DPDPA Breach Notification: The 72-Hour Playbook Every Indian Business Needs

Under Section 8(6) of the DPDP Act 2023 and the DPDP Rules 2025, a personal data breach must be reported to the Data Protection Board and to every affected Data Principal — and unlike the GDPR, there is no "risk threshold": the duty applies to every personal data breach.
Failure to notify can attract a penalty of up to ₹200 crore, separate from the up-to-₹250 crore exposure for failing to maintain reasonable security safeguards in the first place.
What counts as a personal data breach?
The Act defines it broadly: any unauthorised processing of personal data, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access that compromises confidentiality, integrity or availability. A stolen laptop, a misdirected email export, a ransomware event and a misconfigured S3 bucket all qualify.
The clock: what the Rules require
- To affected Data Principals — without delay, in clear and plain language, describing the breach, its likely consequences, the mitigation under way, and safety measures they should take, with a contact for queries.
- To the Data Protection Board — an initial intimation without delay, followed by a detailed report within 72 hours (extendable only if the Board permits), covering facts, circumstances, causes, mitigation and remediation.
The playbook
Hour 0–4: Detect, contain, convene
Trigger the incident response plan. Contain the breach (revoke credentials, isolate systems), preserve forensic evidence, and convene the response team — security, legal/DPO, communications and leadership.
Hour 4–24: Scope and classify
Establish what personal data was affected, whose, how many Data Principals, and whether children's data or high-risk categories are involved. Document everything with timestamps — the Board will expect a coherent timeline.
Hour 24–48: Notify Data Principals and send initial intimation
Draft the plain-language notice and deliver it through the user account or registered contact channel. Send the Board its initial intimation. Do not wait for perfect information — the duty is "without delay".
Hour 48–72: File the detailed Board report
Submit the detailed report with root cause, impact assessment, mitigation and the remediation plan. If facts are still emerging, say so and update.
After: Remediate and evidence
Close the vulnerability, update the risk register, retrain staff if human error contributed, and preserve the full evidence trail — notices, reports, decisions and timestamps.
Prepare before it happens
A breach is the worst time to design a process. Suraksha, Data Adhikaar's breach-response agent, watches security signal feeds, opens incidents, classifies severity and drafts both the Board report and Data Principal notices — with a human approving every transmission. Benchmark your readiness with the free assessment.
Data Adhikaar Editorial Team
DPDPA Compliance Specialists, Qodequay Technologies
Get DPDPA-ready before the enforcement window closes.
Start with a free readiness assessment, or book a demo of the Data Adhikaar agent fabric.
Or call +91 98226 28174