DPDPA Phase II enforcement 13 November 2026 — penalties up to ₹250 crore. Check your readiness →
Book a Demo
Breach Response

DPDPA Breach Notification: The 72-Hour Playbook Every Indian Business Needs

Data Adhikaar Editorial Team 6 July 2026 2 min read
DPDPA Breach Notification: The 72-Hour Playbook Every Indian Business Needs

Under Section 8(6) of the DPDP Act 2023 and the DPDP Rules 2025, a personal data breach must be reported to the Data Protection Board and to every affected Data Principal — and unlike the GDPR, there is no "risk threshold": the duty applies to every personal data breach.

Failure to notify can attract a penalty of up to ₹200 crore, separate from the up-to-₹250 crore exposure for failing to maintain reasonable security safeguards in the first place.

What counts as a personal data breach?

The Act defines it broadly: any unauthorised processing of personal data, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access that compromises confidentiality, integrity or availability. A stolen laptop, a misdirected email export, a ransomware event and a misconfigured S3 bucket all qualify.

The clock: what the Rules require

  • To affected Data Principals — without delay, in clear and plain language, describing the breach, its likely consequences, the mitigation under way, and safety measures they should take, with a contact for queries.
  • To the Data Protection Board — an initial intimation without delay, followed by a detailed report within 72 hours (extendable only if the Board permits), covering facts, circumstances, causes, mitigation and remediation.

The playbook

Hour 0–4: Detect, contain, convene

Trigger the incident response plan. Contain the breach (revoke credentials, isolate systems), preserve forensic evidence, and convene the response team — security, legal/DPO, communications and leadership.

Hour 4–24: Scope and classify

Establish what personal data was affected, whose, how many Data Principals, and whether children's data or high-risk categories are involved. Document everything with timestamps — the Board will expect a coherent timeline.

Hour 24–48: Notify Data Principals and send initial intimation

Draft the plain-language notice and deliver it through the user account or registered contact channel. Send the Board its initial intimation. Do not wait for perfect information — the duty is "without delay".

Hour 48–72: File the detailed Board report

Submit the detailed report with root cause, impact assessment, mitigation and the remediation plan. If facts are still emerging, say so and update.

After: Remediate and evidence

Close the vulnerability, update the risk register, retrain staff if human error contributed, and preserve the full evidence trail — notices, reports, decisions and timestamps.

Prepare before it happens

A breach is the worst time to design a process. Suraksha, Data Adhikaar's breach-response agent, watches security signal feeds, opens incidents, classifies severity and drafts both the Board report and Data Principal notices — with a human approving every transmission. Benchmark your readiness with the free assessment.

#breach-notification#dpdpa#incident-response#data-protection-board

Data Adhikaar Editorial Team

DPDPA Compliance Specialists, Qodequay Technologies

Get DPDPA-ready before the enforcement window closes.

Start with a free readiness assessment, or book a demo of the Data Adhikaar agent fabric.

Or call +91 98226 28174