Ch IPreliminary
S.1 Short title and commencementS.2 DefinitionsS.3 Application and scopeCh IIObligations of Data Fiduciary
S.4 Grounds for processingS.5 NoticeS.6 ConsentS.7 Certain legitimate usesS.8 Data Fiduciary obligationsS.9 Children’s dataS.10 Significant Data FiduciaryCh IIIRights and duties of Data Principal
S.11 Right to accessS.12 Correction and erasureS.13 Grievance redressalS.14 Right to nominateS.15 Duties of the Data PrincipalCh IVSpecial provisions
S.16 Transfer outside IndiaS.17 ExemptionsCh VData Protection Board of India
S.18 Establishment of the BoardS.19 Composition of the BoardS.20 Salary and term of officeS.21 DisqualificationsS.22 Resignation and vacanciesS.23 Proceedings of the BoardS.24 Officers and employeesS.25 Members as public servantsS.26 Powers of the ChairpersonCh VIBoard powers and procedure
S.27 Powers and functions of the BoardS.28 Procedure followed by the BoardCh VIIAppeal and dispute resolution
S.29 Appeal to the Appellate TribunalS.30 Tribunal orders as a decreeS.31 Alternate dispute resolutionS.32 Voluntary undertakingCh VIIIPenalties
S.33 Penalties and the ScheduleS.34 Penalties to Consolidated FundCh IXMiscellaneous
S.35 Good-faith protectionS.36 Power to call for informationS.37 Blocking of accessS.38 Consistency with other lawsS.39 Bar of jurisdictionS.40 Power to make rulesS.41 Laying of rules before ParliamentS.42 Power to amend the ScheduleS.43 Power to remove difficultiesS.44 Amendments to other ActsConcept
A personal data breach is any unauthorised or accidental event that compromises the confidentiality, integrity or availability of personal data.
TL;DR
A personal data breach (Section 2(u)) is any unauthorised or accidental event that compromises the confidentiality, integrity or availability of personal data. It is not only a hack: accidental disclosure, loss of access or unauthorised alteration all count.
"personal data breach" means any unauthorised processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises the confidentiality, integrity or availability of personal data.
A breach is not only a hack. Accidental disclosure, loss of access, or unauthorised alteration all count if they compromise the data.
The definition maps to the classic security triad: confidentiality (who can see it), integrity (whether it is accurate and intact), and availability (whether you can reach it).
Emailing a spreadsheet of customers to the wrong recipient is a breach, even though no attacker was involved.
Is a ransomware lockout a breach?
Yes. Loss of access that compromises availability falls within the definition.
Does a breach have to be malicious?
No. Accidental disclosure or loss is expressly included.
Consultant-led and partner-backed.