Indian Cyber Risk Landscape
The legal setting for cyber risk in India: the IT Act and section 43A, CERT-In's six-hour reporting direction, the phased DPDP Act, 2023 with its penalties and Board, and sector rules including IRDAI's.
Where the rules come from
India's cyber-risk rules come from several sources: the Information Technology Act, 2000 and the rules made under it, the directions of CERT-In, the Digital Personal Data Protection Act, 2023 (DPDP Act), and sector rules issued by RBI, SEBI and IRDAI. A cyber policy's liability and regulatory covers respond to duties created by these laws, so the policy cannot be understood without them.
The IT Act and CERT-In
Section 43A of the IT Act deals with compensation for failure to protect data. A body corporate that handles sensitive personal data is liable to pay compensation if it is negligent in maintaining reasonable security practices and a person suffers loss as a result. The 2011 rules made under the Act set out what counts as sensitive personal data or information.
CERT-In's Directions of 28 April 2022 deal with incident reporting. The entities they cover, namely service providers, intermediaries, data centres, body corporates and government organisations, must report listed cyber incidents within 6 hours of noticing them or being told of them.
The DPDP Act in phases
The DPDP Act is being brought into force in phases. Its Rules were notified in November 2025, and its main duties and penalties take effect eighteen months later. Until then, section 43A and the 2011 rules remain the operative data-protection regime. The DPDP Act provides for the omission of section 43A when the Act's final phase commences.
The Schedule to the Act sets its highest penalty, up to ₹250 crore, for failing to take reasonable security safeguards to prevent a personal data breach. Other contraventions carry lower limits. These penalty provisions come into force in the last phase.
The Data Protection Board of India, set up under the Act, is the body that inquires into personal data breaches and complaints and can impose penalties, once the relevant provisions are in force. A person must first use the data fiduciary's own grievance process. Appeals from the Board lie to the Telecom Disputes Settlement and Appellate Tribunal.
Sector rules and a lesson from 2022
Regulated sectors carry extra duties. IRDAI's Information and Cyber Security Guidelines (2023) require insurers and other regulated entities to maintain information-security governance, carry out regular audits and report incidents.
The ransomware attack on AIIMS Delhi in November 2022 forced services to run manually for days. It exposed how vulnerable critical healthcare IT systems can be and strengthened calls for better incident-response planning in hospitals.
Rules at a glance
Which law applies today
Illustration: in October 2026 a payroll-processing company in Hyderabad discovers that employee bank details held for its clients have been taken. If it is an entity covered by CERT-In's directions and the incident is a listed one, it has 6 hours from noticing the incident to report it. A person who suffers loss because the company was negligent in its security practices looks to section 43A of the IT Act for compensation, because the DPDP Act's main duties and penalties have not yet commenced. Once they do, the Data Protection Board of India becomes the body that inquires into such a breach.
Key points
- Cyber-risk rules in India come from the IT Act, CERT-In's directions, the DPDP Act, 2023 and sector rules of RBI, SEBI and IRDAI.
- Section 43A of the IT Act provides compensation where a body corporate is negligent in protecting sensitive personal data and a person suffers loss.
- CERT-In's Directions of 28 April 2022 require covered entities to report listed incidents within 6 hours.
- The DPDP Rules were notified in November 2025; the main duties and penalties begin eighteen months later.
- The highest DPDP penalty is up to ₹250 crore, for failing to take reasonable security safeguards.
- The Data Protection Board of India inquires into breaches and complaints; appeals lie to the Telecom Disputes Settlement and Appellate Tribunal.
Common misunderstandings
- The DPDP Act is not yet fully in force: its main duties and penalties begin eighteen months after the Rules were notified in November 2025.
- Section 43A has not gone: it remains in force for now and is to be omitted when the DPDP Act's final phase commences.
- ₹250 crore is not the penalty for every contravention: it is the highest limit, and other contraventions carry lower limits.
- The Data Protection Board is not the first stop for a complaint: the data fiduciary's own grievance process comes first.
Questions people ask
Does the 6-hour rule start from the time of the attack?
It runs from the entity noticing the incident or being told of it, under CERT-In's Directions of 28 April 2022.
Who hears an appeal against the Data Protection Board's decision?
The Telecom Disputes Settlement and Appellate Tribunal.
Which regulator requires insurers to maintain information-security governance?
IRDAI, through its Information and Cyber Security Guidelines (2023), which also require regular audits and incident reporting.
What this lesson relies on
- Information Technology Act, 2000 — section 43A, and the 2011 rules on sensitive personal data or information
- CERT-In Directions of 28 April 2022
- Digital Personal Data Protection Act, 2023 and the Rules notified in November 2025
- IRDAI Information and Cyber Security Guidelines (2023)
This lesson was reviewed independently against these sources on 8 October 2026. Rules change: check the current regulation, scheme document or policy wording before relying on any figure. This is education, not advice.

