The direct answer

After a suspected breach, preserve evidence and establish a time-stamped legal decision record. Assess the incident against each potentially applicable reporting regime, contract and jurisdiction. A notification decision must be revisited as facts develop; neither an early assumption of no breach nor a universal reporting deadline is a sound substitute.

The business situation

An illustrative scenario

A cloud provider reports unusual access but cannot yet confirm whether files were downloaded. Security is investigating, procurement holds the contract, and the legal team receives a summary hours later. Each team has part of the incident; no one has the complete reporting assessment.

A privacy review begins with the processing activity: whose data is involved, who decides the purpose and means, and what each participant actually does. A Data Fiduciary and a Processor have different roles; the contract label is evidence, not the final answer. GDPR terminology should not be imported into an Indian assessment without checking the applicable statutory ground.

What needs examining

01. Create one chronology without delaying containment

Record detection, awareness, affected systems and the source of each factual statement. Distinguish confirmed access from suspected exposure and unavailable information. Preserve relevant logs while the security team contains the incident. Legal coordination should help the response proceed; waiting for a perfect forensic report can be incompatible with a reporting obligation.

02. Assess each notification route independently

CERT-In directions, sector requirements, applicable DPDP provisions, foreign law and customer contracts may have different triggers, recipients and clocks. Assess scope and commencement expressly. A Processor's promise to notify its customer does not necessarily discharge the customer's own duties. If an initial report can be supplemented, identify what must be stated now and what remains provisional.

03. Keep communications consistent with the evidence

Use a controlled factual record for regulators, affected individuals, customers and internal decision-makers. Avoid premature assurances that no data was affected when the investigation is incomplete. Explain uncertainty accurately, record the rationale for decisions and schedule reassessment. Do not assume that merely copying a lawyer creates privilege over every incident document.

Law, contract and recommended practice

DPDP Act, 2023: sections 4–8, 11–13 and 16, as relevant. The substantive duties discussed here form part of the phased commencement programme; distinguish readiness work from duties already in force. Existing IT, cybersecurity and sector-specific requirements need their own assessment.

Connect the control to the evidence

Use this table to scope the review. The legal basis and the practical control are identified separately.

Obligation or objectivePractical controlEvidence to retain
Law, where applicable
Meet the relevant reporting duty
Regime-specific trigger and deadline assessmentNotification rationale and submission proof
Contractual control
Preserve customer and vendor cooperation
Named incident contacts and escalationContract notice and response chronology
Recommended practice
Keep decisions aligned with new facts
Versioned decision log and reassessmentDated updates and accountable sign-off

Records to prepare

Bring the complete, current record to the review. Preserve earlier versions where a change or disputed event makes them relevant.

Incident chronology and preserved logs
Data categories and affected-person assessment
Customer, vendor and insurance terms
Applicable reporting requirements register

Common questions

Should reporting wait for forensic certainty?

Not automatically. The applicable trigger may arise before every fact is known. Assess whether the law or contract requires an initial report and permits later updates. Record the decision rather than assuming uncertainty suspends time.

Is a single 72-hour clock adequate for India?

No. Different regimes may impose different requirements, and DPDP commencement must be considered. Maintain separate assessments for CERT-In, sector regulators, contractual commitments and any foreign-law exposure.

The next practical step

Name an owner for the legal reporting assessment at the start of the response. Preserve the rationale for each decision and the factual changes that cause it to be revisited.

Legislation & official resources

These references identify the governing frameworks. Confirm the current text, relevant amendments and applicable judicial position for the matter.

This note is general information. The scenario is hypothetical and does not describe a client matter. The legal result depends on the facts, documents, jurisdiction and operative law. No individual lawyer review is represented by the preparation date.

Explore the AMLEGALS data privacy practice