A personal data breach triggers a cascade of obligations under the DPDPA. The Data Protection Board must be notified. Affected Data Principals must be intimated. The board of directors must be briefed. Forensic evidence must be preserved. And all of this must happen while the breach is being contained and remediated.
The penalty for failure to notify is up to INR 200 crore. The penalty for failure to implement reasonable security safeguards — which the breach itself may evidence — is up to INR 250 crore. The 72 hours after breach discovery determine not just the regulatory outcome, but the organisation\'s legal exposure for years to come.
The 72-Hour Timeline
Confirm and Contain
- ▸Verify the breach is real — distinguish from false positives, test alerts, and authorised access
- ▸Activate the incident response team (IT security, legal, communications, DPO if applicable)
- ▸Isolate affected systems without destroying evidence — image before shutting down
- ▸Revoke compromised credentials, API keys, and access tokens immediately
- ▸Preserve all logs, access records, and forensic evidence — start chain of custody documentation
- ▸Do NOT communicate externally yet — premature disclosure without facts causes more harm
Assess Scope and Impact
- ▸Determine what personal data was compromised — names, contact, financial, health, biometric
- ▸Estimate the number of Data Principals affected
- ▸Determine whether children's data (under 18) is involved — triggers higher penalty exposure (INR 200 crore)
- ▸Assess whether data has been exfiltrated, encrypted (ransomware), or merely accessed
- ▸Identify whether any cross-border data exposure exists
- ▸Begin documenting the timeline — when the breach occurred, when it was discovered, what was done
Board Intimation and Legal Assessment
- ▸Prepare the breach notification to the Data Protection Board of India in the prescribed form under DPDP Rules
- ▸Brief the board of directors/senior management with facts, exposure assessment, and recommended actions
- ▸Engage external breach response counsel — privilege considerations apply to the legal analysis
- ▸Assess parallel reporting obligations: CERT-In (6-hour window for specified incidents), sectoral regulators (RBI, SEBI, IRDAI as applicable)
- ▸Prepare the Data Principal intimation draft for legal review
- ▸Evaluate whether law enforcement notification is warranted (theft, extortion, insider threat)
Data Principal Notification
- ▸Finalise and send intimation to affected Data Principals in the prescribed format
- ▸The intimation must include: nature of breach, categories of data affected, measures taken, contact point for queries
- ▸Establish a helpline or dedicated email for Data Principal inquiries
- ▸If the breach involves a large number of Data Principals, consider public notice in addition to individual notification
- ▸Continue forensic investigation — scope may expand as analysis progresses
- ▸Monitor for secondary exploitation — credential stuffing, phishing using compromised data
Remediation and Documentation
- ▸Implement permanent remediation — patch vulnerabilities, reconfigure access controls, update security measures
- ▸Complete the forensic investigation and prepare the detailed incident report
- ▸File any outstanding regulatory notifications (CERT-In if not yet done, sectoral regulators)
- ▸Assess whether notification to Data Processors is required — they may have independent notification obligations
- ▸Begin the lessons-learned review — what failed, what worked, what changes are needed
- ▸Update the breach response plan based on this incident's experience
Board Intimation: What Management Must Know
The board of directors or senior management briefing should cover seven points:
- 1Nature of the breach — what happened, when, how
- 2Scope — categories of data, estimated number of Data Principals affected
- 3Children\'s data involvement — triggers separate and higher penalty (up to INR 200 crore)
- 4Containment status — is the breach ongoing, contained, or fully remediated
- 5Regulatory timeline — notification obligations and deadlines
- 6Penalty exposure — applicable penalties under the DPDPA Schedule
- 7Legal privilege — whether the investigation should be conducted under legal privilege to protect attorney-client communications
Parallel Reporting Obligations
The DPDPA notification is not the only reporting obligation. Depending on the nature of the breach and the sector, parallel obligations may include:
- ▸CERT-In: 6-hour reporting for specified cyber security incidents under the April 2022 Directions
- ▸RBI: Reporting obligations for banks, NBFCs, and payment system operators under RBI cyber security framework
- ▸SEBI: Reporting for listed entities and market intermediaries under SEBI cyber security framework
- ▸IRDAI: Reporting for insurance companies under IRDAI information and cyber security guidelines
- ▸Stock exchange disclosure: Material event disclosure for listed entities under SEBI LODR Regulations
Related Reading
Frequently Asked Questions
What is the breach notification timeline under DPDPA?
The DPDPA requires notification to the Data Protection Board of India "without unreasonable delay." The DPDP Rules, 2025 prescribe the form and manner of notification. The operative benchmark is 72 hours from the time the Data Fiduciary becomes aware of the breach. Separate intimation to affected Data Principals is also required.
Does every data breach need to be reported under DPDPA?
Yes. Unlike the GDPR which exempts breaches "unlikely to result in a risk," the DPDPA requires every personal data breach to be reported to the Data Protection Board. There is no materiality threshold for Board notification. The threshold for Data Principal notification is determined by the Board based on severity assessment.
What is the penalty for failing to notify a data breach?
The Schedule to the DPDPA prescribes a penalty of up to INR 200 crore for failure to notify the Data Protection Board of a personal data breach. This is a per-contravention penalty.
Is CERT-In notification also required?
CERT-In notification under the Information Technology Act, 2000 and the Cyber Security Directions of April 2022 may also be required in parallel. CERT-In requires reporting within 6 hours for specified cyber security incidents. The DPDPA notification to the Board is a separate obligation and does not substitute for CERT-In reporting.
What should the board of directors know immediately?
The board should be briefed on: (a) nature and scope of the breach, (b) categories and estimated volume of affected Data Principals, (c) whether children's data is involved (higher penalty exposure), (d) containment status, (e) regulatory notification timeline and obligations, (f) potential penalty exposure under the DPDPA schedule, and (g) legal privilege considerations for the investigation.
Data Breach? Act Now.
Every hour counts. We provide immediate breach response counsel — forensic coordination, Board notification preparation, Data Principal communication, and regulatory strategy.