Readiness assessment
The Act
The DPDP Act, explainedThe DPDP Rules 2025

Ch IPreliminary

S.1 Short title and commencementS.2 DefinitionsS.3 Application and scope

Ch IIObligations of Data Fiduciary

S.4 Grounds for processingS.5 NoticeS.6 ConsentS.7 Certain legitimate usesS.8 Data Fiduciary obligationsS.9 Children’s dataS.10 Significant Data Fiduciary

Ch IIIRights and duties of Data Principal

S.11 Right to accessS.12 Correction and erasureS.13 Grievance redressalS.14 Right to nominateS.15 Duties of the Data Principal

Ch IVSpecial provisions

S.16 Transfer outside IndiaS.17 Exemptions

Ch VData Protection Board of India

S.18 Establishment of the BoardS.19 Composition of the BoardS.20 Salary and term of officeS.21 DisqualificationsS.22 Resignation and vacanciesS.23 Proceedings of the BoardS.24 Officers and employeesS.25 Members as public servantsS.26 Powers of the Chairperson

Ch VIBoard powers and procedure

S.27 Powers and functions of the BoardS.28 Procedure followed by the Board

Ch VIIAppeal and dispute resolution

S.29 Appeal to the Appellate TribunalS.30 Tribunal orders as a decreeS.31 Alternate dispute resolutionS.32 Voluntary undertaking

Ch VIIIPenalties

S.33 Penalties and the ScheduleS.34 Penalties to Consolidated Fund

Ch IXMiscellaneous

S.35 Good-faith protectionS.36 Power to call for informationS.37 Blocking of accessS.38 Consistency with other lawsS.39 Bar of jurisdictionS.40 Power to make rulesS.41 Laying of rules before ParliamentS.42 Power to amend the ScheduleS.43 Power to remove difficultiesS.44 Amendments to other Acts
Industries
Implementation
Training
Resources
About
Readiness assessment

DPDP Act How-To

How to Report a Personal Data Breach Under the DPDP Act

A personal data breach has happened. Here is exactly what a Data Fiduciary must do under India's DPDP Act and the DPDP Rules, 2025 — who to notify, in what order, and by when.

Last updated: September 2026 Applicable from: 13 May 2027 Legal anchors: Section 8(6) Rule 7

Effective from 13 May 2027

Section 8(6) of the Act and Rule 7 of the DPDP Rules, 2025 are not yet in force. They commence eighteen months after the Rules were notified on 13 November 2025 — that is, on 13 May 2027. Build and rehearse your response now; the duties below apply from that date. See the full DPDP commencement timeline →

On this page

The three clocks

A personal data breach triggers three notification clocks

There is no single “72-hour DPDP breach deadline.” Rule 7 sets three separate obligations, and only one of them carries the 72-hour clock.

Affected Data Principals

Without delay
  • Nature, extent and timing
  • Likely consequences for them
  • Mitigation measures taken
  • Safety steps they can take
  • A contact point for questions
Legal basis · Rule 7(1)

Data Protection Board — initial

Without delay
  • Nature
  • Extent
  • Timing
  • Location
  • Likely impact
Legal basis · Rule 7(2)(a)

Data Protection Board — detailed

Within 72 hours of awareness
  • Updated, detailed information
  • Facts, circumstances and causes
  • Mitigation measures
  • Findings on who caused it, if any
  • Steps to prevent recurrence
  • Report on the Data Principal notices
Legal basis · Rule 7(2)(b) · extendable only on the Board's written leave
Read this before anything elseDo not reduce Rule 7 to “report within 72 hours.” The first two notifications are required without delay. The 72-hour clock applies only to the detailed submission to the Board.

Quick answer

The Data Fiduciary reports. When a personal data breach occurs, the Data Fiduciary must notify each affected Data Principal without delay and give the Data Protection Board an initial intimation without delay. It must then give the Board detailed information within 72 hours of becoming aware of the breach, unless the Board grants more time on a written request. Rule 7 sets no materiality, severity, risk or affected-person threshold — every event meeting the statutory definition enters the notification framework, so do not import the GDPR's risk-based test. These duties take effect on 13 May 2027. A single incident may also be a CERT-In reportable cyber incident with a separate 6-hour clock — assess both regimes independently.

Practical implementation · not legal text

Breach happened? Start here.

  1. Confirm personal data is actually involved.
  2. Contain the incident and preserve evidence.
  3. Record the awareness time (this starts the 72-hour clock).
  4. Identify affected Data Principals and contact routes.
  5. Start both the DPDP and the CERT-In applicability assessments in parallel.

Scope

What counts as a personal data breach?

The law requires The Act defines a personal data breach as unauthorised processing, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises its confidentiality, integrity or availability. That is broader than hacking or data theft: accidental events count, and so does loss of access (for example, ransomware that locks personal data).

May be a personal data breach
  • An exposed or exfiltrated customer database
  • Ransomware that exposes, destroys or locks personal data
  • A customer spreadsheet emailed to the wrong recipient
  • A stolen laptop or phone with accessible personal data
  • Unauthorised API access exposing user or account data
  • A malicious insider extracting personal data
  • A deployment that makes personal data publicly accessible
Not automatically a DPDP breach
  • A blocked phishing attempt
  • Malware isolated before it reached personal data
  • A system outage that did not affect personal data
  • An attempted intrusion with no compromise
The facts must satisfy the statutory definition. A cybersecurity incident is not automatically a personal data breach — assess each event against the definition of a personal data breach before triggering Rule 7.

Roles

Who has the reporting duty?

The law requires Section 8(6) places the notification duty on the Data Fiduciary. A Data Processor does not replace the Fiduciary as the statutory notifier — and under Section 8(1) the Fiduciary remains responsible for compliance even where a Processor handles the data on its behalf.

Statutory notifier

Data Fiduciary

Notifies the Board and each affected Data Principal under Rule 7. Owns the awareness timestamp, the notices and the 72-hour submission.

Escalates & assists

Data Processor

No express general Rule 7 duty to notify the Board. Escalates to the Fiduciary and supports investigation and notification under its contract.

Practical implementation — not a prescribed statutory DPA clause list

Processor contract provisions to consider:

  • Immediate incident escalation to the Fiduciary
  • Preservation of relevant logs and evidence
  • Reporting of known facts, affected systems and impact
  • Support for containment, remediation and communications
  • Assistance with Board and Data Principal notifications
  • Sub-processor coordination
Note the statutory hook. Section 8(2) requires a valid contract where a Fiduciary engages a Processor for an activity related to offering goods or services to Data Principals; Rule 6 additionally requires appropriate security safeguards in that contract. DPDP does not prescribe an exhaustive clause list.

The workflow

The 10-step breach-response workflow

Each step states what to do, who owns it, what evidence to retain, and its legal status — separating what the law requires from recommended practice.

1

Determine whether personal data is involved

Establish whether there has been unauthorised processing, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access that compromises confidentiality, integrity or availability. Identify affected systems, the personal-data categories, likely affected Data Principals, and whether a Processor or CERT-In duty may also apply.

Who owns it

Security/IT lead technical triage; Privacy/Legal assess the statutory definition.

Evidence to retain

Detection alert, initial summary, affected-system list, preliminary data map.

Legal status

Law requires: notify when there is a personal data breach.

Good practice: keep a data inventory and incident-classification matrix ready in advance.

2

Contain the incident and preserve evidence

Take proportionate steps to stop or limit the unauthorised processing: isolate affected systems, revoke compromised credentials, disable exposed keys or tokens, close misconfigured storage, and preserve forensic evidence.

Who owns it

Security/IT lead; Privacy/Legal kept informed where personal data may be involved.

Evidence to retain

Containment timeline, config/access changes, screenshots and logs, provider communications.

Legal status

Law requires: reasonable security safeguards under Rule 6.

Implementation: isolation and credential revocation are reasonable methods of meeting those duties.

3

Establish the awareness timestamp

Record the date and time the organisation became aware of the breach. Rule 7(2)(b) measures the 72-hour clock from “becoming aware,” so document the source of the information, who received it, the facts known, why they were enough to trigger the response, and who authorised the timestamp.

Interpretive position — not expressly stated in the legislationRule 7 uses “becoming aware” but neither Section 8(6) nor Rule 7 defines awareness. Adopt and consistently apply a documented internal standard: the first point at which an authorised internal function has credible information sufficient to identify a possible personal data breach. Do not invent a statutory definition.
Who owns it

Privacy/Legal own the legal clock; Security/IT provide detection and escalation timestamps.

Evidence to retain

Security-alert time, escalation record, war-room log, the authorised awareness note.

4

Identify affected Data Principals

Determine, as far as reasonably possible, who is affected and how they can be contacted: the affected population, the data categories, available contact channels, whether data was merely exposed or actually accessed, and the likely consequences. Do not wait for full forensic certainty — notification is due without delay.

Who owns it

Privacy/Legal coordinate; Security, customer ops, HR, product and data engineering assist.

Evidence to retain

Population and data-set analysis, contact-method analysis, assumptions and confidence levels.

5

Notify affected Data Principals — without delay

The law requires Rule 7(1) requires a concise, clear, plain-language intimation to each affected Data Principal, sent through their user account or a registered mode of communication.

Your affected-person notice should cover

  • What happened (nature, extent, timing)
  • The likely consequences for them
  • What you have done to mitigate risk
  • Safety steps they should take
  • A contact point for questions

Illustrative structure — not a prescribed Government form.

Who owns it

Privacy/Legal draft and approve; customer/comms teams deliver.

Evidence to retain

Final notice copies, delivery and bounce records, helpdesk script.

6

Give the Board an initial intimation — without delay

The law requires Rule 7(2)(a) requires the Fiduciary to inform the Board without delay of the breach's nature, extent, timing and location, and its likely impact. This is distinct from the detailed 72-hour submission — you need not complete the investigation first.

If no Board portal is published yet: when the duty commences, use the official channel then published by the Board or Government and retain proof of delivery. Do not invent a submission format.
Who owns it

Privacy/Legal lead; Security provide verified facts; approve under a delegation matrix.

Evidence to retain

Initial intimation copy and proof of delivery; note of facts still under investigation.

7

Prepare the 72-hour detailed Board submission

72-hour clock Rule 7(2)(b) requires, within 72 hours of becoming aware: updated detailed information; broad facts, circumstances and causes; mitigation measures; findings on the person responsible, if any; remedial steps to prevent recurrence; and a report on the intimations given to affected Data Principals.

Who owns it

Privacy/DPO map Rule 7; Security supply forensic facts; Legal review; run workstreams in parallel.

Evidence to retain

Investigation and root-cause report, the Board submission and delivery proof, Data Principal notice report.

Initial Board intimationDetailed Board submission
DeadlineWithout delayWithin 72 hours of awareness
PurposeAlert the BoardProvide detailed breach information
Investigation complete?NoMore developed information expected
Core contentNature, extent, timing, location, likely impactUpdated details, causes, mitigation, remediation, findings on the responsible party, Data Principal notice report
BasisRule 7(2)(a)Rule 7(2)(b)
8

Request more time if necessary

The law requires The Board may allow a longer period for the Rule 7(2)(b) information on a request made in writing.

No separate deadline is prescribed for the written request. The Rule does not say extra time is automatic, or that sending a request stops the clock. Treat the original 72-hour deadline as continuing unless and until the Board grants more time.
Practical implementation — a written request should identify
  • Incident reference and original awareness time
  • The information that remains unavailable, and why
  • Steps already completed and interim findings
  • Expected delivery date for outstanding information
  • The person authorised to correspond with the Board
9

Check CERT-In obligations — separately

A single incident can trigger both DPDP and CERT-In duties, but the tests, recipients, deadlines and scope differ. Assess CERT-In applicability immediately and in parallel — do not wait for a final DPDP conclusion. See the comparison below.

Who owns it

Security/IT lead CERT-In assessment; Privacy/Legal consulted.

Legal status

Separate regime: CERT-In's 6-hour rule is under the IT Act, not DPDP.

10

Preserve evidence and close remediation

Preserve the full evidence set (below), complete remediation to prevent recurrence, and conduct a post-incident review covering root cause, control failures, lessons learned and process changes.

Evidence to retain

See the evidence checklist below. Note that Rule 6(1)(e) requires retaining security logs and personal data for one year, and Rule 8(3) separately requires one-year retention of personal data, associated traffic data and processing logs for Seventh-Schedule purposes — these are distinct duties.

Two regimes

DPDP Rule 7 and CERT-In are separate reporting regimes

CERT-In's directions under Section 70B(6) of the IT Act, 2000 (dated 28 April 2022) require covered entities to report listed cyber incidents within six hours of noticing them. That is independent of DPDP Rule 7.

← Scroll to compare →

IssueDPDP Rule 7CERT-In Directions
TriggerA personal data breach (Act definition)A listed cyber incident (Annexure I)
ReporterData FiduciaryCovered service provider, intermediary, data centre, body corporate or Govt organisation
RecipientBoard + each affected Data PrincipalCERT-In
First deadlineWithout delay6 hours of noticing
Detailed deadline72 hours to the BoardPer CERT-In process
ScopePersonal-data compromiseListed cyber-incident categories; may or may not involve personal data
PurposeData protection & individual noticeNational cyber-incident response
Test both regimes separately. Do not assume a report to CERT-In satisfies Rule 7, or that every Rule 7 breach must be reported to CERT-In. Neither discharges the other. See the official CERT-In Directions.

Decision flow

Breach decision flow

Incident detected
Does it involve personal data?
Does it meet the statutory personal-data-breach definition (compromise of confidentiality, integrity or availability)?
No → assess other cyber, contractual, CERT-In and sectoral obligations.
Yes → identify affected Data Principals and contact routes.
Notify affected Data Principals without delay + give the Board an initial intimation without delay.
Investigate and submit the Rule 7(2)(b) detailed information within 72 hours of becoming aware.
Independently assess CERT-In and sector-specific duties.
Preserve evidence, remediate and document closure.

Worked example

Timeline example

An organisation becomes aware on Monday at 10:00 AM that unauthorised API access may have exposed customer account data.

Mon 10:00 AMAwareness
Start the incident record and preserve the 10:00 AM awareness timestamp.
ImmediatelyContain & start
Contain the access path; identify affected data and Data Principals; begin the notices.
First hoursNotify
Initial Board intimation + Data Principal notices without delay; test CERT-In (its 6-hour clock may already run).
By Thu 10:00 AM72-hour report
Submit the detailed Rule 7(2)(b) information to the Board, or make a written request for more time before relying on it.
AfterwardRemediate
Continue support and remediation; preserve evidence; run a root-cause review.
“Without delay” is not a fixed number of hours. This example does not convert it into a statutory 24-hour or 48-hour deadline; it requires prompt action without unjustified delay while giving accurate information.

Operating model

Recommended responsibility matrix

Recommended operating modelThe DPDP Act does not allocate these internal roles by job title. This is a sensible default; adapt it to your organisation.

← Scroll to see all roles →

ActivitySecurity / ITPrivacy / DPOLegalBusiness ownerLeadership
Detect & log incidentLeadInformedInformedInformedInformed
Contain technical incidentLeadConsultedConsultedConsultedInformed
Assess breach definitionConsultedLeadLeadConsultedInformed
Record awareness timestampEvidenceLeadReviewInformedInformed
Identify affected Data PrincipalsSupportLeadReviewSupportInformed
Prepare individual noticeSupportLeadApproveSupportInformed
Board initial intimationFactsLeadApproveSupportEscalate
72-hour detailed submissionFactsLeadApproveSupportOversight
CERT-In applicabilityLeadConsultedReviewConsultedInformed
Remediate & prevent recurrenceLeadMonitorConsultedSupportOversight
Preserve evidence & closeLead (tech)Lead (compliance)Lead (legal)SupportApprove closure

Evidence

Evidence to retain to demonstrate compliance

Expressly required / legally relevant outputs
  • The Data Principal notifications and their Rule 7(1) content
  • The initial Board intimation (Rule 7(2)(a))
  • The detailed Board submission (Rule 7(2)(b))
  • Any extension request and the Board's response
  • Relevant Rule 6(1)(e) security logs/records, where applicable
Recommended compliance evidence
  • Awareness timestamp and supporting records
  • Incident assessment and decision log
  • Forensic report, timeline, affected-system inventory
  • Impact analysis; processor/sub-processor communications
  • Delivery/bounce records; remediation plan and approvals
  • Post-incident review and control improvements

Pitfalls

Common mistakes

Mistake

Treating 72 hours as the only deadline.

CorrectTwo “without delay” notices come first; 72 hours is only the detailed Board report.
Mistake

Waiting for full forensics before the initial Board notice.

CorrectGive the initial intimation without delay with verified facts; mark what is still under investigation.
Mistake

Importing a GDPR materiality/risk threshold.

CorrectRule 7 has no risk or severity threshold; assess against the DPDP definition only.
Mistake

Forgetting the affected Data Principals.

CorrectRule 7(1) requires notifying each affected individual without delay.
Mistake

Assuming a processor's email discharges the Fiduciary's duty.

CorrectSection 8(6) places the duty on the Fiduciary; the processor escalates under contract.
Mistake

Mixing CERT-In's 6-hour rule with DPDP Rule 7.

CorrectThey are separate regimes; assess and file each independently.
Mistake

Failing to record when the organisation became aware.

CorrectDocument a defensible awareness timestamp; the 72-hour clock runs from it.
Mistake

Sending vague individual notices that omit Rule 7(1) content.

CorrectInclude nature, consequences, mitigation, safety steps and a contact point.
Mistake

Treating internal SLAs as statutory deadlines.

CorrectOperational targets help, but the legal standards are “without delay” and 72 hours.
Mistake

Assuming an extension request pauses the clock.

CorrectTime is added only if the Board grants it; keep working to the original deadline.
Mistake

Not preserving delivery/submission evidence.

CorrectRetain copies and proof of delivery for every notice and Board submission.
Mistake

Treating ₹200 crore as an automatic fine.

CorrectIt is a maximum ceiling; the Board weighs the Section 33(2) factors.

Legal risk

Penalty exposure

₹200 crMaximum ceiling

Failure to observe the Section 8(6) breach-intimation obligation may attract a financial penalty of up to ₹200 crore under the Schedule to the Act. This is a maximum ceiling, not an automatic fine: the Board must weigh the Section 33(2) factors — nature, gravity and duration, the data affected, whether the breach was repetitive, any gain or loss avoided, the timeliness of mitigation, proportionality, and the likely impact. Section 33 and the penalty framework commence on 13 May 2027.

Beyond DPDP

DPDP may not be your only reporting duty

DPDP Rule 7 may not be your only incident-reporting obligation. Depending on your sector, separately assess duties under the RBI, SEBI, IRDAI, telecom regulators, CERT-In and any licensing, contractual or critical-infrastructure regimes. A report to one regulator does not necessarily satisfy another. Sector guidance: Fintech & BFSI · Healthcare · SaaS · E-commerce.

FAQ

Frequently asked questions

What is the DPDP breach-reporting deadline?

There is no single deadline. Affected Data Principals must be notified without delay, and the Board must receive an initial intimation without delay. The detailed Board submission is due within 72 hours of becoming aware, unless the Board grants more time on a written request.

Is every personal data breach reportable?

Yes. Rule 7 sets no materiality, severity, risk, financial-harm or affected-person threshold. Every event meeting the statutory definition of a personal data breach enters the notification framework.

Who must notify the Data Protection Board?

The Data Fiduciary. Section 8(6) places the duty on the Fiduciary, which remains responsible even where a Processor handles the data on its behalf.

Does a Data Processor report directly to the Board?

Not under an express general Rule 7 duty. The Processor's role — rapid escalation, evidence preservation and investigation assistance — should be handled through the contract.

When does the 72-hour clock start?

From the Fiduciary “becoming aware” of the breach. The Rules do not define awareness, so document a defensible awareness timestamp based on the facts and your internal escalation record.

What does “without delay” mean?

The law does not fix a number of hours. It should not be presented as a statutory 24-hour or 48-hour deadline; it requires prompt action without unjustified delay, while giving the required information accurately.

Can the Board extend the 72-hour period?

Yes, but only where the Board grants a longer period on a written request. Extra time is not automatic, and sending a request alone does not stop the clock.

Must affected Data Principals always be notified?

Yes. Section 8(6) requires intimation to each affected Data Principal, and Rule 7(1) prescribes the content and delivery route. There is no general risk-based exemption from individual notification.

Is CERT-In reporting also required?

It may be. Where the entity and incident fall within the CERT-In Directions (Annexure I), reporting is due within six hours of noticing the incident. This is separate from Rule 7 — assess both.

When does Rule 7 become effective?

Rule 7 and Section 8(6) commence on 13 May 2027, eighteen months after the Rules were notified on 13 November 2025.


More DPDP Act How-To Guides

Sources

Sources

Primary Government of India sources. Confirm the operative text against the Gazette at the point of use.

Digital Personal Data Protection Act, 2023 (Act 22 of 2023) — Sections 2, 8, 33 and the Schedule.

DPDP Rules, 2025 (G.S.R. 846(E), 13 November 2025) — Rules 6 and 7 and the commencement provision.

Commencement notification (G.S.R. 843(E), 13 November 2025) — staged commencement of the Act.

Corrigendum (G.S.R. 892(E), 10 December 2025) — clerical corrections to the Rules.

CERT-In Directions under Section 70B(6), IT Act, 2000 (28 April 2022) — six-hour reporting and Annexure I.

CERT-In Directions page — official source for the 28 April 2022 directions.

This guide is general information, not legal advice. It reflects the DPDP Act, 2023 and the DPDP Rules, 2025 as notified. Confirm the current operative text and any Board-published procedure before acting on a live incident.