Answer By law4u team
Unauthorized online sharing of personal consumer data is a growing concern in the digital era. Sensitive information such as bank details, Aadhaar number, mobile numbers, or email IDs may be exposed through phishing, hacking, or careless data handling by companies. Prompt reporting is crucial to prevent identity theft, financial loss, or misuse of personal information. Indian laws such as the IT Act 2000, Consumer Protection Act 2019, and guidelines from CERT-In provide legal frameworks for addressing such incidents.
Steps to Report Unauthorized Online Sharing of Personal Data
Identify the Breach
- Confirm that personal information has been shared or accessed without consent.
- Collect evidence like screenshots, emails, transaction records, or messages showing unauthorized access or sharing.
Notify the Responsible Organization
- Contact the company or platform that shared your data.
- Request them to stop further sharing, remove your data, and provide an explanation.
Report to CERT-In (Indian Computer Emergency Response Team)
- CERT-In handles cybersecurity incidents in India.
- File a complaint at https://www.cert-in.org.in with all relevant details.
Lodge a Complaint Under IT Act 2000
- Sections 43A and 72A of IT Act 2000 deal with unauthorized access, data breach, and disclosure of personal information.
- Complaints can be filed with local cybercrime police or online portals.
File a Consumer Complaint (If Applicable)
- If the data breach results in financial loss, misleading practices, or harm, file a complaint under the Consumer Protection Act 2019.
- Approach District, State, or National Consumer Dispute Redressal Commissions depending on claim value.
Legal Enforcement and Remedies
- Compensation for financial or emotional loss caused by data misuse.
- Injunctions to prevent further sharing or publication of personal data.
- Criminal action against offenders for cyber fraud or identity theft.
Monitor Your Accounts and Identity
- Change passwords immediately for email, banking, and other online accounts.
- Enable two-factor authentication (2FA) for additional security.
- Monitor bank statements, credit reports, and digital accounts for suspicious activity.
Consumer Safety Tips to Prevent Data Misuse
- Avoid sharing sensitive information on unsecured websites or social media.
- Use strong, unique passwords and change them regularly.
- Enable alerts for transactions, logins, and account changes.
- Keep devices and apps updated with the latest security patches.
- Educate yourself about phishing, malware, and scam tactics.
Example:
A consumer notices that their email and phone number from an e-commerce platform were leaked, resulting in spam calls and phishing emails attempting financial fraud.
Steps the consumer should take:
- Collect screenshots and records of spam messages and data leaks.
- Contact the e-commerce platform to request deletion of personal data and explanation.
- Report the incident to CERT-In via their online portal.
- Lodge a cybercrime complaint with local police under IT Act 2000.
- If financial loss occurs, file a complaint with the District Consumer Commission under the Consumer Protection Act 2019.
- Change all passwords and enable 2FA on accounts.
- Monitor bank accounts and credit reports to detect unauthorized activity.