· 8 min read
By Correct Editorial — Compliance Research Desk
Data Breach Compliance Under the DPDP Act
Published on: July 29, 2026
Breach response is where India's Digital Personal Data Protection Act, 2023 becomes unforgiving. Two of the three largest penalty heads in the Schedule — ₹250 crore for inadequate security safeguards and ₹200 crore for failing to notify — sit on either side of a single bad weekend. And unlike the GDPR, the Indian framework contains no risk threshold: there is no "unlikely to result in a risk to the rights and freedoms of natural persons" filter that lets you document an incident internally and move on.
From 13 May 2027, when Rule 7 and Sections 8 and 33 commence for business, every personal data breach is a reportable event. This article explains the definition, the two clocks, what goes into the report, the safeguards the Board will assume you had, and how to build a playbook that survives contact with a real incident. The framework context sits in DPDP Act 2023: An Overview for Businesses.
What Counts as a Personal Data Breach?
Section 2(u) defines a personal data breach as any unauthorised processing of personal data, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises the confidentiality, integrity or availability of personal data.
The definition is deliberately wide. It captures, without any severity filter:
- A ransomware event that encrypts a customer database — an availability compromise even if nothing is exfiltrated
- An employee emailing a spreadsheet of customer records to the wrong recipient
- A misconfigured cloud storage bucket exposing documents, whether or not anyone downloaded them
- A vendor's engineer querying production data outside authorised scope
- Accidental deletion of records with no recoverable backup
- Credential stuffing that succeeds against user accounts
Three implications follow. Availability incidents count, so business-continuity failures are privacy events. Internal incidents count, so insider misuse is reportable. And near-misses with actual unauthorised access count, even where no downstream harm is demonstrable.
What Must You Do the Moment You Become Aware?
Rule 7 creates two parallel obligations that both start at the moment of awareness, not at the moment of confirmation, containment, or root-cause analysis.
To each affected Data Principal — without delay. Rule 7(1) requires intimation to the best of your knowledge, in a concise, clear and plain manner, through her user account or any communication mode she registered with you. The intimation must contain:
- A description of the breach, including its nature, extent and timing
- The consequences relevant to her that are likely to arise
- The mitigation measures implemented and being implemented
- The safety measures she can take to protect her own interests
- Business contact information of a person who can answer her questions on your behalf
To the Data Protection Board — in two stages. Rule 7(2) requires, without delay, a description of the breach including its nature, extent, timing and location of occurrence and the likely impact. Then, within 72 hours of becoming aware — or a longer period the Board allows on a written request — a detailed follow-up.
The practical consequence is that you will be writing to individuals while your incident is still live. Pre-approved templates with variable fields, and a named spokesperson with a monitored contact channel, are not nice-to-haves; without them the "without delay" standard is unachievable.
What Goes into the 72-Hour Report?
Rule 7(2)(b) specifies six elements:
| Element | What the Board expects |
|---|---|
| Updated description | The initial notification, corrected and expanded with verified facts |
| Broad facts | Events, circumstances and reasons leading to the breach — a causal narrative, not a log dump |
| Mitigation measures | What you implemented or propose to implement to reduce risk |
| Findings on the actor | Any findings regarding the person who caused the breach |
| Remedial measures | Steps taken to prevent recurrence |
| Intimation report | A report on the intimations given to affected Data Principals |
Read the sixth item carefully: the Board is auditing whether you notified individuals properly. A report that describes a sophisticated technical response but cannot evidence timely, plain-language communication to affected people invites scrutiny on the ₹200 crore head even where containment was competent.
Where investigation genuinely cannot conclude in 72 hours, request an extension in writing before the deadline expires. The Rule expressly contemplates it. Silence is not an extension.
What Security Safeguards Will the Board Assume You Had?
Rule 6(1) converts "reasonable security safeguards" from a standard into a checklist. Every Data Fiduciary must protect personal data in its possession or control, including data processed on its behalf by a Data Processor, with at minimum:
- Data security measures such as encryption, obfuscation, masking, or virtual tokens mapped to the personal data
- Access control over the computer resources used by the fiduciary or its processor
- Visibility on access through appropriate logs, monitoring and review, to enable detection of unauthorised access, its investigation, and remediation
- Continuity measures such as data backups, for cases where confidentiality, integrity or availability is compromised
- Retention of logs and personal data for one year to enable detection, investigation, remediation and continued processing, unless another law requires otherwise
- Contractual provisions obliging Data Processors to take reasonable security safeguards
- Appropriate technical and organisational measures to ensure effective observance
Item 5 is the one most teams discover late. If your log retention is 30 or 90 days for cost reasons, you will be unable to answer the Board's questions about the "broad facts" of an incident discovered four months after intrusion — and the inability to investigate is itself evidence of inadequate safeguards. Item 6 makes the vendor estate part of your security perimeter, which is why role clarity matters; see Data Fiduciary vs Data Processor: Key Differences.
How Does This Interact with CERT-In and Sectoral Rules?
Rule 7 does not sit alone. Most Indian organisations already operate under the CERT-In directions dated 28 April 2022 under Section 70B(6) of the Information Technology Act, 2000, which require:
- Reporting of specified cyber incidents to CERT-In within six hours of noticing or being notified
- Enabling and securely maintaining ICT system logs for a rolling 180 days within Indian jurisdiction
- Synchronisation of system clocks to NPL or NIC servers
Regulated sectors add more. RBI-regulated entities report cyber incidents to the Reserve Bank under their respective master directions; SEBI-regulated intermediaries follow the cybersecurity and cyber resilience framework; insurers follow IRDAI guidelines. Listed companies must additionally assess disclosure obligations for material events.
The result is a layered clock: six hours to CERT-In, sectoral regulator timelines, without-delay intimation to individuals, and 72 hours to the Data Protection Board. A single incident commander should own all of them from one timeline, because inconsistent facts across filings are far more damaging than a slightly delayed one.
What Are the Penalties and How Does the Board Proceed?
| Failure | Statutory head | Maximum penalty |
|---|---|---|
| Inadequate reasonable security safeguards | Section 8(5) | ₹250 crore |
| Failure to notify the Board or affected individuals | Section 8(6) | ₹200 crore |
| Breach of children's data obligations | Section 9 | ₹200 crore |
| Significant Data Fiduciary lapses | Section 10 | ₹150 crore |
| Any other breach of the Act or Rules | Residuary | ₹50 crore |
The Data Protection Board of India operates as a digital office under Rule 20, with proceedings conducted online from intimation to disposal. It may inquire on a complaint or reference, direct urgent remedial or mitigation measures during an inquiry, and impose penalties under Section 33 only after an opportunity of being heard.
Critically, Section 33(2) requires the Board to consider the nature, gravity and duration of the breach; the type and nature of the personal data affected; whether the breach was repetitive; whether the entity realised a gain or avoided a loss; whether it took action to mitigate, and how timely and effective that action was; proportionality and deterrence; and the likely impact of the penalty. Section 32 additionally permits the Board to accept a voluntary undertaking, which bars proceedings on the covered matter unless the undertaking is itself breached. Appeals go to the Telecom Disputes Settlement and Appellate Tribunal within 60 days under Section 29.
The strategic reading is straightforward: documented, fast, honest response is the primary determinant of exposure. Two companies with identical incidents can face materially different outcomes based on the quality of the evidence they can produce.
Building a Playbook That Actually Works
Define awareness. Write down what triggers the clock — an alert triaged and confirmed by the security team, a vendor notification, a customer complaint corroborated by logs. Ambiguity here is where organisations lose hours they cannot recover.
Name the roles. Incident commander, technical lead, legal and regulatory lead, communications lead, customer-support lead, and a board escalation path. One person owns the filing calendar across CERT-In, the Board, and sectoral regulators.
Pre-draft the artefacts. A Rule 7(1) individual notice template covering all five mandated elements; a Rule 7(2)(a) initial Board intimation; a 72-hour report skeleton with the six headings; a support script; and a written extension request template.
Fix the log gap now. Rule 6 expects one year of logs and personal data retained for investigation; CERT-In expects 180 days within India. Reconcile the two, and confirm your cloud regions and vendors comply — a point that intersects with Cross-border Data Transfer Rules Explained.
Align vendor clauses. Processor notification windows must be strictly shorter than 72 hours; 24 hours is common practice and leaves you room to investigate.
Rehearse twice a year. A tabletop exercise with a plausible scenario, timed against the real clocks, retaining the artefacts produced as evidence of preparedness.
Retain evidence of the response itself. The 72-hour report must describe your intimations to individuals; if delivery logs and message versions are not captured, that section will be unverifiable.
The failure modes are predictable: starting the clock at "confirmed" rather than "aware"; notifying the Board but not individuals; short log retention; vendor contracts silent on timelines; no named spokesperson; and treating a ransomware event as an IT problem rather than a privacy breach. Each is cheap to fix before an incident and impossible to fix during one.
More Indian compliance explainers are available at Correct Learn, and the phased implementation view sits in our DPDP compliance roadmap.
References
- Gazette of India — The Digital Personal Data Protection Act, 2023 — Sections 2(u), 8(5), 8(6), 32, 33 and the Schedule.
- Digital Personal Data Protection Rules, 2025 — notified text — Rule 6 safeguards, Rule 7 breach intimation, and Rule 20 digital office.
- MeitY — Explanatory Note to the DPDP Rules, 2025 — Official explanation of breach intimation requirements.
- Indian Computer Emergency Response Team (CERT-In) — Directions dated 28 April 2022 on cyber incident reporting and log retention.
- Ministry of Electronics and Information Technology — DPDP notifications and the Data Protection Board framework.
- Reserve Bank of India — Cyber incident reporting expectations for regulated entities.
- Press Information Bureau — Government releases on the notification and commencement of the DPDP Rules.
- India Code — Consolidated bare Act with commencement annotations.
Frequently asked questions
- What counts as a personal data breach under the DPDP Act?
- Section 2(u) defines it as any unauthorised processing, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises the confidentiality, integrity or availability of personal data. There is no severity threshold or harm test.
- What is the DPDP breach notification timeline?
- Under Rule 7, the Data Fiduciary must intimate each affected Data Principal without delay, and must give the Data Protection Board an initial description without delay followed by a detailed report within 72 hours of becoming aware, unless the Board allows a longer period on written request.
- Does the DPDP Act replace CERT-In incident reporting?
- No. CERT-In directions of 28 April 2022 require reporting of specified cyber incidents within six hours and retention of ICT logs for 180 days within Indian jurisdiction. Those obligations run in parallel with Rule 7, so most breaches trigger both clocks.
- What is the penalty for failing to report a data breach?
- The Schedule to the Act allows up to ₹200 crore for failing to notify the Board or affected individuals under Section 8(6), and up to ₹250 crore for failing to take reasonable security safeguards under Section 8(5). Both heads can arise from a single incident.