Skip to main content

The 3rd and main DPDP commencement date is computed as 13 May 2027, which is interpretation until officially confirmed.

Sources last verified on 23 September 2026. Methodology

A data breach just hit your organisation: the hour by hour response under DPDP

Breach response

By · Primary sources verified by dpdprules.orgPublished · Last reviewed 10 min read

What should my organisation do after a personal data breach?

The short answer

Once Rule 7 of the DPDP Rules 2025 is in force, 2 legal clocks start the moment your organisation becomes aware of a personal data breach. First, as a matter of practice rather than of Rule 7, contain the incident, record the exact awareness time and instruct your Data Processors, because section 8 keeps you responsible for their processing. Then run 2 duties in parallel, both without delay: intimate each affected Data Principal in plain language with 5 required contents, and send the Data Protection Board a description of the breach. Within 72 hours of awareness, file the detailed Board submission with its 6 required contents; a longer period needs the Board's permission on a written request. Afterwards, again as practice rather than as a requirement of Rule 7, verify the fix, preserve the record, and be ready for a possible Board inquiry. Rule 7 sits in the commencement group computed to 13 May 2027, interpretation until officially confirmed, and building the workflow before the duty begins is the practical move.

More answered questions →

Diagram: The breach response playbook, and the Rule 7 duties in it are not in force yet, as at 3 September 2026. The same diagram appears further down this article, where it is described in full.
Status as at 3 September 2026: the Rule 7 duties are not in force, because Rule 7 sits in the 18 month commencement group, computed 13 May 2027 and interpretation until officially confirmed.

It is 9:58 pm and your monitoring just confirmed it: someone accessed a database holding customer personal data. Once Rule 7 is in force, India's DPDP framework treats your organisation as aware of a personal data breach from this exact moment, and 2 legal clocks start running. Rule 7 is not in force yet: it commences on 13 May 2027, a date computed from the notification, so treat it as interpretation until officially confirmed. This article walks the response hour by hour, with the official source behind every required step.

Everything starts at awareness, not at certainty

Rule 7 of the DPDP Rules 2025 frames both breach duties around one trigger: on becoming aware. There is no materiality threshold in the rule's text and no waiting period to confirm the details. The single most valuable thing you can do in the first minutes is record the exact date and time of awareness in your incident log, because every deadline that follows is measured from it.

The 2 clocks of Rule 7, and neither of them is running yet. Read as at 3 September 2026 the diagram carries a NOT IN FORCE TODAY marker, with commencement computed to 13 May 2027 and labelled interpretation until officially confirmed. Both duties start at T+0, which is awareness and not confirmation of details. Track A, labelled Rule 7(1), intimates every affected person without delay with 5 required contents, in plain language, through her user account or a registered mode. Track B stage one, labelled Rule 7(2)(a), sends the Board a description of the nature, extent, timing, location and likely impact, also without delay. At T+72h, Rule 7(2)(b) is the Board's stage two submission, 6 required contents in 72 hours, and a longer period is possible only if the Board allows it on a request made in writing. A strip beneath gives the basis for the status: Rule 1(4), as corrected by corrigenda G.S.R. 892(E), reads 'Rules 3, 5 to 16, 22 and 23 shall come into force eighteen months after the date of publication in the Official Gazette', Rule 7 sits inside 5 to 16, and, labelled in the strip as this site's reading, section 8(6) is the Act duty behind Rule 7 with section 8 in the Act's 18 month group.

The first hour: contain and anchor

Before any notification, stop the bleeding. Isolate the affected systems, revoke exposed credentials, close the entry point, and preserve evidence while you do it. Assemble the response team in one room or one channel: an incident lead, security, engineering, legal, communications and support. Open a timestamped incident log that records events, circumstances and reasons as they become known; the 72 hour Board submission will ask for exactly those facts, so a disciplined log writes most of it for you.

One legal point matters immediately: if a Data Processor holds or touches the affected data, instruct it to contain on its side and report what it knows to you. Section 8 of the Act keeps the Data Fiduciary responsible for complying with the framework, including in respect of processing undertaken on its behalf by a Data Processor. The breach happening inside a vendor does not move the duty.

Duty one: tell each affected person, without delay

Rule 7(1) requires an intimation to each affected Data Principal, to the best of your knowledge, in a concise, clear and plain manner, through the person's user account or a registered mode of communication. The rule fixes 5 contents:

  • a description of the breach, including its nature, extent and the timing of its occurrence;
  • the consequences relevant to that person that are likely to arise;
  • the measures implemented and being implemented to mitigate risk;
  • the safety measures the person may take to protect their interests;
  • business contact information of a person able to respond to their queries.

Write it like a human being. The people receiving this message did nothing wrong, and the rule's plain manner requirement is on your side: no legal boilerplate, no burying the point. Log every send, with recipient, time and channel, because the Board submission must include a report on these intimations.

Duty two: tell the Board, twice

The Board intimation is staged, and the official text carries both clocks:

DPDP Rules 2025, r. 7 · Intimation of personal data breach · verbatim

"On becoming aware of any personal data breach, the Data Fiduciary shall intimate to the Board, — (a) without delay, a description of the breach, including its nature, extent, timing and location of occurrence and the likely impact; (b) within seventy-two hours of becoming aware of the breach, or within such longer period as the Board may allow on a request made in writing in this behalf …"

Rule 7(2), truncated before items (i) to (vi), which are restated below.

Stage one, Rule 7(2)(a), is a description, sent without delay on the facts you have. Do not hold it back for the full picture; stage two exists to update and complete it. Stage two, Rule 7(2)(b), due within 72 hours of awareness, carries 6 required contents: updated and detailed information on the description already sent; the broad facts related to the events, circumstances and reasons leading to the breach; measures implemented or proposed to mitigate risk; any findings regarding the person who caused the breach; remedial measures taken to prevent recurrence; and a report regarding the intimations given to affected Data Principals. If 72 hours is genuinely not enough, the only lawful route to more time is a request to the Board made in writing; send it before the deadline passes.

A practical note on where to send it: as of our last verification, the Board has not published a dedicated intimation channel in any primary source we track. What is official so far is that notification G.S.R. 844(E) establishes the Data Protection Board of India with its head office in the National Capital Region, and the Act has the Board function, as far as practicable, as a digital office. Watch the MeitY website for the channel; this site will add it, with its source, the day it is published.

After the deadline: what the Board can do

The intimation is not a formality that disappears into a mailbox. Under section 27(1)(a), the Board's powers switch on the moment it receives one:

DPDP Act 2023, s. 27 · Powers and functions of Board · verbatim

"on receipt of an intimation of personal data breach under sub-section (6) of section 8, to direct any urgent remedial or mitigation measures in the event of a personal data breach, and to inquire into such personal data breach and impose penalty as provided in this Act;"

Section 27(1)(a) of the DPDP Act 2023.

Read as at 3 September 2026, none of that is live either: clause (c) of the Act's commencement notification puts section 27, except clause (d) of sub section (1), and sections 28 to 34 in the same 18 month group as section 8, so the Board's power to act on an intimation, the section 33 power to impose any of the Schedule's amounts and the section 32 settlement track all begin when the duty does. Those powers are why phase 4 of a good response is unglamorous but essential: verify that the remedial measures actually closed the gap, run a post incident review, and preserve the incident log, both intimations and the send records in one place. The Schedule's numbers explain the stakes: failing reasonable security safeguards carries a cap of 250 crore rupees, and failing the breach notice duty carries 200 crore rupees. If proceedings do begin, the Act also has a settlement track: under section 32, the Board may accept a voluntary undertaking at any stage of a section 28 proceeding, and acceptance bars proceedings under the Act as regards the undertaking's contents, except where a term of the undertaking is not adhered to.

The 4 phases at a glance

The breach response playbook, and the Rule 7 duties in it are not in force yet. The diagram carries a NOT IN FORCE TODAY marker read as at 3 September 2026, with commencement computed to 13 May 2027 and labelled interpretation until officially confirmed, and each of the 4 phases is typed with what stands behind it. Phase 1, contain and anchor: record the awareness time, assemble the team, contain, open the log and instruct your Data Processors, labelled this site's recommended practice for the first hour. Phase 2, 2 duties at once: Track A to every affected person with 5 required contents and Track B to the Board with a description of the breach, labelled Rule 7(1) and Rule 7(2)(a), without delay. Phase 3, detailed submission: 6 required contents to the Board or a longer period if the Board allows it on a request made in writing, labelled Rule 7(2)(b), within 72 hours. Phase 4, stabilise: verify the fix, review and preserve the record for a possible Board inquiry under section 27(1)(a), labelled this site's recommended practice after the clock. A panel at the foot splits the basis in the rules' own words from this site's reading. The quoted half gives Rule 1(4), as corrected by corrigenda G.S.R. 892(E), as 'Rules 3, 5 to 16, 22 and 23 shall come into force eighteen months after the date of publication in the Official Gazette', then Rule 7(2) on the 2 Board stages and Rule 7(1) on the concise, clear and plain manner of the intimation. The reading half says that Rule 7 sits inside the range 5 to 16 so Rule 1(4) puts it in the 18 month group, that section 8(6) is the Act duty behind Rule 7 and section 8 is itself in the Act's own 18 month group, that 13 May 2027 is computed from the publication date printed on Gazette issue No. 760, and that phases 1 and 4 are this site's recommended practice and not requirements of Rule 7, which prescribes only the 2 intimations and their contents.

Prepare on a calm day

Every step above is easier if 4 things exist before any incident: named owners for each track with deputies, the 2 intimation drafts kept ready with your standing details, a current list of Data Processors with breach contacts, and 1 tabletop rehearsal from awareness to the 72 hour submission. The downloadable starting templates cover both intimations.

When this becomes law, and what to do now

Read as at 3 September 2026, Rule 7 is not in force. Rule 1(4) puts "Rules 3, 5 to 16, 22 and 23" into force "eighteen months after the date of publication in the Official Gazette", with those closing words as corrigenda G.S.R. 892(E) corrected them, and Rule 7 sits inside 5 to 16. Computed from the publication date of 13 November 2025, the group is due on 13 May 2027, and that calendar date is interpretation until officially confirmed. Section 8(6) is the Act duty behind Rule 7, and section 8 is itself in the Act's own 18 month group, so on this site's reading the Act duty and the rule that gives it form and manner begin together. The clocks in Rule 7 are short and start on awareness, which makes building the workflow before the duty begins the entire point.

One boundary is worth stating plainly, because both diagrams on this page now draw it: Rule 7 prescribes only the 2 intimations and their contents. Nothing in it requires an incident log, a named response team, a post incident review or a rehearsal. Logs of a different kind are required elsewhere: Rule 6(1)(c) requires visibility on the accessing of personal data through appropriate logs, monitoring and review, and Rule 6(1)(e) requires such logs and personal data to be retained for one year unless compliance with any law for the time being in force requires otherwise. Neither of those is the incident log described above, and both sit in the same 18 month group as Rule 7, so they are no more in force today than it is. Phases 1 and 4 of the playbook are therefore this site's recommended practice rather than a requirement of Rule 7, and the diagram labels them that way.

A Hindi explainer of the same 2 clocks, quoting Rule 7 from the Hindi Gazette rather than translating the English, is at डेटा ब्रीच होने पर क्या करें.

The interactive version of everything in this article is the data breach response playbook: enter your awareness time and it runs the live 72 hour countdown, lays out the phases with parallel tracks, tracks your progress in your browser, previews and downloads sample intimations, and exports the whole plan to Excel.

Rule 7, official text with sources →Section 8, official text with sources →Downloadable intimation templates →

Data breachRule 7Incident responsePlaybookBoard intimation

Share this: