top of page

How to Comply with Personal Data Breach Notification Requirements Under the DPDP Act and Rules in India

  • Writer: Kaustav Chowdhury
    Kaustav Chowdhury
  • 2 hours ago
  • 9 min read

Introduction

India's data protection landscape has undergone a fundamental transformation with the enactment of the Digital Personal Data Protection Act, 2023 (DPDP Act) and the notification of the DPDP Rules, 2025 on November 13, 2025. Among the most operationally significant obligations introduced by this framework is the requirement to notify personal data breaches to both the Data Protection Board of India and affected Data Principals. With the 18-month enforcement clock ticking towards May 2027, organisations acting as Data Fiduciaries must urgently build robust breach notification mechanisms. This article provides a detailed, practice-oriented guide to complying with personal data breach notification requirements, covering statutory timelines, notification content, the interplay with CERT-In reporting obligations, penalties for non-compliance, and best practices for breach response planning.



What Constitutes a Personal Data Breach Under the DPDP Act

Section 2(r) of the DPDP Act defines a "personal data breach" as any unauthorised or accidental processing, or disclosure, of personal data that compromises its confidentiality, integrity, or availability. This definition is intentionally broad and captures a wide spectrum of incidents, including:

  • Unauthorised access to databases containing personal data (for example, through cyberattacks, credential theft, or insider threats);

  • Accidental exposure of personal data due to misconfigured cloud storage, erroneous email transmissions, or software vulnerabilities;

  • Ransomware attacks that render personal data unavailable, even if no exfiltration occurs;

  • Loss or theft of physical devices (laptops, hard drives, USB drives) containing unencrypted personal data.

Notably, the definition does not require actual harm to Data Principals for the breach to be reportable. The mere compromise of confidentiality, integrity, or availability triggers the notification obligation. Organisations must therefore adopt a low threshold for classifying incidents as personal data breaches.



Legislative Framework: DPDP Act, DPDP Rules 2025, and CERT-In Directions

The breach notification regime in India operates across three interconnected legal instruments:

  • Section 8(6) of the DPDP Act, 2023 mandates that every Data Fiduciary must notify both the Data Protection Board of India and each affected Data Principal in the event of a personal data breach.

  • Rule 7 of the DPDP Rules, 2025 operationalises Section 8(6) by specifying the procedural requirements, timelines, and content for breach notifications. The Rules were notified on November 13, 2025, with an 18-month enforcement window ending in May 2027.

  • CERT-In Directions dated April 28, 2022 (effective June 27, 2022), issued under Section 70B(6) of the Information Technology Act, 2000, impose a separate 6-hour reporting obligation for cybersecurity incidents, including data breaches, to the Indian Computer Emergency Response Team.

These obligations are complementary and operate in parallel. A single data breach incident may require notifications to CERT-In (within 6 hours), to the Data Protection Board (initial alert without delay, detailed report within 72 hours), and to affected Data Principals (within 72 hours). For a detailed analysis of the Data Protection Board's enforcement architecture, see our earlier article on the subject.



Notification to the Data Protection Board of India

Rule 7, read with Section 8(6), establishes a two-stage notification process for reporting breaches to the Data Protection Board:

Stage 1: Initial Alert (Without Delay)

Upon becoming aware of a personal data breach, the Data Fiduciary must dispatch an initial notification to the Board "without delay." While the Rules do not prescribe a fixed number of hours for this initial alert, the phrase "without delay" is understood to mean as soon as practicable after the breach is confirmed or reasonably suspected. This initial alert need not contain exhaustive details but should inform the Board that a breach has occurred and that a detailed report will follow.

Stage 2: Detailed Report (Within 72 Hours)

Within 72 hours of becoming aware of the breach, the Data Fiduciary must submit a detailed report to the Board. This report must include the following information:

  • The nature and extent of the breach;

  • The timing and location of the breach (when it was detected and which systems were affected);

  • The likely impact of the breach on affected Data Principals;

  • Categories and approximate number of Data Principals affected;

  • Measures taken or proposed to be taken to address the breach and mitigate its effects.



Notification to Affected Data Principals

In addition to notifying the Board, Section 8(6) requires the Data Fiduciary to inform each affected Data Principal about the breach. Under Rule 7, this notification must be dispatched after the Board notification has been sent and within 72 hours of becoming aware of the breach.

Content Requirements

The notification to Data Principals must contain:

  • A plain-language description of the breach and the circumstances surrounding it;

  • A description of the categories of personal data that were exposed or compromised;

  • Protective measures that Data Principals can take to safeguard their interests (such as changing passwords, monitoring financial accounts, or enabling multi-factor authentication);

  • The Data Fiduciary's contact details for further enquiries.

Manner and Language of Notification

The notification must be communicated in a concise, clear, and plain manner. It must be delivered through the Data Principal's user account on the Data Fiduciary's platform, or through a registered mode of communication (such as email or SMS). Crucially, if the Data Principal has indicated a preferred Indian language, the notification must be provided in that language. This multilingual requirement necessitates advance planning: organisations must maintain records of language preferences and have translation capabilities readily available.



Internal Breach Assessment and Documentation

Before external notifications are dispatched, a structured internal assessment is essential. Section 8(5) of the DPDP Act requires every Data Fiduciary to implement reasonable security safeguards to prevent personal data breaches. Rule 6 elaborates on what constitutes reasonable security safeguards, which include:

  • Encryption and tokenisation of personal data;

  • Implementation of access controls to restrict data access on a need-to-know basis;

  • Maintaining logs and audit trails for monitoring and forensic analysis;

  • Maintaining data backups to ensure availability;

  • Requiring Data Processors to implement equivalent safeguards through contractual obligations;

  • Implementing technical and organisational measures proportionate to the nature of data processed.

The reasonableness of these safeguards is assessed against recognised standards such as ISO/IEC 27001, the NIST Cybersecurity Framework, CERT-In Directions, and applicable sectoral norms. In the event of a breach, whether the Data Fiduciary had implemented these safeguards in advance will be a critical factor in determining liability and the quantum of penalties. Organisations should therefore ensure that SaaS and vendor agreements incorporate robust data protection clauses. For guidance on structuring such agreements, see our article on drafting and negotiating SaaS agreements under Indian law.

Upon detecting a potential breach, the internal response team should immediately document: the time of detection, the systems and data categories affected, the suspected cause, containment actions taken, and the individuals involved in the response. This documentation serves dual purposes: it populates the Board notification and creates an evidentiary record that may be critical during regulatory proceedings.



Role of the Data Protection Officer

Under Section 10 of the DPDP Act, every Significant Data Fiduciary (SDF) is required to appoint a Data Protection Officer (DPO) who is based in India. The DPO serves as the primary point of contact for the Data Protection Board and is responsible for overseeing the organisation's compliance with the Act, including the breach notification process.

The obligations specific to Significant Data Fiduciaries extend beyond appointing a DPO. SDFs must also:

  • Appoint an independent data auditor to conduct periodic audits of data processing activities;

  • Conduct periodic Data Protection Impact Assessments (DPIAs) to evaluate risks associated with processing activities;

  • Submit periodic audit reports and DPIA findings to the Board.

Even organisations that are not classified as SDFs should consider designating a senior individual to coordinate breach response efforts. Having a clearly identified breach response lead streamlines decision-making during the critical early hours of a breach when timelines are tight. Organisations with established vigil mechanisms and whistleblower policies should integrate data breach escalation channels into those existing frameworks.



Interaction with CERT-In 6-Hour Reporting Obligations

The CERT-In Directions dated April 28, 2022, issued under Section 70B(6) of the Information Technology Act, 2000, require all service providers, intermediaries, data centres, body corporates, and government organisations to report cybersecurity incidents to CERT-In within 6 hours of noticing such incidents, or being notified about them. Data breaches involving personal data fall squarely within the categories of reportable incidents under these Directions.

The CERT-In and DPDP Act obligations are complementary and must be discharged independently. This means that a single personal data breach incident may require:

  • Reporting to CERT-In within 6 hours;

  • An initial alert to the Data Protection Board without delay;

  • A detailed report to the Board within 72 hours;

  • Notification to affected Data Principals within 72 hours.

Failure to comply with CERT-In reporting requirements carries separate penalties under Section 70B(7) of the IT Act: imprisonment of up to 1 year, a fine of up to Rs 1 lakh, or both. Organisations must therefore maintain parallel notification workflows and ensure that their incident response plans address both reporting streams simultaneously.



Penalties for Non-Compliance

The DPDP Act prescribes substantial financial penalties for breach-related non-compliance:

  • Failure to notify a personal data breach under Section 8(6): penalty of up to Rs 200 crore;

  • Failure to implement reasonable security safeguards under Section 8(5): penalty of up to Rs 250 crore.

Under Section 33, the Data Protection Board will determine the penalty quantum by considering several factors: the nature, gravity, and duration of the breach; the type and sensitivity of personal data affected; the repetitive nature of the default; whether the Data Fiduciary took remedial measures; the impact on Data Principals; and any gain or loss avoided by the non-compliance. Additionally, the Board has the power to enhance the penalty by up to twice the standard quantum in appropriate cases.

It is important to note that penalties under the DPDP Act are in addition to any penalties imposed under the IT Act for failure to report to CERT-In. Organisations therefore face cumulative financial and legal exposure from a single breach event if they fail to comply with both notification frameworks.



Best Practices for Breach Response Planning

Given the compressed timelines and the severity of penalties, proactive breach response planning is not optional. Organisations should consider the following best practices:

  • Develop a comprehensive Breach Response Plan (BRP) that maps out roles, responsibilities, escalation chains, and communication templates for each stage of the notification process.

  • Conduct periodic tabletop exercises simulating breach scenarios to test the organisation's response capabilities and identify procedural gaps.

  • Pre-draft notification templates for both Board notifications and Data Principal communications. Pre-drafted templates in multiple Indian languages will help meet the multilingual notification requirement without delay.

  • Integrate CERT-In and DPDP notification workflows into a single incident response process to ensure parallel compliance without duplicating effort or introducing delays.

  • Maintain a data inventory that maps personal data categories to storage locations, processing activities, and Data Processors. This enables rapid identification of affected data and Data Principals during a breach.

  • Engage external legal counsel and forensic investigators in advance through retainer arrangements so that they can be mobilised immediately when a breach occurs.

  • Ensure contractual obligations on Data Processors include immediate breach notification to the Data Fiduciary and cooperation with the investigation, so that the Data Fiduciary can meet its own reporting timelines.



Compliance Checklist: Breach Notification Action Items

Organisations should use the following checklist to assess their readiness for personal data breach notification compliance:

  • A documented Breach Response Plan has been approved by senior management and is accessible to all relevant personnel.

  • An internal breach response team has been constituted with defined roles and an identified lead (or DPO, in the case of Significant Data Fiduciaries).

  • Notification templates for the Data Protection Board (initial alert and detailed report) have been prepared and reviewed by legal counsel.

  • Notification templates for Data Principals have been prepared in plain language and in relevant Indian languages based on known user preferences.

  • CERT-In reporting procedures and contact details have been documented, and a 6-hour reporting workflow has been tested.

  • Data Processor contracts include breach notification clauses requiring immediate notification to the Data Fiduciary and cooperation with investigations.

  • Reasonable security safeguards (encryption, access controls, logging, backups) have been implemented and are aligned with ISO/IEC 27001, NIST CSF, or equivalent standards.

  • Tabletop exercises simulating a breach scenario have been conducted at least once, and findings have been incorporated into the BRP.

  • A comprehensive data inventory mapping personal data to storage, systems, and Data Processors is maintained and regularly updated.

  • External legal counsel and forensic investigators are identified and engaged (or on retainer) for immediate mobilisation.



Conclusion

Personal data breach notification is one of the most time-sensitive and operationally demanding obligations under the DPDP Act, 2023 and the DPDP Rules, 2025. The requirement to notify the Data Protection Board without delay, submit a detailed report within 72 hours, and simultaneously inform affected Data Principals in their preferred language places significant demands on an organisation's incident response capabilities. When combined with the CERT-In 6-hour reporting obligation under the IT Act, the compliance burden on organisations that process personal data in India is substantial.

However, with penalties reaching up to Rs 250 crore for security safeguard failures and Rs 200 crore for notification failures, and with the Board empowered to enhance penalties by up to twice the standard quantum, the cost of non-compliance far exceeds the investment required to build a robust breach response framework. Organisations should treat the enforcement window ending in May 2027 as a firm deadline and begin implementing their breach notification compliance programmes without further delay. The key to effective compliance lies in advance preparation: pre-drafted templates, tested response plans, integrated notification workflows, and a clearly defined chain of command that can be activated the moment a breach is detected.


Comments


bottom of page