Justice in the Cloud: Can Victims Cross the Digital Border? Bridging Victim Rights and Cross-Border Data Protection

Authors

  • Shambhavi Gour Amity University Haryana
  • Kratika Bhardwaj Amity University, Haryana

DOI:

https://doi.org/10.66668/rfm.v34i2.99

Keywords:

victim-centric justice; Bharatiya Nagarik Suraksha Sanhita; Digital Personal Data Protection Act, 2023; cross-border data transfer; GDPR; informational privacy.

Abstract

India stands at a constitutional inflection point where two ambitious legal projects the recalibration of criminal justice around the victim, and the construction of a modern data-protection regime have begun to intersect in ways that scholarship has yet to map. On 1 July 2024, the Bharatiya Nyaya Sanhita, 2023 (BNS), the Bharatiya Nagarik Suraksha Sanhita, 2023 (BNSS) and the Bharatiya Sakshya Adhiniyam, 2023 (BSA) replaced the colonial trinity of the Indian Penal Code, the Code of Criminal Procedure and the Indian Evidence Act, reorienting the system from a punitive, State-centred paradigm toward one that treats the victim as a rights-bearing stakeholder entitled to information, participation, compensation and dignity. Contemporaneously, the Digital Personal Data Protection Act, 2023 (DPDP Act) operationalised in phases from November 2025 alongside the Digital Personal Data Protection Rules, 2025 has erected a statutory architecture for informational privacy anchored in the Supreme Court’s recognition of privacy as a fundamental right in K.S. Puttaswamy. This paper argues that these reforms are not parallel silos but converging vectors: the victim of the digital age is simultaneously a ‘data principal’ whose personal information traverses servers, jurisdictions and forensic pipelines. Adopting a doctrinal and comparative method, the study juxtaposes India’s ‘negative-list’ model of cross-border transfer under Section 16 of the DPDP Act against the European Union’s ‘adequacy’ architecture under Chapter V of the GDPR, and situates the victim at the fault line between investigative necessity and privacy protection. It concludes by proposing a victim-centric data-governance model reconciling dignity, due process and data sovereignty.

Downloads

Published

11-07-2026

Issue

Section

Articles