1.3 Independent causes of action under other laws
Section 39 should not be understood as barring every civil proceeding connected factually with personal data.
The critical question is whether the suit asks the court to determine a matter entrusted to the Board, or whether it asserts an independent legal right and seeks a remedy that the Board is not empowered to grant.
The same incident may potentially involve:
-
a DPDPA complaint before the Board;
-
breach of contract;
-
deficiency in service under consumer law;
-
negligence;
-
breach of confidence;
-
an employment dispute;
-
an insurance dispute; or
-
another independently recognised cause of action.
Section 38 provides that the DPDPA ordinarily operates in addition to other laws. Section 39 should therefore not automatically extinguish an independent claim merely because the facts also involve personal data. The court or authority would need to examine the substance of the claim, the relief sought and whether deciding it would require adjudication of a matter reserved for the Board.
1.4 Illustration: Financial loss after a banking breach
A bank suffers a personal data breach, and a customer later incurs financial loss through fraudulent transactions.
The customer may complain to the Board about the bank’s compliance with DPDPA security and breach-notification obligations. The Board may inquire into the breach and impose a monetary penalty where the statutory conditions are satisfied.
If the customer separately claims reimbursement or compensation under consumer, banking, contractual or civil law, Section 39 should not automatically bar that claim merely because the same breach forms part of the factual background. The Board does not award the Section 33 penalty to the customer, and the independent forum must determine whether it has jurisdiction over the separate cause of action and remedy.
The customer cannot, however, use the civil proceeding to ask the court to perform the Board’s regulatory function, impose a DPDPA penalty or restrain the Board’s inquiry.