Readiness assessment
The Act
The DPDP Act, explainedThe DPDP Rules 2025

Ch IPreliminary

S.1 Short title and commencementS.2 DefinitionsS.3 Application and scope

Ch IIObligations of Data Fiduciary

S.4 Grounds for processingS.5 NoticeS.6 ConsentS.7 Certain legitimate usesS.8 Data Fiduciary obligationsS.9 Children’s dataS.10 Significant Data Fiduciary

Ch IIIRights and duties of Data Principal

S.11 Right to accessS.12 Correction and erasureS.13 Grievance redressalS.14 Right to nominateS.15 Duties of the Data Principal

Ch IVSpecial provisions

S.16 Transfer outside IndiaS.17 Exemptions

Ch VData Protection Board of India

S.18 Establishment of the BoardS.19 Composition of the BoardS.20 Salary and term of officeS.21 DisqualificationsS.22 Resignation and vacanciesS.23 Proceedings of the BoardS.24 Officers and employeesS.25 Members as public servantsS.26 Powers of the Chairperson

Ch VIBoard powers and procedure

S.27 Powers and functions of the BoardS.28 Procedure followed by the Board

Ch VIIAppeal and dispute resolution

S.29 Appeal to the Appellate TribunalS.30 Tribunal orders as a decreeS.31 Alternate dispute resolutionS.32 Voluntary undertaking

Ch VIIIPenalties

S.33 Penalties and the ScheduleS.34 Penalties to Consolidated Fund

Ch IXMiscellaneous

S.35 Good-faith protectionS.36 Power to call for informationS.37 Blocking of accessS.38 Consistency with other lawsS.39 Bar of jurisdictionS.40 Power to make rulesS.41 Laying of rules before ParliamentS.42 Power to amend the ScheduleS.43 Power to remove difficultiesS.44 Amendments to other Acts
Industries
Implementation
Training
Resources
About
Readiness assessment

Concept

Personal Data Breach

A personal data breach is any unauthorised or accidental event that compromises the confidentiality, integrity or availability of personal data.

Defined inSection 2(u)
CategoryCore Concepts
Applies toAny incident affecting personal data security

TL;DR

A personal data breach (Section 2(u)) is any unauthorised or accidental event that compromises the confidentiality, integrity or availability of personal data. It is not only a hack: accidental disclosure, loss of access or unauthorised alteration all count.

What Does the DPDP Act Say About Personal Data Breaches?

DPDP Act 2023, Section 2(u)

"personal data breach" means any unauthorised processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises the confidentiality, integrity or availability of personal data.

What is a Personal Data Breach in Simple Words?

A breach is not only a hack. Accidental disclosure, loss of access, or unauthorised alteration all count if they compromise the data.

The definition maps to the classic security triad: confidentiality (who can see it), integrity (whether it is accurate and intact), and availability (whether you can reach it).

Personal Data Breach: Example

Emailing a spreadsheet of customers to the wrong recipient is a breach, even though no attacker was involved.

Related terms

Related sections of the Act

Related Rules

Personal Data Breach: Frequently Asked Questions

Is a ransomware lockout a breach?

Yes. Loss of access that compromises availability falls within the definition.

Does a breach have to be malicious?

No. Accidental disclosure or loss is expressly included.

Continue learning