Readiness assessment
The Act
The DPDP Act, explainedThe DPDP Rules 2025

Ch IPreliminary

S.1 Short title and commencementS.2 DefinitionsS.3 Application and scope

Ch IIObligations of Data Fiduciary

S.4 Grounds for processingS.5 NoticeS.6 ConsentS.7 Certain legitimate usesS.8 Data Fiduciary obligationsS.9 Children’s dataS.10 Significant Data Fiduciary

Ch IIIRights and duties of Data Principal

S.11 Right to accessS.12 Correction and erasureS.13 Grievance redressalS.14 Right to nominateS.15 Duties of the Data Principal

Ch IVSpecial provisions

S.16 Transfer outside IndiaS.17 Exemptions

Ch VData Protection Board of India

S.18 Establishment of the BoardS.19 Composition of the BoardS.20 Salary and term of officeS.21 DisqualificationsS.22 Resignation and vacanciesS.23 Proceedings of the BoardS.24 Officers and employeesS.25 Members as public servantsS.26 Powers of the Chairperson

Ch VIBoard powers and procedure

S.27 Powers and functions of the BoardS.28 Procedure followed by the Board

Ch VIIAppeal and dispute resolution

S.29 Appeal to the Appellate TribunalS.30 Tribunal orders as a decreeS.31 Alternate dispute resolutionS.32 Voluntary undertaking

Ch VIIIPenalties

S.33 Penalties and the ScheduleS.34 Penalties to Consolidated Fund

Ch IXMiscellaneous

S.35 Good-faith protectionS.36 Power to call for informationS.37 Blocking of accessS.38 Consistency with other lawsS.39 Bar of jurisdictionS.40 Power to make rulesS.41 Laying of rules before ParliamentS.42 Power to amend the ScheduleS.43 Power to remove difficultiesS.44 Amendments to other Acts
Industries
Implementation
Training
Resources
About
Readiness assessment
Share this article

The DPDP Act data breach notification rule, explained (Section 8, Rule 7)

What counts as a personal data breach under the DPDP Act, who you must notify and how fast, the ₹200 crore penalty band, and a first-hours response checklist.

A personal data breach under the DPDP Act is not only a hack, it includes any unauthorised access, disclosure, or loss of personal data. Section 8 obligations and Rule 7 of the DPDP Rules, 2025 require you to notify both the affected people and the Data Protection Board, and there is a tight reporting window. Here is the shape of a plan that meets it.

What the rule requires

On becoming aware of a breach, a Data Fiduciary must inform each affected Data Principal in plain language, what happened, likely consequences, and what you are doing, and report to the Board, with a detailed follow-up report inside the prescribed window. The penalty band for failing to report a breach reaches ₹200 crore, which is why this is a board-level plan, not an afterthought.

A first-hours checklist

Breach response, first hours
BREACH RESPONSE: first hours
[ ] Detect & contain; freeze affected systems.
[ ] Assess scope: what data, how many principals.
[ ] Notify each affected Data Principal (plain language).
[ ] Notify the Data Protection Board without delay.
[ ] File the detailed report within the required window.
[ ] Log everything: timeline, decisions, comms.

The single biggest determinant of how a breach goes is whether this plan existed before the breach. Write it, name an owner, and rehearse it once. The report-a-data-breach workflow has the full sequence.

What good preparation looks like

  • A named incident owner and an escalation path.
  • Pre-drafted notification templates for principals and the Board.
  • Logging that lets you reconstruct the timeline afterwards.

Frequently asked questions

What counts as a data breach under DPDP Act?
Any unauthorised processing, accidental disclosure, acquisition, sharing, loss, or destruction of personal data that compromises its confidentiality, integrity, or availability.
Who do I have to notify?
Both the affected Data Principals, in plain language, and the Data Protection Board, with a detailed report within the prescribed window under Rule 7.
What is the penalty for not reporting a breach?
The Schedule to the Act sets a maximum penalty of up to ₹200 crore for failure to notify a personal data breach.

Guidance, not legal advice. dpdpactindia.in is an independent resource, not affiliated with the Government of India. Confirm specifics against the enacted Act and Rules.