A data breach just hit your organisation: the hour by hour response under DPDP
By dpdprules.org editorial team · Reviewed by dpdprules.org source verificationPublished · Last reviewed 6 min read
The short answer
The moment your organisation becomes aware of a personal data breach, two legal clocks start under Rule 7 of the DPDP Rules 2025. First, contain the incident, record the exact awareness time and instruct your Data Processors, because section 8 keeps you responsible for their processing. Then run two duties in parallel, both without delay: intimate each affected Data Principal in plain language with five required contents, and send the Data Protection Board a description of the breach. Within seventy two hours of awareness, file the detailed Board submission with its six required contents; a longer period needs the Board's permission on a written request. Afterwards, verify the fix, preserve the record, and be ready for a possible Board inquiry. Rule 7 sits in the commencement group computed to 13 May 2027, interpretation until officially confirmed, and building the workflow before the duty begins is the practical move.
It is 9:58 pm and your monitoring just confirmed it: someone accessed a database holding customer personal data. From this exact moment, India's DPDP framework treats your organisation as aware of a personal data breach, and two legal clocks are already running. This article walks the response hour by hour, with the official source behind every required step.
Everything starts at awareness, not at certainty
Rule 7 of the DPDP Rules 2025 frames both breach duties around one trigger: on becoming aware. There is no materiality threshold in the rule's text and no waiting period to confirm the details. The single most valuable thing you can do in the first minutes is record the exact date and time of awareness in your incident log, because every deadline that follows is measured from it.
The two clocks of Rule 7: from awareness at T+0, Track A intimates every affected person and Track B sends the Board a description, both without delay; the detailed Board submission with six required contents is due at T+72 hours, extendable only on a written request.
The first hour: contain and anchor
Before any notification, stop the bleeding. Isolate the affected systems, revoke exposed credentials, close the entry point, and preserve evidence while you do it. Assemble the response team in one room or one channel: an incident lead, security, engineering, legal, communications and support. Open a timestamped incident log that records events, circumstances and reasons as they become known; the seventy two hour Board submission will ask for exactly those facts, so a disciplined log writes most of it for you.
One legal point matters immediately: if a Data Processor holds or touches the affected data, instruct it to contain on its side and report what it knows to you. Section 8 of the Act keeps the Data Fiduciary responsible for complying with the framework, including in respect of processing undertaken on its behalf by a Data Processor. The breach happening inside a vendor does not move the duty.
Duty one: tell each affected person, without delay
Rule 7(1) requires an intimation to each affected Data Principal, to the best of your knowledge, in a concise, clear and plain manner, through the person's user account or a registered mode of communication. The rule fixes five contents:
- a description of the breach, including its nature, extent and the timing of its occurrence;
- the consequences relevant to that person that are likely to arise;
- the measures implemented and being implemented to mitigate risk;
- the safety measures the person may take to protect their interests;
- business contact information of a person able to respond to their queries.
Write it like a human being. The people receiving this message did nothing wrong, and the rule's plain manner requirement is on your side: no legal boilerplate, no burying the point. Log every send, with recipient, time and channel, because the Board submission must include a report on these intimations.
Duty two: tell the Board, twice
The Board intimation is staged, and the official text carries both clocks:
"On becoming aware of any personal data breach, the Data Fiduciary shall intimate to the Board, — (a) without delay, a description of the breach, including its nature, extent, timing and location of occurrence and the likely impact; (b) within seventy-two hours of becoming aware of the breach, or within such longer period as the Board may allow on a request made in writing in this behalf …"
Rule 7(2), truncated before items (i) to (vi), which are restated below.
Stage one is a description, sent without delay on the facts you have. Do not hold it back for the full picture; stage two exists to update and complete it. Stage two, due within seventy two hours of awareness, carries six required contents: updated and detailed information on the description already sent; the broad facts related to the events, circumstances and reasons leading to the breach; measures implemented or proposed to mitigate risk; any findings regarding the person who caused the breach; remedial measures taken to prevent recurrence; and a report regarding the intimations given to affected Data Principals. If seventy two hours is genuinely not enough, the only lawful route to more time is a request to the Board made in writing; send it before the deadline passes.
A practical note on where to send it: as of our last verification, the Board has not published a dedicated intimation channel in any primary source we track. What is official so far is that notification G.S.R. 844(E) establishes the Data Protection Board of India with its head office in the National Capital Region, and the Act has the Board function, as far as practicable, as a digital office. Watch the MeitY website for the channel; this site will add it, with its source, the day it is published.
After the deadline: what the Board can do
The intimation is not a formality that disappears into a mailbox. Under section 27(1)(a), the Board's powers switch on the moment it receives one:
"on receipt of an intimation of personal data breach under sub-section (6) of section 8, to direct any urgent remedial or mitigation measures in the event of a personal data breach, and to inquire into such personal data breach and impose penalty as provided in this Act;"
Section 27(1)(a) of the DPDP Act 2023.
That is why phase four of a good response is unglamorous but essential: verify that the remedial measures actually closed the gap, run a post incident review, and preserve the incident log, both intimations and the send records in one place. The Schedule's numbers explain the stakes: failing reasonable security safeguards carries a cap of two hundred and fifty crore rupees, and failing the breach notice duty carries two hundred crore rupees. If proceedings do begin, the Act also has a settlement track: under section 32, the Board may accept a voluntary undertaking at any stage of a section 28 proceeding, and acceptance bars further proceedings on the undertaking's contents.
The four phases at a glance
The playbook phases: contain and anchor the clock in the first hour; run the two intimation duties in parallel without delay; file the detailed Board submission within seventy two hours; then stabilise, review and preserve the record.
Prepare on a calm day
Every step above is easier if four things exist before any incident: named owners for each track with deputies, the two intimation drafts kept ready with your standing details, a current list of Data Processors with breach contacts, and one tabletop rehearsal from awareness to the seventy two hour submission. The downloadable starting templates cover both intimations.
When this becomes law, and what to do now
Rule 7 sits in the eighteen month commencement group; computed from the publication date of 13 November 2025, the group is due on 13 May 2027, and that calendar date is interpretation until officially confirmed. The clocks in Rule 7 are short and start on awareness, which makes building the workflow before the duty begins the entire point.
The interactive version of everything in this article is the data breach response playbook: enter your awareness time and it runs the live seventy two hour countdown, lays out the phases with parallel tracks, tracks your progress in your browser, previews and downloads sample intimations, and exports the whole plan to Excel.
Rule 7, official text with sources →Section 8, official text with sources →Downloadable intimation templates →
Sources cited on this page
- [1]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 7, p. 26. Published 13 November 2025. Official source ↗ · Official requirement · Verified 20 August 2026Rule 7(2), truncated before items (i) to (vi), which are restated in the article.
- [2]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 7, (1), p. 26. Published 13 November 2025. Official source ↗ · Official requirement · Verified 20 August 2026Rule 7(1) requires intimation to each affected Data Principal, to the best of the Data Fiduciary's knowledge, in a concise, clear and plain manner, through her user account or a registered mode of communication, covering the five contents restated in the article.
- [3]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 8, p. 7. Published 11 August 2023. Official source ↗ · Official requirement · Verified 20 August 2026Section 8 makes the Data Fiduciary responsible for complying with the Act and the rules, including in respect of any processing undertaken on its behalf by a Data Processor, requires reasonable security safeguards under section 8(5), and requires breach intimation under section 8(6). Section 8 begins on Gazette page 7 and concludes on page 8.
- [4]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 27, p. 14. Published 11 August 2023. Official source ↗ · Official requirement · Verified 20 August 2026Section 27(1)(a), the Board's power on receiving a breach intimation.
- [5]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 32, p. 16. Published 11 August 2023. Official source ↗ · Official requirement · Verified 20 August 2026Section 32 lets the Board accept a voluntary undertaking at any stage of a proceeding under section 28; acceptance bars proceedings on the contents of the undertaking, and breaking a term revives the penalty route.
- [6]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), The Schedule Schedule, p. 21. Published 11 August 2023. Official source ↗ · Official requirement · Verified 20 August 2026The Schedule caps the penalty for failing reasonable security safeguards under section 8(5) at two hundred and fifty crore rupees and for failing breach notice under section 8(6) at two hundred crore rupees.
- [7]Notification establishing the Data Protection Board of India (G.S.R. 844(E)), p. 2. Published 13 November 2025. Official source ↗ · Plain English explanation · Verified 20 August 2026Notification G.S.R. 844(E) establishes the Data Protection Board of India with its head office in the National Capital Region of India. As of the verification date, no dedicated breach intimation channel of the Board has been published in the primary sources tracked here.
- [8]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 28, (1), p. 14. Published 11 August 2023. Official source ↗ · Official requirement · Verified 20 August 2026Section 28(1): the Board shall function as an independent body and shall, as far as practicable, function as a digital office.
- [9]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 1, (4), p. 24. Published 13 November 2025. Official source ↗ · Official requirement · Verified 20 August 2026Rule 7 is in the eighteen month commencement group under Rule 1(4).
- [10]Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)), p. 1. Published 13 November 2025. Official source ↗ · Interpretation, requires judgment · Verified 20 August 2026The calendar date 13 May 2027 is computed from the publication date printed on Gazette issue No. 760 and is presented as interpretation until officially confirmed.