Dispute over breach and data protection.

Dispute Over Breach and Data Protection

1. Introduction

A dispute over breach and data protection arises when one party to a commercial, technology, employment, outsourcing, SaaS, cloud, banking, healthcare, or other agreement alleges that the other party has:

  • failed to protect personal or confidential data;
  • disclosed information without authorization;
  • suffered a cybersecurity incident because of inadequate safeguards;
  • processed data beyond the agreed purpose;
  • transferred data to an unauthorized third party;
  • failed to comply with contractual privacy obligations;
  • failed to notify the other party of a data breach;
  • retained or deleted data contrary to contractual requirements; or
  • caused financial, reputational, regulatory, or privacy-related harm through negligent data handling.

In an arbitration context, these disputes are particularly significant because a single incident can generate multiple overlapping claims: contractual breach, confidentiality breach, negligence, statutory liability, indemnity, cybersecurity obligations, privacy rights, and regulatory consequences.

Indian law now has to be considered principally through the Digital Personal Data Protection Act, 2023 (DPDP Act), together with the Information Technology Act, 2000, contractual principles under the Indian Contract Act, 1872, applicable sectoral regulations, and the constitutional right to privacy.

2. Nature of a Data-Protection Breach

A data-protection breach may involve several different forms of misconduct.

A. Unauthorized disclosure

For example, a software provider may disclose a customer's employee database to a marketing company without authorization.

B. Unauthorized access

A hacker, employee, subcontractor, or third-party service provider may gain access to protected information.

C. Loss of data

Loss may result from:

  • ransomware;
  • deletion;
  • system failure;
  • inadequate backup;
  • cloud misconfiguration;
  • accidental destruction.

D. Unauthorized processing

A processor may use information for a purpose different from the purpose for which it was supplied.

E. Failure to secure data

A contractual party may have promised encryption, access controls, penetration testing, backup, or other security measures but failed to implement them.

F. Failure to notify

A contract may require immediate notification of a security incident. Failure to notify can itself constitute an independent contractual breach even where the underlying cyberattack was caused by a third party.

3. Legal Framework in India

A. Digital Personal Data Protection Act, 2023

The DPDP Act provides India's principal horizontal framework for digital personal data.

Its important concepts include:

  • Data Principal – the individual to whom personal data relates;
  • Data Fiduciary – the person determining the purpose and means of processing;
  • Data Processor – a person processing personal data on behalf of a Data Fiduciary;
  • consent and other permitted grounds for processing;
  • obligations relating to security safeguards;
  • breach-related obligations;
  • duties relating to erasure and retention;
  • rights of Data Principals; and
  • penalties for statutory non-compliance.

An important contractual point is that outsourcing processing does not necessarily eliminate the Data Fiduciary's regulatory responsibility.

4. Information Technology Act, 2000

Section 43A of the Information Technology Act, 2000 historically provided a significant statutory basis for compensation where a body corporate negligently failed to implement reasonable security practices for sensitive personal data and information.

Section 43A is particularly important when analyzing older contracts and historical breaches.

The contractual definition of "reasonable security practices" can also be important because section 43A contemplated security practices specified by agreement between parties.

Therefore, a well-drafted data-processing agreement can become legally significant in determining the standard of security that the parties undertook to maintain.

5. Indian Contract Act, 1872

A data breach may constitute a contractual breach under:

Section 37

Parties must perform their contractual promises.

Section 39

Repudiation or refusal to perform contractual obligations may entitle the innocent party to terminate, subject to the statutory requirements.

Section 55

Relevant where contractual compliance is tied to a stipulated time.

Section 73

Provides compensation for loss or damage caused by breach of contract.

Section 74

May become relevant where the agreement contains:

  • liquidated damages;
  • contractual penalties;
  • predetermined compensation.

Section 124

Relevant to indemnity provisions.

Section 125

Deals with rights of an indemnity-holder.

Thus, a data breach can generate a contractual damages claim independently of regulatory penalties.

6. Constitutional Right to Privacy

The Supreme Court's decision in Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1 established privacy as a constitutionally protected fundamental right under Article 21 and other provisions of Part III.

The judgment is foundational for Indian data-protection law.

The Court recognized privacy as encompassing aspects such as:

  • personal autonomy;
  • informational privacy;
  • control over personal information;
  • dignity;
  • decisional autonomy.

Consequently, personal data cannot be treated merely as an ordinary commercial commodity.

For arbitration, however, an important distinction must be maintained between:

  1. constitutional/privacy claims against the State, and
  2. private contractual disputes between commercial parties.

An arbitral tribunal derives its jurisdiction from the arbitration agreement and cannot simply exercise the constitutional jurisdiction of a constitutional court.

7. Major Case Laws

Case 1: Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1

Facts

The Supreme Court considered whether privacy constituted a fundamental right under the Constitution.

Decision

A nine-judge Constitution Bench unanimously recognized privacy as a fundamental right.

The judgment emphasized informational privacy and individual autonomy.

Importance for data breaches

The case establishes the constitutional foundation upon which India's modern data-protection regime rests.

It demonstrates that privacy is not merely a contractual or statutory interest.

Arbitration significance

Suppose a technology company contracts with a government entity and personal data is compromised.

The dispute may contain both:

  • contractual issues suitable for arbitration; and
  • constitutional/public-law issues that may fall within the jurisdiction of constitutional courts.

An arbitral tribunal therefore must carefully distinguish between arbitrable contractual obligations and non-arbitrable public-law remedies.

Case 2: K.S. Puttaswamy (Retd.) v. Union of India (Aadhaar), (2019) 1 SCC 1

Facts

The Supreme Court considered constitutional challenges surrounding the Aadhaar scheme, including collection and use of biometric and personal information.

Decision

The Court examined:

  • informational privacy;
  • proportionality;
  • purpose limitation;
  • data collection;
  • data security;
  • retention;
  • surveillance concerns.

Importance

The judgment reinforces the principle that interference with personal information must satisfy constitutional standards such as:

  1. legality;
  2. legitimate objective;
  3. proportionality; and
  4. appropriate safeguards.

Contractual relevance

A commercial contract involving highly sensitive information should therefore not be drafted solely around the question:

"Did the parties consent?"

It must also consider statutory and regulatory restrictions.

Case 3: Karmanya Singh Sareen v. Union of India, 2017 SCC OnLine Del 9886

Facts

The litigation concerned WhatsApp's proposed privacy-policy changes and sharing of user information with Facebook.

The petitioners raised concerns concerning privacy and protection of user data.

Decision

The Delhi High Court considered the contractual nature of WhatsApp's terms and the then-existing legal position concerning privacy.

The Court also recognized concerns relating to users' information and directed attention to deletion and protection issues in the circumstances before it.

Importance

The case illustrates a fundamental problem in data disputes:

Can a company unilaterally alter the manner in which customer data is used merely by modifying its terms of service?

That question remains particularly important in:

  • SaaS contracts;
  • platform agreements;
  • mobile applications;
  • cloud services;
  • fintech;
  • e-commerce.

Case 4: WhatsApp LLC v. Competition Commission of India

The WhatsApp privacy-policy litigation before Indian competition authorities and courts has become an important modern example of the intersection between:

  • data protection;
  • contractual consent;
  • platform power;
  • consumer choice;
  • competition law; and
  • data exploitation.

The dispute concerned WhatsApp's 2021 privacy-policy changes and data-sharing practices.

Legal significance

The case demonstrates that data-related contractual disputes may not remain purely contractual.

A company's processing of personal information can potentially attract:

  • privacy law;
  • competition law;
  • consumer law;
  • contractual remedies; and
  • regulatory scrutiny.

Arbitration significance

An arbitration clause in a platform agreement cannot necessarily prevent statutory authorities from exercising their regulatory jurisdiction.

Thus:

Arbitration does not provide immunity from regulatory proceedings.

A tribunal may determine contractual consequences, while a statutory regulator may separately determine regulatory liability.

Case 5: Manohar Joshi / Pegasus Surveillance Litigation — Manohar Lal Sharma v. Union of India, (2021) 2 SCC 152

The Pegasus litigation is significant in understanding privacy and cybersecurity.

Facts

Allegations concerned the use of Pegasus spyware to target mobile devices and potentially obtain access to highly sensitive information.

Supreme Court approach

The Court constituted a technical committee to investigate the allegations and emphasized the importance of privacy, surveillance safeguards and national-security considerations.

Importance for data protection

The case illustrates that unauthorized access to a person's digital environment can involve:

  • privacy;
  • cybersecurity;
  • unauthorized surveillance;
  • interception;
  • informational autonomy.

Commercial relevance

A similar principle can arise in a corporate environment.

For example, an employer's unauthorized surveillance of employees or a vendor's unauthorized access to client systems may produce both:

  • contractual claims; and
  • statutory/privacy claims.

Case 6: People's Union for Civil Liberties v. Union of India, (1997) 1 SCC 301

Facts

The case concerned telephone interception and protection against unauthorized governmental surveillance.

Supreme Court's approach

The Court laid down procedural safeguards governing telephone interception.

Importance

Although the case predates modern cloud computing and GDPR-style data protection, its principles are highly relevant to digital privacy.

It recognizes that communications cannot be subjected to unrestricted surveillance without appropriate legal safeguards.

Commercial relevance

The principles can inform disputes concerning:

  • employee monitoring;
  • recording of communications;
  • interception;
  • unauthorized access to business communications;
  • surveillance technologies.

Case 7: R. Rajagopal v. State of Tamil Nadu, (1994) 6 SCC 632

Facts

The dispute concerned privacy and publication of information relating to an individual's life.

Principle

The Supreme Court recognized a right to privacy and considered circumstances in which private information could be disclosed.

Relevance to data disputes

The case supports the proposition that information concerning an individual may attract legal protection even when it exists outside traditional physical forms.

In modern contracts this principle can arise in relation to:

  • employee records;
  • customer databases;
  • medical information;
  • financial records;
  • photographs;
  • communications;
  • biometric information.

8. What Constitutes Breach of a Data-Protection Clause?

A contract may contain an express obligation such as:

"The service provider shall implement appropriate technical and organizational measures to protect personal data."

A dispute may arise over what constitutes "appropriate."

The tribunal may examine:

1. Contractual standard

What exactly did the provider promise?

2. Industry standard

Did the provider comply with recognized cybersecurity practices?

3. Regulatory standard

Were applicable statutory and regulatory requirements satisfied?

4. Causation

Did the alleged failure actually cause the loss?

5. Foreseeability

Was the loss a foreseeable consequence of the breach?

6. Contributory conduct

Did the customer itself:

  • disclose passwords;
  • fail to patch systems;
  • ignore security warnings;
  • permit unauthorized access?

7. Third-party attack

Was the breach caused by an independent hacker or criminal?

A cyberattack does not automatically establish contractual liability. The claimant ordinarily needs to establish the relevant contractual obligation, breach, and legally recoverable loss.

9. Data Processor and Vendor Liability

A common dispute occurs between:

Customer → Data Fiduciary → Vendor → Sub-processor → Cloud provider

For example:

Bank → Fintech vendor → Cloud provider

If the cloud database is compromised, several questions arise:

  1. Who had possession of the data?
  2. Who controlled the processing?
  3. Who was responsible for cybersecurity?
  4. Was encryption contractually required?
  5. Was the cloud provider authorized?
  6. Was subcontracting permitted?
  7. Was the customer informed?
  8. Was the incident reported within the contractual period?
  9. Was the breach caused by negligence?
  10. Does the indemnity cover the incident?

10. Contractual Data-Protection Clauses

A sophisticated Data Processing Agreement should address at least:

A. Purpose limitation

The processor must use data only for specified purposes.

B. Security

The contract should specify:

  • encryption;
  • access controls;
  • authentication;
  • logging;
  • backups;
  • vulnerability management;
  • penetration testing;
  • incident response.

C. Breach notification

The agreement should establish:

  • what constitutes an incident;
  • notification period;
  • information to be provided;
  • cooperation obligations;
  • forensic investigation;
  • preservation of evidence.

D. Sub-processors

The processor should not freely appoint third parties without contractual controls.

E. Data deletion

Upon termination, data should be:

  • returned;
  • deleted;
  • anonymized where appropriate.

F. Audit rights

The customer may require:

  • security certifications;
  • audit reports;
  • penetration-testing summaries;
  • compliance documentation.

11. Breach Notification Disputes

One of the most common arbitration issues is whether a party notified the other party sufficiently quickly.

Consider:

Contract: Provider must notify customer "without undue delay" after becoming aware of a data breach.

A cyberattack occurs on Monday.

The provider discovers it on Tuesday.

It informs the customer on Friday.

The customer claims breach of contract.

The provider argues that forensic investigation was incomplete.

The tribunal must determine:

  • when the provider actually became aware;
  • what information it possessed;
  • whether immediate notification was contractually required;
  • whether investigation could reasonably precede notification;
  • whether delay caused additional loss.

This is why precise drafting is extremely important.

12. Causation in Data-Breach Claims

A claimant cannot necessarily recover every loss that follows a cyberattack.

The tribunal may separate:

Direct losses

  • investigation expenses;
  • data restoration;
  • system recovery;
  • notification costs;
  • emergency cybersecurity expenditure.

Consequential losses

  • lost profits;
  • loss of customers;
  • reputational damage;
  • business interruption.

Regulatory losses

  • statutory penalties;
  • regulatory investigation costs.

Third-party claims

Claims brought by:

  • customers;
  • employees;
  • suppliers;
  • consumers.

The contract's liability and indemnity provisions become critical.

13. Limitation of Liability

Technology contracts frequently contain clauses such as:

"The aggregate liability of the service provider shall not exceed the fees paid during the preceding twelve months."

A data breach may produce losses vastly exceeding that amount.

Consequently, parties often negotiate a super-cap for:

  • confidentiality breach;
  • data breach;
  • privacy violations;
  • intellectual-property infringement;
  • fraud;
  • wilful misconduct.

A sophisticated contract may therefore have:

General liability cap: ₹10 crore

Data/privacy super-cap: ₹25 crore

Fraud/wilful misconduct: unlimited, subject to applicable law.

The enforceability and interpretation of such provisions will depend upon the governing law and exact contractual language.

14. Indemnity Claims

Data breaches frequently trigger indemnification.

For example:

"The Service Provider shall indemnify the Customer against third-party claims arising from the Service Provider's breach of applicable data-protection law."

A dispute may then arise over whether the indemnity covers:

  • regulatory fines;
  • customer claims;
  • legal fees;
  • forensic costs;
  • incident-response costs;
  • business interruption;
  • reputational losses.

The tribunal must carefully interpret the indemnity rather than assuming that every consequence of a breach automatically falls within it.

15. Arbitration of Data-Protection Disputes

A. Is the dispute arbitrable?

Many contractual disputes concerning data protection are capable of arbitration.

Examples include:

  • failure to encrypt;
  • breach of confidentiality;
  • failure to follow cybersecurity specifications;
  • unauthorized contractual disclosure;
  • failure to notify;
  • indemnification;
  • allocation of cyber-risk.

However, an arbitral tribunal generally cannot replace a statutory regulator.

For example:

Arbitration:
Whether a service provider breached the DPA.

Regulator:
Whether statutory requirements were violated and whether a statutory penalty should be imposed.

These proceedings can coexist.

16. Confidentiality of Arbitration

Data-protection disputes create a special procedural problem.

The arbitration itself may involve:

  • customer databases;
  • medical information;
  • employee records;
  • passwords;
  • source code;
  • security architecture;
  • vulnerability reports;
  • penetration-testing results.

Accordingly, the tribunal may need to adopt:

  • confidentiality orders;
  • restricted-access electronic bundles;
  • anonymization;
  • redaction;
  • protective orders;
  • secure virtual hearing platforms;
  • limited disclosure.

17. Electronic Evidence

Data-breach disputes are highly dependent upon electronic evidence.

Typical evidence includes:

  • server logs;
  • access logs;
  • SIEM records;
  • firewall logs;
  • authentication records;
  • emails;
  • database records;
  • source code;
  • cloud audit trails;
  • forensic reports;
  • penetration-test reports.

The party presenting such evidence must establish its authenticity and evidentiary reliability.

A tribunal may also appoint a technical expert where the dispute requires specialized cybersecurity knowledge.

18. Burden of Proof

The claimant generally needs to establish:

Contractual obligation → Breach → Causation → Loss

For example:

Provider promised AES encryption → database was stored without required encryption → unauthorized access occurred → customer suffered specified recoverable losses.

The respondent may argue:

The contract did not require that particular encryption method → all reasonable security measures were implemented → breach resulted from sophisticated third-party criminal conduct → no causal connection to claimed losses.

The tribunal must determine these questions from the contract and evidence.

19. Force Majeure and Cyberattacks

A respondent may argue that a cyberattack constituted force majeure.

That argument is not automatically successful.

The tribunal should examine:

  1. Does the force-majeure clause include cyberattacks?
  2. Was the event beyond reasonable control?
  3. Was the incident foreseeable?
  4. Could reasonable security measures have prevented or mitigated it?
  5. Did the contract exclude negligence?
  6. Did the party comply with mitigation obligations?

A ransomware attack may therefore constitute force majeure in one contract but not another.

The precise wording of the clause matters.

20. Data Protection and Confidentiality Are Not Identical

This distinction is crucial.

Confidentiality

Protects information because the parties agreed to keep it secret.

Data protection

Regulates the collection, use, processing, disclosure, retention and security of personal data.

Therefore:

Every privacy breach may not necessarily be a confidentiality breach, and every confidentiality breach may not necessarily involve personal data.

For example, disclosure of a company's secret source code may breach confidentiality but involve no personal data.

Conversely, improper processing of customer information may violate data-protection obligations even where the information was not publicly disclosed.

21. Remedies Available in Arbitration

Depending upon the contract and applicable law, a tribunal may grant:

Monetary damages

For proven contractual loss.

Indemnification

For covered third-party claims and specified expenses.

Declaratory relief

Determining that a party breached the agreement.

Specific contractual relief

Where legally available.

Injunctive/interim relief

Courts may be approached for urgent measures where necessary, particularly concerning:

  • continuing unauthorized disclosure;
  • destruction of evidence;
  • unauthorized system access;
  • misuse of confidential information.

Costs

Cybersecurity disputes can involve extremely high expert and forensic costs, making allocation of arbitration costs significant.

22. Important Issues for the Arbitral Tribunal

A tribunal dealing with a data-breach dispute should normally consider the following sequence:

Step 1 — Identify the data

What information was involved?

Step 2 — Identify the legal relationship

Who was:

  • Data Fiduciary?
  • Data Processor?
  • controller/service provider?
  • subcontractor?

Step 3 — Examine the contract

Identify:

  • privacy clause;
  • DPA;
  • confidentiality clause;
  • cybersecurity schedule;
  • SLA;
  • indemnity;
  • limitation of liability.

Step 4 — Determine the security standard

What level of protection was promised?

Step 5 — Establish the incident

When and how did the breach occur?

Step 6 — Establish responsibility

Was the incident caused by:

  • negligence;
  • employee misconduct;
  • subcontractor failure;
  • technical vulnerability;
  • external criminal activity?

Step 7 — Examine causation

Did the breach cause the claimed losses?

Step 8 — Determine remedies

What compensation or other relief is legally and contractually available?

23. Illustrative Arbitration Problem

Suppose Company A appoints Company B, a SaaS provider, to store the personal information of 500,000 customers.

The contract requires B to:

  • encrypt data;
  • restrict administrative access;
  • maintain security monitoring;
  • notify A of incidents;
  • use only approved subprocessors.

A ransomware attack occurs.

Investigation shows that:

  • B failed to patch a known vulnerability;
  • an administrator's credentials were compromised;
  • B discovered the attack after three days;
  • B informed A seven days later;
  • B's subcontractor had unauthorized access;
  • customer data was subsequently leaked.

A commences arbitration.

A may claim:

  1. breach of cybersecurity obligations;
  2. breach of data-processing obligations;
  3. breach of confidentiality;
  4. failure to notify;
  5. indemnity;
  6. investigation expenses;
  7. restoration costs;
  8. third-party claims.

B may argue:

  1. the attack was caused by a sophisticated criminal group;
  2. the vulnerability was not reasonably foreseeable;
  3. A contributed to the incident;
  4. losses are too remote;
  5. liability is capped;
  6. regulatory penalties are excluded from the indemnity.

The tribunal must determine each issue separately rather than treating "data breach" as automatically establishing liability.

24. Key Lessons from the Case Law

The above cases collectively demonstrate several important principles.

PrincipleLeading authority
Privacy is a fundamental rightK.S. Puttaswamy v. Union of India
Informational privacy is constitutionally significantPuttaswamy (Aadhaar)
Platform privacy policies can generate significant legal disputesKarmanya Singh Sareen v. Union of India
Data practices may attract regulatory scrutiny beyond contract lawWhatsApp v. CCI
Digital surveillance raises serious privacy concernsManohar Lal Sharma v. Union of India
Communications privacy requires safeguardsPUCL v. Union of India
Publication/use of private information engages privacy interestsR. Rajagopal v. State of Tamil Nadu

25. Best Drafting Practices for Data-Protection Contracts

A good arbitration/data-protection clause should expressly address:

1. Governing law

Specify the law governing:

  • main agreement;
  • DPA;
  • privacy obligations.

2. Seat of arbitration

Specify the legal seat clearly.

3. Confidentiality

Extend confidentiality to:

  • personal data;
  • cybersecurity information;
  • forensic reports;
  • vulnerabilities;
  • source code.

4. Cybersecurity standard

Avoid vague language such as:

"commercially reasonable security."

Where appropriate, specify concrete obligations.

5. Incident notification

Specify:

  • trigger;
  • notice period;
  • contents;
  • responsible contact;
  • continuing updates.

6. Subprocessor liability

The principal service provider should remain contractually responsible for approved subprocessors to the extent agreed.

7. Audit rights

Specify the customer's rights to verify compliance.

8. Evidence preservation

Require preservation of:

  • logs;
  • forensic images;
  • access records;
  • communications.

9. Liability cap

Create an appropriate data/privacy super-cap if the commercial parties consider ordinary caps inadequate.

10. Regulatory cooperation

Require parties to cooperate with lawful investigations and regulatory requirements.

26. Conclusion

A dispute over breach and data protection is no longer merely a conventional confidentiality dispute. It sits at the intersection of contract law, privacy law, cybersecurity, technology law, regulatory law and arbitration.

The central legal question is usually:

What level of data protection did the party undertake to provide, did it fail to provide that protection, and what legally recoverable loss resulted from that failure?

Indian jurisprudence beginning with Puttaswamy has elevated privacy to constitutional significance, while cases involving WhatsApp, Aadhaar, Pegasus, telephone interception and private information demonstrate the increasingly sophisticated treatment of informational privacy.

For commercial arbitration, the most important distinction is between contractual data-protection obligations, which can ordinarily be determined by an arbitral tribunal where the arbitration agreement covers them, and public-law/regulatory questions, which may remain within the jurisdiction of statutory authorities or constitutional courts.

LEAVE A COMMENT