Assure · Breach Readiness & Response

Breach notification under DPDP

Three clocks start the moment you become aware, and two of them are already running while you are still deciding whether this counts.

Talk to us What we do, in four steps We write the plan, rehearse it with your team, and run the clock if it happens.
What we actually do

The engagement, in four steps

Most of it happens on an ordinary week. The last step is the one you are buying the first three for.

1

We find out what would happen today

We walk your current process with the people who would be in it — or establish that there is not one, which is the usual answer and a perfectly good place to start.

2

We write the plan and the drafts

Who decides, who drafts, who signs. The Board intimation and the notices to affected people, written in your words now rather than at 2am, in the languages you need.

3

We rehearse it with your team

A tabletop exercise against a scenario that could actually happen to you. Nearly every one finds the same thing: nobody knew who was allowed to decide.

4

We are reachable when it happens

If a breach comes, we run the legal clock alongside whoever is containing it — the reportability call, the Rule 7 filings, and the evidence trail as you go.

Scoped to the size of your operation rather than sold as a package, and steps one to three are worth having on their own. Plenty of clients stop there, which is a reasonable decision and one we will tell you is available.

§2(u)

There is no “too small to report”

The Act carries no materiality threshold. If it is a personal data breach, it is notifiable — and the definition is wider than people expect.

It covers availability, not just theft. A personal data breach is any unauthorised processing, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access, that compromises the confidentiality, integrity or availability of personal data. Nothing has to leave the building for one to have happened.

01

Ransomware where nothing was taken

Your systems are locked and the attacker exfiltrated nothing. Availability is compromised, so it is a breach — a distinction people find surprising and expensive.

02

Data deleted with no backup

A migration goes wrong, or somebody drops the wrong table. Destruction and loss of access are both named. Your own mistake is still a breach.

03

The email to the wrong address

A patient list, a payroll file, an attachment sent to a similar name. The commonest breach in every jurisdiction, and the one least likely to be reported internally.

04

The employee who took a copy

A departing salesperson with the customer database on a personal drive. Unauthorised processing, whatever the employment contract says about it.

05

The storage left open

A misconfigured bucket, exposed for weeks. The question is not whether anyone found it — it is whether you can show nobody did.

06

Your vendor’s breach

They lost it; you answer for it. Section 8(1) makes you responsible for processing on your behalf irrespective of any agreement to the contrary.

This matters more than it sounds, because the instinct in the room is always to find a reason it does not count. Under DPDP there usually is not one, and an organisation that spends two days looking for it has spent two of the three days it had.

Rule 7

Everyone quotes 72 hours. Two duties come sooner

Seventy-two hours is the deadline for the detailed report. Treating it as the deadline gives you two days you do not have.

1

Tell the Board — without delay

Rule 7(2)(a). On becoming aware, intimate the Data Protection Board with a description of the breach: its nature, extent, timing and location. Not a full account — a first notification, made before you have finished understanding it.

2

Tell each affected person — without delay

Rule 7(1). Concise, clear and plain, to each affected data principal: what happened, the consequences likely for them, what you are doing about it, what they should do, and a contact who can answer them.

3

The detailed report — 72 hours

Rule 7(2)(b), from the moment you became aware. Six things, and one of them requires an investigation most organisations have not started by then. The Board may allow longer, on a written request.

And the clock starts at awareness

Not at confirmation, not when the report lands on the DPO’s desk. Which makes it worth deciding in advance who inside the business is capable of making you “aware”, and how fast that reaches someone who can act.

Rule 7(2)(b)

What the 72-hour report has to contain

Six items. Read them as a to-do list for the three days, because that is what they are.

(i)₹200 Cr

Updated and detailed information on the nature, extent, timing and location — the first notification, now with the facts filled in.

Detail
(ii)₹200 Cr

The facts, circumstances and reasons that led to it. Not the symptom — the cause, established well enough to write down.

Cause
(iii)₹200 Cr

The measures you implemented to mitigate risk. Section 33(2)(e) will read this again later, when the penalty is being set.

Mitigation
(iv)₹200 Cr

Findings regarding the person who caused it. An attribution exercise, in three days, and the item nobody expects to be there.

Attribution
(v)₹200 Cr

Remedial measures to prevent recurrence. Which means having decided what changes, not merely that something will.

Remediation
(vi)₹200 Cr

A report on the intimations given to affected data principals. You have to be able to evidence that you told them, and when.

Proof

Two of these are usually the problem. Item (iv) is a forensic question, and an organisation without a year of logs cannot answer it — which is one reason Rule 6 requires logs, monitoring and review to be retained for a year. Item (vi) is a records question, and it catches out anybody who notified people by whatever means came to hand.

The part that actually takes the time

You cannot tell people you do not know about

The forms are the easy half. Working out whose data was in there is what consumes the seventy-two hours.

What you must establish, fast

  • Which systems were touched, and what personal data each of them holds
  • Which categories — health, financial, children’s data all change the picture
  • How many people, and enough identity to reach each of them
  • What each person needs to be told about consequences for them
  • Whether a processor of yours is involved, and what they know
  • Whether any of it left India, and where it went

Why it takes days without preparation

  • Nobody has a list of which systems hold personal data
  • The people who know are the people already busy containing it
  • Contact details live in a system nobody has queried this way before
  • The vendor is being cautious and slow, because their lawyers are involved
  • Somebody is still arguing about whether it is reportable at all

Every one of these is answerable in advance, on an ordinary afternoon, for a fraction of what it costs to answer during.

The engagement

Before, and during

Most of the value is in the first column. The second is what you are buying the first one for.

Readiness, in advance

  • A written response plan naming who decides, who drafts and who signs
  • The awareness path — how a helpdesk ticket reaches a decision-maker in hours
  • Draft Board intimations and data-principal notices, written before the pressure
  • A scoping method against your systems, so “whose data” is hours not days
  • Vendor notification clauses checked, since their delay becomes your breach
  • A tabletop exercise with the people who would actually be in the room

Response, on the day

  • A reportability call you can defend, made quickly rather than comfortably
  • The Board intimation drafted and the seventy-two-hour report assembled
  • Data-principal notices in the languages your people read
  • Evidence captured as you go, for Rule 7(2)(b)(vi) and for section 33(2)
  • The extension request in writing, where the facts genuinely need longer

We are not incident responders. Your security team or forensics firm contains it; we run the legal clock alongside them.

Preparation is not just insurance. It is priced in.

Section 33(2)(e) makes mitigation and its timeliness an express factor in what a failure costs. The rehearsed response and the improvised one end up at different numbers.

Questions

Straight answers

Is a small breach really reportable?

Yes. This is the single most common misunderstanding, and it comes from GDPR, which lets you skip notifying the supervisory authority where a breach is unlikely to result in a risk to people. The DPDP Act contains no equivalent carve-out and no materiality threshold — if there has been a personal data breach, Rule 7's duties apply. One misdirected email containing personal data is, on the face of the Act, notifiable. That is a genuinely demanding position and it is worth knowing before you are relying on the opposite.

Is ransomware a breach if nothing was stolen?

Yes. The definition covers unauthorised processing, accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access — anything compromising confidentiality, integrity or availability. A lockout compromises availability, so nothing has to leave the building for a breach to have occurred. The same reasoning catches an accidental deletion with no usable backup, which surprises people more, because it means your own mistake can be a reportable breach.

When exactly does the clock start?

On becoming aware — not on confirming, not when it reaches the DPO. That makes awareness a design question rather than a legal one: who in the business is capable of making the organisation aware, and how quickly does what they noticed reach somebody who can act? A support agent who sees something odd on a Friday evening has, in practice, started your clock. Most of the readiness work is about shortening the distance between that moment and a decision.

What if we do not have all the facts within 72 hours?

Often you will not, and the Rules anticipate it. The first intimation to the Board is due without delay and is a description rather than a full account — nature, extent, timing and location. The seventy-two-hour deadline is for the detailed report, and the Board may allow a longer period on a written request. What is not available is silence while you investigate. The two "without delay" duties do not wait for certainty, and an extension you asked for is in a different position from a deadline you missed.

Our cloud provider had the incident. Is it ours to report?

If they were processing personal data on your behalf, yes. Section 8(1) makes you responsible for processing carried out on your behalf by a processor irrespective of any agreement to the contrary. Practically this is why the notification clause in your vendor contracts matters so much: if they are only obliged to tell you "without undue delay", they can be within their contract while putting you outside your Rules. Fixing that wording is part of the readiness work rather than something to discover afterwards.

Do you do the technical incident response as well?

No, and you should be wary of a firm claiming both. Containment, forensics and recovery belong to your security team or a specialist forensics firm, and they will be fully occupied. What we run alongside them is the legal clock: the reportability decision, the Board intimation, the data-principal notices, the seventy-two-hour report, and the evidence trail that supports both Rule 7(2)(b)(vi) and any later argument under section 33(2). The two workstreams need each other and they are not the same skill.

In their words

What compliance teams tell us

“We always thought DPDP compliance was the client’s responsibility since we were only executing services. The evaluation made it clear that how we handle client data creates risk on our side too. It changed how we work internally.”
DSFounderDigital services firm
“We had a basic understanding of DPDP requirements, but the scorecard highlighted gaps we hadn’t identified internally — especially around consent handling and data visibility. It gave us a much clearer starting point.”
BSFounderB2B SaaS company
“The DPDP score was surprisingly insightful. Within minutes we could see where we stood and what needed immediate attention. It simplified something that initially felt quite complex.”
FPProduct HeadFintech platform
“After reviewing our score we opted for a consultation. The discussion was very practical — we got clear direction on what to fix first and how to approach DPDP compliance in a structured way.”
LGFounderLogistics company

Real client quotes, attributed by role and sector — we never name a client.

Insights

DPDP, explained properly

All articles

Working across

Healthcare & HospitalsDiagnostics & Labs Education & EdtechBFSI & Fintech InsuranceLogistics & Mobility Retail & E-commerceIT & SaaS ManufacturingReal Estate
Hospitality & TravelMedia & Publishing Professional ServicesStaffing & HR TelecomOnline Gaming NGO & Non-profitGovernment & PSU Pharma & Life SciencesAutomotive

Decide this on a quiet afternoon.

Every question the Rules ask has an answer you could write down today, calmly, for a fraction of what it costs to work out at 2am.