← Back to Knowledge Hub

A data breach is no longer just an IT problem in India β€” it's a reporting obligation with a clock on it and a fine attached. Under the DPDP Act, the moment you learn that personal data has been exposed, a sequence of legal duties starts running: tell the affected people, tell the Data Protection Board, and file a detailed report within 72 hours. Miss it, and the penalty for non-reporting alone can reach β‚Ή200 crore β€” separate from any fine for the weak security that let the breach happen.

Here's what counts as a breach, exactly who you must notify and when, how it interacts with CERT-In's separate six-hour rule, and the response plan every business should have ready before anything goes wrong.

Quick answer: Under the DPDP Act, every Data Fiduciary must, on becoming aware of a personal data breach, intimate the Data Protection Board and affected individuals without delay, and file a detailed report with the Board within 72 hours. The notice to individuals must explain, in plain language, what happened, what data was exposed, what they can do, and how to contact you. Failing to notify can cost up to β‚Ή200 crore; failing the underlying security safeguards, up to β‚Ή250 crore. This runs in parallel with CERT-In's six-hour cyber-incident rule.

What counts as a data breach?

A personal data breach is any unauthorised processing, accidental disclosure, acquisition, sharing, use, alteration, destruction, or loss of access to personal data that compromises its confidentiality, integrity, or availability. That's broad on purpose. It isn't only a hacker stealing a database β€” it includes an employee emailing a customer list to the wrong address, a misconfigured cloud bucket left public, a lost laptop, or ransomware locking you out of your own records. If personal data's security is compromised, the duty to notify is triggered.

Who you must notify, and when

On becoming aware of a breach, a Data Fiduciary has two notification duties:

  1. The affected Data Principals β€” intimate them without delay, individually, about the breach.
  2. The Data Protection Board β€” give an initial intimation without delay, followed by a detailed report within 72 hours (the Board may allow a longer period on request).

There's no severity threshold that lets you stay quiet β€” the obligation is built around prompt transparency, not internal judgment calls about whether a breach was "serious enough."

What the notice to individuals must say

The notice to affected people has to be genuinely useful, not legal boilerplate. In plain language, it must describe:

  • what happened β€” the nature and broad cause of the breach;
  • what data was exposed β€” the categories of personal data involved;
  • the likely consequences for the individual;
  • the protective steps they can take (for example, resetting passwords or watching for fraud); and
  • your contact details for questions and the safeguards you've put in place.

The detailed report to the Board goes further β€” timing, circumstances, mitigation taken, and remedial measures.

The DPDP clock vs CERT-In's six-hour rule

This is the part that catches people out. The DPDP obligation runs in parallel with CERT-In's existing 2022 direction, which requires reporting specified cyber incidents within six hours. The same incident may have to be reported to two regulators on two different clocks through two different channels β€” CERT-In within six hours, the Data Protection Board without delay with a 72-hour detailed report. Your incident-response plan needs both workflows wired in from the start, or you'll meet one deadline and blow the other.

The penalties

The numbers are large and they stack:

FailureMaximum penalty
Failure to notify a personal data breachβ‚Ή200 crore
Failure to implement reasonable security safeguardsβ‚Ή250 crore

A single incident can trigger both β€” the weak security that caused the breach, and the failure to report it properly β€” because penalties apply per contravention. The Board also weighs statutory factors (the nature and gravity of the breach, steps taken to mitigate, and so on) before fixing the actual amount, and it can publish the violation.

⚠️ The reputational hit often outlasts the fine. Indian data-breach costs already run into crores per incident before any regulatory penalty; the published-violation power adds lasting brand damage.

Your breach-response playbook

You cannot draft this during a live incident. Prepare it now:

  1. Detect and contain β€” monitoring that flags anomalous access, and a way to isolate affected systems fast.
  2. Assess β€” identify what data, whose data, how much, and the likely impact.
  3. Notify on parallel clocks β€” CERT-In within six hours; the Board without delay; the detailed report within 72 hours.
  4. Notify individuals β€” clear, plain-language notices with protective steps.
  5. Mitigate and remediate β€” close the hole, reset credentials, document everything.
  6. Review β€” post-incident analysis and a fix to prevent recurrence.

Run a tabletop drill against it at least once before May 2027, so the timeline is muscle memory, not a scramble.

Worked example: the first 72 hours

A health-tech app discovers at 9 a.m. on a Monday that a misconfigured server exposed 40,000 users' names, phone numbers, and appointment histories.

  • By 3 p.m. Monday (6 hours): file the cyber-incident report with CERT-In.
  • Without delay (same day): send an initial intimation to the Data Protection Board, and begin notifying the 40,000 affected users in plain language β€” what leaked, what to watch for, who to contact.
  • By Thursday 9 a.m. (72 hours): file the detailed report with the Board β€” cause, scope, mitigation, and remedial measures.
  • In parallel: contain the server, rotate credentials, and start the root-cause fix.

The company that has this written down executes calmly. The one that doesn't loses its first day arguing about who's responsible.

Common mistakes

  • Sitting on a breach to "investigate first." The duty is prompt notification, not a finished investigation.
  • Forgetting CERT-In. The six-hour cyber rule is separate from DPDP and runs faster.
  • Vague notices. Individuals need specific, actionable information, not legalese.
  • No written playbook. Drafting under pressure guarantees a missed clock.
  • Treating it as IT-only. Breach response is legal, comms, and engineering together.

Checklist

  1. Write a breach-response playbook covering both CERT-In and the Board.
  2. Define who declares a breach and who notifies whom.
  3. Pre-draft notice templates for individuals and the Board.
  4. Set up monitoring that detects anomalous access early.
  5. Map which systems hold personal data (so you can scope a breach fast).
  6. Run a tabletop drill before the May 2027 deadline.

Frequently asked questions

What is the breach notification timeline under the DPDP Act? Intimate the Board and affected individuals without delay, and file a detailed report with the Board within 72 hours.

What is the penalty for not reporting a data breach? Up to β‚Ή200 crore for failing to notify, and up to β‚Ή250 crore for failing the underlying security safeguards β€” per contravention.

How does DPDP interact with CERT-In's six-hour rule? They apply in parallel. The same incident may need a CERT-In report within six hours and a DPDP report to the Board within 72 hours, through different channels.

Do I have to tell affected users about every breach? Yes. The Act requires intimating affected Data Principals without delay, with plain-language details and protective steps.

Who must report a breach? Every Data Fiduciary β€” the business that determines the purpose and means of processing β€” even if a processor was handling the data.

This article is for legal awareness and education only and is not legal advice. Breach obligations and timelines may be refined by notification; confirm the current rules and consult a qualified professional when building your incident-response plan.