What counts as a personal data breach under DPDP?
Not just hacks — the Act's definition is broader than you think.
The three-part test
A breach hits any of confidentiality (data exposed to the wrong people), integrity (data altered or corrupted), or availability (data lost or inaccessible). An accidental deletion with no backup is a breach just as much as a leak.
Everyday examples
A spreadsheet emailed to the wrong client, a shared drive set to 'anyone with the link', a stolen phone with unencrypted data, a former employee retaining access — all are breaches. The most common incidents are mundane mistakes, not movie-style intrusions.
Why the definition matters
Because the definition is broad, your detection and reporting processes must catch more than malware. Train staff to flag misdirected data and access mistakes, and treat them with the same 72-hour seriousness as a cyberattack.
Frequently asked questions
Is a misdirected email a data breach?
Yes. Accidental disclosure of personal data to the wrong recipient is a breach under the Act, even without malicious intent.
Does losing access to our own data count?
Yes. A loss of availability — for example ransomware or accidental deletion without backup — is a breach.
Do I report every minor breach?
The Act's breach-notification duty is broad; build a process to assess and report incidents rather than assuming small ones are exempt.
Check your breach readiness
Run the Breach Response Readiness check to see whether you'd detect and report incidents in time.
Breach Readiness Check