India's Premier Full-Service Law Firm — Precision. Pedigree. Global Reach.
Goldschmidt Pallonji& Associates
Get in Touch
Home / Practices / Cybersecurity & DPDP
★★★ Differentiator Practice

Cybersecurity & DPDP

India had over 13 million cyber incidents in 2023. The average cost of a data breach in India exceeded Rs.17 crore. The DPDP Act creates penalties of up to Rs.250 crore for a single violation. The organisation that builds its cybersecurity and data protection legal framework before an incident does not need to rebuild it in the middle of one.

DPDP Act 2023 · CERT-In · Breach Response · IT Act · SEBI Cyber · RBI Cyber
Data Breach Response · Ransomware · Cross-Border Data Flows · Significant Data Fiduciary
The Practice

A data breach is not primarily a technical event. It is a legal event with a six-hour CERT-In reporting clock, a DPDP Act penalty exposure of up to Rs.250 crore, a regulatory notification obligation to multiple sectoral regulators simultaneously, and a reputational consequence that will outlast the technical incident by years. The organisations that manage a breach well do so because they prepared the legal response before the breach happened.

India's cybersecurity legal framework has developed rapidly. The CERT-In Direction of 2022 — now the most operationally demanding cybersecurity regulation in India — requires organisations to report cybersecurity incidents to CERT-In within six hours of discovery, maintain logs for 180 days, use only NTP-synchronised systems with Indian time zones, and deploy a raft of technical and procedural security measures. The Digital Personal Data Protection Act 2023 overlays data protection obligations on every organisation that processes the personal data of Indian residents — with penalties scaled to the nature of the breach and the organisation's compliance posture at the time of the incident.

Goldschmidt Pallonji's Cybersecurity and DPDP practice operates at the intersection of two disciplines that most law firms handle separately: the regulatory compliance framework (DPDP Act implementation, CERT-In compliance, sector-specific cybersecurity requirements from SEBI, RBI, IRDAI, and TRAI), and the incident response framework (the legal steps that must be taken in the hours and days following a cybersecurity incident to manage the regulatory, reputational, and litigation consequences). GP handles both — and provides the pre-incident preparation that makes the incident response manageable when it is needed.

For international businesses processing Indian personal data from overseas — Australian companies with Indian customer bases, Singaporean platforms with Indian users, GCC businesses with Indian employee data — the DPDP Act creates compliance obligations that apply regardless of where the data processor is located. GP advises overseas organisations on their DPDP Act obligations — consent architecture, data principal rights management, cross-border data transfer compliance, and the incident response obligations that apply when their systems are breached and Indian personal data is affected.

Key Legislation & Frameworks
DPDP Act 2023 CERT-In Direction 2022 IT Act 2000 / IT Rules SEBI Cyber Framework RBI Cyber Risk Framework IRDAI Cyber Guidelines GDPR — EU Cross-Border
Practice at a Glance
Tier
★★★ Differentiator Practice
Client Types
Financial services · Technology companies · Healthcare · E-commerce · Platforms · Overseas companies with Indian data · Critical infrastructure
Core Services
DPDP implementation · CERT-In compliance · Breach response · Ransomware · Sector cyber regulation · Cross-border data · Privacy audits · DPA representations
Emergency Response
24/7 breach response · CERT-In reporting within 6-hour window · Regulator notification management · Crisis communications legal support
Cross-Border
DPDP + GDPR · AUS Privacy Act · SGP PDPA · UAE PDPL · Cross-border transfer compliance
Speak to Our Cyber & DPDP Team
What We Do

Our Cybersecurity & DPDP Services

Pre-incident preparation, real-time breach response, and post-incident regulatory management — across the DPDP Act, CERT-In, and every sector-specific cybersecurity obligation.

🔒

DPDP Act Implementation

End-to-end DPDP Act compliance programme — data mapping and processing activity inventory, consent architecture design and implementation, privacy notice drafting, Data Principal rights management (access, correction, nomination, erasure, and grievance), Data Protection Officer appointment where required, and the annual compliance review. Significant Data Fiduciary obligations for platforms above the threshold — Data Protection Impact Assessment framework, government audit preparation, and the Data Protection Board complaint management system. DPDP Rules compliance as the implementing rules are notified — building the framework before enforcement begins.

Learn More →
🚨

Data Breach & Incident Response

24/7 legal response to cybersecurity incidents — managing the six-hour CERT-In reporting clock from the moment of incident discovery, coordinating regulatory notifications to CERT-In and sector-specific regulators (SEBI, RBI, IRDAI, TRAI) where applicable, managing the DPDP Act breach notification obligations, advising on communications to affected data principals, and managing the forensic investigation to establish scope and cause. Post-breach regulatory management — responding to CERT-In follow-up enquiries, DPDP Board investigations, and sector regulator enforcement actions. Litigation risk management following a breach — privilege strategy for forensic reports and internal communications.

Learn More →
📋

CERT-In Compliance Programme

Compliance with the CERT-In Direction 2022 — the six-hour incident reporting obligation, the 180-day log retention requirement, the NTP synchronisation mandates, the Virtual Private Server and VPN provider obligations, and the information sharing requirements. Gap analysis against the CERT-In requirements for organisations that have not conducted a compliance review since the Direction was issued. Incident reporting template library — pre-approved CERT-In report formats for the most common incident types, ready for deployment in the first hour of a breach. CERT-In Direction compliance audit and certification of compliance for regulated entities requiring formal compliance evidence.

Learn More →
🏥

Sector Cybersecurity — RBI, SEBI & IRDAI

Sector-specific cybersecurity compliance for regulated financial entities — the RBI Cyber Security Framework for banks and NBFCs, SEBI's Cyber Security and Cyber Resilience Framework for market infrastructure institutions and intermediaries, and IRDAI's Guidelines on Information and Cyber Security for insurers. Board-level cyber governance frameworks required under these sector regulations — the Board Cyber Security Policy, the cyber risk appetite statement, and the annual cyber audit requirements. Regulatory examination preparation — assisting financial sector organisations in preparing for RBI, SEBI, and IRDAI cyber security examinations and responding to regulatory findings.

Learn More →
🌎

Cross-Border Data Flows & Multi-Jurisdiction

Cross-border personal data transfer compliance — the DPDP Act's framework for transferring Indian personal data to overseas jurisdictions (pending the government's Negative List), Standard Contractual Clauses for India-EU transfers under the GDPR, and the bilateral adequacy positions for transfers to Australia, Singapore, and the UAE. For multinational organisations with Indian data in overseas systems — the DPDP Act obligations that follow Indian personal data regardless of where it is processed. DPDP Act compliance for overseas organisations processing Indian personal data — the extraterritorial reach of the Act and what it means for global data governance frameworks.

Learn More →
💰

Ransomware Response & Cyber Extortion

Legal management of ransomware incidents — the decision-making framework for ransom payment (legality under Indian law, sanctions risk for payments to designated entities, the CERT-In reporting obligation which applies even if no payment is made), the law enforcement notification question, and the regulatory reporting obligations triggered by a ransomware incident that involves personal data. Cyber extortion — threats to publish stolen data, demands for payment to prevent publication, and the legal tools available to respond including injunctions, law enforcement engagement, and take-down mechanisms for published data. Post-incident recovery — the contractual claims against vendors whose systems were compromised and the cyber insurance claim management.

Learn More →
Key Highlights

The four legal obligations that activate the moment a cybersecurity incident is discovered — and what happens to organisations that are not prepared for them.

Six hours — the CERT-In reporting window that most organisations cannot meet unprepared
The CERT-In Direction 2022 requires organisations to report cybersecurity incidents to CERT-In within six hours of becoming aware of the incident. This window includes the time needed to identify the incident as a reportable incident, determine the scope and nature of the incident, prepare the CERT-In report in the prescribed format, and submit it to CERT-In's portal. For an organisation discovering a ransomware attack at 2am, the six-hour clock expires at 8am — before most people are in the office. Organisations that have not built their incident response procedure, their CERT-In reporting template, and their emergency legal notification process before the incident occurs will not be able to comply with the six-hour obligation. GP builds this capability for clients before it is needed.
Rs.250 crore — the DPDP Act's maximum penalty for a single violation
The Digital Personal Data Protection Act 2023 provides for penalties of up to Rs.250 crore per violation for failure to implement reasonable security safeguards that results in a personal data breach. The Act does not define "reasonable security safeguards" — leaving the standard to be established through the Data Protection Board's decisions and the implementing Rules. Organisations that have implemented a documented security programme — risk assessments, technical and organisational measures, incident response procedures — will be better positioned to demonstrate that their safeguards were reasonable. The compliance posture at the time of the breach, not just the breach itself, determines the penalty. GP builds that compliance posture before the breach occurs.
Multiple regulators — all notified simultaneously, none notified the same way
A financial services company experiencing a data breach must notify CERT-In (within six hours), the DPDP Board (when the Rules specify the notification obligation), the RBI (within two to six hours under its own framework for banks and payment systems), potentially SEBI (for market intermediaries), IRDAI (for insurance companies), and the affected data principals themselves. Each regulator has its own notification format, its own timeline, and its own follow-up requirements. Managing five simultaneous regulatory notifications in the immediate aftermath of a breach, while also managing the technical response and the communications strategy, requires a pre-built multi-regulator notification protocol. GP builds and manages that protocol.
The forensic report — privileged or discoverable?
When an organisation engages a forensic firm to investigate a cybersecurity incident, the resulting report — which may identify security failures, document the scope of the breach, and establish causation — can be a powerful piece of evidence in the regulatory proceedings, private litigation, and class actions that follow the breach. Whether that report is protected by legal professional privilege — and therefore shielded from disclosure in subsequent proceedings — depends entirely on how the forensic engagement is structured. The engagement letter, the instruction chain, and the reporting relationship must all be structured through legal counsel from the first moment of the investigation. GP structures forensic investigations for privilege from day one.
For Overseas Companies Processing Indian Personal Data

The DPDP Act applies to the processing of digital personal data of Indian residents — regardless of where the processing takes place. An Australian company that processes the personal data of Indian customers through its India-based app, an Singapore platform with Indian users, a GCC employer with Indian employees whose data is processed in UAE systems — all of these are potentially subject to the DPDP Act's obligations. Consent architecture, privacy notices in English and the prescribed Indian languages, Data Principal rights management, and the cross-border transfer framework all apply to overseas processors of Indian personal data. GP advises overseas organisations on their DPDP Act obligations before the enforcement regime activates — because retrofitting global data governance frameworks to add DPDP compliance is significantly more expensive than building it in from the beginning.

Significant Data Fiduciary — The Obligations That Apply to Large Platforms

The DPDP Act empowers the central government to designate organisations as Significant Data Fiduciaries — those that process large volumes of personal data or sensitive personal data, or whose processing is assessed to pose a significant risk to individual rights. Significant Data Fiduciaries face additional obligations: appointment of a Data Protection Officer based in India, appointment of an independent Data Auditor, periodic Data Protection Impact Assessments, and government audit rights. The criteria for Significant Data Fiduciary designation have not yet been finalised — but large e-commerce platforms, fintech companies, healthcare platforms, and EdTech companies processing millions of records are likely candidates. GP advises companies on preparing for potential SDF designation — building the governance infrastructure before designation, not after.

You Have Been Breached. It Is 3am. The Six-Hour Clock Has Started.

GP maintains a 24/7 cybersecurity incident response capability — a dedicated line for breach notifications that connects directly to a senior lawyer and a forensic coordinator within minutes of the call. The first hour of a breach response determines the regulatory and litigation trajectory for the next three years. GP's incident response team activates immediately: the CERT-In clock is identified and managed, the scope of the regulatory notification obligation is assessed, the forensic engagement is structured for privilege, the initial communications are reviewed before they are sent, and the multi-regulator notification protocol is initiated. Organisations that have retained GP as their cyber response counsel have their incident response plan, their CERT-In report templates, and their notification protocol already in place. Organisations that call us for the first time during a breach get our immediate response and our best effort under time pressure. The difference between these two situations is the difference between a managed incident and a crisis.

The GP Difference

Why GP for Cybersecurity & DPDP

1

Prevention + response — one retained team, available around the clock

Most cyber legal practices are either compliance practices (DPDP implementation, privacy audits, policy drafting) or incident response practices (breach management, regulatory notification, litigation). GP is both — and the team that builds your DPDP compliance programme is the same team that responds when you are breached. The institutional knowledge of your data architecture, your regulatory profile, and your incident response protocol built during the compliance engagement is the most valuable asset in the first hours of a breach. Retained cyber legal counsel — not just a firm to call when things go wrong.

2

Multi-regulator in one call — not five separate firms

A financial services data breach triggers obligations to CERT-In, the DPDP Board, the RBI, potentially SEBI, and potentially IRDAI — simultaneously, with different timelines and different formats. Coordinating five separate regulatory notifications through five different advisers, under time pressure, with inconsistent messages, is a compliance failure waiting to happen. GP manages every regulatory notification from one team — ensuring the messages are consistent, the timelines are met, and the regulatory relationships are managed coherently from the first contact.

3

India + global compliance — DPDP, GDPR, PDPA, Privacy Act — mapped together

Multinational organisations processing Indian personal data alongside EU, Australian, Singaporean, and UAE personal data cannot build four separate compliance programmes. The data protection frameworks in these jurisdictions have significant overlaps — and a privacy programme that is designed from the ground up to address multiple jurisdictions simultaneously is significantly more efficient than one built for one jurisdiction and then retrofitted for others. GP's corridor expertise — and specific knowledge of the Australian Privacy Act, Singapore PDPA, UAE PDPL, and EU GDPR alongside the DPDP Act — allows us to build privacy programmes that address all relevant jurisdictions from one architecture.

Representative Matters

The type of work we do.

Complete confidentiality maintained.

India Ransomware — CERT-In + RBI Response

NBFC — ransomware attack, CERT-In and RBI notified within window, forensic investigation privileged, enforcement action avoided

Managed the legal response to a ransomware attack on a mid-size NBFC that encrypted its core banking systems and threatened to publish customer financial data. GP was engaged within two hours of the incident's discovery. GP immediately structured the forensic investigation engagement through legal counsel for privilege purposes, managed the CERT-In notification within the six-hour window, managed the RBI notification within the RBI's cyber incident reporting framework for NBFCs, and advised on the communications to affected customers. GP simultaneously assessed the ransom payment question — advising that payment to the identified threat actor's wallet address did not trigger known sanctions risks — and managed the negotiation with the threat actor. The customer data was not published. The CERT-In and RBI investigations were managed without formal enforcement action.

India + AUS + SGP DPDP — Multi-Jurisdiction Implementation

Multinational e-commerce company — DPDP + Australian Privacy Act + Singapore PDPA compliance programme, single unified architecture

Advised a multinational e-commerce company with operations and customers in India, Australia, and Singapore on a unified data protection compliance programme covering the DPDP Act 2023, the Australian Privacy Act 1988, and the Singapore Personal Data Protection Act 2012. GP mapped the three frameworks onto the company's single global data architecture — identifying the highest-common-denominator obligations that a single consent architecture and privacy notice could satisfy across all three jurisdictions simultaneously. The resulting programme — consent notices in English and prescribed Indian languages, a unified Data Principal/Data Subject rights portal, and a single Data Protection Officer covering all three jurisdictions — reduced the company's compliance cost by approximately 40% compared to three separate jurisdiction-specific implementations.

India SEBI Cyber Examination — Regulatory Preparation

Stock broker — SEBI cyber security examination preparation, gap remediation, clean examination outcome

Advised a large stock broking firm in preparation for a SEBI cyber security and cyber resilience framework examination. GP conducted a gap analysis against SEBI's Cyber Security and Cyber Resilience Framework, identified 14 documentation and procedural gaps in the firm's compliance programme, and managed a 90-day remediation programme covering the Board Cyber Security Policy, the cyber risk appetite statement, the incident response procedure, the vendor risk management programme, and the required cyber audit documentation. The SEBI examination resulted in no adverse findings. Separately, GP assisted the firm in designing a DPDP Act implementation programme for its 2.4 million retail customer accounts — integrating the SEBI data governance requirements with the DPDP Act consent and rights management obligations.

Practice Leadership

Our Cybersecurity and DPDP practice is India's most operationally ready cyber legal practice — with 24/7 breach response capability, pre-built CERT-In notification protocols, and multi-regulator coordination experience.

The practice is led by a senior technology and data protection lawyer with specific expertise in the DPDP Act, CERT-In compliance, and cybersecurity incident response — working alongside sector regulatory specialists for the RBI, SEBI, and IRDAI cyber frameworks, and GP's international corridor team for the multi-jurisdiction compliance programmes that multinational clients require. The practice maintains a 24/7 emergency response line for cybersecurity incidents, staffed by a senior lawyer on rotating availability.

For clients in the financial services sector, the practice coordinates directly with GP's Banking and Finance, Regulatory, and Capital Markets practices — because a cybersecurity incident in a regulated financial entity is simultaneously a technical event, a regulatory event, and a reputational event, and it must be managed as all three at once.

GP
Cybersecurity & DPDP Team
Data Protection + Cyber Response + Sector Regulatory
DPDP Act 2023 CERT-In Direction 2022 24/7 Breach Response Multi-Jurisdiction Privacy SEBI / RBI / IRDAI Cyber
Multi-jurisdiction: DPDP (India) · GDPR (EU) · Privacy Act (AUS) · PDPA (SGP) · PDPL (UAE) · UK GDPR
✉ Write to Our Cyber & DPDP Team Meet All Our Partners
Latest Insights
Incident Response Guide

The First Six Hours — Legal Steps When Your Organisation Is Breached

The CERT-In six-hour clock, the RBI and SEBI notification obligations for financial entities, forensic investigation privilege structuring, the ransom payment decision, and the communications that must be reviewed before they are sent — a step-by-step legal guide for the first six hours of a cybersecurity incident.

Read Guide →
DPDP Alert

DPDP Act Implementation Readiness — The Checklist Every Indian Organisation Needs Before the Rules Are Notified

Data mapping, consent architecture, privacy notices, Data Principal rights management, grievance mechanisms, and Significant Data Fiduciary preparation — the 24 implementation steps that every organisation processing Indian personal data must complete before DPDP enforcement begins.

Read Alert →
Cybersecurity & DPDP

Speak to Our Cyber & DPDP Team

Whether you need a DPDP implementation programme, a CERT-In compliance audit, a sector cyber regulatory preparation, or an emergency breach response — our team is available immediately for incidents and responds within 24 hours for all other matters.

24/7 breach response — CERT-In clock management from the first call
Multi-regulator notifications — CERT-In, RBI, SEBI, IRDAI — coordinated from one team
Multi-jurisdiction privacy — DPDP, GDPR, Privacy Act, PDPA — one architecture
Response immediately for incidents — 24 hours for all other matters
Send Us a Message

By submitting you agree to our Privacy Policy. All communications are strictly confidential.