ABSTRACT
Aggregation is itself a security risk. A big data repository is not simply a larger filing cabinet; it is a concentration of attack value, and every major Indian data breach of the last decade has exploited exactly that concentration. This paper maps the legal architecture that is supposed to secure such repositories: section 43A of the Information Technology Act and the SPDI Rules, the CERT-In reporting regime as tightened by the April 2022 Directions, and the security and breach-notification obligations of the Digital Personal Data Protection Act, 2023 read with the 2025 Rules. Measured against Articles 32 to 34 of the GDPR and the American breach-notification experience, the Indian framework emerges as newly strengthened on paper but fragmented in design: overlapping regulators, undefined standards of “reasonable security safeguards,” a breach-notification duty unmoored from any risk threshold, and an adjudicatory body whose independence is doubtful. The paper argues that big data security regulation must shift from incident-reporting to architecture, and offers a set of doctrinally grounded suggestions to that end.
Keywords: Data Breach, CERT-In, Section 43A, DPDP Act 2023, Reasonable Security Safeguards, Breach Notification, Cybersecurity.
- INTRODUCTION
Data protection law and data security law are usually taught as one subject, but they answer different questions. Data protection asks whether information ought to be processed; security asks whether, once processed, it can be kept. Indian scholarship has spent most of the post-Puttaswamy decade on the first question.[1] The second has received less sustained attention, which is odd, because it is on the security side that Indian residents have been most visibly failed. The alleged exposure of some 81.5 crore records linked to the ICMR’s COVID testing database in October 2023, the ransomware attack that crippled AIIMS Delhi for a fortnight in November 2022, and the 2021 MobiKwik incident involving data of roughly 3.5 crore users are only the incidents that reached the newspapers.[2] Each involved a large aggregated dataset. None resulted in compensation to a single affected individual.
This paper examines why. Part II makes the conceptual point that scale converts a privacy problem into a security problem. Parts III and IV set out the statutory architecture, before and after the Digital Personal Data Protection Act, 2023.[3] Part V draws comparisons with the GDPR and American law. Part VI identifies the structural gaps, and Part VII closes with suggestions. The method throughout is doctrinal; I am concerned with what the enacted texts require, permit and omit, not with compliance behaviour in the field.
[1]Justice K.S. Puttaswamy v. Union of India, (2017) 10 SCC 1 (India) [hereinafter Puttaswamy].
[2]These incidents are drawn from contemporaneous reportage and CERT-In’s public acknowledgements; in the ICMR matter, the agency confirmed investigation of the claimed sale of the dataset on a cybercrime forum in October 2023. Precise figures in breach reporting are, notoriously, contested, and are cited here as claimed rather than adjudicated.
[3]The Digital Personal Data Protection Act, 2023, No. 22, Acts of Parliament, 2023 (India) [hereinafter DPDP Act].