Skip to content
🚨 DPDP Rules 2025: Compliance Deadline 36 weeks awayRead handbook →

When Privacy Penalties Disappear in Bankruptcy: India's DPDP Act Has a Clean Slate Problem

A structural gap between India's DPDP Act and IBC's clean slate doctrine may let insolvent companies escape Data Protection Board penalties entirely.

D
DPDPBot Research Team
🕐 11 min read
A gavel resting on ledger books whose pages dissolve into drifting ash
A gavel resting on ledger books whose pages dissolve into drifting ash

#When Privacy Penalties Disappear in Bankruptcy: India's DPDP Act Has a Clean Slate Problem

A company can violate India's data protection law, expose millions of users' financial records, trigger a Data Protection Board inquiry — and then escape every rupee of penalty simply by entering insolvency. This is not a hypothetical. A LiveLaw analysis published July 15, 2026 has identified a structural gap at the intersection of two of India's most consequential statutes: the Digital Personal Data Protection Act 2023 and the Insolvency and Bankruptcy Code 2016. The gap is real, it is unresolved, and it has consequences for every data-intensive business in India's insolvency pipeline.


#What the DPDP Act Promises on Enforcement

India's Digital Personal Data Protection Act 2023 — which came into force in November 2025 with the DPDP Rules — is built on the premise that accountability follows violation. The Data Protection Board of India (DPBI), now constituted as an independent quasi-judicial body, can impose monetary penalties reaching ₹250 crore per breach for failure to maintain adequate security safeguards. Failure to notify the Board or affected individuals of a personal data breach can attract penalties of up to ₹200 crore. Any other contravention by a Data Fiduciary can draw penalties up to ₹50 crore.

These are not small numbers, and they were designed to hurt. Unlike the EU's GDPR — which calculates fines as a percentage of global annual turnover — the DPDP Act's penalties are fixed maximum amounts. A startup and a Fortune 500 company face the same ₹250 crore ceiling, making the penalty model relatively more severe for mid-sized data processors and fintech platforms that handle large user volumes without the global revenue to absorb a percentage-based fine.

The Board's enforcement process works through a formal inquiry mechanism: a complaint or self-identified breach triggers an investigation, the fiduciary is given an opportunity to be heard, and the Board issues a reasoned order. Critically, this process takes time — often months, sometimes longer — before a final penalty order is issued.

That timeline is where the DPDP Act's enforcement architecture runs directly into the Insolvency and Bankruptcy Code.


#What the IBC's Clean Slate Doctrine Erases

The Insolvency and Bankruptcy Code 2016 transformed how India handles corporate financial failure. Its centrepiece resolution mechanism — the Corporate Insolvency Resolution Process (CIRP) — allows creditors to take over a financially distressed company, approve a resolution plan, and hand ownership to a new acquiring entity that assumes a defined set of liabilities and leaves the rest behind.

The "clean slate" principle is the IBC's mechanism for making this work. Under Section 31(1) of the Code, once the National Company Law Tribunal (NCLT) approves a resolution plan, it becomes binding on all stakeholders — including the Central and State governments, regulatory authorities, and creditors who did not participate in the process. Pre-CIRP liabilities not included in the approved plan are extinguished. The acquiring entity gets a fresh start, unencumbered by legacy claims. Without this guarantee, no rational acquirer would take on a distressed business: the commercial logic of resolution depends on the certainty that unknown or delayed claims will not arrive years later.

The Supreme Court reinforced this doctrine in a series of rulings that treated the clean slate as near-absolute. In practice, this means regulatory penalties that are pending, unquantified, or not notified in time during the CIRP process are candidates for extinguishment when the NCLT approves a plan.

The IBC does contain one carve-out. Section 32A provides immunity from criminal prosecution for the acquiring entity and its management for offences committed by the corporate debtor before the resolution plan is approved — but only if the acquirer had no involvement in those offences. This provision was added specifically to encourage legitimate acquirers, who would otherwise face criminal exposure for the prior company's conduct.

The critical word is criminal. Section 32A does not address civil or administrative penalties. It was never extended to cover regulatory fines imposed by bodies like the Data Protection Board.


#Where the Two Laws Collide

The structural problem emerges from the interaction of three facts:

First, DPDP Act investigations are slow relative to CIRP timelines. The Board's inquiry process — notice, hearing, order — routinely takes months to conclude. A company that suffered a data breach in January might not receive a final penalty order until August or September. A CIRP, by contrast, can proceed to resolution plan approval in 270 days or less.

Second, claims in CIRP must be submitted with quantified values during the claims window. DPDP Act penalties are inherently unquantifiable at the point they are submitted: the Board determines the penalty amount only after completing its inquiry, weighing factors like the nature of the breach, the company's cooperation, and the harm caused to data principals. The LiveLaw analysis notes that the penalty range — zero to ₹250 crore — makes even a rough estimate legally unreliable. Submitting an unquantified regulatory claim of this nature is "structurally impossible" within the IBC's claims framework.

Third, the clean slate doctrine is enforced broadly. Even if the Data Protection Board files a claim, a creditor-approved resolution plan that does not account for it — because the penalty was unquantified or unpublicised during the CIRP — can lawfully extinguish the Board's enforcement right once the NCLT approves the plan.

The result: a data fiduciary company enters CIRP while a Board inquiry is pending. The inquiry concludes after the resolution plan is approved. The Board issues a ₹200 crore penalty order. The acquiring entity argues it cannot be held liable for pre-CIRP violations, and that the penalty is extinguished by the clean slate. Indian courts, applying Section 31(1) strictly, may agree.


#The Perverse Incentive This Creates

This gap is not just a technical legal puzzle. It creates a perverse compliance incentive that should concern every Indian regulator and data subject.

A data-intensive company facing financial distress has an implicit incentive to delay Board proceedings. Under the current legal framework, every month of delay increases the probability that the CIRP timeline and the penalty order timeline will overlap in the acquirer's favour. There is no mechanism currently preventing a well-advised company from exploiting this overlap.

The incentive is compounded by a feature of the DPDP Act that is often overlooked: penalties collected by the Board flow to the Consolidated Fund of India — they are not distributed to affected data principals. This means that individuals whose financial data was exposed, whose Aadhaar numbers were compromised, or whose healthcare records were mishandled receive nothing from the enforcement action regardless of its outcome. If the penalty is extinguished through insolvency proceedings, the same individuals who suffered the underlying violation now face a second injury: not only were their rights violated, but the entity responsible faced zero legal consequence.

The parallel to other regulatory penalties is instructive and discouraging. In Regional Provident Fund Commissioner v. Jayesh Sanghrajka, the National Company Law Appellate Tribunal applied the clean slate doctrine rigidly to EPF claims — rejecting even belated provident fund claims whose quantum crystallised only after the resolution plan was approved. If a social security regime as established as the EPF faces extinguishment through CIRP, the DPDP Act's younger and less institutionally embedded enforcement architecture is at even greater risk.


#India's Fintech and Banking Data Exposure

This is not an abstract corporate law question. India's insolvency courts handle hundreds of active CIRPs at any time, and the companies entering this process increasingly include data-intensive players: fintech lenders holding millions of loan application records, ed-tech platforms with detailed user learning profiles, healthcare aggregators managing patient histories, and digital payment processors with transaction-level financial data.

India's banking and financial sector is moving quickly toward DPDP compliance: just this week, Union Bank of India announced its engagement of Leegality's Consentin platform for consent management across its 8,675-plus domestic branches — one of the most significant public sector DPDP compliance rollouts to date. But compliance adoption is uneven. The same EY survey cited by Business Standard this week found that 70 percent of surveyed compliance professionals lacked familiarity with the DPDP Act and Rules as of mid-2026.

In a sector where compliance readiness is still being built from the ground up, the companies most likely to face financial distress are also the companies least likely to have invested in privacy infrastructure — precisely the organisations whose DPDP exposure may be most significant when insolvency arrives.


#Two Paths to Closing the Gap

The LiveLaw analysis identifies two routes India can take to prevent DPDP Act penalties from disappearing into insolvency proceedings.

Purposive judicial interpretation. Courts adjudicating IBC-DPDP overlaps can apply the proportionality framework the Supreme Court established in K.S. Puttaswamy v. Union of India — which requires that any mechanism affecting fundamental rights be subject to legal safeguards and oversight. A court applying this framework could hold that extinguishing a DPDP penalty through the clean slate doctrine is constitutionally inadequate where the underlying violation involved large-scale infringement of privacy rights under Article 21. Indian courts have shown willingness to engage in purposive statutory interpretation when fundamental rights are engaged, particularly in the post-Puttaswamy landscape.

Legislative amendment to Section 32A. The cleaner solution is a targeted amendment extending the IBC's liability framework to cover civil regulatory penalties arising from violations of fundamental rights — analogous to the way Parliament has already treated EPF and certain employee-related dues as protected claims in insolvency. The DPDP Act is Parliament's own enactment to give effect to Puttaswamy's requirement of a legal privacy framework. Permitting IBC proceedings to erode that framework through the clean slate doctrine creates a structural inconsistency between two statutes passed by the same legislature.

The GDPR comparison is instructive on the policy question. Several EU member states have adapted their insolvency frameworks to treat data protection regulatory penalties as protected liabilities, recognising that allowing privacy enforcement to be gamed through financial restructuring would undermine the credibility of the entire regulatory framework. India's DPDP Act is younger and its enforcement infrastructure is still being built, making the precedent set now — before the first wave of significant enforcement actions — more consequential than it would be in a mature system.


#What Compliance Teams and Investors Should Do Now

The IBC-DPDP gap is live today, not a future hypothetical. The Data Protection Board is conducting inquiries, the Consent Manager Framework goes live in November 2026, and the first wave of major penalty orders may arrive before the full compliance deadline in May 2027. CIRP processes running concurrently with active Board investigations will face this legal question.

For compliance teams: Assess whether your company's data processing exposure would constitute a material contingent liability in an insolvency context. If your company holds or manages sensitive data at scale — financial, health, or identity data — your legal team's insolvency scenario planning should include DPDP Act liability as an unquantifiable but material contingent claim, and consider proactively notifying the resolution professional of pending Board proceedings.

For investors and acquirers in distressed M&A: Standard DPDP Act due diligence for a distressed target must now include an assessment of pending or likely Board inquiries, even if no order has been issued. The inability to quantify these at claims submission is a risk that should be reflected in resolution plan pricing and indemnity structures.

For the Data Protection Board: The Board's operating procedures should be reviewed for urgency mechanisms that allow expedited inquiry completion when a data fiduciary enters CIRP — reducing the window during which the timeline gap can be exploited.

Visit /resources for updated DPDP Act compliance templates and a guide to data protection liability assessments under the current regulatory framework.


#Conclusion

The DPDP Act was designed to make data protection accountability real in India — backed by penalties serious enough to change corporate behaviour. The Insolvency and Bankruptcy Code was designed to make distressed asset resolution viable — backed by a clean slate principle that gives acquirers the certainty they need to take on difficult assets. Both statutes serve legitimate and important purposes.

But they were not designed together, and the gap between them is not theoretical. When a data-intensive company enters insolvency while a Data Protection Board inquiry is pending, the architecture of Indian law currently allows privacy enforcement to evaporate entirely — without judicial scrutiny, without legislative sanction, and without any consequence reaching either the violating company or the data subjects whose rights were breached.

The LiveLaw analysis published this week is, to this author's knowledge, the first systematic examination of this intersection. It deserves serious attention from the Ministry of Electronics and Information Technology, the Insolvency and Bankruptcy Board of India, and the Parliament's standing committees overseeing both statutes. The fix — whether through courts or legislation — is achievable. The cost of not fixing it is an enforcement regime that can be gamed before it has ever issued its first major ruling.

India's DPDP Act will be judged not by the penalties it threatens, but by those it collects. The IBC gap is the first test of whether that accountability is real.


Tracking DPDP Act enforcement developments and compliance deadlines? Visit /resources for updated regulatory guides or review our /consent-manager tools ahead of the November 2026 Consent Manager Framework deadline.

Automate your DPDP compliance

Capture consent, honour data principal rights, and stay audit-ready — all in one platform.

Start free trial