AMLEGALS — Strategic Lawyering
← All Insights
Article

Board-Level Liability Under DPDPA: What Global Directors of Indian Subsidiaries Must Understand

Anandaday MisshraJuly 2026
Board-Level Liability Under DPDPA: What Global Directors of Indian Subsidiaries Must Understand

Section 36: Personal Liability for Officers in Default

Section 36 of the DPDPA creates personal liability for every person who, at the time a contravention was committed, was in charge of and responsible for the conduct of the business of the body corporate. This provision mirrors Section 141 of the Negotiable Instruments Act and similar corporate veil-piercing provisions across Indian statutes — but applies it to data protection for the first time.

Who Is "In Charge of and Responsible For"

Indian courts have consistently interpreted "in charge of and responsible for the conduct of the business" broadly. It includes: managing directors, whole-time directors, any director who participates in operational decisions, the CEO and COO, and any officer who exercises managerial control. For a foreign subsidiary in India, this typically captures: the India Country Head, the local Managing Director, the board of directors of the Indian entity, and potentially the global DPO if they exercise control over Indian data processing decisions.

The Consent and Connivance Standard

Section 36(2) extends liability further. If a contravention is committed with the consent or connivance of, or is attributable to neglect on the part of, any director, manager, secretary or other officer — that person is also deemed guilty. "Neglect" is the critical word. A global director who is on the board of an Indian subsidiary but claims they were not involved in day-to-day operations faces exposure if the Board determines that the contravention was attributable to their neglect of oversight duties.

Implications for Global Boards

Global companies routinely appoint nominee directors to Indian subsidiary boards. Post-DPDPA, this appointment carries personal liability risk. A nominee director who does not actively ensure the subsidiary's DPDPA compliance may face personal penalty proceedings. The defense of "I was merely a nominee director" has been rejected by Indian courts in analogous contexts under other statutes.

D&O Insurance Considerations

Most global Directors and Officers (D&O) insurance policies exclude fines and penalties imposed by regulatory authorities. DPDPA penalties — being imposed by the Data Protection Board — are regulatory penalties. Companies must review their D&O policies to determine whether DPDPA exposure is covered, and if not, seek riders or standalone cyber liability coverage that explicitly addresses Indian data protection penalties.

Practical Compliance Architecture

Directors of Indian subsidiaries should ensure: (a) board-level reporting on DPDPA compliance status at least quarterly, (b) documented evidence that data protection was on the board agenda, (c) a designated officer responsible for DPDPA implementation (DPO for SDF entities, or equivalent for non-SDF), (d) periodic compliance audits with findings reported to the board, and (e) board-approved budgets for data protection implementation. The absence of any of these creates evidence of "neglect" under Section 36(2).

Need guidance on this topic?

We advise organisations across India on DPDPA compliance, AI governance and cross border data transfers.

Get in Touch →