AMLEGALS — Strategic Lawyering
Finance — Exposure, Insurability, Provisioning

DPDPA for the CFO

Every privacy briefing a finance function receives ends at the number. Very few explain what the number is, who fixes it, whether an insurer will pay it, and which line of the accounts it belongs on before it is fixed.

Schedule to Section 33Section 33(2) FactorsInsurabilityInd AS 37Section 32 Undertaking

A cyber policy pays for the response. It does not ordinarily pay the penalty. The distinction is the whole of the finance case for building compliance before the event.

The Position in One Paragraph

What a DPDPA penalty is, in financial terms

A DPDPA penalty is a civil monetary penalty imposed by the Data Protection Board of India under Section 33, within the ceilings set by the Schedule, on the factors listed in Section 33(2). Sums realised are credited to the Consolidated Fund of India under Section 34. An appeal lies to the Appellate Tribunal under Section 29.

Because it is a penalty for the company's own statutory breach, it is not ordinarily an insurable loss. Indian cyber wordings generally exclude fines and penalties. What such policies cover is the cost of response, namely forensics, legal representation, notification, monitoring and third party civil claims.

For accounting, Ind AS 37 applies. A provision arises only where there is a present obligation from a past event, outflow is probable and a reliable estimate exists. Otherwise the matter is a contingent liability and is disclosed.

Which means the exposure is uninsured, unprovided and undisclosed in most Indian companies today. That is a governance position, not an accounting one.

Statutory Ceilings

The Schedule to Section 33, Stated Accurately

Penalty Ceilings by Category of Breach

Failure to take reasonable security safeguards to prevent a personal data breach

Section 8(5)
Up to ₹250 crore

Failure to intimate a personal data breach to the Board and to affected Data Principals

Section 8(6)
Up to ₹200 crore

Breach of the additional obligations in relation to children

Section 9
Up to ₹200 crore

Breach of the additional obligations of a Significant Data Fiduciary

Section 10
Up to ₹150 crore

Breach of the duties of a Data Principal

Section 15
Up to ₹10,000

Breach of any term of a voluntary undertaking accepted by the Board

Section 32
As applicable to that breach

Breach of any other provision of the Act or the Rules

Residuary entry
Up to ₹50 crore

Each entry is a ceiling. Section 33(2) requires the Board to fix the amount having regard to the nature, gravity and duration of the breach, the type and nature of the personal data affected, the repetitive nature of the breach, any gain realised or loss avoided, the mitigation undertaken and its timeliness and effectiveness, proportionality, and the likely impact of the penalty. No entry operates per instance.

Six Questions

What a CFO Should Be Asking This Quarter

Does our cyber policy pay a Board imposed penalty?

Read the exclusion clause, not the summary of cover. Most Indian cyber wordings exclude fines and penalties, occasionally with a carve back where insurable by law. That carve back does very little in a jurisdiction where indemnity against one's own statutory penalty is regarded as opposed to public policy.

Is our exposure a provision or a contingent liability this quarter?

Ind AS 37 turns on present obligation, probable outflow and reliable estimate. Before any inquiry, most DPDPA exposure sits in disclosure rather than provision. The moment a proceeding opens, that assessment must be revisited with counsel, in writing, before the auditor asks.

Can we quantify exposure at all before enforcement begins?

Yes, as a range. The Schedule fixes the ceilings and Section 33(2) fixes the factors. A defensible model prices the factors the company controls, namely the promptness and effectiveness of mitigation and whether the breach is repetitive.

Who signs off on the assessment internally?

The Data Protection Officer or equivalent produces the facts. Counsel produces the legal assessment of probability. Finance produces the accounting treatment. The Audit Committee should see all three, not a single summary line from any one of them.

What does remediation spend buy in penalty terms?

Section 33(2) expressly directs the Board to consider the action taken to mitigate the effect and consequences of the breach and the timeliness and effectiveness of that action. Documented, dated remediation is one of the few inputs to the penalty calculation that a company can still influence after the event.

Is a penalty recoverable from a vendor?

Contractual indemnity against a third party for the company's own statutory penalty raises the same public policy problem. What is recoverable in practice is the cost of response and the loss caused by the vendor's own breach of contract, which is why the Section 8(2) processor contract matters more than the indemnity headline.

The Lever Nobody Uses

Section 32 and the Voluntary Undertaking

Section 32 allows the Board to accept a voluntary undertaking from a person at any stage of a proceeding. It may involve doing an act, refraining from an act, or a publicity measure. It may be varied on application.

Where the Board accepts the undertaking, proceedings in respect of that breach cease. Breach of a term of the undertaking is itself actionable.

For a finance function this is the only mechanism in the Act that turns an open, unquantified exposure into a defined commitment with a known cost. It is a negotiation, and like every negotiation it rewards the party that arrives with evidence.

The evidence is the remediation ledger. Which is built before the breach, not after it.

Deliverable

The Eight Item Audit Committee Pack

What Should Reach the Committee

  • Exposure register mapping each processing activity to the applicable Schedule entry and its ceiling
  • Written legal assessment of probability of outflow for each open or foreseeable matter
  • Accounting treatment note under Ind AS 37 with the reason for provision or disclosure
  • Insurance coverage analysis quoting the exclusion clause verbatim, not the brochure
  • Remediation ledger with dated evidence, since timeliness is a statutory factor under Section 33(2)
  • Vendor concentration analysis showing which processors carry the largest share of personal data
  • Readiness position against 13 May 2027 with the residual gap stated in plain numbers
  • A decision on whether a voluntary undertaking under Section 32 is the better commercial route

Finance Grade DPDPA Exposure Advisory

An exposure register mapped to the Schedule, a written legal assessment that supports the accounting treatment, an insurance opinion that reads the exclusion, and a board pack the Audit Committee can act on.

Request a Confidential Briefing

Our data privacy counsel will reach out within one working day.

Insights & Answers

What finance functions and audit committees are asking

Is a DPDPA penalty covered by cyber liability insurance in India?

As a general position, no. A penalty imposed by a regulator for the insured's own statutory breach is not ordinarily treated as an insurable loss, because indemnifying a person against the consequence of their own wrong is regarded as opposed to public policy. Indian cyber wordings usually express this as an exclusion for fines and penalties, sometimes with a narrow carve back where insurable by law. What these policies do cover is the response cost, namely forensics, legal representation, notification, monitoring and third party civil claims.

How should a company account for potential DPDPA exposure?

Ind AS 37 requires a provision where a present obligation arises from a past event, outflow is probable and a reliable estimate can be made. Where those conditions are not satisfied, the matter is disclosed as a contingent liability. DPDPA exposure typically starts in disclosure and moves to provision only when an inquiry or adverse finding makes outflow probable. Because probability is a legal judgement, the accounting conclusion should rest on a written legal assessment.

Is the ₹250 crore penalty applied per violation or per instance?

Neither. The Schedule to Section 33 sets ceilings for specified categories, the highest extending up to two hundred and fifty crore rupees for failure to take reasonable security safeguards under Section 8(5). Section 33(2) requires the Board to determine the amount having regard to nature, gravity and duration, the type of personal data affected, whether the breach is repetitive, gain realised or loss avoided, mitigation and its timeliness and effectiveness, proportionality and the likely impact. It is a Board determined ceiling, not a per record multiplier.

What is a voluntary undertaking under Section 32 of DPDPA?

Section 32 permits the Board to accept a voluntary undertaking at any stage of a proceeding. It may involve doing an act, refraining from an act, or a publicity measure, and it may be varied on application. On acceptance, proceedings in respect of that breach cease. Breach of a term of the undertaking is itself actionable. For finance, it is the only route in the Act that converts an open and unquantified exposure into a defined commitment.

Where does an appeal against a penalty go?

Section 29 of the Act provides an appeal to the Appellate Tribunal, which is the Telecom Disputes Settlement and Appellate Tribunal, within the period specified in that section. Penalties collected are credited to the Consolidated Fund of India under Section 34. A CFO should assume an appeal timeline measured in years and provide accordingly, not on the assumption of immediate finality.

Should the company disclose DPDPA readiness in the annual report?

Materiality decides. Where a company holds large volumes of personal data, or is likely to be notified as a Significant Data Fiduciary under Section 10, the risk section of the board report and the contingent liability note are the ordinary places for that disclosure. Silence in the report combined with a known internal gap is a governance problem separate from the data protection problem.

How much should we budget for DPDPA readiness?

Budget by obligation rather than by benchmark. The cost drivers are the number of processing systems that must produce a rights response inside the Rule 14 window, the number of processors that must be recontracted under Section 8(2), the retention engine, and the notice and consent rebuild. Two companies of identical revenue can differ by an order of magnitude on those four lines.

What does AMLEGALS deliver to a finance function?

An exposure register mapped to the Schedule, a written legal assessment supporting the accounting treatment, an insurance coverage opinion that reads the exclusion rather than the summary, and a board pack the Audit Committee can act on. Where a proceeding is live, we advise on whether a voluntary undertaking under Section 32 is the better commercial route.