Dispute over breach and data protection.
Dispute Over Breach and Data Protection
1. Introduction
A dispute over breach and data protection arises when one party to a commercial, technology, employment, outsourcing, SaaS, cloud, banking, healthcare, or other agreement alleges that the other party has:
- failed to protect personal or confidential data;
- disclosed information without authorization;
- suffered a cybersecurity incident because of inadequate safeguards;
- processed data beyond the agreed purpose;
- transferred data to an unauthorized third party;
- failed to comply with contractual privacy obligations;
- failed to notify the other party of a data breach;
- retained or deleted data contrary to contractual requirements; or
- caused financial, reputational, regulatory, or privacy-related harm through negligent data handling.
In an arbitration context, these disputes are particularly significant because a single incident can generate multiple overlapping claims: contractual breach, confidentiality breach, negligence, statutory liability, indemnity, cybersecurity obligations, privacy rights, and regulatory consequences.
Indian law now has to be considered principally through the Digital Personal Data Protection Act, 2023 (DPDP Act), together with the Information Technology Act, 2000, contractual principles under the Indian Contract Act, 1872, applicable sectoral regulations, and the constitutional right to privacy.
2. Nature of a Data-Protection Breach
A data-protection breach may involve several different forms of misconduct.
A. Unauthorized disclosure
For example, a software provider may disclose a customer's employee database to a marketing company without authorization.
B. Unauthorized access
A hacker, employee, subcontractor, or third-party service provider may gain access to protected information.
C. Loss of data
Loss may result from:
- ransomware;
- deletion;
- system failure;
- inadequate backup;
- cloud misconfiguration;
- accidental destruction.
D. Unauthorized processing
A processor may use information for a purpose different from the purpose for which it was supplied.
E. Failure to secure data
A contractual party may have promised encryption, access controls, penetration testing, backup, or other security measures but failed to implement them.
F. Failure to notify
A contract may require immediate notification of a security incident. Failure to notify can itself constitute an independent contractual breach even where the underlying cyberattack was caused by a third party.
3. Legal Framework in India
A. Digital Personal Data Protection Act, 2023
The DPDP Act provides India's principal horizontal framework for digital personal data.
Its important concepts include:
- Data Principal – the individual to whom personal data relates;
- Data Fiduciary – the person determining the purpose and means of processing;
- Data Processor – a person processing personal data on behalf of a Data Fiduciary;
- consent and other permitted grounds for processing;
- obligations relating to security safeguards;
- breach-related obligations;
- duties relating to erasure and retention;
- rights of Data Principals; and
- penalties for statutory non-compliance.
An important contractual point is that outsourcing processing does not necessarily eliminate the Data Fiduciary's regulatory responsibility.
4. Information Technology Act, 2000
Section 43A of the Information Technology Act, 2000 historically provided a significant statutory basis for compensation where a body corporate negligently failed to implement reasonable security practices for sensitive personal data and information.
Section 43A is particularly important when analyzing older contracts and historical breaches.
The contractual definition of "reasonable security practices" can also be important because section 43A contemplated security practices specified by agreement between parties.
Therefore, a well-drafted data-processing agreement can become legally significant in determining the standard of security that the parties undertook to maintain.
5. Indian Contract Act, 1872
A data breach may constitute a contractual breach under:
Section 37
Parties must perform their contractual promises.
Section 39
Repudiation or refusal to perform contractual obligations may entitle the innocent party to terminate, subject to the statutory requirements.
Section 55
Relevant where contractual compliance is tied to a stipulated time.
Section 73
Provides compensation for loss or damage caused by breach of contract.
Section 74
May become relevant where the agreement contains:
- liquidated damages;
- contractual penalties;
- predetermined compensation.
Section 124
Relevant to indemnity provisions.
Section 125
Deals with rights of an indemnity-holder.
Thus, a data breach can generate a contractual damages claim independently of regulatory penalties.
6. Constitutional Right to Privacy
The Supreme Court's decision in Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1 established privacy as a constitutionally protected fundamental right under Article 21 and other provisions of Part III.
The judgment is foundational for Indian data-protection law.
The Court recognized privacy as encompassing aspects such as:
- personal autonomy;
- informational privacy;
- control over personal information;
- dignity;
- decisional autonomy.
Consequently, personal data cannot be treated merely as an ordinary commercial commodity.
For arbitration, however, an important distinction must be maintained between:
- constitutional/privacy claims against the State, and
- private contractual disputes between commercial parties.
An arbitral tribunal derives its jurisdiction from the arbitration agreement and cannot simply exercise the constitutional jurisdiction of a constitutional court.
7. Major Case Laws
Case 1: Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1
Facts
The Supreme Court considered whether privacy constituted a fundamental right under the Constitution.
Decision
A nine-judge Constitution Bench unanimously recognized privacy as a fundamental right.
The judgment emphasized informational privacy and individual autonomy.
Importance for data breaches
The case establishes the constitutional foundation upon which India's modern data-protection regime rests.
It demonstrates that privacy is not merely a contractual or statutory interest.
Arbitration significance
Suppose a technology company contracts with a government entity and personal data is compromised.
The dispute may contain both:
- contractual issues suitable for arbitration; and
- constitutional/public-law issues that may fall within the jurisdiction of constitutional courts.
An arbitral tribunal therefore must carefully distinguish between arbitrable contractual obligations and non-arbitrable public-law remedies.
Case 2: K.S. Puttaswamy (Retd.) v. Union of India (Aadhaar), (2019) 1 SCC 1
Facts
The Supreme Court considered constitutional challenges surrounding the Aadhaar scheme, including collection and use of biometric and personal information.
Decision
The Court examined:
- informational privacy;
- proportionality;
- purpose limitation;
- data collection;
- data security;
- retention;
- surveillance concerns.
Importance
The judgment reinforces the principle that interference with personal information must satisfy constitutional standards such as:
- legality;
- legitimate objective;
- proportionality; and
- appropriate safeguards.
Contractual relevance
A commercial contract involving highly sensitive information should therefore not be drafted solely around the question:
"Did the parties consent?"
It must also consider statutory and regulatory restrictions.
Case 3: Karmanya Singh Sareen v. Union of India, 2017 SCC OnLine Del 9886
Facts
The litigation concerned WhatsApp's proposed privacy-policy changes and sharing of user information with Facebook.
The petitioners raised concerns concerning privacy and protection of user data.
Decision
The Delhi High Court considered the contractual nature of WhatsApp's terms and the then-existing legal position concerning privacy.
The Court also recognized concerns relating to users' information and directed attention to deletion and protection issues in the circumstances before it.
Importance
The case illustrates a fundamental problem in data disputes:
Can a company unilaterally alter the manner in which customer data is used merely by modifying its terms of service?
That question remains particularly important in:
- SaaS contracts;
- platform agreements;
- mobile applications;
- cloud services;
- fintech;
- e-commerce.
Case 4: WhatsApp LLC v. Competition Commission of India
The WhatsApp privacy-policy litigation before Indian competition authorities and courts has become an important modern example of the intersection between:
- data protection;
- contractual consent;
- platform power;
- consumer choice;
- competition law; and
- data exploitation.
The dispute concerned WhatsApp's 2021 privacy-policy changes and data-sharing practices.
Legal significance
The case demonstrates that data-related contractual disputes may not remain purely contractual.
A company's processing of personal information can potentially attract:
- privacy law;
- competition law;
- consumer law;
- contractual remedies; and
- regulatory scrutiny.
Arbitration significance
An arbitration clause in a platform agreement cannot necessarily prevent statutory authorities from exercising their regulatory jurisdiction.
Thus:
Arbitration does not provide immunity from regulatory proceedings.
A tribunal may determine contractual consequences, while a statutory regulator may separately determine regulatory liability.
Case 5: Manohar Joshi / Pegasus Surveillance Litigation — Manohar Lal Sharma v. Union of India, (2021) 2 SCC 152
The Pegasus litigation is significant in understanding privacy and cybersecurity.
Facts
Allegations concerned the use of Pegasus spyware to target mobile devices and potentially obtain access to highly sensitive information.
Supreme Court approach
The Court constituted a technical committee to investigate the allegations and emphasized the importance of privacy, surveillance safeguards and national-security considerations.
Importance for data protection
The case illustrates that unauthorized access to a person's digital environment can involve:
- privacy;
- cybersecurity;
- unauthorized surveillance;
- interception;
- informational autonomy.
Commercial relevance
A similar principle can arise in a corporate environment.
For example, an employer's unauthorized surveillance of employees or a vendor's unauthorized access to client systems may produce both:
- contractual claims; and
- statutory/privacy claims.
Case 6: People's Union for Civil Liberties v. Union of India, (1997) 1 SCC 301
Facts
The case concerned telephone interception and protection against unauthorized governmental surveillance.
Supreme Court's approach
The Court laid down procedural safeguards governing telephone interception.
Importance
Although the case predates modern cloud computing and GDPR-style data protection, its principles are highly relevant to digital privacy.
It recognizes that communications cannot be subjected to unrestricted surveillance without appropriate legal safeguards.
Commercial relevance
The principles can inform disputes concerning:
- employee monitoring;
- recording of communications;
- interception;
- unauthorized access to business communications;
- surveillance technologies.
Case 7: R. Rajagopal v. State of Tamil Nadu, (1994) 6 SCC 632
Facts
The dispute concerned privacy and publication of information relating to an individual's life.
Principle
The Supreme Court recognized a right to privacy and considered circumstances in which private information could be disclosed.
Relevance to data disputes
The case supports the proposition that information concerning an individual may attract legal protection even when it exists outside traditional physical forms.
In modern contracts this principle can arise in relation to:
- employee records;
- customer databases;
- medical information;
- financial records;
- photographs;
- communications;
- biometric information.
8. What Constitutes Breach of a Data-Protection Clause?
A contract may contain an express obligation such as:
"The service provider shall implement appropriate technical and organizational measures to protect personal data."
A dispute may arise over what constitutes "appropriate."
The tribunal may examine:
1. Contractual standard
What exactly did the provider promise?
2. Industry standard
Did the provider comply with recognized cybersecurity practices?
3. Regulatory standard
Were applicable statutory and regulatory requirements satisfied?
4. Causation
Did the alleged failure actually cause the loss?
5. Foreseeability
Was the loss a foreseeable consequence of the breach?
6. Contributory conduct
Did the customer itself:
- disclose passwords;
- fail to patch systems;
- ignore security warnings;
- permit unauthorized access?
7. Third-party attack
Was the breach caused by an independent hacker or criminal?
A cyberattack does not automatically establish contractual liability. The claimant ordinarily needs to establish the relevant contractual obligation, breach, and legally recoverable loss.
9. Data Processor and Vendor Liability
A common dispute occurs between:
Customer → Data Fiduciary → Vendor → Sub-processor → Cloud provider
For example:
Bank → Fintech vendor → Cloud provider
If the cloud database is compromised, several questions arise:
- Who had possession of the data?
- Who controlled the processing?
- Who was responsible for cybersecurity?
- Was encryption contractually required?
- Was the cloud provider authorized?
- Was subcontracting permitted?
- Was the customer informed?
- Was the incident reported within the contractual period?
- Was the breach caused by negligence?
- Does the indemnity cover the incident?
10. Contractual Data-Protection Clauses
A sophisticated Data Processing Agreement should address at least:
A. Purpose limitation
The processor must use data only for specified purposes.
B. Security
The contract should specify:
- encryption;
- access controls;
- authentication;
- logging;
- backups;
- vulnerability management;
- penetration testing;
- incident response.
C. Breach notification
The agreement should establish:
- what constitutes an incident;
- notification period;
- information to be provided;
- cooperation obligations;
- forensic investigation;
- preservation of evidence.
D. Sub-processors
The processor should not freely appoint third parties without contractual controls.
E. Data deletion
Upon termination, data should be:
- returned;
- deleted;
- anonymized where appropriate.
F. Audit rights
The customer may require:
- security certifications;
- audit reports;
- penetration-testing summaries;
- compliance documentation.
11. Breach Notification Disputes
One of the most common arbitration issues is whether a party notified the other party sufficiently quickly.
Consider:
Contract: Provider must notify customer "without undue delay" after becoming aware of a data breach.
A cyberattack occurs on Monday.
The provider discovers it on Tuesday.
It informs the customer on Friday.
The customer claims breach of contract.
The provider argues that forensic investigation was incomplete.
The tribunal must determine:
- when the provider actually became aware;
- what information it possessed;
- whether immediate notification was contractually required;
- whether investigation could reasonably precede notification;
- whether delay caused additional loss.
This is why precise drafting is extremely important.
12. Causation in Data-Breach Claims
A claimant cannot necessarily recover every loss that follows a cyberattack.
The tribunal may separate:
Direct losses
- investigation expenses;
- data restoration;
- system recovery;
- notification costs;
- emergency cybersecurity expenditure.
Consequential losses
- lost profits;
- loss of customers;
- reputational damage;
- business interruption.
Regulatory losses
- statutory penalties;
- regulatory investigation costs.
Third-party claims
Claims brought by:
- customers;
- employees;
- suppliers;
- consumers.
The contract's liability and indemnity provisions become critical.
13. Limitation of Liability
Technology contracts frequently contain clauses such as:
"The aggregate liability of the service provider shall not exceed the fees paid during the preceding twelve months."
A data breach may produce losses vastly exceeding that amount.
Consequently, parties often negotiate a super-cap for:
- confidentiality breach;
- data breach;
- privacy violations;
- intellectual-property infringement;
- fraud;
- wilful misconduct.
A sophisticated contract may therefore have:
General liability cap: ₹10 crore
Data/privacy super-cap: ₹25 crore
Fraud/wilful misconduct: unlimited, subject to applicable law.
The enforceability and interpretation of such provisions will depend upon the governing law and exact contractual language.
14. Indemnity Claims
Data breaches frequently trigger indemnification.
For example:
"The Service Provider shall indemnify the Customer against third-party claims arising from the Service Provider's breach of applicable data-protection law."
A dispute may then arise over whether the indemnity covers:
- regulatory fines;
- customer claims;
- legal fees;
- forensic costs;
- incident-response costs;
- business interruption;
- reputational losses.
The tribunal must carefully interpret the indemnity rather than assuming that every consequence of a breach automatically falls within it.
15. Arbitration of Data-Protection Disputes
A. Is the dispute arbitrable?
Many contractual disputes concerning data protection are capable of arbitration.
Examples include:
- failure to encrypt;
- breach of confidentiality;
- failure to follow cybersecurity specifications;
- unauthorized contractual disclosure;
- failure to notify;
- indemnification;
- allocation of cyber-risk.
However, an arbitral tribunal generally cannot replace a statutory regulator.
For example:
Arbitration:
Whether a service provider breached the DPA.
Regulator:
Whether statutory requirements were violated and whether a statutory penalty should be imposed.
These proceedings can coexist.
16. Confidentiality of Arbitration
Data-protection disputes create a special procedural problem.
The arbitration itself may involve:
- customer databases;
- medical information;
- employee records;
- passwords;
- source code;
- security architecture;
- vulnerability reports;
- penetration-testing results.
Accordingly, the tribunal may need to adopt:
- confidentiality orders;
- restricted-access electronic bundles;
- anonymization;
- redaction;
- protective orders;
- secure virtual hearing platforms;
- limited disclosure.
17. Electronic Evidence
Data-breach disputes are highly dependent upon electronic evidence.
Typical evidence includes:
- server logs;
- access logs;
- SIEM records;
- firewall logs;
- authentication records;
- emails;
- database records;
- source code;
- cloud audit trails;
- forensic reports;
- penetration-test reports.
The party presenting such evidence must establish its authenticity and evidentiary reliability.
A tribunal may also appoint a technical expert where the dispute requires specialized cybersecurity knowledge.
18. Burden of Proof
The claimant generally needs to establish:
Contractual obligation → Breach → Causation → Loss
For example:
Provider promised AES encryption → database was stored without required encryption → unauthorized access occurred → customer suffered specified recoverable losses.
The respondent may argue:
The contract did not require that particular encryption method → all reasonable security measures were implemented → breach resulted from sophisticated third-party criminal conduct → no causal connection to claimed losses.
The tribunal must determine these questions from the contract and evidence.
19. Force Majeure and Cyberattacks
A respondent may argue that a cyberattack constituted force majeure.
That argument is not automatically successful.
The tribunal should examine:
- Does the force-majeure clause include cyberattacks?
- Was the event beyond reasonable control?
- Was the incident foreseeable?
- Could reasonable security measures have prevented or mitigated it?
- Did the contract exclude negligence?
- Did the party comply with mitigation obligations?
A ransomware attack may therefore constitute force majeure in one contract but not another.
The precise wording of the clause matters.
20. Data Protection and Confidentiality Are Not Identical
This distinction is crucial.
Confidentiality
Protects information because the parties agreed to keep it secret.
Data protection
Regulates the collection, use, processing, disclosure, retention and security of personal data.
Therefore:
Every privacy breach may not necessarily be a confidentiality breach, and every confidentiality breach may not necessarily involve personal data.
For example, disclosure of a company's secret source code may breach confidentiality but involve no personal data.
Conversely, improper processing of customer information may violate data-protection obligations even where the information was not publicly disclosed.
21. Remedies Available in Arbitration
Depending upon the contract and applicable law, a tribunal may grant:
Monetary damages
For proven contractual loss.
Indemnification
For covered third-party claims and specified expenses.
Declaratory relief
Determining that a party breached the agreement.
Specific contractual relief
Where legally available.
Injunctive/interim relief
Courts may be approached for urgent measures where necessary, particularly concerning:
- continuing unauthorized disclosure;
- destruction of evidence;
- unauthorized system access;
- misuse of confidential information.
Costs
Cybersecurity disputes can involve extremely high expert and forensic costs, making allocation of arbitration costs significant.
22. Important Issues for the Arbitral Tribunal
A tribunal dealing with a data-breach dispute should normally consider the following sequence:
Step 1 — Identify the data
What information was involved?
Step 2 — Identify the legal relationship
Who was:
- Data Fiduciary?
- Data Processor?
- controller/service provider?
- subcontractor?
Step 3 — Examine the contract
Identify:
- privacy clause;
- DPA;
- confidentiality clause;
- cybersecurity schedule;
- SLA;
- indemnity;
- limitation of liability.
Step 4 — Determine the security standard
What level of protection was promised?
Step 5 — Establish the incident
When and how did the breach occur?
Step 6 — Establish responsibility
Was the incident caused by:
- negligence;
- employee misconduct;
- subcontractor failure;
- technical vulnerability;
- external criminal activity?
Step 7 — Examine causation
Did the breach cause the claimed losses?
Step 8 — Determine remedies
What compensation or other relief is legally and contractually available?
23. Illustrative Arbitration Problem
Suppose Company A appoints Company B, a SaaS provider, to store the personal information of 500,000 customers.
The contract requires B to:
- encrypt data;
- restrict administrative access;
- maintain security monitoring;
- notify A of incidents;
- use only approved subprocessors.
A ransomware attack occurs.
Investigation shows that:
- B failed to patch a known vulnerability;
- an administrator's credentials were compromised;
- B discovered the attack after three days;
- B informed A seven days later;
- B's subcontractor had unauthorized access;
- customer data was subsequently leaked.
A commences arbitration.
A may claim:
- breach of cybersecurity obligations;
- breach of data-processing obligations;
- breach of confidentiality;
- failure to notify;
- indemnity;
- investigation expenses;
- restoration costs;
- third-party claims.
B may argue:
- the attack was caused by a sophisticated criminal group;
- the vulnerability was not reasonably foreseeable;
- A contributed to the incident;
- losses are too remote;
- liability is capped;
- regulatory penalties are excluded from the indemnity.
The tribunal must determine each issue separately rather than treating "data breach" as automatically establishing liability.
24. Key Lessons from the Case Law
The above cases collectively demonstrate several important principles.
| Principle | Leading authority |
|---|---|
| Privacy is a fundamental right | K.S. Puttaswamy v. Union of India |
| Informational privacy is constitutionally significant | Puttaswamy (Aadhaar) |
| Platform privacy policies can generate significant legal disputes | Karmanya Singh Sareen v. Union of India |
| Data practices may attract regulatory scrutiny beyond contract law | WhatsApp v. CCI |
| Digital surveillance raises serious privacy concerns | Manohar Lal Sharma v. Union of India |
| Communications privacy requires safeguards | PUCL v. Union of India |
| Publication/use of private information engages privacy interests | R. Rajagopal v. State of Tamil Nadu |
25. Best Drafting Practices for Data-Protection Contracts
A good arbitration/data-protection clause should expressly address:
1. Governing law
Specify the law governing:
- main agreement;
- DPA;
- privacy obligations.
2. Seat of arbitration
Specify the legal seat clearly.
3. Confidentiality
Extend confidentiality to:
- personal data;
- cybersecurity information;
- forensic reports;
- vulnerabilities;
- source code.
4. Cybersecurity standard
Avoid vague language such as:
"commercially reasonable security."
Where appropriate, specify concrete obligations.
5. Incident notification
Specify:
- trigger;
- notice period;
- contents;
- responsible contact;
- continuing updates.
6. Subprocessor liability
The principal service provider should remain contractually responsible for approved subprocessors to the extent agreed.
7. Audit rights
Specify the customer's rights to verify compliance.
8. Evidence preservation
Require preservation of:
- logs;
- forensic images;
- access records;
- communications.
9. Liability cap
Create an appropriate data/privacy super-cap if the commercial parties consider ordinary caps inadequate.
10. Regulatory cooperation
Require parties to cooperate with lawful investigations and regulatory requirements.
26. Conclusion
A dispute over breach and data protection is no longer merely a conventional confidentiality dispute. It sits at the intersection of contract law, privacy law, cybersecurity, technology law, regulatory law and arbitration.
The central legal question is usually:
What level of data protection did the party undertake to provide, did it fail to provide that protection, and what legally recoverable loss resulted from that failure?
Indian jurisprudence beginning with Puttaswamy has elevated privacy to constitutional significance, while cases involving WhatsApp, Aadhaar, Pegasus, telephone interception and private information demonstrate the increasingly sophisticated treatment of informational privacy.
For commercial arbitration, the most important distinction is between contractual data-protection obligations, which can ordinarily be determined by an arbitral tribunal where the arbitration agreement covers them, and public-law/regulatory questions, which may remain within the jurisdiction of statutory authorities or constitutional courts.

comments