Star Health, Angel One and Beyond: What Indian Data Breaches Teach Us About Disposal Hygiene

Updated: September 21, 2026 · 16 min read

Key Takeaways

  • The Digital Personal Data Protection Act, 2023 (DPDPA) Section 33 empowers MeitY to levy fines of up to ₹250 crore on data fiduciaries that fail to implement adequate security safeguards — including physical disposal controls.
  • The E-Waste (Management) Rules, 2022 mandate that decommissioned IT hardware be channelled exclusively through CPCB-authorised dismantlers and recyclers; routing assets outside this chain simultaneously creates an environmental liability and a data-exposure risk.
  • Indian breach disclosures between 2023 and 2025 — including incidents linked to Star Health Insurance and Angel One — point to weak asset-lifecycle hygiene, not just perimeter failures, as a contributing vector.
  • SEBI’s BRSR Core framework (circular dated 12 July 2023) now requires listed companies to disclose data-security governance as part of their Business Responsibility and Sustainability Report — elevating disposal controls to board-level visibility.

Between late 2023 and mid-2025, India’s financial-services sector disclosed more significant personal-data exposure events than in the preceding five years combined. The breach post-mortems almost universally focused on network intrusion, compromised credentials, and third-party API vulnerabilities. What received far less scrutiny — and what MeitY’s enforcement posture under the Digital Personal Data Protection Act, 2023 (DPDPA) is beginning to correct — is the physical disposal leg of the data lifecycle. When a decommissioned server leaves a data centre without certified data destruction, the residual data on that device is a breach waiting for an incident. For CISOs and audit committees, that distinction matters: a ₹250 crore fine does not require a hacker. It requires only a regulator and a hard drive that should have been shredded.

The Breach Pattern Indian Boards Keep Missing

Indian data breach discourse is dominated by the intrusion narrative — phishing, ransomware, misconfigured cloud buckets. These are real and serious. But the global body of breach forensics, including data published by the Ponemon Institute and i-SIGMA (the international trade association for secure destruction), consistently shows that 15–20% of confirmed data exposures involve physical or asset-disposal failures: hard drives sold through grey markets, decommissioned laptops re-entering secondary markets with corporate data intact, backup tapes physically lost during logistics handovers.

Video: Data Security: Protect your critical data (or else) – IBM Technology

India’s informal IT asset resale market amplifies this risk materially. A laptop retired by a Bengaluru fintech typically passes through three to five intermediaries before reaching its end buyer — an OEM refurbisher, a local dealer, a component stripper, and eventually a waste aggregator. At each transfer point, the probability that data-wiping was performed to any verifiable standard drops significantly. There is no equivalent of a chain-of-custody certificate unless the original data fiduciary mandated one. Under the DPDPA, the absence of that certificate is now the data fiduciary’s legal problem, not the recycler’s.

This is the data breach disposal lesson that boards in India have been slowest to internalise: cybersecurity spend protects data in transit and at rest on live systems. It does nothing for data on a decommissioned asset that left the building last quarter.

Star Health, Angel One and the Asset-Lifecycle Blindspot

Two incidents are worth examining in the context of disposal hygiene, even if their primary breach vectors were different. In late 2024, Star Health Insurance faced a widely reported data-exposure event involving the alleged exfiltration of policyholder records — names, health information, policy details — reportedly numbering in the tens of millions. The disclosed vector involved a Telegram-based distribution channel, suggesting insider access or API compromise. However, forensic questions remained open: specifically, whether any portion of the exposed data originated from decommissioned or improperly retired systems.

red padlock on black computer keyboard | The National Recycling Corporation
Photo by FlyD on Unsplash

Angel One, the retail broking platform, disclosed a separate breach involving client data including contact information and financial details. Again, the primary vector appeared to be application-layer, but the incident raised broader questions about data governance across the full asset lifecycle — including what happens to KYC documentation, account records, and transaction histories when the storage media on which they sit is retired.

The common thread is not that either company necessarily failed at disposal — the investigations are ongoing and the facts remain disputed. The thread is structural: neither company’s public breach disclosure addressed disposal controls at all. That silence is itself informative. It suggests that disposal-hygiene was not a live variable in their incident-response analysis, which means it is unlikely to have been a mature control before the breach occurred. For any CISO reading this as a post-mortem exercise, the question to ask is: could your organisation answer, right now, where every decommissioned server, laptop, and storage device from the past three years went — and produce a destruction certificate for each one?

Need Certified Data Destruction for Your Decommissioned IT Assets?

The National Recycling Corporation works with CPCB-authorised disposal partners across India to provide end-to-end IT asset retirement — including data wiping certificates, hard-drive shredding, and GST-compliant recycling documentation that satisfies both DPDPA and E-Waste Rules, 2022 obligations.

Request a Destruction Certificate Quote

₹250 Crore: What DPDPA Sections 8 and 33 Actually Require of You

The Digital Personal Data Protection Act, 2023 received Presidential assent on 11 August 2023. The rules under it — the Digital Personal Data Protection Rules — were under consultation through 2024 and into 2025, with MeitY signalling phased enforcement commencement. By the time this article is published in September 2026, data fiduciaries in regulated sectors (financial services, health, telecom) are expected to be within the first enforcement window. The numbers in the penalty schedule are not rhetorical.

Video: India Arrests Former Coinbase Support Agent Over Data Breach: – Crypto World Daily

Section 8 of the DPDPA is the operational spine. It requires a data fiduciary to “implement appropriate technical and organisational measures to ensure effective observance of the provisions of this Act and the rules made thereunder.” The phrase “organisational measures” is deliberately broad. A regulator or adjudicating officer can read physical asset disposal controls — or their absence — directly into this obligation. If your organisation disposes of IT assets through an unregistered aggregator with no destruction record, you have a Section 8 gap, regardless of how sophisticated your perimeter firewall is.

Section 33 is where financial consequence crystallises. The Data Protection Board of India, once constituted, can impose penalties of up to ₹250 crore for a breach attributable to a failure of adequate safeguards under Section 8. For a mid-sized NBFC or a regional insurer, ₹250 crore is not an abstract number — it is comparable to a full year of operating profit. Beyond the fine, Section 33 also creates reputational and regulatory knock-on effects: SEBI-regulated entities face the additional burden of material disclosure to the stock exchanges, and IRDAI-regulated insurers face parallel supervisory scrutiny.

The practical takeaway for data protection officers is this: your data breach disposal procedures are not a sub-clause in your ISO 27001 documentation. They are a primary DPDPA compliance obligation with a named penalty quantum.

The E-Waste (Management) Rules, 2022 and Why They Are a Data-Security Instrument

Most IT teams think of the E-Waste (Management) Rules, 2022 — notified by MoEFCC and enforced by the Central Pollution Control Board (CPCB) — as an environmental compliance matter. They are that, but they are also a data-security instrument by design. Rule 11 of the 2022 Rules requires producers, bulk consumers, and intermediaries to ensure that e-waste is handled only by registered dismantlers and recyclers. A company that hands its decommissioned laptops to an unregistered aggregator is in breach of Rule 11 — and simultaneously handing over potentially unwiped storage media to a party with no legal obligation to destroy it securely.

a computer keyboard with a padlock on top of it | The National Recycling Corporation
Photo by Sasun Bughdaryan on Unsplash

The 2022 Rules also introduced Extended Producer Responsibility (EPR) obligations for IT and telecom equipment producers, with collection and recycling targets indexed to annual sales. For the current financial year (FY 2026-27), CPCB-notified EPR targets for IT equipment producers stand at 70% of units sold in the preceding three years, channelled through authorised collection points. Bulk consumers — which includes any corporate with more than a threshold volume of IT assets — are required to hand assets only to registered entities and maintain disposal records. These records, critically, must be retained for a minimum of two years under the CPCB’s record-keeping mandate, and they constitute your primary audit trail in any DPDPA investigation.

The Hazardous and Other Wastes (Management and Transboundary Movement) Rules, 2016 — administered jointly by MoEFCC and CPCB — are also relevant where decommissioned assets contain cathode-ray tubes, lead-acid batteries, or mercury-containing components. Storage media that accompanies such waste must be destroyed before the material is transferred. The overlap between hazardous-waste rules and data protection obligations is an area where Indian compliance teams routinely create a gap by treating the two regulatory streams as entirely separate.

The 7-Step Disposal Control Set Auditors Now Expect

The following checklist reflects the minimum control set that a sophisticated internal auditor or a MeitY-appointed adjudicating officer would look for when assessing an organisation’s data-breach disposal readiness. Each step is actionable this quarter.

Video: How can Insurance Service Provider Protect Data of Policyholders? | Data Privacy – Insurance Sector – DSCI IN

  1. Maintain a live IT Asset Register. Every device that stores personal data — servers, laptops, desktops, mobile devices, NAS drives, photocopier hard disks, USB tokens — must be tagged with a unique identifier, its data-classification level, and its assigned custodian. Gaps in the register are gaps in your DPDPA Section 8 defence.
  2. Define a formal End-of-Life (EoL) trigger. Set a documented policy: assets reaching four years of age, or any device failing hardware diagnostics, enters the EoL queue automatically. Ad hoc disposal decisions create untracked devices.
  3. Mandate DoD 5220.22-M or equivalent data wiping for all functional drives. This is the United States Department of Defense standard for software-based overwriting, but it is the benchmark referenced by i-SIGMA-certified destruction vendors and accepted by ISO 27001 auditors. Require a timestamped wipe certificate for every drive processed.
  4. Require physical destruction for drives storing Tier 1 data. For drives that held sensitive personal data (health records, financial details, Aadhaar-linked information), software wiping is not sufficient. Require degaussing followed by physical shredding, with a certificate of destruction naming the asset serial number, the destruction method, and the authorised facility’s CPCB registration number.
  5. Use only CPCB-authorised recyclers. Obtain a copy of the recycler’s current CPCB or SPCB authorisation before transferring any asset. This satisfies Rule 11 of the E-Waste (Management) Rules, 2022 and simultaneously ensures the receiving party has legal obligations around secure handling. File this authorisation alongside your asset-disposal log.
  6. Generate a GST-compliant transaction record for every disposal. Whether the asset is sold as scrap or surrendered for recycling, a proper tax invoice under the Goods and Services Tax framework creates an auditable financial trail that corroborates your disposal records in any DPDPA investigation.
  7. Conduct a quarterly disposal audit. Reconcile the number of devices retired against destruction certificates received. Any unreconciled asset — a device on the register for which no destruction certificate exists — is an open incident that must be escalated to the CISO and the Data Protection Officer within 72 hours. The DPDPA’s breach notification clock starts ticking the moment you have reason to believe personal data may have been exposed.

Disposal Risk by Asset Class: A Quick-Reference Table

Not all decommissioned assets carry the same data-exposure risk or the same regulatory complexity. The table below maps common IT asset classes to their primary data risk, the applicable regulatory obligation, and the minimum disposal control required under Indian law as of FY 2026-27.

Asset Class Primary Data Risk Key Regulation Minimum Disposal Control DPDPA Penalty Exposure
Data-centre servers Bulk personal data, transaction logs E-Waste (Management) Rules, 2022; DPDPA 2023 Physical shredding + CPCB-authorised recycler certificate Up to ₹250 crore
Corporate laptops / desktops Email, credentials, HR data E-Waste (Management) Rules, 2022; DPDPA 2023 DoD 5220.22-M wipe or HDD shred; recycler authorisation on file Up to ₹250 crore
Photocopier / MFP hard disks Scanned KYC docs, contracts DPDPA 2023 Section 8 Vendor-performed disk wipe before lease return; confirm in writing Up to ₹250 crore
Network switches / routers Configuration data, VLAN maps, credentials in flash memory E-Waste (Management) Rules, 2022 Factory reset + flash memory destruction; CPCB recycler Up to ₹200 crore (network data)
Mobile devices (BYOD / corporate) Personal data, OTP logs, app data DPDPA 2023; E-Waste Rules, 2022 MDM remote wipe + physical collection through authorised channel Up to ₹250 crore
Legacy tape backups Archival personal data, financial records DPDPA 2023 Section 8; Hazardous Wastes Rules, 2016 (if CRT) Degaussing + physical shredding; chain-of-custody certificate Up to ₹250 crore

Retiring IT Assets Across Multiple Offices? We Cover Pan-India Pickups.

From Mumbai data centres to Bengaluru branch offices, The National Recycling Corporation coordinates bulk IT asset collection with full chain-of-custody documentation — CPCB-authorised recycling, data destruction certificates, and BRSR-grade disposal records, all on a single GST invoice.

Schedule a Pan-India Pickup

BRSR Core and the Board-Level Disclosure Trap

SEBI’s BRSR Core framework, introduced under the circular dated 12 July 2023, requires the top 150 listed entities (by market capitalisation) to obtain independent assurance on a subset of ESG metrics from FY 2023-24 onwards, expanding to the top 250 entities from FY 2024-25. By FY 2026-27, this obligation is fully embedded in the annual reporting cycle for India’s largest listed companies. One of the governance principles assessed under BRSR Core is data-security governance — which, in the context of a post-DPDPA regulatory environment, auditors are increasingly reading to include physical data lifecycle controls.

For a board member signing off on a BRSR Core report, the risk is specific: if your company has disclosed a data breach in the preceding twelve months and your BRSR Core report simultaneously shows no documented IT asset disposal controls, the combination is precisely the kind of inconsistency that draws SEBI scrutiny. Audit committees in financial services, healthcare, and consumer sectors should be asking management — not just the CISO — to confirm the existence of a certified disposal programme before the FY 2026-27 annual report is filed.

The intersection of DPDPA, E-Waste Rules, and BRSR Core is not coincidental. All three regulatory instruments reflect the same underlying principle: that an organisation’s responsibility for data it collects does not end when a device is switched off. It ends when the data on that device is demonstrably, irreversibly destroyed, and the destruction is documented. India’s regulatory architecture in 2026 has closed most of the gaps that allowed organisations to argue otherwise. The board-level question is no longer whether this is a compliance requirement — it is whether your organisation can prove it has met one.

Our CPCB-authorised e-waste recycling service is specifically designed to provide the documentation trail that listed companies need for BRSR Core and DPDPA compliance — including asset-level certificates of destruction that name device serial numbers and destruction methods. Organisations managing large-volume decommissioning can also explore our EPR compliance services, which cover producer-side obligations under the E-Waste (Management) Rules, 2022 in conjunction with data-secure disposal.

Related Articles

Frequently Asked Questions

What does DPDPA Section 8 specifically require regarding physical disposal of IT assets?

Section 8 of the Digital Personal Data Protection Act, 2023 requires data fiduciaries to implement “appropriate technical and organisational measures” to protect personal data. MeitY’s guidance — and the draft Digital Personal Data Protection Rules — make clear that “organisational measures” encompasses the full data lifecycle, including how storage media is retired. A data fiduciary that cannot produce a destruction certificate for a decommissioned device holding personal data has a demonstrable Section 8 gap, which can support a penalty proceeding under Section 33, with fines of up to ₹250 crore.

Are all Indian companies required to use CPCB-authorised recyclers for IT asset disposal?

Under Rule 11 of the E-Waste (Management) Rules, 2022, bulk consumers — broadly, any corporate entity disposing of IT and telecom equipment above a threshold volume — must channel e-waste exclusively through CPCB-registered dismantlers and recyclers. This obligation applies regardless of company size or sector. The CPCB maintains a publicly searchable register of authorised entities on its e-waste portal. Using an unregistered aggregator simultaneously breaches the E-Waste Rules and creates an uncontrolled data-exposure risk.

How long must IT asset disposal records be retained under Indian law?

The CPCB’s record-keeping mandate under the E-Waste (Management) Rules, 2022 requires disposal records — including transfer manifests, recycler certificates, and EPR credit documentation — to be retained for a minimum of two years. Separately, a DPDPA investigation or a SEBI BRSR Core audit may require documentation from up to three financial years prior. Best practice is to retain destruction certificates, recycler authorisation copies, and GST invoices for at least three years from the date of disposal.

Does the DPDPA apply to data stored on hardware, or only to digital transmission?

The DPDPA 2023 applies to “digital personal data” — defined as personal data in digital form, regardless of how it is stored or transmitted. Data resident on a server hard drive, a laptop SSD, or a backup tape is fully within scope. The Act’s obligations do not distinguish between live systems and decommissioned hardware. A data fiduciary’s duty to protect personal data under Section 8 continues until the data is provably destroyed, which is why physical destruction with a certificate is the only legally defensible end-state for Tier 1 data assets.

What is the BRSR Core requirement for data-security disclosures, and which companies are in scope for FY 2026-27?

Under SEBI’s circular dated 12 July 2023, BRSR Core with mandatory third-party assurance applies to the top 150 listed entities by market cap from FY 2023-24, expanding to the top 250 from FY 2024-25 and expected to extend further in subsequent years. For FY 2026-27, any company within the top 250 by market cap must include independently assured ESG metrics in their annual report. Data-security governance — including IT asset disposal controls — falls within the scope of assessed metrics. Boards should ensure their disposal programme is documented and auditable before the FY 2026-27 reporting cycle closes.

Work With The National Recycling Corporation

The National Recycling Corporation is a Mumbai-headquartered, pan-India B2B recycling and scrap trading company with deep expertise in IT asset retirement, e-waste management, and compliance documentation. We work with corporate IT departments, data centres, financial-services firms, and healthcare organisations to ensure that decommissioned hardware exits your premises with a full chain of custody — not as an open liability.

Our disposal process covers the entire compliance stack: data destruction certificates referencing individual device serial numbers and destruction methods; CPCB-authorised recycling partnerships that satisfy Rule 11 of the E-Waste (Management) Rules, 2022; GST-compliant invoicing that creates an auditable financial trail; and BRSR-grade documentation packages that your audit committee can place in front of an assurance provider without qualification. For listed companies managing DPDPA readiness and BRSR Core reporting simultaneously, we offer disposal documentation formatted to align with both frameworks.

Our services include:

  • Pan-India scheduled pickup for bulk IT asset retirement — from single-office collections in Mumbai and Thane to multi-site national decommissioning programmes
  • Data wiping to DoD 5220.22-M standard for functional drives, with timestamped wipe certificates
  • Physical hard-drive shredding for Tier 1 data assets, with photographic and documentary evidence of destruction
  • CPCB-authorised e-waste recycling through verified dismantler partners — recycler registration numbers provided on every certificate
  • GST-compliant invoicing and fair-market scrap valuation indexed to current LME benchmarks for recoverable metals
  • BRSR-grade disposal reports suitable for internal audit, external assurance, and regulatory disclosure

Contact us to discuss your IT asset retirement requirements. You can also learn more about our e-waste management services or explore our EPR compliance support for producer-side obligations under the E-Waste (Management) Rules, 2022.

Sources and References

Leave a Comment

Your email address will not be published. Required fields are marked *