How to handle a personal data breach under DPDP — a step-by-step guide
When a data breach happens, every minute counts. Here is exactly what to do — from detection to Board notification — under the DPDP Act.
What counts as a personal data breach under DPDP?
A personal data breach includes any unauthorised access, disclosure, alteration, or destruction of personal data — as well as accidental loss. Examples: a ransomware attack encrypting your customer database; a misconfigured S3 bucket exposing user records; an employee emailing customer data to the wrong recipient; a vendor's system being breached, exposing data you shared with them; or a laptop containing customer data being stolen. Any of these triggers your breach response obligations under the Act.
What are the first steps after discovering a breach?
Immediately on discovery: contain the breach to stop further exposure (isolate compromised systems, revoke credentials, block malicious access); preserve evidence (logs, access records) for the forensic investigation; assess the scope (what data, how many individuals, what risk of harm); and start the clock — your notification window runs from the moment of discovery, not from when your investigation concludes. Assemble your incident response team: IT/security, legal, privacy/DPO, communications, and senior management.
What must a Data Protection Board notification contain?
The Board notification must include: the nature of the breach (what happened); the categories of personal data affected; an estimate of the number of data principals affected; the likely consequences of the breach; the measures taken or proposed to address it; and the contact details of your DPO or privacy contact. You may notify in phases — an initial notification within 72 hours (working assumption from draft Rules) and a more complete follow-up as facts emerge. Do not delay the initial notification while waiting for a perfect investigation report.
Must you notify affected data principals of a breach?
Yes — data principals must be notified when the breach is likely to cause harm to them. The notification must be: clear and plain-language (not legal boilerplate); prompt; describe what data was affected and what risk it poses; and explain what steps the individual should take to protect themselves (change passwords, monitor bank accounts, freeze credit). Send notification directly to each affected individual by email, SMS, or in-app notification — not just a buried website notice.
How does CERT-In's 6-hour incident report interact with DPDP?
CERT-In's Cyber Security Directions (2022) require organisations to report a broad range of cybersecurity incidents to CERT-In within 6 hours of knowledge. This is separate from and runs in parallel to your DPDP Board notification. For a breach that is both a cybersecurity incident and a personal data breach — most serious breaches will be both — you need to notify CERT-In within 6 hours AND notify the DPDP Board within 72 hours (draft Rules assumption). Run both notifications simultaneously. Sector regulators (RBI, SEBI, IRDAI) have their own notification requirements on top of these.
What should your incident response runbook cover?
A DPDP incident response runbook should specify: who is in the incident response team and their roles; how incidents are detected and escalated; the 6-hour CERT-In and 72-hour Board notification timelines and who is responsible for each; the breach notification template for data principals; the communication tree for senior management and Board of Directors; the process for engaging external forensic support if needed; and post-incident review procedures. Test the runbook with a tabletop exercise at least annually before an incident occurs.
Frequently asked questions
If a vendor (Data Processor) is breached, who notifies the Board?
The Data Fiduciary — your organisation — is responsible for notifying the Data Protection Board. Your DPA with the vendor should require the vendor to notify you immediately (within 24–48 hours is the recommended DPA provision) so that your notification window to the Board starts from when you learn of the breach, not from when the vendor first discovered it. Enforce this clause — a vendor that delays notifying you can put you in breach of your own notification obligation.
Does every breach require notification to the Board?
The Act requires notification when a breach 'is likely to harm' the data principal. A breach of genuinely anonymised data (where re-identification is not possible) would not trigger notification. A breach of personal data where there is no realistic risk of harm — for example, a technical system error that briefly exposed data internally, immediately contained, with no evidence of external access — may fall below the notification threshold. However, when in doubt, notify — the risk of under-reporting is greater than the administrative burden of an unnecessary notification.
What happens if you miss the DPDP breach notification deadline?
Failure to notify the Board of a breach is an independent violation of the Act and carries a financial penalty. The Act sets a penalty ceiling of ₹200 crore for a single breach-of-obligations incident. Proactive, timely notification — even if your initial notification is incomplete — is treated much more favourably by regulators than late discovery of a covered-up breach. Build notification timeliness into your incident response culture, not as a compliance afterthought.
Build your breach response capability now
Niti Bharat's Breach Response Tabletop Exercise Kit tests your team's readiness with realistic DPDP scenarios — notification timelines, regulator templates, and incident communications.
Get the Breach Response Kit