After a suspected breach, preserve evidence and establish a time-stamped legal decision record. Assess the incident against each potentially applicable reporting regime, contract and jurisdiction. A notification decision must be revisited as facts develop; neither an early assumption of no breach nor a universal reporting deadline is a sound substitute.
The business situation
A cloud provider reports unusual access but cannot yet confirm whether files were downloaded. Security is investigating, procurement holds the contract, and the legal team receives a summary hours later. Each team has part of the incident; no one has the complete reporting assessment.
A privacy review begins with the processing activity: whose data is involved, who decides the purpose and means, and what each participant actually does. A Data Fiduciary and a Processor have different roles; the contract label is evidence, not the final answer. GDPR terminology should not be imported into an Indian assessment without checking the applicable statutory ground.
What needs examining
01. Create one chronology without delaying containment
Record detection, awareness, affected systems and the source of each factual statement. Distinguish confirmed access from suspected exposure and unavailable information. Preserve relevant logs while the security team contains the incident. Legal coordination should help the response proceed; waiting for a perfect forensic report can be incompatible with a reporting obligation.
02. Assess each notification route independently
CERT-In directions, sector requirements, applicable DPDP provisions, foreign law and customer contracts may have different triggers, recipients and clocks. Assess scope and commencement expressly. A Processor's promise to notify its customer does not necessarily discharge the customer's own duties. If an initial report can be supplemented, identify what must be stated now and what remains provisional.
03. Keep communications consistent with the evidence
Use a controlled factual record for regulators, affected individuals, customers and internal decision-makers. Avoid premature assurances that no data was affected when the investigation is incomplete. Explain uncertainty accurately, record the rationale for decisions and schedule reassessment. Do not assume that merely copying a lawyer creates privilege over every incident document.
Law, contract and recommended practice
DPDP Act, 2023: sections 4–8, 11–13 and 16, as relevant. The substantive duties discussed here form part of the phased commencement programme; distinguish readiness work from duties already in force. Existing IT, cybersecurity and sector-specific requirements need their own assessment.
Connect the control to the evidence
Use this table to scope the review. The legal basis and the practical control are identified separately.
| Obligation or objective | Practical control | Evidence to retain |
|---|---|---|
| Law, where applicable Meet the relevant reporting duty | Regime-specific trigger and deadline assessment | Notification rationale and submission proof |
| Contractual control Preserve customer and vendor cooperation | Named incident contacts and escalation | Contract notice and response chronology |
| Recommended practice Keep decisions aligned with new facts | Versioned decision log and reassessment | Dated updates and accountable sign-off |
Records to prepare
Bring the complete, current record to the review. Preserve earlier versions where a change or disputed event makes them relevant.
Common questions
Should reporting wait for forensic certainty?
Not automatically. The applicable trigger may arise before every fact is known. Assess whether the law or contract requires an initial report and permits later updates. Record the decision rather than assuming uncertainty suspends time.
Is a single 72-hour clock adequate for India?
No. Different regimes may impose different requirements, and DPDP commencement must be considered. Maintain separate assessments for CERT-In, sector regulators, contractual commitments and any foreign-law exposure.
Name an owner for the legal reporting assessment at the start of the response. Preserve the rationale for each decision and the factual changes that cause it to be revisited.
Legislation & official resources
These references identify the governing frameworks. Confirm the current text, relevant amendments and applicable judicial position for the matter.
- Digital Personal Data Protection frameworkMinistry of Electronics and Information Technology · Official framework resource. Apply the relevant Act, Rules and commencement notifications together.
- DPDP Act commencement notification: G.S.R. 843(E)MeitY · Gazette of India · Notification dated 13 November 2025. Different provisions commence in different phases.
- CERT-In Directions under section 70B(6), 28 April 2022Indian Computer Emergency Response Team · Assess covered entities, incident categories and the applicable reporting trigger independently of other regimes.
This note is general information. The scenario is hypothetical and does not describe a client matter. The legal result depends on the facts, documents, jurisdiction and operative law. No individual lawyer review is represented by the preparation date.
Explore the AMLEGALS data privacy practice