How do I report a data breach to the Data Protection Board?
What the Data Protection Board expects, and in what order.
Two-stage reporting
The process is staged: a prompt initial intimation flags the incident, and a fuller detailed report follows within 72 hours once you've investigated. Don't wait for full forensics to send the initial intimation — partial, honest information on time beats a complete report that's late.
What the detailed report covers
Describe the nature and extent of the breach, when it occurred and when you detected it, the likely impact on individuals, the remediation and mitigation steps taken, and how and when you informed affected data principals. Attach your evidence and timeline.
Notify individuals too
Reporting to the Board doesn't discharge your duty to the people affected. Tell them in plain language what data was involved and what they can do — change passwords, watch for fraud — and keep proof you did so.
Frequently asked questions
What's in the initial intimation vs the detailed report?
The initial intimation is a prompt summary of the breach; the detailed report, within 72 hours, adds scope, root cause, remediation and proof of individual notifications.
What if I don't have all the facts yet?
Send the initial intimation on time with what you know. The detailed report follows as your investigation completes.
What's the penalty for not reporting?
Failure to notify a breach can attract penalties up to ₹200 crore, so timely reporting matters.
Draft your breach notification
Use the Breach Notification Generator to produce Board and data-principal notices fast.
Breach Notification Generator