What do I do in the first 72 hours of a data breach under DPDP?

What do I do in the first 72 hours of a data breach under DPDP?
Breach

What do I do in the first 72 hours of a data breach under DPDP?

A clear sequence for the worst 72 hours — before they happen.

Quick Answer: When you become aware of a personal data breach under DPDP, act immediately: contain and investigate, assess what data and how many people are affected, send an initial intimation to the Data Protection Board without delay, notify affected data principals with plain-language guidance, and file a detailed report to the Board within 72 hours. The clock runs continuously, including nights and weekends, so the time to build this plan is now.

Hours 0-6: contain and convene

Stop the bleeding — isolate affected systems, revoke compromised credentials — and convene your response team. Start a written timeline immediately; you'll need it for the Board report. Remember CERT-In's separate cyber-incident reporting can run in parallel on a much shorter clock.

Within 72 hours: notify and report

Send an initial intimation to the Board promptly, then a detailed report within 72 hours covering the nature and extent of the breach, timing, likely impact, root cause, and remediation. Notify affected individuals with what happened, what data was involved, and the steps they can take to protect themselves.

After: fix and document

Close the root cause, update controls, and keep evidence of every notification. Organisations that can show reasonable safeguards were in place and that they responded promptly are in a far better position than those who can't.

Frequently asked questions

When does the 72-hour clock start?

From when you become aware of the breach. It runs continuously, including weekends and holidays.

Do I notify the Board or the individuals first?

Both are required. Send an initial intimation to the Board without delay and notify affected individuals; a detailed report to the Board follows within 72 hours.

Does CERT-In reporting still apply?

Yes. CERT-In's cyber-incident reporting can run in parallel on a shorter timeline, so a single event may trigger multiple obligations.

Build your breach playbook

Use the Breach Response Workflow to set roles, timelines and templates before an incident hits.

Breach Response Workflow
Previous Post Next Post

Get Free DPDP Checklist