Author: Khushi Keshari
College: Maa Vaishno Devi Educational Law College, University of Lucknow
Abstract
The rapid digitisation of Indian businesses has transformed cybersecurity from a purely technical concern into an important issue of corporate governance. Companies today collect and process substantial volumes of personal, financial, commercial and proprietary information. A cyber incident can therefore affect not only a company’s information systems but also its customers, employees, shareholders, business partners and overall corporate reputation.
The legal framework governing corporate cybersecurity in India is developing through multiple statutes and regulatory mechanisms. The Information Technology Act, 2000, the Digital Personal Data Protection Act, 2023 (DPDP Act), the Digital Personal Data Protection Rules, 2025, sector-specific regulations and judicial decisions collectively contribute to this framework.
The notification of the Digital Personal Data Protection Rules, 2025 has added greater operational significance to data protection compliance. Consequently, cybersecurity can no longer be treated solely as the responsibility of an organisation’s information-technology department. Boards of directors and senior management increasingly have to consider data protection, cyber-risk management, incident response and confidentiality as components of responsible corporate governance.
To the Point
The rapid digitisation of Indian businesses has transformed cybersecurity from a purely technical concern into an important issue of corporate governance. Companies today collect and process substantial volumes of personal, financial, commercial and proprietary information. A cyber incident can therefore affect not only a company’s information systems but also its customers, employees, shareholders, business partners and overall corporate reputation.
The legal framework governing corporate cybersecurity in India is developing through multiple statutes and regulatory mechanisms. The Information Technology Act, 2000, the Digital Personal Data Protection Act, 2023 (DPDP Act), the Digital Personal Data Protection Rules, 2025, sector-specific regulations and judicial decisions collectively contribute to this framework.
The notification of the Digital Personal Data Protection Rules, 2025 has added greater operational significance to data protection compliance. The Rules establish a framework for safeguarding personal data and provide a phased approach to compliance.
Consequently, cybersecurity can no longer be treated solely as the responsibility of an organisation’s information-technology department. Boards of directors and senior management increasingly have to consider data protection, cyber-risk management, incident response and confidentiality as components of responsible corporate governance.
Use of Legal Jargon
Under the Information Technology Act, 2000, Section 43A historically established liability for a body corporate where negligence in implementing and maintaining reasonable security practices and procedures resulted in wrongful loss or wrongful gain in connection with sensitive personal data or information.
The statutory framework is supplemented by the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. Judicial decisions have examined the conditions necessary for liability under Section 43A, including the nature of the entity, possession or handling of sensitive personal data and failure to maintain reasonable security practices.
The DPDP Act introduces the concepts of a Data Principal and a Data Fiduciary. A Data Fiduciary determines the purpose and means of processing personal data and consequently assumes significant compliance responsibilities.
The Act emphasises lawful processing, notice and consent requirements, purpose limitation and protection of personal data. Section 6, for example, requires consent to be free, specific, informed, unconditional and unambiguous, accompanied by clear affirmative action.
The Digital Personal Data Protection Rules, 2025 provide additional implementation details. The Rules were notified on 14 November 2025, together with an enforcement timeline and measures relating to the Data Protection Board of India.
For corporate entities, these provisions create the need for an effective compliance framework, including appropriate security safeguards, access controls, data-management policies, vendor due diligence, incident-response mechanisms and documentation of compliance.
Cybersecurity governance also intersects with concepts such as fiduciary responsibility, corporate accountability, confidentiality, reasonable security practices, regulatory compliance and risk management.
The Proof
Recent judicial proceedings demonstrate that cybersecurity incidents can directly affect corporate interests.
In Generali Central Insurance Company Ltd. v. Union of India, a cybersecurity incident resulted in the alleged exfiltration of a substantial quantity of confidential data from the company’s systems. The Bombay High Court considered the potential consequences of misuse or disclosure of such information while dealing with interim relief. The case illustrates how a cyberattack may create legal consequences extending beyond the immediate technological incident to questions of confidentiality, protection of customer information and judicial remedies.
Similarly, in HDFC Asset Management Company Ltd. v. Union of India, the Bombay High Court dealt with an alleged ransomware incident involving the exfiltration of a large quantity of critical data. The Court granted interim protection against the use, publication, distribution or disclosure of the allegedly stolen confidential information, recognising the potential for serious and irreversible consequences from disclosure.
These proceedings demonstrate an important corporate-law principle: information itself can constitute a valuable corporate asset. Confidential business information, customer information, financial information, employee data and proprietary material may have substantial commercial significance. Accordingly, protecting such information is increasingly connected with the broader responsibility of corporate management.
The issue is also relevant in employment and commercial relationships. In Pandorum Technologies Private Limited v. Phani Kiran Karra, proceedings before the Delhi High Court concerned alleged retention of company property and confidential information, including electronic data and research material, after termination of employment. The dispute demonstrates the importance of contractual confidentiality obligations and protection of proprietary information within corporate relationships.
Further, in Elcom Innovation Pvt. Ltd. v. Harish Sharma & Ors., the Delhi High Court considered allegations involving unauthorised access and misuse of confidential company information. The proceedings show how cyber-related misconduct can intersect with contractual obligations, intellectual property interests and civil remedies.
These developments indicate that cybersecurity risks may produce consequences under multiple areas of law simultaneously. Depending on the facts, a single incident may involve data-protection obligations, contractual liability, confidentiality claims, regulatory consequences and requests for injunctive relief.
Case Laws
1. Justice K.S. Puttaswamy (Retd.) v. Union of India (2017)
The Supreme Court recognised privacy as a constitutionally protected fundamental right under Article 21 and other provisions of the Constitution. The judgment established an important constitutional foundation for informational privacy in India. For corporate entities, the decision is significant because businesses routinely process personal information of customers, employees and other individuals. The recognition of privacy reinforces the importance of responsible handling and protection of personal information.
2. Elcom Innovation Pvt. Ltd. v. Harish Sharma & Ors. (2022)
The Delhi High Court dealt with allegations concerning unauthorised access and transmission of confidential company information. The matter demonstrates that unauthorised handling of corporate information may give rise to civil and legal consequences, particularly where confidential information is misused.
3. Generali Central Insurance Company Ltd. v. Union of India (2025)
The Bombay High Court considered an alleged cyberattack involving the exfiltration of confidential information. The proceedings highlight the importance of immediate legal protection where stolen corporate or customer data may be disclosed or misused.
4. HDFC Asset Management Company Ltd. v. Union of India (2026)
The Bombay High Court considered an alleged ransomware incident involving substantial quantities of confidential data. Interim protection was granted against the use, copying, publication, distribution or disclosure of the allegedly stolen information. The case illustrates the growing judicial significance of cyber-risk and confidential-data protection in corporate disputes.
Conclusion
Cybersecurity is increasingly becoming an essential component of corporate governance in India. The expansion of digital business operations means that companies are responsible for protecting not merely physical and financial assets but also valuable information and digital infrastructure.
The emergence of the DPDP framework, together with the Information Technology Act and judicial developments, indicates that organisations must approach cybersecurity as a continuing legal and governance responsibility rather than merely an IT function.
Boards and senior management should therefore encourage appropriate cybersecurity policies, employee awareness, contractual safeguards, vendor-risk assessment, access controls, incident-response mechanisms and periodic compliance reviews.
The objective should not be to eliminate every possible cyber threat, which may be practically impossible, but to establish a legally sound and proportionate system for identifying, preventing, responding to and mitigating cyber risks.
In the digital economy, effective corporate governance increasingly depends upon effective information governance. Cybersecurity is consequently not only a technological requirement but also an important element of corporate accountability, regulatory compliance and stakeholder protection.
