The DPDP Act 2023 and the DPDP Rules 2025 require a Data Fiduciary to report a personal data breach to the Data Protection Board of India and to every affected individual. Missing the deadlines can attract a penalty of up to ₹200 crore, separate from any penalty for the breach itself.
What counts as a personal data breach
Any unauthorised processing of personal data, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to it, that compromises its confidentiality, integrity or availability. A lost laptop, a misdirected email, a ransomware lockout and a vendor leak all qualify.
The reporting timeline
| Step | Who | When |
|---|---|---|
| Inform each affected Data Principal | Data Fiduciary | Without delay |
| Intimate the Board | Data Fiduciary | Without delay |
| Detailed report to the Board | Data Fiduciary | Within 72 hours of becoming aware, or longer if the Board allows |
What the notice to individuals must contain
- What happened, and when it happened
- What personal data is affected and the likely consequences for the individual
- What the organisation has done to mitigate the risk
- What the individual can do to protect themselves
- A contact person who can answer questions
What the 72-hour report to the Board covers
- The facts and circumstances, including the nature, extent, timing and location of the breach
- The cause, and the person responsible if known
- Mitigation steps taken
- Findings on the events that led to the breach
- Remedial measures to prevent recurrence
- A record of the notifications sent to affected individuals
CERT-In reporting runs in parallel
CERT-In directions already require specified cyber incidents to be reported within 6 hours. DPDP does not replace this. A single incident response plan should drive both, and also the notification to individuals, which banks and other regulated entities often forget.
Breach response checklist
- Define who declares a breach and starts the clock.
- Keep templates ready for the individual notice and the Board report.
- Make sure vendors must tell you about incidents immediately, by contract.
- Retain logs for at least one year so you can establish what happened.
- Rehearse the 72-hour report at least once a year.
See DPDP Rules 2025 explained and the DPDP audit checklist for the related controls.
