This repository presents a legal analysis of the 2017 Zomato data breach through the lens of India's Digital Personal Data Protection (DPDP) Act, 2023. The paper explores the regulatory, compliance, and enforcement consequences that would arise if an identical breach occurred in 2026, after the implementation of India's comprehensive data protection framework.
The purpose of this analysis is to examine how the DPDP Act, 2023 has transformed corporate accountability for personal data breaches by introducing statutory obligations relating to security safeguards, breach notification, regulatory oversight, and financial penalties.
- Security Safeguards (Section 8(5))
- Personal Data Breach Notification (Section 8(6))
- Significant Data Fiduciary (SDF) Obligations (Section 10)
- Grievance Redressal Mechanisms (Section 13)
- Data Protection Board Inquiries (Section 28)
- Financial Penalties (Section 33)
The paper contrasts the actual legal outcome of the 2017 breach with the hypothetical regulatory consequences under the DPDP Act, highlighting the evolution of India's data protection regime.
Ankita Kumari