Does the DPDP Act make cyber insurance mandatory?
No. The DPDP Act, passed in August 2023 and operationalized through the DPDP Rules, 2025, notified by the Ministry of Electronics and Information Technology (MeitY) on November 13, 2025, doesn't contain any provision requiring companies to purchase cyber insurance. It's a data governance framework, setting out how organizations, called data fiduciaries under the Act, must collect, process, store, and secure the personal data of individuals, called data principals. Nothing in the Act or its Rules ties compliance status to holding an insurance policy.
Difference between being DPDP compliant and having cyber insurance
These are two separate things that are often confused with each other.
- DPDP compliance means actually meeting the law's requirements: obtaining valid consent, implementing reasonable security safeguards, enabling data principal rights such as access and correction, and notifying breaches to the Data Protection Board of India and affected individuals when required. Compliance is a legal and operational obligation, not something an insurance policy can substitute for.
- Cyber insurance is a financial product that helps cover the costs a company incurs after a cyber incident, breach response, forensic investigation, legal costs, business interruption, and third-party liability, depending on the policy. It doesn't make a company compliant with the DPDP Act, and it generally doesn't prevent a violation from happening in the first place.
| Feature |
DPDP Compliance |
Cyber Insurance |
| What It Is |
A legal and operational obligation under the DPDP Act |
A financial product purchased from an insurer |
| What It Covers |
Consent collection, security safeguards, data principal rights, breach notification |
Breach response, forensic investigation, legal costs, business interruption, third-party liability |
| Who It Protects |
Data principals, by requiring proper handling of their personal data |
The company, financially, after an incident occurs |
| Does It Prevent a Breach? |
Reduces risk when implemented properly, but doesn't guarantee prevention |
No, it responds after the fact rather than preventing the incident |
| Can One Replace the Other? |
No, a company can have insurance and still be non-compliant |
No, a company can be compliant and still have no insurance |
A company can be fully DPDP compliant and still choose not to carry cyber insurance, and a company can carry a comprehensive cyber insurance policy while still being non-compliant with the DPDP Act's actual requirements. The two need to be pursued separately, not treated as substitutes for each other.
Why has cyber insurance become more relevant under the DPDP Act?
- The financial stakes of a breach just went up substantially: With penalties potentially reaching ₹250 crore for serious violations, the cost of getting data security wrong is no longer a vague reputational risk, it's a defined, material financial exposure.
- Breach response itself is expensive, regardless of penalties: Forensic investigation, legal counsel, notifying affected individuals and the Data Protection Board, and any resulting business interruption all cost money well before any penalty is even assessed. This is true even outside a DPDP context, ransomware alone has become one of the costlier incidents Indian businesses face, and whether a cyber policy actually responds to a ransomware attack often comes down to specific policy conditions worth understanding in advance.
- Enforcement infrastructure now exists: The Data Protection Board of India was established as part of the November 2025 notification, giving the DPDP Act an active enforcement body with the power to investigate complaints and impose penalties, rather than a law with no mechanism to act on it.
- The compliance runway is closing: Most operational obligations under the DPDP Rules are being phased in over 18 months, with full compliance expected by mid-May 2027, which means the window to get security practices, and financial protection, in order is a defined and shrinking one.
What penalties can companies face under the DPDP Act?
The DPDP Act sets out penalties by violation type, with the Data Protection Board of India assessing the actual amount based on the nature, gravity, duration, and impact of the non-compliance, along with the fiduciary's compliance history. Reported penalty tiers include:
- Up to ₹250 crore for failing to implement reasonable security safeguards to prevent a personal data breach.
- Up to ₹200 crore for processing personal data without valid consent.
- Up to ₹200 crore for failing to fulfil additional obligations related to children's personal data.
- Up to ₹200 crore for failing to notify the Data Protection Board and affected individuals of a personal data breach.
These are per-violation penalties, which means a single incident affecting a large number of individuals could potentially trigger multiple counts rather than one flat fine.
What does the DPDP Act require companies to do?
- Obtain valid, informed consent before processing an individual's personal data, with clear notice of what data is collected and why.
- Implement reasonable security safeguards to prevent personal data breaches, a requirement carrying the Act's highest penalty tier when it isn't met.
- Enable data principal rights, including the right to access, correct, and request erasure of personal data.
- Notify the Data Protection Board of India and affected individuals in the event of a personal data breach, within the timelines the DPDP Rules prescribe.
- Limit data retention to what's necessary for the purpose it was collected for, rather than holding personal data indefinitely.
- Manage processor relationships carefully, since obligations extend to any third party a data fiduciary shares personal data with for processing.
What happens when a company suffers a data breach?
Under the DPDP framework, a data fiduciary that suffers a personal data breach is expected to notify both the Data Protection Board of India and the affected data principals, within the timelines set out in the DPDP Rules.
The Board then has the authority to investigate the incident, and can examine whether the company had implemented reasonable security safeguards in the first place, whether the breach was notified appropriately, and whether the company's broader data handling practices met the Act's requirements. Where the Board finds non-compliance, it can direct remedial measures and impose penalties under the tiers described above, in addition to any reputational impact from the breach becoming public.
Separately from the regulatory process, the company still has to fund the immediate practical costs of responding to the breach itself, forensic investigation, system remediation, customer notification, and legal advice, regardless of what the Board eventually decides.
Does cyber insurance cover DPDP penalties?
This is genuinely uncertain, and worth understanding clearly rather than assuming either way. Cyber insurance policies typically cover costs like breach response, forensic investigation, legal defense costs, notification expenses, and certain third-party liability claims, and understanding exactly what a cyber policy tends to cover and where the common gaps sit is a useful starting point before assuming any specific cost, including a DPDP penalty, falls under it. Statutory fines and regulatory penalties, however, are frequently excluded from standard cyber insurance coverage, or only insurable in limited circumstances depending on the policy wording and applicable law, since many jurisdictions treat regulatory penalties as a matter of public policy that insurance shouldn't be used to soften. Because the DPDP Act's enforcement mechanism is still new, with full penalty enforcement expected around May 2027, there isn't yet a settled market practice in India on whether, or how, DPDP-specific penalties will be treated under cyber insurance policies. What cyber insurance can more reliably help with is the surrounding cost of a breach, the investigation, the legal defense, and the response, even if the penalty itself sits outside what the policy pays for. This is exactly why the specific policy wording matters, and why it's worth reviewing directly with an insurer or broker rather than assuming coverage either way.
Protect your business against cyber risks with cyber insurance
Even setting the DPDP Act's penalty structure aside, a cyber incident is expensive to respond to on its own terms, and this is worth planning for as a distinct financial risk alongside DPDP compliance work, not as an afterthought to it.
- Breach response cost coverage: cyber insurance typically covers forensic investigation, legal counsel, and crisis management costs incurred immediately after a breach is discovered.
- Notification and credit monitoring costs: many policies cover the cost of notifying affected individuals and offering monitoring services where required.
- Business interruption coverage: where a cyberattack disrupts operations, some policies cover the resulting loss of income during downtime.
- Third-party liability protection: if affected individuals or business partners bring claims following a breach, cyber insurance can cover legal defense and settlement costs, depending on the policy.
Pazcare works with businesses to structure cyber insurance coverage that reflects their actual data handling risk, comparing across insurers so the policy addresses real exposure rather than a generic template. Talk to a Pazcare cyber insurance expert to review your current coverage against your DPDP compliance exposure.