How to handle a data breach under the DPDP Act: a step-by-step response guide
When a breach hits, you have hours — not days — to act. Here is the DPDP breach response sequence every organisation needs to have rehearsed before it needs it.
What counts as a personal data breach under the DPDP Act?
A personal data breach is any event that results in the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. This includes: ransomware attacks that encrypt and exfiltrate customer data; misconfigured cloud storage that exposes records publicly; employee laptops with unencrypted customer data that are stolen or lost; insider theft of data; and third-party vendor breaches where your customer data was also affected. A breach does not have to be malicious — negligent loss of data counts just as much.
What must you do in the first hours after discovering a DPDP data breach?
The moment a breach is suspected, activate your incident response plan. Contain the immediate threat: isolate affected systems, revoke compromised credentials, disable vulnerable entry points. Preserve forensic evidence — do not wipe affected systems before you understand what happened. Assemble your incident response team: IT security, legal, senior management, and HR if employee data is involved. Within the first few hours, determine: Is this actually a breach? What data was affected? How many individuals are affected? Is the breach ongoing or contained?
How do you notify the Data Protection Board of India after a data breach?
Once you confirm a breach has occurred, you must notify the Data Protection Board within the prescribed timeline. Your notification should cover: the nature of the breach; the categories and approximate volume of personal data affected; the likely consequences for data principals; the measures taken or proposed to address the breach; contact details for your data protection point of contact. Even if you do not have full information, file an initial notification within the deadline and update it as you learn more. A late notification will be harder to defend than an early one that was updated.
When and how must you notify individuals after a personal data breach?
Where a breach is likely to adversely affect data principals — for example, where financial data or sensitive personal data was exposed — you must notify them individually. The notification should be in plain language, explain what happened, what data was involved, what risks they face, and what steps they should take (change passwords, monitor bank statements, freeze credit, etc.). Do not be vague or minimise the risk — individuals need accurate information to protect themselves.
What investigation and remediation steps does DPDP require after a breach?
Parallel to notification, conduct a thorough investigation: identify the root cause, the attack vector, the scope of data exposed, and any systems that remain vulnerable. Document everything — regulators will want to see your investigation record. Remediate the vulnerability. If a vendor was involved, trigger your DPA's breach notification and audit provisions. Conduct a post-incident review to identify systemic failures and update your controls accordingly.
How do you make your organisation breach-ready before a DPDP incident occurs?
The worst time to design your breach response is during a breach. Before May 2027, every organisation should have: a documented incident response plan with clear ownership and escalation paths; detection capability (SIEM, log monitoring, or at minimum alerting from your security tools); a breach register for logging incidents that may or may not meet the notification threshold; notification templates for the Board and for individuals; and at least one tabletop exercise where the leadership team walks through a simulated breach scenario.
Frequently asked questions
Do we need to notify for every security incident, or only major breaches?
Not every incident requires notification. A minor internal security event with no personal data exposure — for example, a failed phishing attempt with no data accessed — does not trigger notification. You must notify when personal data has actually been accessed, altered, or lost, and when that event is likely to result in risk to the rights and freedoms of individuals. Document all incidents in a breach register even if they do not reach the notification threshold, as this demonstrates diligent monitoring to regulators.
What if the breach was at a vendor, not in our own systems?
If your vendor has a breach that involves your customers' personal data, that is your breach for DPDP notification purposes — you are the Data Fiduciary. Your DPA with the vendor should require them to notify you immediately when they discover a breach. Once you are notified, your clock starts for Board notification and individual notification. This is why breach notification clauses in your DPAs are non-negotiable.
How long do we have to notify affected individuals?
The DPDP Act requires notification 'in the prescribed manner', and the timeline for individual notification will be specified in rules. The Act does not specify an explicit 24/48/72 hour window for individual notification the way GDPR does for Board notification, but the intent is prompt notification. Plan for individual notification as soon as you have enough information to communicate meaningfully — do not wait for the investigation to be complete if data principals are at risk of harm in the meantime.
Test your breach response readiness
Niti Bharat's Breach Response Tabletop Exercise Kit walks your leadership team through a simulated breach scenario — testing your notification process, DPA chain, and communication plan before a real incident.
Get the Breach Response Kit