arises — Real-World Scenarios

Scenario 1 — The CEO Who "Delegated" Data Protection
High personal risk

A FinTech CEO appointed an IT manager as "data protection lead" and considered the matter handled. The company collected customer Aadhaar and PAN numbers without proper consent notices. The Board never discussed data protection. A breach exposed 800,000 records.

Personal liability exposure:
Under IT Act Section 85 — deemed guilty of the company's data offences. Cannot claim ignorance when the company's core product processes financial data. "I delegated it" is not the IT Act's due diligence defence — the defence requires active oversight, not mere delegation. Criminal proceedings possible alongside company's DPDPA penalties.
Scenario 2 — The CTO Who Skipped the Security Audit
Very high personal risk

A SaaS company's CTO cancelled a scheduled security audit to save costs during a funding crunch. Six months later, an unpatched vulnerability was exploited. 2 million user records were stolen. The vulnerability would have been identified and patched had the audit taken place.

Personal liability exposure:
The CTO had constructive knowledge of the security risk — audits are the very tool that reveals such vulnerabilities. Cancelling the audit does not eliminate constructive knowledge; it actively destroys the due diligence defence. Under IT Act Section 43A, the company owes damages to all 2 million affected users. The CTO's decision was the proximate cause. Criminal exposure under IT Act Section 66 for negligent computer security.
Scenario 3 — The Board That Concealed a Breach
Extreme personal risk

A hospital's Board of Directors was briefed on a patient data breach. Fearing reputational damage before a planned IPO, they decided not to notify the Data Protection Board or affected patients. The concealment was discovered during IPO due diligence 4 months later.

Personal liability exposure:
Every director who participated in the concealment decision has direct, actual knowledge. DPDPA breach notification penalty: up to ₹200 crore on the company. IT Act liability: individual directors face personal prosecution for breach of confidentiality. SEBI action: concealment during IPO preparation constitutes a separate securities law violation. No due diligence defence — deliberate concealment is the opposite of due diligence.
Scenario 4 — The CFO Who Cut the Compliance Budget
Moderate personal risk

An e-commerce company's CFO cut the data protection budget over CLO objections, citing cost pressures. The CLO sent a written note to the board documenting the compliance risks of the budget cut. Eight months later, inadequate security led to a significant breach.

Personal liability exposure:
The CLO's written note creates a documented record that the risks were known and the decision was made anyway. The CFO's budget decision is a direct causal link in the compliance failure chain. While the CFO may avoid criminal prosecution (no direct IT offence), shareholder derivative action citing breach of director duty of care is viable. Regulatory investigations will examine board-level decision-making.

6. The Board's Affirmative Duty Under DPDPA

Beyond individual officer liability, the DPDPA creates a structural obligation at board level for organisations designated as Significant Data Fiduciaries. Even for standard Data Fiduciaries, the Act's gravity — and the penalties it carries — demands board-level attention.

Board Obligations Under DPDPA — Significant Data Fiduciaries
DPO Reports to Board
Section 10 requires the DPO to be responsible to the Board of Directors. This creates a formal information flow — the Board receives data protection reports and must act on them.
DPIA Oversight
The Board must ensure Data Protection Impact Assessments are conducted before high-risk processing — and must receive and consider their findings at board level.
Independent Audit Results
The independent data auditor's findings must flow to the Board. A board that receives adverse audit findings and fails to act on them has actual knowledge of compliance failures.
Budget & Resource Allocation
The Board is ultimately responsible for allocating adequate resources for data protection. Systematic under-resourcing in the face of known compliance obligations is a governance failure.

7. The Corporate Veil — When It Protects and When It Doesn't

Many directors assume the company's separate legal personality shields them from personal liability. In data protection, this assumption is increasingly unreliable.

✅ When the Corporate Veil Protects Directors
  • Genuine oversight exercised — board regularly reviewed data protection
  • Adequate budget allocated for compliance
  • Qualified personnel appointed (DPO, legal counsel)
  • Board acted on reports and audit findings
  • Individual director had no direct involvement in the violation
  • Company had documented compliance programme
  • Officer proactively escalated concerns before the violation
❌ When the Corporate Veil Fails Directors
  • Director was personally "in charge" under IT Act Section 85
  • Deliberate concealment of a breach — board decision
  • Director personally authorised the violating data practice
  • Company's compliance failure was the result of director's resource decisions
  • Director received warnings and ignored them
  • Director had a personal financial interest in the violation
  • No genuine oversight — compliance entirely delegated without monitoring

8. How Directors Protect Themselves — 10 Practical Steps

1
Put DPDPA on the Board Agenda — Formally
Data protection must appear as a standing agenda item in board meetings — not just when a crisis occurs. Create a Data Protection Committee or designate an existing committee. Minutes documenting board consideration of data protection provide evidence of governance.
2
Pass a Board Resolution on DPDPA Compliance
A formal board resolution authorising and mandating a DPDPA compliance programme — with named accountability, a timeline, and budget allocation — creates documented evidence that the Board took its governance duties seriously. This is a direct mitigation of the IT Act Section 85 "in charge" liability.
3
Engage Qualified Legal Counsel — and Document Their Advice
Seeking independent legal advice on DPDPA compliance — and acting on it — demonstrates due diligence. Communications between directors and their advocates are protected by legal professional privilege and cannot be compelled as evidence in Board proceedings.
4
Receive — and Respond to — Compliance Reports in Writing
When the DPO, legal team, or compliance officer raises a data protection issue in writing, board members must respond in writing — acknowledging receipt, requesting action plans, or approving remediation. Oral reassurances are invisible to a subsequent investigation.
5
Never Vote to Conceal a Data Breach
Concealing a breach is the fastest route from board governance failure to personal criminal liability. Any director who is present at a board discussion about concealing a breach — and does not dissent — is personally implicated. If a board moves to conceal, a director must formally dissent in the minutes.
6
Ensure Adequate Budget Is Allocated
Data protection compliance requires resources. Board approval of a dedicated compliance budget is documented evidence of commitment. If you vote against adequate compliance budget over legal counsel's objection, document your dissent — because the decision will be scrutinised if a breach follows.
7
Conduct a DPDPA Compliance Audit — and Receive the Report
A formal compliance audit that is presented to and acknowledged by the Board is evidence of active oversight. More importantly — act on the findings. A board that receives an audit finding gaps and does nothing has actual knowledge of non-compliance.
8
Understand Your Company's Data — Personally
Directors — especially CEOs, CTOs, and CIOs — should have a basic understanding of what personal data their company processes, how it is protected, and what would happen in a breach. This is not IT knowledge — it is governance knowledge. "I had no idea what data we were holding" is exactly the constructive knowledge problem.
9
Consider Directors' and Officers' (D&O) Insurance
D&O insurance policies increasingly include cyber liability and data protection clauses. Review your policy to ensure it covers data protection regulatory proceedings, legal defence costs, and personal civil liability arising from DPDPA and IT Act proceedings. This is no longer optional risk management for directors of data-intensive businesses.
10
Appoint Advocates Experienced in DPDPA — Not Just IT Lawyers
Data protection law sits at the intersection of privacy law, cyber law, corporate law, and sector regulation. Ensure the legal counsel advising your board on DPDPA has specific DPDPA and IT Act expertise — not just a general corporate practice. Communications with your advocates are privileged and provide the most legally protected evidence of your due diligence.

9. What to Put on the Board Agenda Now

If your board has not yet formally addressed DPDPA compliance, here is a minimum agenda for the next meeting:

📋 Recommended Board Resolution — DPDPA Governance
Resolution 1
The Board notes its obligations under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 and resolves that the company shall implement a documented DPDPA compliance programme by [date].
Resolution 2
[Named officer/role] is appointed as the accountable officer for DPDPA compliance and shall report to the Board on compliance status at each quarterly meeting.
Resolution 3
A budget of ₹[amount] is allocated for DPDPA compliance activities including legal advisory, privacy policy drafting, security safeguards, and staff training.
Resolution 4
The company shall retain [advocate firm] to conduct a DPDPA compliance audit and the findings shall be presented to the Board within [60/90] days.

Data Protection is a Board Issue — Not an IT Issue

The DPDPA era marks the point at which data protection governance became a board-level responsibility in India — comparable to financial governance, ESG oversight, and audit committee functions. Directors who treat it as someone else's problem face personal liability exposure they may not be aware of until it is too late.

The good news is that building the right governance structure — formal board oversight, documented compliance programme, qualified legal counsel, and a culture of transparency about data incidents — creates a robust personal defence while simultaneously protecting the company.

Our advocates advise boards and CXOs on DPDPA governance, personal liability exposure, and building documented compliance programmes that satisfy both the Data Protection Board and the requirements of the IT Act due diligence defence.

AD
Adv. Deepak Kumar
IP & Legal Expert · Vakil Help Desk
Our editorial team comprises experienced IP advocates, DPDPA compliance specialists, and legal professionals dedicated to making India's legal landscape accessible to every business. We cover trademark law, patent filing, copyright protection, and DPDP Act 2023 compliance.
Found this helpful? Share it →
💼 LinkedIn

Need Expert Help with DPDP?

Our team of advocates and compliance specialists are ready to help. Free consultation — response within 2 hours.

⚡ Get Free Consultation →
📋 Table of Contents
    Free Consultation
    Get expert advice on DPDP matters. We respond within 2 hours.
    Book Free Call → 💬 WhatsApp Us
    DPDPA Deadline
    Days to May 2027 enforcement
    Get Compliant Now →
    Get Free Consultation
    Call Now WhatsApp