Does your company need cyber insurance to follow India's DPDP Law?

The DPDP Act doesn't require cyber insurance, but with penalties up to ₹250 crore, here's why more companies are buying it anyway.

Quick Answer

No, the Digital Personal Data Protection Act, 2023 (DPDP Act) does not make cyber insurance mandatory. It's a data protection law, not an insurance mandate, and nowhere does it require a company to hold a cyber insurance policy. What it does do is create serious financial exposure, penalties of up to ₹250 crore for certain violations, which is exactly why cyber insurance has become far more relevant to Indian businesses since the Act and its rules came into force. Compliance and insurance solve two different problems: compliance is about following the law in the first place, while insurance is a financial backstop for what happens when something still goes wrong.

Book a Demo

FAQ: People also ask

Is the DPDP Act enforced in India?

accordion icon

Yes, partially. The Data Protection Board of India was established as part of the DPDP Rules notification on November 13, 2025, and some provisions took effect immediately. Most day-to-day compliance obligations, such as consent and breach notification requirements, are being phased in over an 18-month period, with full enforcement expected around May 2027.

What are the latest updates on the DPDP Act?

accordion icon

The DPDP Rules, 2025 were notified by MeitY on November 13, 2025, alongside the establishment of the Data Protection Board of India. Implementation is phased, with governance structures and the Board's setup effective immediately, and most operational requirements, including consent mechanisms and breach notification, expected to be fully enforceable by mid-2027.

What are the penalties imposed under the DPDP Act?

accordion icon

Penalties vary by violation type and can reach up to ₹250 crore for failing to implement reasonable security safeguards, with other violations, including processing without valid consent or failing to notify a breach, carrying penalties of up to ₹200 crore. The Data Protection Board of India determines the actual amount based on the nature, gravity, and duration of the violation.

Should businesses conduct a cyber risk assessment before purchasing coverage?

accordion icon

Yes, generally. Understanding what personal data a company actually holds, how it's secured, and where the biggest gaps sit helps determine what cyber insurance coverage is actually needed, rather than purchasing a generic policy that may not address the company's real exposure.

Can cyber insurance directly cover DPDP penalties?

accordion icon

This isn't clearly established either way. Cyber insurance policies commonly cover breach response, legal, and notification costs, but regulatory fines and penalties are often excluded from standard coverage or only insurable under specific conditions, depending on the policy and applicable law. Since DPDP enforcement is still being phased in, it's best to confirm directly with an insurer how a specific policy treats regulatory penalties rather than assuming they're covered.