
Introduction
As India’s data protection regime moves from legislation to enforcement, businesses are increasingly treating cyber insurance as a ready answer to their compliance worries. The Digital Personal Data Protection Act, 2023 (“DPDP Act”) became operational once the DPDP Rules were notified in November 2025, with phased implementation expected through 2027, and insurers are already reporting a sharp rise in enquiries as companies rush to shore up their risk cover.
This growing appetite for cyber insurance is a welcome development. However, a closer reading of the DPDP Act’s penalty framework, coupled with how commercial insurance policies actually operate in India, reveals a persistent and potentially costly misunderstanding among businesses that a cyber insurance policy can substitute for genuine data protection compliance. It cannot, and the scale of DPDP Act penalties, along with the peculiarities of Indian insurance law, make this distinction especially important for Indian businesses to grasp.
Understanding the Rising Stakes Behind the Insurance Rush
Chapter VIII of the DPDP Act, particularly Sections 33 and 34, sets out a stringent penalty regime enforced by the Data Protection Board of India (“Board”), a statutory authority empowered to inquire into personal data breaches and impose financial penalties on erring data fiduciaries. Penalties range from INR 10 crore for administrative lapses, such as failing to appoint a Data Protection Officer, to INR 200 crore for failing to implement reasonable security safeguards, and up to INR 250 crore for non-compliance with Board directions, capped overall at INR 500 crore per instance.
Unsurprisingly, insurers have reported a marked increase in demand for cyber insurance since these penalty provisions came into sharper focus, with businesses now treating such cover as a necessity rather than an optional add-on. Yet a large proportion of eligible businesses, particularly small and mid-sized enterprises, remain uninsured or under-insured, exposing a gap between growing awareness and actual preparedness.
Risk Transfer vs. Legal Mandate: A Crucial Distinction
At its core, cyber insurance is a mechanism of risk transfer. It shifts the financial burden of a cyber incident, such as forensic costs, business interruption, or third-party liability, from the insured business to the insurer, for a premium. Data protection compliance, by contrast, is a legal mandate, requiring businesses to implement safeguards such as consent management, breach notification protocols, and data protection impact assessments, regardless of whether they hold insurance.
These two concepts operate on different planes. A well-structured policy can soften the financial blow of a breach, but it does not extinguish the underlying statutory obligation to prevent that breach in the first place. Businesses that conflate the two often discover, only after a breach occurs, that purchasing a policy did nothing to reduce their regulatory exposure under the DPDP Act.
Coverage Exclusions for Negligence
A recurring point of friction between policyholders and insurers arises from exclusions relating to negligence and inadequate security controls. Insurers increasingly scrutinise an applicant’s cybersecurity maturity before underwriting, and many policies now require documented proof of security controls, logging, monitoring, and incident response readiness as a condition of coverage.
Where a breach results from an organisation’s failure to maintain such baseline safeguards, insurers may treat this as negligence or gross misconduct falling outside the scope of the policy. Without adequate documentation of active security governance, claims may be reduced, delayed, or denied altogether. Insurers are beginning to expect the very compliance discipline some businesses assume the policy itself will excuse them from maintaining.
Fines and Penalties Are Not Always Insurable
Perhaps the most significant misconception concerns whether regulatory fines under the DPDPA can be covered by insurance at all. Commercial cyber insurance in India typically operates through first-party coverage, addressing the policyholder’s own losses, and third-party liability coverage, addressing claims by affected individuals or entities. Within third-party coverage, insurers may offer defence cost coverage during regulatory proceedings and, in limited circumstances, coverage for certain fines where legally permissible.
However, Indian public policy principles generally disfavour the insurability of penalties arising from an organisation’s own wilful default, intentional misconduct, or gross negligence. Even where a policy nominally extends to regulatory fines, insurers are likely to resist indemnifying penalties stemming from a deliberate or reckless failure to comply with the DPDP Act. Businesses must therefore scrutinise policy wordings closely, particularly exclusions relating to intentional acts and statutory non-compliance, rather than assuming a large sum insured automatically translates into fine-shielding.
Insurance as a Layer, Not a Substitute for Compliance
The Insurance Regulatory and Development Authority of India (“IRDAI”) has itself signalled the direction of travel. Its revised Information and Cyber Security Guidelines tighten governance expectations for insurers, mandating board-level oversight, an independent Chief Information Security Officer, and continuous monitoring rather than one-time audits. This logic increasingly filters down to policyholders: insurers underwriting cyber risk expect the businesses they cover to demonstrate ongoing, documented compliance, not a static, one-time security assessment.
For Indian businesses, cyber insurance is best understood as one layer within a broader risk management strategy, sitting alongside, and never replacing, lawful consent mechanisms, data governance frameworks, breach response procedures, vendor oversight, and employee training required under the DPDP Act. A cyber risk assessment, reviewed periodically as regulatory expectations evolve, remains essential to determining appropriate coverage limits and identifying vulnerabilities before an insurer, or the Board, identifies them first.
AMLEGALS Remarks
As India’s data protection enforcement architecture matures, businesses must resist the temptation to treat cyber insurance as a proxy for compliance. Risk transfer and legal mandate serve different purposes, and the growing sophistication of Indian insurers in scrutinising security posture at underwriting makes negligence-based exclusions a real threat to inadequately prepared policyholders. Equally, public policy limits on insuring wilful defaults mean that DPDP Act penalties cannot always be transferred away, however comprehensive the policy may appear on paper. The most resilient businesses will build genuine compliance infrastructure first, and layer cyber insurance on top as a financial safety net, rather than the other way around. As DPDP Act scrutiny intensifies, the real question may not be how much coverage a business can buy, but how well it can demonstrate, to regulators and insurers alike, that it was compliant all along.
For any queries or feedback, feel free to connect with mridusha.guha@amlegals.com or Khilansha.mukhija@amlegals.com
