DPDP Audits

DPDP Data Breach Notification: The 72-Hour Reporting Guide

What counts as a personal data breach under the DPDP Act, who must be notified, what the 72-hour Board report contains, and how it fits alongside CERT-In reporting.

By Ram Krishan Dudeja, CISA CAIIB · Last reviewed 4 October 2026

The DPDP Act 2023 and the DPDP Rules 2025 require a Data Fiduciary to report a personal data breach to the Data Protection Board of India and to every affected individual. Missing the deadlines can attract a penalty of up to ₹200 crore, separate from any penalty for the breach itself.

What counts as a personal data breach

Any unauthorised processing of personal data, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to it, that compromises its confidentiality, integrity or availability. A lost laptop, a misdirected email, a ransomware lockout and a vendor leak all qualify.

The reporting timeline

StepWhoWhen
Inform each affected Data PrincipalData FiduciaryWithout delay
Intimate the BoardData FiduciaryWithout delay
Detailed report to the BoardData FiduciaryWithin 72 hours of becoming aware, or longer if the Board allows

What the notice to individuals must contain

What the 72-hour report to the Board covers

CERT-In reporting runs in parallel

CERT-In directions already require specified cyber incidents to be reported within 6 hours. DPDP does not replace this. A single incident response plan should drive both, and also the notification to individuals, which banks and other regulated entities often forget.

Breach response checklist

  1. Define who declares a breach and starts the clock.
  2. Keep templates ready for the individual notice and the Board report.
  3. Make sure vendors must tell you about incidents immediately, by contract.
  4. Retain logs for at least one year so you can establish what happened.
  5. Rehearse the 72-hour report at least once a year.

See DPDP Rules 2025 explained and the DPDP audit checklist for the related controls.

Frequently asked questions

How soon must a data breach be reported under the DPDP Act?

Affected Data Principals and the Board must be informed without delay, and a detailed report must reach the Board within 72 hours of becoming aware, or a longer period if the Board allows.

Must individuals be told about every personal data breach under DPDP?

Yes. A Data Fiduciary must inform each affected Data Principal, unlike GDPR, which limits individual notice to high-risk breaches.

What is the penalty for not reporting a data breach under DPDP?

Failing to notify the Board and affected Data Principals can attract a penalty of up to ₹200 crore, separate from any penalty for the breach itself.

Does DPDP breach reporting replace CERT-In reporting?

No. CERT-In directions require specified cyber incidents to be reported within 6 hours and continue to apply. One incident response plan should cover both, plus notice to individuals.

Need an independent DPDP audit?

67 controls, auditor-signed findings, and a remediation roadmap you can act on.

Book a Free Consultation

Related guides

This guide is general information, not legal advice. Refer to the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025 as notified for the authoritative text.