Three clocks start the moment you become aware, and two of them are already running while you are still deciding whether this counts.
Most of it happens on an ordinary week. The last step is the one you are buying the first three for.
We walk your current process with the people who would be in it — or establish that there is not one, which is the usual answer and a perfectly good place to start.
Who decides, who drafts, who signs. The Board intimation and the notices to affected people, written in your words now rather than at 2am, in the languages you need.
A tabletop exercise against a scenario that could actually happen to you. Nearly every one finds the same thing: nobody knew who was allowed to decide.
If a breach comes, we run the legal clock alongside whoever is containing it — the reportability call, the Rule 7 filings, and the evidence trail as you go.
Scoped to the size of your operation rather than sold as a package, and steps one to three are worth having on their own. Plenty of clients stop there, which is a reasonable decision and one we will tell you is available.
The Act carries no materiality threshold. If it is a personal data breach, it is notifiable — and the definition is wider than people expect.
It covers availability, not just theft. A personal data breach is any unauthorised processing, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access, that compromises the confidentiality, integrity or availability of personal data. Nothing has to leave the building for one to have happened.
Your systems are locked and the attacker exfiltrated nothing. Availability is compromised, so it is a breach — a distinction people find surprising and expensive.
A migration goes wrong, or somebody drops the wrong table. Destruction and loss of access are both named. Your own mistake is still a breach.
A patient list, a payroll file, an attachment sent to a similar name. The commonest breach in every jurisdiction, and the one least likely to be reported internally.
A departing salesperson with the customer database on a personal drive. Unauthorised processing, whatever the employment contract says about it.
A misconfigured bucket, exposed for weeks. The question is not whether anyone found it — it is whether you can show nobody did.
They lost it; you answer for it. Section 8(1) makes you responsible for processing on your behalf irrespective of any agreement to the contrary.
This matters more than it sounds, because the instinct in the room is always to find a reason it does not count. Under DPDP there usually is not one, and an organisation that spends two days looking for it has spent two of the three days it had.
Seventy-two hours is the deadline for the detailed report. Treating it as the deadline gives you two days you do not have.
Rule 7(2)(a). On becoming aware, intimate the Data Protection Board with a description of the breach: its nature, extent, timing and location. Not a full account — a first notification, made before you have finished understanding it.
Rule 7(1). Concise, clear and plain, to each affected data principal: what happened, the consequences likely for them, what you are doing about it, what they should do, and a contact who can answer them.
Rule 7(2)(b), from the moment you became aware. Six things, and one of them requires an investigation most organisations have not started by then. The Board may allow longer, on a written request.
Not at confirmation, not when the report lands on the DPO’s desk. Which makes it worth deciding in advance who inside the business is capable of making you “aware”, and how fast that reaches someone who can act.
Six items. Read them as a to-do list for the three days, because that is what they are.
Updated and detailed information on the nature, extent, timing and location — the first notification, now with the facts filled in.
DetailThe facts, circumstances and reasons that led to it. Not the symptom — the cause, established well enough to write down.
CauseThe measures you implemented to mitigate risk. Section 33(2)(e) will read this again later, when the penalty is being set.
MitigationFindings regarding the person who caused it. An attribution exercise, in three days, and the item nobody expects to be there.
AttributionRemedial measures to prevent recurrence. Which means having decided what changes, not merely that something will.
RemediationA report on the intimations given to affected data principals. You have to be able to evidence that you told them, and when.
ProofTwo of these are usually the problem. Item (iv) is a forensic question, and an organisation without a year of logs cannot answer it — which is one reason Rule 6 requires logs, monitoring and review to be retained for a year. Item (vi) is a records question, and it catches out anybody who notified people by whatever means came to hand.
The forms are the easy half. Working out whose data was in there is what consumes the seventy-two hours.
Every one of these is answerable in advance, on an ordinary afternoon, for a fraction of what it costs to answer during.
Most of the value is in the first column. The second is what you are buying the first one for.
We are not incident responders. Your security team or forensics firm contains it; we run the legal clock alongside them.
Section 33(2)(e) makes mitigation and its timeliness an express factor in what a failure costs. The rehearsed response and the improvised one end up at different numbers.
Yes. This is the single most common misunderstanding, and it comes from GDPR, which lets you skip notifying the supervisory authority where a breach is unlikely to result in a risk to people. The DPDP Act contains no equivalent carve-out and no materiality threshold — if there has been a personal data breach, Rule 7's duties apply. One misdirected email containing personal data is, on the face of the Act, notifiable. That is a genuinely demanding position and it is worth knowing before you are relying on the opposite.
Yes. The definition covers unauthorised processing, accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access — anything compromising confidentiality, integrity or availability. A lockout compromises availability, so nothing has to leave the building for a breach to have occurred. The same reasoning catches an accidental deletion with no usable backup, which surprises people more, because it means your own mistake can be a reportable breach.
On becoming aware — not on confirming, not when it reaches the DPO. That makes awareness a design question rather than a legal one: who in the business is capable of making the organisation aware, and how quickly does what they noticed reach somebody who can act? A support agent who sees something odd on a Friday evening has, in practice, started your clock. Most of the readiness work is about shortening the distance between that moment and a decision.
Often you will not, and the Rules anticipate it. The first intimation to the Board is due without delay and is a description rather than a full account — nature, extent, timing and location. The seventy-two-hour deadline is for the detailed report, and the Board may allow a longer period on a written request. What is not available is silence while you investigate. The two "without delay" duties do not wait for certainty, and an extension you asked for is in a different position from a deadline you missed.
If they were processing personal data on your behalf, yes. Section 8(1) makes you responsible for processing carried out on your behalf by a processor irrespective of any agreement to the contrary. Practically this is why the notification clause in your vendor contracts matters so much: if they are only obliged to tell you "without undue delay", they can be within their contract while putting you outside your Rules. Fixing that wording is part of the readiness work rather than something to discover afterwards.
No, and you should be wary of a firm claiming both. Containment, forensics and recovery belong to your security team or a specialist forensics firm, and they will be fully occupied. What we run alongside them is the legal clock: the reportability decision, the Board intimation, the data-principal notices, the seventy-two-hour report, and the evidence trail that supports both Rule 7(2)(b)(vi) and any later argument under section 33(2). The two workstreams need each other and they are not the same skill.
Real client quotes, attributed by role and sector — we never name a client.
Working across
Every question the Rules ask has an answer you could write down today, calmly, for a fraction of what it costs to work out at 2am.
Thank you — we have it. Someone will reply by email, usually within one working day.
Nothing else is needed from you. If it is urgent, email tushar@ruleexpert.com and it will reach the same people.