Readiness assessment
Share this article

The DPDP data breach notification rule, explained (Section 8, Rule 7)

What counts as a personal data breach under the DPDP Act, who you must notify and how fast, the ₹200 crore penalty band, and a first-hours response checklist.

A personal data breach under the DPDP Act is not only a hack, it includes any unauthorised access, disclosure, or loss of personal data. Section 8 obligations and Rule 7 of the DPDP Rules, 2025 require you to notify both the affected people and the Data Protection Board, and there is a tight reporting window. Here is the shape of a plan that meets it.

What the rule requires

On becoming aware of a breach, a Data Fiduciary must inform each affected Data Principal in plain language, what happened, likely consequences, and what you are doing, and report to the Board, with a detailed follow-up report inside the prescribed window. The penalty band for failing to report a breach reaches ₹200 crore, which is why this is a board-level plan, not an afterthought.

A first-hours checklist

Breach response, first hours
BREACH RESPONSE: first hours
[ ] Detect & contain; freeze affected systems.
[ ] Assess scope: what data, how many principals.
[ ] Notify each affected Data Principal (plain language).
[ ] Notify the Data Protection Board without delay.
[ ] File the detailed report within the required window.
[ ] Log everything: timeline, decisions, comms.

The single biggest determinant of how a breach goes is whether this plan existed before the breach. Write it, name an owner, and rehearse it once. The report-a-data-breach workflow has the full sequence.

What good preparation looks like

  • A named incident owner and an escalation path.
  • Pre-drafted notification templates for principals and the Board.
  • Logging that lets you reconstruct the timeline afterwards.

Frequently asked questions

What counts as a data breach under DPDP?
Any unauthorised processing, accidental disclosure, acquisition, sharing, loss, or destruction of personal data that compromises its confidentiality, integrity, or availability.
Who do I have to notify?
Both the affected Data Principals, in plain language, and the Data Protection Board, with a detailed report within the prescribed window under Rule 7.
What is the penalty for not reporting a breach?
The Schedule to the Act sets a maximum penalty of up to ₹200 crore for failure to notify a personal data breach.

Guidance, not legal advice. dpdpactindia.in is an independent resource, not affiliated with the Government of India. Confirm specifics against the enacted Act and Rules.