Section 36: Personal Liability for Officers in Default
Section 36 of the DPDPA creates personal liability for every person who, at the time a contravention was committed, was in charge of and responsible for the conduct of the business of the body corporate. This provision mirrors Section 141 of the Negotiable Instruments Act and similar corporate veil-piercing provisions across Indian statutes — but applies it to data protection for the first time.
Who Is "In Charge of and Responsible For"
Indian courts have consistently interpreted "in charge of and responsible for the conduct of the business" broadly. It includes: managing directors, whole-time directors, any director who participates in operational decisions, the CEO and COO, and any officer who exercises managerial control. For a foreign subsidiary in India, this typically captures: the India Country Head, the local Managing Director, the board of directors of the Indian entity, and potentially the global DPO if they exercise control over Indian data processing decisions.
The Consent and Connivance Standard
Section 36(2) extends liability further. If a contravention is committed with the consent or connivance of, or is attributable to neglect on the part of, any director, manager, secretary or other officer — that person is also deemed guilty. "Neglect" is the critical word. A global director who is on the board of an Indian subsidiary but claims they were not involved in day-to-day operations faces exposure if the Board determines that the contravention was attributable to their neglect of oversight duties.
Implications for Global Boards
Global companies routinely appoint nominee directors to Indian subsidiary boards. Post-DPDPA, this appointment carries personal liability risk. A nominee director who does not actively ensure the subsidiary's DPDPA compliance may face personal penalty proceedings. The defense of "I was merely a nominee director" has been rejected by Indian courts in analogous contexts under other statutes.
D&O Insurance Considerations
Most global Directors and Officers (D&O) insurance policies exclude fines and penalties imposed by regulatory authorities. DPDPA penalties — being imposed by the Data Protection Board — are regulatory penalties. Companies must review their D&O policies to determine whether DPDPA exposure is covered, and if not, seek riders or standalone cyber liability coverage that explicitly addresses Indian data protection penalties.
Practical Compliance Architecture
Directors of Indian subsidiaries should ensure: (a) board-level reporting on DPDPA compliance status at least quarterly, (b) documented evidence that data protection was on the board agenda, (c) a designated officer responsible for DPDPA implementation (DPO for SDF entities, or equivalent for non-SDF), (d) periodic compliance audits with findings reported to the board, and (e) board-approved budgets for data protection implementation. The absence of any of these creates evidence of "neglect" under Section 36(2).

