What do I do in the first 72 hours of a data breach under DPDP?
A clear sequence for the worst 72 hours — before they happen.
Hours 0-6: contain and convene
Stop the bleeding — isolate affected systems, revoke compromised credentials — and convene your response team. Start a written timeline immediately; you'll need it for the Board report. Remember CERT-In's separate cyber-incident reporting can run in parallel on a much shorter clock.
Within 72 hours: notify and report
Send an initial intimation to the Board promptly, then a detailed report within 72 hours covering the nature and extent of the breach, timing, likely impact, root cause, and remediation. Notify affected individuals with what happened, what data was involved, and the steps they can take to protect themselves.
After: fix and document
Close the root cause, update controls, and keep evidence of every notification. Organisations that can show reasonable safeguards were in place and that they responded promptly are in a far better position than those who can't.
Frequently asked questions
When does the 72-hour clock start?
From when you become aware of the breach. It runs continuously, including weekends and holidays.
Do I notify the Board or the individuals first?
Both are required. Send an initial intimation to the Board without delay and notify affected individuals; a detailed report to the Board follows within 72 hours.
Does CERT-In reporting still apply?
Yes. CERT-In's cyber-incident reporting can run in parallel on a shorter timeline, so a single event may trigger multiple obligations.
Build your breach playbook
Use the Breach Response Workflow to set roles, timelines and templates before an incident hits.
Breach Response Workflow