{"id":384516,"date":"2026-05-19T12:30:32","date_gmt":"2026-05-19T07:00:32","guid":{"rendered":"https:\/\/www.scconline.com\/blog\/?p=384516"},"modified":"2026-05-19T10:55:10","modified_gmt":"2026-05-19T05:25:10","slug":"dpdpa-harm-definition-privacy-adjudication-analysis","status":"publish","type":"post","link":"https:\/\/www.scconline.com\/blog\/post\/2026\/05\/19\/dpdpa-harm-definition-privacy-adjudication-analysis\/","title":{"rendered":"Is the Absence of a Statutory Definition of \u201cHarm\u201d under the Digital Personal Data Protection Act, 2023 Likely to Create Interpretational Uncertainty in Privacy Adjudication?"},"content":{"rendered":"<div style=\"text-align: justify; line-height: 150%;\">\n<p style=\"margin-bottom: 3%; font-style: italic; text-align: center;\">There is a clear need for a uniform legislative definition of harm. The definition would reinforce the Act&#8217;s constitutional values of dignity, autonomy, and informational self-determination, while ensuring legal certainty, consistent adjudication, and proportionate enforcement.<\/p>\n<h2>Introduction<\/h2>\n<p style=\"margin-bottom: 3%;\">The term &#8220;harm&#8221; occupies a peculiar position in the <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593555\" target=\"_blank\">Digital Personal Data Protection Act, 2023<\/a> (DPDPA). While it conspicuously appears in the definitional provision, <a href=\"https:\/\/www.dpdpa.com\/dpdpa2023\/chapter-1\/section2.html\" target=\"_blank\">Section 2(u)<\/a> for &#8220;personal data breach&#8221;, in Section <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593454\" target=\"_blank\">14<\/a> discussing the data principal&#8217;s right to nominate a representative and under <a href=\"https:\/\/www.dpdpa.com\/dpdpa2023\/chapter-6\/section27.html\" target=\"_blank\">Section 27<\/a>, discussing mandates to the Data Protection Board of India (DPBI), the very term &#8220;harm&#8221; itself has not been defined.<a id=\"fnref1\" href=\"#fn1\" title=\"1. Digital Personal Data Protection Act, 2023, Ss. 2(u), 14 and 27.\"><sup>1<\/sup><\/a><!-- LE to confirm Section 8(x) or Section 8(6), as Section 8(x) is not mentioned in the Act. --> The term does have decisive legal consequences but the architecture of the DPDPA does not provide any content to make it operative.<a id=\"fnref2\" href=\"#fn2\" title=\"2. Sriya Sridhar, &#8220;The Elephant Not in the Room: The DPDPA's Failure to Regulate Behavioural Tracking&#8221; (7-5-2024) Law School Policy Review, available at &lt;https:\/\/lawschoolpolicyreview.com\/2024\/05\/07\/the-elephant-not-in-the-room-the-dpdpas-failure-to-regulate-behavioural-tracking\/&gt; last accessed 15-4-2026.\"><sup>2<\/sup><\/a> Such ambiguities in Indian statutory drafting are not new. For nearly a decade, the <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-0002796572\" target=\"_blank\">Information Technology Act, 2000<\/a> used the term &#8220;damage&#8221; in Section <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-0001540620\" target=\"_blank\">43<\/a> before judicial interpretation clarified its nature. In this context, the absence of a definition of &#8220;harm&#8221; is not merely an inconvenience but rather an invitation to adjudicative inconsistency that cuts against the statute&#8217;s own constitutional foundations.<\/p>\n<p style=\"margin-bottom: 3%;\">The discussion in this article argues that the DPDPA&#8217;s failure to define &#8220;harm&#8221; creates uncertainty in enforcement, interpretation, and penalty assessment. It proposes a clear statutory definition encompassing material and non-material harms, grounded in constitutional values, to ensure consistency, fairness, and effective data protection while avoiding arbitrary or inconsistent regulatory outcomes.<\/p>\n<h2>The operative presence of &#8220;harm&#8221; in the DPDPA<\/h2>\n<p style=\"font-style: italic; background-image: linear-gradient(to left, #FFFFFF, rgb(236, 198, 198));\">Section <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593460\" target=\"_blank\">2(u)<\/a><\/p>\n<p style=\"margin-bottom: 3%;\">Section <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593460\" target=\"_blank\"><span class=\"Hyperlink\">2(<span style=\"font-style: italic;\">u<\/span>)<\/span><\/a> <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593555\" target=\"_blank\">DPDPA<\/a> defines a &#8220;personal data breach&#8221; as &#8220;any unauthorised processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises the confidentiality, integrity or availability of personal data&#8221;.<\/p>\n<p style=\"margin-bottom: 3%;\">Even though the term &#8220;harm&#8221; is not explicitly mentioned, the breach notification obligation pursuant to Section <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593491\" target=\"_blank\">8(6)<\/a> is based on the fact that in the event of a breach, there arises an instant notification duty with no harm-capacity threshold irrespective of whether the breach has the capacity to harm the data principals.<a id=\"fnref3\" href=\"#fn3\" title=\"3. Digital Personal Data Protection Act, 2023, S. 8(6).\"><sup>3<\/sup><\/a> The absence of a threshold discussing harm thus, creates a subsidiary definitional problem, wherein every unauthorised access, however trivial will technically trigger a notification that produces compliance inflation, diluting its protective function.<\/p>\n<p style=\"font-style: italic; background-image: linear-gradient(to left, #FFFFFF, rgb(236, 198, 198));\">Section 27<\/p>\n<p style=\"margin-bottom: 3%;\">The definitional gap caused by the absence of a definition of harm is most prominently seen in <a href=\"https:\/\/www.dpdpa.com\/dpdpa2023\/chapter-6\/section27.html\" target=\"_blank\">Section 27<\/a>. Data principals submit their complaints to DPBI pursuant to <a href=\"https:\/\/www.dpdpa.com\/dpdpa2023\/chapter-6\/section27.html\" target=\"_blank\">Section 27<\/a> wherein the DPBI will then determine whether the data fiduciary has failed in its compliance duties.<a id=\"fnref4\" href=\"#fn4\" title=\"4. Digital Personal Data Protection Act, 2023, S. 27&#9;\"><sup>4<\/sup><\/a> <a href=\"https:\/\/www.dpdpa.com\/dpdpa2023\/chapter-6\/section27.html\" target=\"_blank\">Section 27<\/a> empowers the DPBI to impose monetary penalties specified in <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593448\" target=\"_blank\">Schedule <\/a> the DPDPA upon determining contravention.<a id=\"fnref5\" href=\"#fn5\" title=\"5. Ibid\"><sup>5<\/sup><\/a> The <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593448\" target=\"_blank\">Schedule <\/a> then ties the quantification of the penalty to be ascertained by &#8220;nature, gravity and duration&#8221; of the non-compliance.<a id=\"fnref6\" href=\"#fn6\" title=\"6. Digital Personal Data Protection Act, 2023, Sch. \"><sup>6<\/sup><\/a> However, neither provision define what is this nature of &#8220;harm&#8221; to a data principal that needs to be established, or the standard of proof to govern its determination. The Board will thus be left to construct its own jurisprudence with no legislative anchor on the subject.<\/p>\n<p style=\"font-style: italic; background-image: linear-gradient(to left, #FFFFFF, rgb(236, 198, 198));\">Section 14<\/p>\n<p style=\"margin-bottom: 3%;\">Section <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593454\" target=\"_blank\">14<\/a> permits data principals to nominate other individuals to exercise rights on their behalf in an event of incapacity.<a id=\"fnref7\" href=\"#fn7\" title=\"7. Digital Personal Data Protection Act, 2023, S. 14.\"><sup>7<\/sup><\/a> The provision assumes that the rights it protects &#8212; access, correction, erasure and grievance redressal &#8212; are sufficiently consequential to survive the death of the data principal. The link between the rights and harm prevention is self-evident but unstated. The silence is not immediately problematic but becomes one when the court or the DPBI is called upon to determine posthumously, the threshold of harm that the deceased data principal&#8217;s rights were intended to guard against.<\/p>\n<h2>Sections <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593489\" target=\"_blank\">6<\/a> through <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593492\" target=\"_blank\">9<\/a><\/h2>\n<p style=\"margin-bottom: 3%;\">Sections <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593489\" target=\"_blank\">6<\/a>&#8212;<a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593492\" target=\"_blank\">9<\/a> <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593555\" target=\"_blank\">DPDPA<\/a> lays down a comprehensive framework for how consent is to be obtained for processing personal data, however, it fails to articulate &#8220;harm&#8221; as an explicit threshold for determining the unlawfulness of processing.<a id=\"fnref8\" href=\"#fn8\" title=\"8. Digital Personal Data Protection Act, 2023, Ss. 6, 7, 8 and 9\"><sup>8<\/sup><\/a><\/span><\/span> The legitimacy of processing data in the absence of consent under Section <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593490\" target=\"_blank\">7<\/a> is only permitted for specific purposes which carry an implicit harm-avoidance rationale.<a id=\"fnref9\" href=\"#fn9\" title=\"9. Digital Personal Data Protection Act, 2023, S. 7.\"><sup>9<\/sup><\/a> However, without a statutory definition of harm, the implicit proportionality calibration that underlies this provision remains opaque and susceptible to inconsistent application.<\/span><\/p>\n<h2>Interpretational uncertainty<\/h2>\n<p style=\"font-style: italic; background-image: linear-gradient(to left, #FFFFFF, rgb(236, 198, 198));\">The absence of a threshold for harm<\/p>\n<p style=\"margin-bottom: 3%;\">One of the most fundamental uncertainties in the DPDPA comes from the fact that there is no identifying point to determine when a data processing or breach becomes &#8220;harmful&#8221;. This is a concern because data related consequences may exist across a spectrum, wherein in one end, a large-scale disclosure of sensitive financial information may lead to direct monetary loss and on the other end, a minor unauthorised disclosure may not have big tangible consequences.<a id=\"fnref10\" href=\"#fn10\" title=\"10. Daniel J. Solove, &#8220;A Taxonomy of Privacy&#8221; (2006) 154 University of Pennsylvania Law Review 529&#8212;531.\"><sup>10<\/sup><\/a> The Act does not offer any guidance to determine where this harm may begin.<\/p>\n<p style=\"\">In the absence of a proper statutory direction to determine harm, the following frameworks may emerge:<\/p>\n<p style=\"margin-left: 36pt; text-indent: -18pt;\">1. A subjective harm framework: Wherein harm is determined on the basis of the individual data principal&#8217;s experience. This approach may be sensitive to personal vulnerabilities but will be risky and unpredictable since identical breaches may yield different outcomes depending on individual perception.<a id=\"fnref11\" href=\"#fn11\" title=\"11. Ryan Calo, &#8220;The Boundaries of Privacy Harm&#8221; (2011) 86 Indiana Law Journal 1145&#8212;1146.\"><sup>11<\/sup><\/a><\/p>\n<p style=\"margin-bottom: 3%; margin-left: 36pt; text-indent: -18pt;\">2. Objective harm framework: In this framework, harm is assessed on the basis of whether a reasonable person in the same position would suffer harm. This may enhance consistency but may overlook structural inequalities. When a neutral reasonable person&#8217;s standard if not properly calibrated could undervalue harm experiences by marginalised groups. <a id=\"fnref12\" href=\"#fn12\" title=\"12. Ryan Calo, &#8220;The Boundaries of Privacy Harm&#8221; (2011) 86 Indiana Law Journal 1147&#8212;1149.\"><sup>12<\/sup><\/a><\/p>\n<p style=\"margin-bottom: 3%;\">The DPDPA does not indicate which framework should govern. This raises the risk of inconsistent application by the DPBI, potentially varying across cases or types of data fiduciaries.<\/p>\n<p style=\"font-style: italic; background-image: linear-gradient(to left, #FFFFFF, rgb(236, 198, 198));\">The problem of correct taxonomy of harm<\/p>\n<p style=\"margin-bottom: 3%;\">Even if a threshold were to be established, uncertainty would still persist with respect to the kinds of harm that are legally cognizable. In such instances, comparative data protection framework recognises these multiple categories such as material harm, non-material harm, harm over autonomy such as loss of control over personal data and lastly systemic harm from losing trust over the system.<a id=\"fnref13\" href=\"#fn13\" title=\"13. Daniel J. Solove, &#8220;A Taxonomy of Privacy&#8221; (2006) 154 University of Pennsylvania Law Review 524&#8212;529.\"><sup>13<\/sup><\/a><\/p>\n<p style=\"margin-bottom: 3%;\"><span style=\"Open Sans&quot;;\">The Act does not clarify whether non-material or autonomy-based harms can be actionable and this omission will have constitutional implications. For instance, with respect to right to privacy, it was determined in <span class=\"Hyperlink\" style=\"font-style: italic;\"><a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-0002748027\" target=\"_blank\">Puttaswamy<\/a> case<\/span><a id=\"fnref14\" href=\"#fn14\" title=\"14. K.S. Puttaswamy (Privacy-9J.) v. Union of India, (2017) 10 SCC 1.\"><sup>14<\/sup><\/a> that, privacy is grounded in dignity, autonomy and informational self-determination wherein values cannot be merely reduced to financial loss. Thus, a regime that only recognises material harm would diverge from the constitutional foundation. In contrast, the <a href=\"http:\/\/www.scconline.com\/DocumentLink\/PXFVBb1i\" target=\"_blank\">European Union&#8217;s (EU&#8217;s) General Data Protection Regulation, 2016 (GDPR)<\/a> explicitly includes non-material harm.<a id=\"fnref15\" href=\"#fn15\" title=\"15. General Data Protection Regulation, 2016, Recital 85.\"><sup>15<\/sup><\/a> Judicial interpretation through various cases has confirmed that distress or anxiety can be compensated if its real and linked causally to a violation. In both <a href=\"http:\/\/www.scconline.com\/DocumentLink\/957MuT6u\" target=\"_blank\"><span style=\"font-style: italic;\">S. Nambi Narayanan<\/span> v. <span style=\"font-style: italic;\">Siby Mathews<\/span><\/a><a id=\"fnref16\" href=\"#fn16\" title=\"16. S. Nambi Narayanan v. Siby Mathews, (2018) 10 SCC 804\"><sup>16<\/sup><\/a> and <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-0000018597\" target=\"_blank\"><span class=\"Hyperlink\"><span style=\"font-style: italic;\">Nilabati Behera<\/span> v. <span style=\"font-style: italic;\">State of Orissa<\/span><\/span><\/a><a id=\"fnref17\" href=\"#fn17\" title=\"17. (1993) 2 SCC 746 : 1993 SCC (Cri) 527.\"><sup>17<\/sup><\/a>, the Supreme Court affirmed that compensation will be awarded for non-tangible harm such as trauma, humiliation and reputational damage. While the analysis in these cases can be used as analogical support instead of direct authority, they still affirm that constitutional remedies cannot be confined to merely pecuniary loss.<\/span><\/p>\n<p style=\"margin-bottom: 3%;\">However, no equivalent clarity of this nature is provided in the DPDPA. The DPBI may thus either exclude such claims due to a lack of statutory basis or recognise them inconsistently, eventually undermining both deterrence and compensatory approaches.<\/p>\n<p style=\"font-style: italic; background-image: linear-gradient(to left, #FFFFFF, rgb(236, 198, 198));\">Complexities involving the establishment of cause<\/p>\n<p style=\"margin-bottom: 3%;\">Even if harm were to be recognised, establishing cause in data protection cases can be a complex case. Data flows through multiple agencies and time-frames and can be difficult to monitor.<\/p>\n<p style=\"margin-bottom: 3%;\"><span style=\"text-decoration: underline; text-underline-style: solid; text-underline-mode: continuous;\">Example:<\/span> financial loss after a data breach can be the result of a chain of events, involving multiple intermediaries, external factors and independent criminal activities.<\/p>\n<p style=\"margin-bottom: 3%;\">No causation standards are specified within the DPDPA and as a result, adjudication is left to general principles under the Indian tort law. The doctrines under the Indian tort law system are not designed to deal with digital ecosystems and the outcome may misalign with the protective intent of the Act.<a id=\"fnref18\" href=\"#fn18\" title=\"18. Digital Personal Data Protection Bill, 2023. PRS Legislative Research, &#8220;The Digital Personal Data Protection Bill, 2023 Ministry: Electronics and Information Technology&#8221;, available at &lt;https:\/\/prsindia.org\/billtrack\/digital-personal-data-protection-bill-2023&gt; last accessed 15-4-2026.\"><sup>18<\/sup><\/a> Specifically, traditional requirements for establishing direct cause may fail to capture systemic harms that emerge from large-scale data practices such as surveillance driven models, even if the DPDPA does reference such models for determining harm to individuals.<a id=\"fnref19\" href=\"#fn19\" title=\"19. Digital Personal Data Protection Bill, 2023.\"><sup>19<\/sup><\/a><\/p>\n<p style=\"font-style: italic; background-image: linear-gradient(to left, #FFFFFF, rgb(236, 198, 198));\">Complexities involving the calibration of penalties<\/p>\n<p style=\"margin-bottom: 3%;\">The DPDPA&#8217;s <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593448\" target=\"_blank\">Schedule <\/a> prescribes a penalty of up to Rs 250 crores for the failure to implement security safeguards and Rs 200 crores for violations involving data of minors.<a id=\"fnref20\" href=\"#fn20\" title=\"20. Digital Personal Data Protection Act, 2023, Sch. \"><sup>20<\/sup><\/a> However, this determination of penalty is tied to harm and only references general factors such as the &#8220;nature, gravity, and duration&#8221; of non-compliance. Scholarship on administration of penalty shows that in the absence of a concrete concept of harm, the calibration of penalty will become discretionary to the point that it may create risks of both under and over-enforcement. Penalties can be disproportionately imposed to the actual harm or be insufficient to reflect serious violations. This weakens both fairness and deterrence.<a id=\"fnref21\" href=\"#fn21\" title=\"21. Jerry L. Anderson and Amy Grace Vaughan, &#8220;Environmental Penalties: Discretion and Disparity&#8221; (2023) 42 Stanford Environmental Law Journal 7.\"><sup>21<\/sup><\/a><\/p>\n<h2>Possibility of filling the gaps without legislative action<\/h2>\n<p style=\"font-style: italic; background-image: linear-gradient(to left, #FFFFFF, rgb(236, 198, 198));\">Constitutional interpretation<\/p>\n<p style=\"margin-bottom: 3%;\">The most principled interpretive resource is the privacy framework developed in <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-0002748027\" target=\"_blank\"><span style=\"text-decoration: underline; text-underline-style: solid; text-underline-mode: continuous; text-underline-color: #0000ff; color: #0000ff;\"><span style=\"font-style: italic;\">K.S. Puttaswamy (Privacy-9J.)<\/span> v. <span style=\"font-style: italic;\">Union of India<\/span><\/span><\/a>.<a id=\"fnref22\" href=\"#fn22\" title=\"22. (2017) 10 SCC 1.\"><sup>22<\/sup><\/a> It is understood to protect bodily integrity, mental integrity and informational self-determination. Any interferences with privacy rights must satisfy proportional requirements. When applied to the DPDPA, it would suggest that harm includes any impairment, actual or likely of these protected interests. Such interpretation supports the recognition of non-material and autonomy-based harms and aligns the statute with constitutional values. <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-0002748027\" target=\"_blank\"><span class=\"Hyperlink\" style=\"font-style: italic;\">Puttaswamy case<\/span><\/a> primarily addresses State action. Extending its principles to private data fiduciaries requires a form of horizontal application that remains doctrinally unsettled in Indian law.<a id=\"fnref23\" href=\"#fn23\" title=\"23. Anujay Shrivastava, &#8220;Indian Supreme Court's Judgment on &#8216;Horizontal Application&#8217; of Fundamental Rights: An &#8216;Unconstitutional Informal Constitutional Change&#8217;?&#8221; (31-1-2023) IACL-AIDC Blog, available at &lt;https:\/\/blog-iacl-aidc.org\/2023-posts\/2023\/1\/31\/indian-supreme-courts-judgment-on-horizontal-application-of-fundamental-rights-an-unconstitutional-informal-constitutional-change&gt; last accessed 15-4-2026.\"><sup>23<\/sup><\/a> While the DPDPA must be interpreted consistently with constitutional rights, the mechanism for importing constitutional harm concepts into statutory adjudication is unclear.<\/p>\n<p style=\"font-style: italic; background-image: linear-gradient(to left, #FFFFFF, rgb(236, 198, 198));\">Purposive interpretation<\/p>\n<p style=\"margin-bottom: 3%;\">The Statement of Objects and Reasons to the DPDPA emphasise balancing individual rights with legal data processing.<a id=\"fnref24\" href=\"#fn24\" title=\"24. Digital Personal Data Protection Act, 2023 S. 8 &lt;https:\/\/www.dpdpa.com\/dpdpa2023\/chapter-2\/section8.html&gt; accessed 15 April 2026.\"><sup>24<\/sup><\/a> A purposive reading would infer that harm includes the consequences which the Act seeks to prevent, such as financial, physical or reputational damage. However, purposive interpretation does not have the legal certainty that comes with explicit statutory language and its conclusions are inherently provisional, while varying across jurisdictions and thus limits its efficacy as a substitute for statutory language.<a id=\"fnref25\" href=\"#fn25\" title=\"25. Maneka Gandhi v. Union of India, (1978) 1 SCC 248; Internet Governance Blog (Centre for Internet and Society) available at&lt;https:\/\/cis-india.org\/internet-governance\/blog&gt; last accessed 15-4-2026.\"><sup>25<\/sup><\/a><\/p>\n<p style=\"font-style: italic; background-image: linear-gradient(to left, #FFFFFF, rgb(236, 198, 198));\">Comparative law<\/p>\n<p style=\"margin-bottom: 3%;\"><span style=\"Open Sans&quot;;\">The EU&#8217;s <a href=\"http:\/\/www.scconline.com\/DocumentLink\/PXFVBb1i\" target=\"_blank\">GDPR<\/a> provides a detailed articulation of harm that covers all aspects such as financial, reputational, emotional and social consequences, as well as loss of control over data.<a id=\"fnref26\" href=\"#fn26\" title=\"26. General Data Protection Regulation, 2016, Recitals 85 and 75.\"><sup>26<\/sup><\/a> Similarly, in UK, the regulatory practice under the <a href=\"https:\/\/www.legislation.gov.uk\/ukpga\/2018\/12\/contents\" target=\"_blank\">Data Protection Act, 2018<\/a><\/span><a href=\"https:\/\/www.legislation.gov.uk\/ukpga\/2018\/12\/contents\" target=\"_blank\"><span class=\"annotation&nbsp;reference\" style=\"text-decoration: underline; text-underline-style: solid; text-underline-mode: continuous; text-underline-color: #0000ff; color: #0000ff;\"><\/span><!-- XML to hyperlink throughout&nbsp; --><\/span><\/span><\/a><a href=\"https:\/\/www.legislation.gov.uk\/ukpga\/2018\/12\/contents\" target=\"_blank\"> (UK)<\/a> and ICO (Information Commissioner&#8217;s Office) guidance recognises multiple harm categories while excluding trivial claims.<a id=\"fnref27\" href=\"#fn27\" title=\"27. Vidal-Hall v. Google Inc. 2015 EWCA Civ 311; Data Protection Act, 2018, S. 168 (United Kingdom).\"><sup>27<\/sup><\/a><\/span><\/span><!-- Vidal-Hall v. Google Inc., (2015) 3 WLR 609 XML to hyperlink<br \/>and<br \/>Data Protection Act, 2018, S. 168 (UK) XML to hyperlink --><\/span><\/span><\/span><!-- XML pls hyperlink --><\/span> While these regimes are instructive, they are not binding in the Indian legal regime. Their adoption would require a deliberate and consistent comparative reasoning by the DPBI, something that is yet to be established in Tribunal practice. While selective borrowing can risk inconsistency and normative distortion, they can also serve as great guides that readily available for a speedy drafting and incorporation of provisions into the current Indian regime on data protection.<a id=\"fnref28\" href=\"#fn28\" title=\"28. Vaibhav Dharod and Kevin Tauro, &#8220;Assessing India's Digital Personal Data Protection Act, 2023: A Comparative Study with the GDPR&#8221; (2025) 7(2) Indian Journal of Law and Legal Research 1325.\"><sup>28<\/sup><\/a><\/span><\/p>\n<h2>Regulatory Guidance<\/h2>\n<p style=\"margin-bottom: 3%;\">The DPBI and the Central Government have the powers to issue guidelines and rules to clarify the concept of &#8220;harm&#8221;.<a id=\"fnref29\" href=\"#fn29\" title=\"29. Digital Personal Data Protection Act, 2023, S. 40.\"><sup>29<\/sup><\/a> While this route offers great flexibility and speed of incorporation, the subordinate legislation cannot substitute for a statutory definition. Guidelines may lack the necessary authority, permanence, and democratic legitimacy of primary legislation. Making this vulnerable to legal challenges. Judicial observances in cases such as <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-0000013899\" target=\"_blank\"><span class=\"Hyperlink\"><span style=\"font-style: italic;\">Indian Express Newspapers (Bombay) (P) Ltd.<\/span> v. <span style=\"font-style: italic;\">Union of India<\/span><\/span><\/a><a id=\"fnref30\" href=\"#fn30\" title=\"30. (1985) 1 SCC 641 : 1985 SCC (Tax) 121 : (1986) 159 ITR 856.\"><sup>30<\/sup><\/a> and <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-0000037831\" target=\"_blank\"><span class=\"Hyperlink\"><span style=\"font-style: italic;\">State of T.N.<\/span> v. <span style=\"font-style: italic;\">P. Krishnamurthy<\/span><\/span><\/a><a id=\"fnref31\" href=\"#fn31\" title=\"31. (2006) 4 SCC 517.\"><sup>31<\/sup><\/a> observed that guidelines may be supplemental but cannot resolve the structural gap.<\/p>\n<h2>The case for legislative intervention<\/h2>\n<p>From the discussion above, it has become evident that a statutory definition of harm is absolutely necessary, keeping the following elements in mind:<\/p>\n<p style=\"margin-left: 36pt; text-indent: -18pt;\">1. <span style=\"font-style: italic;\">The existing Rule of Law:<\/span> Wherein individuals and organisations must know in advance as to what constitutes harmful conduct and its consequences. An undefined harm standard will undermine legal certainty.<\/p>\n<p style=\"margin-left: 36pt; text-indent: -18pt;\">2. <span style=\"font-style: italic;\">Coherence with the constitutional standards<\/span>: Since the enforcement of DPDPA which is rooted in privacy must be reflective of dignity, autonomy and informational self-determination in a consistent manner.<\/p>\n<p style=\"margin-left: 36pt; text-indent: -18pt; margin-bottom: 3%;\">3. <span style=\"font-style: italic;\">Effective deterrence<\/span>: In the absence of a defined concept of harm, the penalty regime risks either a chilling legitimate processing or failing to prevent harmful conduct.<\/p>\n<p>Thus, a workable statutory definition would have to define &#8220;harm&#8221; as any adverse consequence caused, being caused, or likely to be caused to a data principal, including but not limited to<a id=\"fnref32\" href=\"#fn32\" title=\"32. General Data Protection Regulation, 2016, Recitals 85 and 75, and Art. 82.\"><sup>32<\/sup><\/a>:<\/p>\n<p style=\"margin-left: 36pt; text-indent: -18pt;\">&#8220;1. Discrimination.<\/p>\n<p style=\"margin-left: 36pt; text-indent: -18pt;\">2. Financial loss.<\/p>\n<p style=\"margin-left: 36pt; text-indent: -18pt;\">3. Loss of autonomy over personal data.<\/p>\n<p style=\"margin-left: 36pt; text-indent: -18pt;\">4. Loss of employment or livelihood.<\/p>\n<p style=\"margin-left: 36pt; text-indent: -18pt;\">5. Other significant economic, social, or personal disadvantages.<\/p>\n<p style=\"margin-left: 36pt; text-indent: -18pt;\">6. Physical injury or safety risks.<\/p>\n<p style=\"margin-left: 36pt; text-indent: -18pt;\">7. Psychological distress.<\/p>\n<p style=\"margin-left: 36pt; text-indent: -18pt; margin-bottom: 3%;\">8. Reputational damage.&#8221;<\/p>\n<p style=\"margin-bottom: 3%;\">This definition is inspired from the <a href=\"http:\/\/www.scconline.com\/DocumentLink\/PXFVBb1i\" target=\"_blank\">GDPR framework<\/a>, not derived from it. Adjudicators would still have to consider various contextual factors such as the nature of the data, the context in which it was being processed, the vulnerability of the data principal and the reasonable expectations at the time of collection.<a id=\"fnref33\" href=\"#fn33\" title=\"33. Anujay Shrivastava, &#8220;Indian Supreme Court's Judgment on &#8216;Horizontal Application&#8217; of Fundamental Rights: An &#8216;Unconstitutional Informal Constitutional Change&#8217;?&#8221; (31-1-2023) IACL-AIDC Blog, available at &lt;https:\/\/blog-iacl-aidc.org\/2023-posts\/2023\/1\/31\/indian-supreme-courts-judgment-on-horizontal-application-of-fundamental-rights-an-unconstitutional-informal-constitutional-change&gt; last accessed 15-4-2026.\"><sup>33<\/sup><\/a><\/p>\n<p style=\"margin-bottom: 3%;\">This approach has several advantages. It aligns with constitutional principles by explicitly including dignity and autonomy harms while also recognising informational self-determination as an independent interest. Most importantly, it incorporates a contextual analysis that allows harm to be assessed in a manner that is relative to the norms governing specific data relationships. Lastly, it also remains open-ended, enabling the recognition of new harm categories as technology evolves.<\/p>\n<h2>Conclusion<\/h2>\n<p style=\"margin-bottom: 3%;\">The silence of the DPDPA on what precisely constitutes harm may not just be a minor drafting omission, but rather a structural weakness that adversely impacts its operative provision. As observed from Sections 2, 6-9, 14 and 27, the Act implicitly relies on harm as a triggering and calibrating factor and still fails to define its threshold or evidentiary standards. The resulting interpretational uncertainty forces the DPBI to navigate subjective, objective, or risk-based frameworks without legislative guidance, and to determine causation and penalties in an inconsistent and potentially arbitrary manner. Even if the DPBI or the judicial authorities refer to constitutional interpretation, purposive reading, comparative frameworks, and regulatory guidance, it is still a partial solution that inherently limits them since such a solution lacks authority, clarity, and uniformity that only statutory articulation can fulfil.<\/p>\n<p style=\"margin-bottom: 3%;\">There is a clear need for a uniform legislative definition of harm. The definition would reinforce the Act&#8217;s constitutional values of dignity, autonomy, and informational self-determination, while ensuring legal certainty, consistent adjudication, and proportionate enforcement. Most importantly, the recognition of both material and non-material harms, and incorporating a contextual and forward-looking approach, would strengthen deterrence without stifling legitimate data practices. Ultimately, without explicitly defining harm, the DPDPA risks undermining its own protective purpose; with it, the Act can evolve into a coherent and effective data protection regime.<\/p>\n<\/div>\n<hr\/>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><strong><span style=\"color: #000080;\">*Legal Counsel, Blancco Technology Group. Author can be reached at: <a href=\"mailto:pen.paper.law@gmail.com\" target=\"_blank\">pen.paper.law@gmail.com<\/a>.<\/span><\/strong><\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><strong><span style=\"color: #000080;\">**Jr. Legal Counsel, Blancco Technology Group. Author can be reached at: <a href=\"mailto:shayna.jagtap@gmail.com\" target=\"_blank\">shayna.jagtap@gmail.com<\/a>.<\/span><\/strong><\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn1\" href=\"#fnref1\">1.<\/a> <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593555\" target=\"_blank\">Digital Personal Data Protection Act, 2023<\/a>, <a href=\"https:\/\/www.dpdpa.com\/dpdpa2023\/chapter-1\/section2.html\" target=\"_blank\">Ss. 2(u),<\/a> <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593454\" target=\"_blank\">14<\/span><\/a> and <a href=\"https:\/\/www.dpdpa.com\/dpdpa2023\/chapter-6\/section27.html\" target=\"_blank\">27.<\/a><\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn2\" href=\"#fnref2\">2.<\/a> Sriya Sridhar, &#8220;The Elephant Not in the Room: The DPDPA&#8217;s Failure to Regulate Behavioural Tracking&#8221; (7-5-2024) Law School Policy Review, available at &lt;<a href=\"https:\/\/lawschoolpolicyreview.com\/2024\/05\/07\/the-elephant-not-in-the-room-the-dpdpas-failure-to-regulate-behavioural-tracking\/\" target=\"_blank\">https:\/\/lawschoolpolicyreview.com\/2024\/05\/07\/the-elephant-not-in-the-room-the-dpdpas-failure-to-regulate-behavioural-tracking\/<\/a>&gt; last accessed 15-4-2026.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn3\" href=\"#fnref3\">3.<\/a> <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593555\" target=\"_blank\">Digital Personal Data Protection Act, 2023<\/a><\/span>, S. <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593491\" target=\"_blank\">8(6)<\/a>.<\/span><\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn4\" href=\"#fnref4\">4.<\/a> <a href=\"https:\/\/www.dpdpa.com\/dpdpa2023\/chapter-6\/section27.html\" target=\"_blank\">Digital Personal Data Protection Act, 2023, S. 27&#9;<\/a><\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn5\" href=\"#fnref5\">5.<\/a> Ibid<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn6\" href=\"#fnref6\">6.<\/a> <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593555\" target=\"_blank\">Digital Personal Data Protection Act, 2023<\/a>, <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593448\" target=\"_blank\">Sch. <\/a><\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn7\" href=\"#fnref7\">7.<\/a> <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593555\" target=\"_blank\">Digital Personal Data Protection Act, 2023<\/a><\/span>, S. <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593454\" target=\"_blank\">14<\/a>.<\/span><\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn8\" href=\"#fnref8\">8.<\/a> <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593555\" target=\"_blank\">Digital Personal Data Protection Act, 2023<\/a>, Ss<a href=\"https:\/\/www.dpdpa.com\/dpdpa2023\/chapter-2\/section6.html\" target=\"_blank\">. 6<\/a>, <a href=\"https:\/\/www.dpdpa.com\/dpdpa2023\/chapter-2\/section7.html\" target=\"_blank\">7<\/a>, <a href=\"https:\/\/www.dpdpa.com\/dpdpa2023\/chapter-2\/section8.html\" target=\"_blank\">8<\/a> and <a href=\"https:\/\/www.dpdpa.com\/dpdpa2023\/chapter-2\/section9.html\" target=\"_blank\">9<\/a><\/span><\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn9\" href=\"#fnref9\">9.<\/a> <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593555\" target=\"_blank\">Digital Personal Data Protection Act, 2023<\/a><\/span>, S. <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593490\" target=\"_blank\">7<\/a>.<\/span><\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn10\" href=\"#fnref10\">10.<\/a> Daniel J. Solove, &#8220;A Taxonomy of Privacy&#8221; (2006) 154 University of Pennsylvania Law Review 529&#8212;531.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn11\" href=\"#fnref11\">11.<\/a> Ryan Calo, &#8220;The Boundaries of Privacy Harm&#8221; (2011) 86 Indiana Law Journal 1145&#8212;1146.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn12\" href=\"#fnref12\">12.<\/a> Ryan Calo, &#8220;The Boundaries of Privacy Harm&#8221; (2011) 86 Indiana Law Journal 1147&#8212;1149.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn13\" href=\"#fnref13\">13.<\/a> Daniel J. Solove, &#8220;A Taxonomy of Privacy&#8221; (2006) 154 University of Pennsylvania Law Review 524&#8212;529.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn14\" href=\"#fnref14\">14.<\/a> <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-0002748027\" target=\"_blank\"><span style=\"text-decoration: underline; text-underline-style: solid; text-underline-mode: continuous; text-underline-color: #0000ff; color: #0000ff;\"><span style=\"font-style: italic;\">K.S. Puttaswamy (Privacy-9J.)<\/span> v. <span style=\"font-style: italic;\">Union of India<\/span><\/span><\/a><span style=\"font-style: italic;\"><\/span>, <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-0002748027\" target=\"_blank\">(2017) 10 SCC 1<\/a>.<\/span><\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn15\" href=\"#fnref15\">15.<\/a> General Data Protection Regulation, 2016, Recital 85.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn16\" href=\"#fnref16\">16.<\/a> <span style=\"font-style: italic;\">S. Nambi Narayanan<\/span> v. <span style=\"font-style: italic;\">Siby Mathews<\/span>, <a href=\"http:\/\/www.scconline.com\/DocumentLink\/957MuT6u\" target=\"_blank\">(2018) 10 SCC 804<\/a><\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn17\" href=\"#fnref17\">17.<\/a> <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-0000018597\" target=\"_blank\">(1993) 2 SCC 746<\/a> : 1993 SCC (Cri) 527.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn18\" href=\"#fnref18\">18.<\/a> <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001591748\" target=\"_blank\">Digital Personal Data Protection Bill, 2023<\/a>.<\/span> PRS Legislative Research, &#8220;The Digital Personal Data Protection Bill, 2023 Ministry: Electronics and Information Technology&#8221;, available at &lt;<a href=\"https:\/\/prsindia.org\/billtrack\/digital-personal-data-protection-bill-2023\" target=\"_blank\">https:\/\/prsindia.org\/billtrack\/digital-personal-data-protection-bill-2023<\/a>&gt; last accessed 15-4-2026.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn19\" href=\"#fnref19\">19.<\/a> <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001591748\" target=\"_blank\">Digital Personal Data Protection Bill, 2023<\/a>.<\/span><\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn20\" href=\"#fnref20\">20.<\/a> <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593555\" target=\"_blank\">Digital Personal Data Protection Act, 2023<\/a>, <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593448\" target=\"_blank\">Sch. <\/a><\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn21\" href=\"#fnref21\">21.<\/a> Jerry L. Anderson and Amy Grace Vaughan, &#8220;Environmental Penalties: Discretion and Disparity&#8221; (2023) 42 Stanford Environmental Law Journal 7.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn22\" href=\"#fnref22\">22.<\/a> <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-0002748027\" target=\"_blank\">(2017) 10 SCC 1<\/a>.<\/span><\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn23\" href=\"#fnref23\">23.<\/a> Anujay Shrivastava, &#8220;Indian Supreme Court&#8217;s Judgment on &#8216;Horizontal Application&#8217; of Fundamental Rights: An &#8216;Unconstitutional Informal Constitutional Change&#8217;?&#8221; (31-1-2023) IACL-AIDC Blog, available at &lt;<a href=\"https:\/\/blog-iacl-aidc.org\/2023-posts\/2023\/1\/31\/indian-supreme-courts-judgment-on-horizontal-application-of-fundamental-rights-an-unconstitutional-informal-constitutional-change\" target=\"_blank\">https:\/\/blog-iacl-aidc.org\/2023-posts\/2023\/1\/31\/indian-supreme-courts-judgment-on-horizontal-application-of-fundamental-rights-an-unconstitutional-informal-constitutional-change<\/a>&gt; last accessed 15-4-2026.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn24\" href=\"#fnref24\">24.<\/a> Digital Personal Data Protection Act, 2023 S. 8 &lt;<a href=\"https:\/\/www.dpdpa.com\/dpdpa2023\/chapter-2\/section8.html\" target=\"_blank\">https:\/\/www.dpdpa.com\/dpdpa2023\/chapter-2\/section8.html<\/a>&gt; accessed 15 April 2026.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn25\" href=\"#fnref25\">25.<\/a> <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-0000010952\" target=\"_blank\"><span style=\"text-decoration: underline; text-underline-style: solid; text-underline-mode: continuous; text-underline-color: #0000ff; color: #0000ff;\"><span style=\"font-style: italic;\">Maneka Gandhi<\/span> v. <span style=\"font-style: italic;\">Union of India<\/span><\/span><\/a>, <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-0000010952\" target=\"_blank\">(1978) 1 SCC 248<\/a>; Internet Governance Blog (Centre for Internet and Society) available at&lt;<a href=\"https:\/\/cis-india.org\/internet-governance\/blog\" target=\"_blank\">https:\/\/cis-india.org\/internet-governance\/blog<\/a>&gt; last accessed 15-4-2026.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn26\" href=\"#fnref26\">26.<\/a> General Data Protection Regulation, 2016, Recitals 85 and 75.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn27\" href=\"#fnref27\">27.<\/a> <a href=\"https:\/\/www.5rb.com\/case\/vidal-hall-v-google-inc\/\" target=\"_blank\"><span style=\"font-style: italic;\">Vidal-Hall<\/span> v. <span style=\"font-style: italic;\">Google Inc.<\/span> 2015 EWCA Civ 311<\/span><\/a>; Data Protection Act, 2018, S. 168 (United Kingdom).<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn28\" href=\"#fnref28\">28.<\/a> Vaibhav Dharod and Kevin Tauro, &#8220;Assessing India&#8217;s Digital Personal Data Protection Act, 2023: A Comparative Study with the GDPR&#8221; (2025) 7(2) Indian Journal of Law and Legal Research 1325.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn29\" href=\"#fnref29\">29.<\/a> <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593555\" target=\"_blank\">Digital Personal Data Protection Act, 2023<\/a>, S. <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593483\" target=\"_blank\">40<\/a>.<\/span><\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn30\" href=\"#fnref30\">30.<\/a> <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-0000013899\" target=\"_blank\">(1985) 1 SCC 641<\/a> : 1985 SCC (Tax) 121 : (1986) 159 ITR 856.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn31\" href=\"#fnref31\">31.<\/a> <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-0000037831\" target=\"_blank\">(2006) 4 SCC 517<\/a>.<\/span><\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn32\" href=\"#fnref32\">32.<\/a> General Data Protection Regulation, 2016, Recitals 85 and 75, and Art. 82.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn33\" href=\"#fnref33\">33.<\/a> Anujay Shrivastava, &#8220;Indian Supreme Court&#8217;s Judgment on &#8216;Horizontal Application&#8217; of Fundamental Rights: An &#8216;Unconstitutional Informal Constitutional Change&#8217;?&#8221; (31-1-2023) IACL-AIDC Blog, available at &lt;<a href=\"https:\/\/blog-iacl-aidc.org\/2023-posts\/2023\/1\/31\/indian-supreme-courts-judgment-on-horizontal-application-of-fundamental-rights-an-unconstitutional-informal-constitutional-change\" target=\"_blank\">https:\/\/blog-iacl-aidc.org\/2023-posts\/2023\/1\/31\/indian-supreme-courts-judgment-on-horizontal-application-of-fundamental-rights-an-unconstitutional-informal-constitutional-change<\/a>&gt; last accessed 15-4-2026.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>by Yash Bajpai* and Shayna Jagtap**<\/p>\n","protected":false},"author":67011,"featured_media":384517,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[42503,1191],"tags":[104632,104636,104634,104631,104635,104633],"class_list":["post-384516","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-legal-analysis","category-op-ed","tag-digital-personal-data-protection-act-2023-harm-interpretation","tag-digital-personal-data-protection-act-enforcement-uncertainty-india","tag-dpbi-privacy-harm-adjudication-data-protection-india","tag-dpdpa-harm-definition-privacy-adjudication-india-analysis","tag-informational-privacy-autonomy-harm-dpdpa-analysis","tag-undefined-harm-under-dpdpa-constitutional-privacy-concerns"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.4 (Yoast SEO v27.4) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>DPDPA Harm Definition and Privacy Adjudication | SCC Times<\/title>\n<meta name=\"description\" content=\"Analysis of interpretational uncertainty caused by undefined &quot;harm&quot; under the DPDPA.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.scconline.com\/blog\/post\/2026\/05\/19\/dpdpa-harm-definition-privacy-adjudication-analysis\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Is the Absence of a Statutory Definition of \u201cHarm\u201d under the Digital Personal Data Protection Act, 2023 Likely to Create Interpretational Uncertainty in Privacy Adjudication?\" \/>\n<meta property=\"og:description\" content=\"Analysis of interpretational uncertainty caused by undefined &quot;harm&quot; under the DPDPA.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.scconline.com\/blog\/post\/2026\/05\/19\/dpdpa-harm-definition-privacy-adjudication-analysis\/\" \/>\n<meta property=\"og:site_name\" content=\"SCC Times\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/scc.online\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-05-19T07:00:32+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.scconline.com\/blog\/wp-content\/uploads\/2026\/05\/DPDPA-harm-definition-privacy-adjudication-India-analysis.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"886\" \/>\n\t<meta property=\"og:image:height\" content=\"590\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Editor\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"Is the Absence of a Statutory Definition of \u201cHarm\u201d under the Digital Personal Data Protection Act, 2023 Likely to Create Interpretational Uncertainty in Privacy Adjudication?\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Editor\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/post\\\/2026\\\/05\\\/19\\\/dpdpa-harm-definition-privacy-adjudication-analysis\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/post\\\/2026\\\/05\\\/19\\\/dpdpa-harm-definition-privacy-adjudication-analysis\\\/\"},\"author\":{\"name\":\"Editor\",\"@id\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/#\\\/schema\\\/person\\\/84e42bab48238baf12c7e33b3d9761fe\"},\"headline\":\"Is the Absence of a Statutory Definition of \u201cHarm\u201d under the Digital Personal Data Protection Act, 2023 Likely to Create Interpretational Uncertainty in Privacy Adjudication?\",\"datePublished\":\"2026-05-19T07:00:32+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/post\\\/2026\\\/05\\\/19\\\/dpdpa-harm-definition-privacy-adjudication-analysis\\\/\"},\"wordCount\":2840,\"commentCount\":0,\"image\":{\"@id\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/post\\\/2026\\\/05\\\/19\\\/dpdpa-harm-definition-privacy-adjudication-analysis\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/DPDPA-harm-definition-privacy-adjudication-India-analysis.webp\",\"keywords\":[\"Digital Personal Data Protection Act 2023 harm interpretation\",\"Digital Personal Data Protection Act enforcement uncertainty India\",\"DPBI privacy harm adjudication data protection India\",\"DPDPA harm definition privacy adjudication India analysis\",\"informational privacy autonomy harm DPDPA analysis\",\"undefined harm under DPDPA constitutional privacy concerns\"],\"articleSection\":[\"Op Eds\",\"OP. ED.\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.scconline.com\\\/blog\\\/post\\\/2026\\\/05\\\/19\\\/dpdpa-harm-definition-privacy-adjudication-analysis\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/post\\\/2026\\\/05\\\/19\\\/dpdpa-harm-definition-privacy-adjudication-analysis\\\/\",\"url\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/post\\\/2026\\\/05\\\/19\\\/dpdpa-harm-definition-privacy-adjudication-analysis\\\/\",\"name\":\"DPDPA Harm Definition and Privacy Adjudication | SCC Times\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/post\\\/2026\\\/05\\\/19\\\/dpdpa-harm-definition-privacy-adjudication-analysis\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/post\\\/2026\\\/05\\\/19\\\/dpdpa-harm-definition-privacy-adjudication-analysis\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/DPDPA-harm-definition-privacy-adjudication-India-analysis.webp\",\"datePublished\":\"2026-05-19T07:00:32+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/#\\\/schema\\\/person\\\/84e42bab48238baf12c7e33b3d9761fe\"},\"description\":\"Analysis of interpretational uncertainty caused by undefined \\\"harm\\\" under the DPDPA.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/post\\\/2026\\\/05\\\/19\\\/dpdpa-harm-definition-privacy-adjudication-analysis\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.scconline.com\\\/blog\\\/post\\\/2026\\\/05\\\/19\\\/dpdpa-harm-definition-privacy-adjudication-analysis\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/post\\\/2026\\\/05\\\/19\\\/dpdpa-harm-definition-privacy-adjudication-analysis\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/DPDPA-harm-definition-privacy-adjudication-India-analysis.webp\",\"contentUrl\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/DPDPA-harm-definition-privacy-adjudication-India-analysis.webp\",\"width\":886,\"height\":590,\"caption\":\"DPDPA harm definition privacy adjudication India analysis\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/post\\\/2026\\\/05\\\/19\\\/dpdpa-harm-definition-privacy-adjudication-analysis\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Is the Absence of a Statutory Definition of \u201cHarm\u201d under the Digital Personal Data Protection Act, 2023 Likely to Create Interpretational Uncertainty in Privacy Adjudication?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/\",\"name\":\"SCC Times\",\"description\":\"Bringing you the Best Analytical Legal News\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/#\\\/schema\\\/person\\\/84e42bab48238baf12c7e33b3d9761fe\",\"name\":\"Editor\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/34e366be721c41333586de05faa13743195f5b142dcd7a015c6fabd2389521d0?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/34e366be721c41333586de05faa13743195f5b142dcd7a015c6fabd2389521d0?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/34e366be721c41333586de05faa13743195f5b142dcd7a015c6fabd2389521d0?s=96&d=mm&r=g\",\"caption\":\"Editor\"},\"url\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/post\\\/author\\\/editor_4\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"DPDPA Harm Definition and Privacy Adjudication | SCC Times","description":"Analysis of interpretational uncertainty caused by undefined \"harm\" under the DPDPA.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.scconline.com\/blog\/post\/2026\/05\/19\/dpdpa-harm-definition-privacy-adjudication-analysis\/","og_locale":"en_US","og_type":"article","og_title":"Is the Absence of a Statutory Definition of \u201cHarm\u201d under the Digital Personal Data Protection Act, 2023 Likely to Create Interpretational Uncertainty in Privacy Adjudication?","og_description":"Analysis of interpretational uncertainty caused by undefined \"harm\" under the DPDPA.","og_url":"https:\/\/www.scconline.com\/blog\/post\/2026\/05\/19\/dpdpa-harm-definition-privacy-adjudication-analysis\/","og_site_name":"SCC Times","article_publisher":"https:\/\/www.facebook.com\/scc.online\/","article_published_time":"2026-05-19T07:00:32+00:00","og_image":[{"width":886,"height":590,"url":"https:\/\/www.scconline.com\/blog\/wp-content\/uploads\/2026\/05\/DPDPA-harm-definition-privacy-adjudication-India-analysis.jpg","type":"image\/jpeg"}],"author":"Editor","twitter_card":"summary_large_image","twitter_title":"Is the Absence of a Statutory Definition of \u201cHarm\u201d under the Digital Personal Data Protection Act, 2023 Likely to Create Interpretational Uncertainty in Privacy Adjudication?","twitter_misc":{"Written by":"Editor"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.scconline.com\/blog\/post\/2026\/05\/19\/dpdpa-harm-definition-privacy-adjudication-analysis\/#article","isPartOf":{"@id":"https:\/\/www.scconline.com\/blog\/post\/2026\/05\/19\/dpdpa-harm-definition-privacy-adjudication-analysis\/"},"author":{"name":"Editor","@id":"https:\/\/www.scconline.com\/blog\/#\/schema\/person\/84e42bab48238baf12c7e33b3d9761fe"},"headline":"Is the Absence of a Statutory Definition of \u201cHarm\u201d under the Digital Personal Data Protection Act, 2023 Likely to Create Interpretational Uncertainty in Privacy Adjudication?","datePublished":"2026-05-19T07:00:32+00:00","mainEntityOfPage":{"@id":"https:\/\/www.scconline.com\/blog\/post\/2026\/05\/19\/dpdpa-harm-definition-privacy-adjudication-analysis\/"},"wordCount":2840,"commentCount":0,"image":{"@id":"https:\/\/www.scconline.com\/blog\/post\/2026\/05\/19\/dpdpa-harm-definition-privacy-adjudication-analysis\/#primaryimage"},"thumbnailUrl":"https:\/\/www.scconline.com\/blog\/wp-content\/uploads\/2026\/05\/DPDPA-harm-definition-privacy-adjudication-India-analysis.webp","keywords":["Digital Personal Data Protection Act 2023 harm interpretation","Digital Personal Data Protection Act enforcement uncertainty India","DPBI privacy harm adjudication data protection India","DPDPA harm definition privacy adjudication India analysis","informational privacy autonomy harm DPDPA analysis","undefined harm under DPDPA constitutional privacy concerns"],"articleSection":["Op Eds","OP. ED."],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.scconline.com\/blog\/post\/2026\/05\/19\/dpdpa-harm-definition-privacy-adjudication-analysis\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.scconline.com\/blog\/post\/2026\/05\/19\/dpdpa-harm-definition-privacy-adjudication-analysis\/","url":"https:\/\/www.scconline.com\/blog\/post\/2026\/05\/19\/dpdpa-harm-definition-privacy-adjudication-analysis\/","name":"DPDPA Harm Definition and Privacy Adjudication | SCC Times","isPartOf":{"@id":"https:\/\/www.scconline.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.scconline.com\/blog\/post\/2026\/05\/19\/dpdpa-harm-definition-privacy-adjudication-analysis\/#primaryimage"},"image":{"@id":"https:\/\/www.scconline.com\/blog\/post\/2026\/05\/19\/dpdpa-harm-definition-privacy-adjudication-analysis\/#primaryimage"},"thumbnailUrl":"https:\/\/www.scconline.com\/blog\/wp-content\/uploads\/2026\/05\/DPDPA-harm-definition-privacy-adjudication-India-analysis.webp","datePublished":"2026-05-19T07:00:32+00:00","author":{"@id":"https:\/\/www.scconline.com\/blog\/#\/schema\/person\/84e42bab48238baf12c7e33b3d9761fe"},"description":"Analysis of interpretational uncertainty caused by undefined \"harm\" under the DPDPA.","breadcrumb":{"@id":"https:\/\/www.scconline.com\/blog\/post\/2026\/05\/19\/dpdpa-harm-definition-privacy-adjudication-analysis\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.scconline.com\/blog\/post\/2026\/05\/19\/dpdpa-harm-definition-privacy-adjudication-analysis\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.scconline.com\/blog\/post\/2026\/05\/19\/dpdpa-harm-definition-privacy-adjudication-analysis\/#primaryimage","url":"https:\/\/www.scconline.com\/blog\/wp-content\/uploads\/2026\/05\/DPDPA-harm-definition-privacy-adjudication-India-analysis.webp","contentUrl":"https:\/\/www.scconline.com\/blog\/wp-content\/uploads\/2026\/05\/DPDPA-harm-definition-privacy-adjudication-India-analysis.webp","width":886,"height":590,"caption":"DPDPA harm definition privacy adjudication India analysis"},{"@type":"BreadcrumbList","@id":"https:\/\/www.scconline.com\/blog\/post\/2026\/05\/19\/dpdpa-harm-definition-privacy-adjudication-analysis\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.scconline.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Is the Absence of a Statutory Definition of \u201cHarm\u201d under the Digital Personal Data Protection Act, 2023 Likely to Create Interpretational Uncertainty in Privacy Adjudication?"}]},{"@type":"WebSite","@id":"https:\/\/www.scconline.com\/blog\/#website","url":"https:\/\/www.scconline.com\/blog\/","name":"SCC Times","description":"Bringing you the Best Analytical Legal News","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.scconline.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.scconline.com\/blog\/#\/schema\/person\/84e42bab48238baf12c7e33b3d9761fe","name":"Editor","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/34e366be721c41333586de05faa13743195f5b142dcd7a015c6fabd2389521d0?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/34e366be721c41333586de05faa13743195f5b142dcd7a015c6fabd2389521d0?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/34e366be721c41333586de05faa13743195f5b142dcd7a015c6fabd2389521d0?s=96&d=mm&r=g","caption":"Editor"},"url":"https:\/\/www.scconline.com\/blog\/post\/author\/editor_4\/"}]}},"jetpack_featured_media_url":"https:\/\/www.scconline.com\/blog\/wp-content\/uploads\/2026\/05\/DPDPA-harm-definition-privacy-adjudication-India-analysis.webp","jetpack_sharing_enabled":true,"jetpack-related-posts":[],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/www.scconline.com\/blog\/wp-json\/wp\/v2\/posts\/384516","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.scconline.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.scconline.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.scconline.com\/blog\/wp-json\/wp\/v2\/users\/67011"}],"replies":[{"embeddable":true,"href":"https:\/\/www.scconline.com\/blog\/wp-json\/wp\/v2\/comments?post=384516"}],"version-history":[{"count":3,"href":"https:\/\/www.scconline.com\/blog\/wp-json\/wp\/v2\/posts\/384516\/revisions"}],"predecessor-version":[{"id":384520,"href":"https:\/\/www.scconline.com\/blog\/wp-json\/wp\/v2\/posts\/384516\/revisions\/384520"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.scconline.com\/blog\/wp-json\/wp\/v2\/media\/384517"}],"wp:attachment":[{"href":"https:\/\/www.scconline.com\/blog\/wp-json\/wp\/v2\/media?parent=384516"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.scconline.com\/blog\/wp-json\/wp\/v2\/categories?post=384516"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.scconline.com\/blog\/wp-json\/wp\/v2\/tags?post=384516"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}