
Data Breach–[1] More than [a] 8,00,000 records of TCS — [b] 2,50,000 records of HCL Tech–and [c] 20,000 of Hexaware– were hit [2] All three issued statements to Exchanges saying that even if certain employee information may have been breached, the information was old and limited [3] From the DPDP Act perspective, this distinction between old and new becomes useful for the companies. Employee directory data is clearly personal data under the Act. By characterising the incident as an older event that occurred well before the DPDP provisions became fully operative the companies can argue that the strict new notification times and penalties exposure do not automatically apply –That is a legitimate legal distinction but also a convenient one–Courtesy BL
