A breach that reads like a warning label
On September 1, 2026, the FBI's New Orleans field office opened a formal investigation into an apparent breach at IDScan.net, an identity-verification vendor whose scanners sit behind the counter at Hertz, Target, FedEx, Motorola Solutions, Caesars Entertainment and Jack Henry, among others. A dark-web forum listing on a service called Nexus had surfaced the day before, offering searchable access to more than 153 million scanned US and Canadian driver's licenses, plus 10 million ID cards and 579,000 medical cards. IDScan.net confirmed on September 8 that an unauthorized party had accessed customer identification data and began offering credit monitoring (Krebs on Security).
The story is American, but the design flaw it exposes is universal: identity-verification vendors accumulate scanned government IDs as a byproduct of compliance — age checks, rental agreements, anti-fraud rules — and nobody outside the vendor really knows how long that data sits, who can query it, or how it's secured. India is mid-build on a legal framework meant to answer exactly that question. It's worth asking whether that framework would actually have prevented, or even caught, something like this.
What India's law would punish — and how hard
Under the Digital Personal Data Protection Act, 2023, and the DPDP Rules notified in 2025, a data fiduciary that suffers a breach must intimate the Data Protection Board of India "without delay" and follow up with a detailed report within 72 hours, with no minimum size threshold — a breach of ten records triggers the same duty as one of ten million (Rule 7, DPDP Rules). Failure to notify carries a penalty of up to ₹200 crore (~$24 million); failing to maintain reasonable security safeguards in the first place carries up to ₹250 crore (penalty analysis, K&K). On paper, that's a materially tougher regime than the patchwork of US state breach laws that currently govern IDScan.net — there is no federal breach-notification statute in the US at all, and states vary widely on timelines and thresholds.
Separately, CERT-In's April 2022 directions under Section 70B of the IT Act already require any "body corporate" operating in India to report a defined list of cyber incidents to CERT-In within six hours of first becoming aware — 12 times faster than the GDPR's 72-hour standard, and applicable regardless of whether the incident poses risk to individuals (CERT-In Directions, 28.04.2022). An Indian equivalent of IDScan.net would face two overlapping, unforgiving clocks the US company never had to watch.
The exemption that swallows the rule
The DPDP Act's tougher stance on vendors sits next to a much looser one on government access. Section 17 exempts processing carried out for "prevention, detection, investigation or prosecution of any offence" from most of the Act's obligations to data principals, and Section 36 lets the Central Government call for information from the Data Protection Board or any data fiduciary — without a warrant requirement, judicial sign-off, or a defined necessity-and-proportionality test written into the statute itself (PRS India, DPDP Bill 2023 track). As one analysis put it at the time the bill moved through Parliament: "Are we now in a situation where private parties are collecting data, which the government can call upon whenever they want without any restrictions?" (MediaNama, August 2023)
Steelmanning the exemption
The case for broad law-enforcement access isn't frivolous. Identity-verification data is exactly the kind of record that helps solve fraud, trafficking and terrorism cases quickly, and requiring court authorization for every routine request to a KYC vendor would slow investigations that often depend on speed — a suspect's rental history or hotel check-in trail is perishable evidence. Legislatures everywhere carve out law enforcement access to some degree; the UK's Investigatory Powers Act and the US Stored Communications Act both do it. India isn't an outlier for having an exemption. It's an outlier for how little structure sits around it.
Where the gap actually bites
India runs its own version of the IDScan.net exposure: e-KYC agencies, hotel and rental ID-scanning vendors, and Aadhaar-linked verification intermediaries hold comparable troves of scanned government IDs, often for compliance reasons that have nothing to do with the transaction itself. If one of them is compromised, the DPDP Act's penalty schedule will bite hard on the vendor. But the same statute gives the government wide, largely unreviewable latitude to pull data out of that same vendor pool beforehand — with none of the audit trail, judicial order, or proportionality review that would let anyone outside government verify the request was necessary. A framework that fines companies ₹200 crore for losing control of data, while asking almost nothing of the state when it demands that data directly, isn't proportionate regulation — it's regulation aimed at the wrong actor.
The fix is procedural, not partisan
None of this requires weakening India's breach-notification regime, which is genuinely stronger than what currently governs IDScan.net. It requires writing a floor under Section 36: a written necessity test, an internal review record, and Data Protection Board visibility into how often the exemption is invoked and for what. That's the same proportionality principle the Act already applies to companies — extended, finally, to the government that regulates them.