A data breach just hit your organisation: the hour by hour response under DPDP
By Abhijeet Singh · Primary sources verified by dpdprules.orgPublished · Last reviewed 10 min read
What should my organisation do after a personal data breach?
The short answer
Once Rule 7 of the DPDP Rules 2025 is in force, 2 legal clocks start the moment your organisation becomes aware of a personal data breach. First, as a matter of practice rather than of Rule 7, contain the incident, record the exact awareness time and instruct your Data Processors, because section 8 keeps you responsible for their processing. Then run 2 duties in parallel, both without delay: intimate each affected Data Principal in plain language with 5 required contents, and send the Data Protection Board a description of the breach. Within 72 hours of awareness, file the detailed Board submission with its 6 required contents; a longer period needs the Board's permission on a written request. Afterwards, again as practice rather than as a requirement of Rule 7, verify the fix, preserve the record, and be ready for a possible Board inquiry. Rule 7 sits in the commencement group computed to 13 May 2027, interpretation until officially confirmed, and building the workflow before the duty begins is the practical move.

It is 9:58 pm and your monitoring just confirmed it: someone accessed a database holding customer personal data. Once Rule 7 is in force, India's DPDP framework treats your organisation as aware of a personal data breach from this exact moment, and 2 legal clocks start running. Rule 7 is not in force yet: it commences on 13 May 2027, a date computed from the notification, so treat it as interpretation until officially confirmed. This article walks the response hour by hour, with the official source behind every required step.
Everything starts at awareness, not at certainty
Rule 7 of the DPDP Rules 2025 frames both breach duties around one trigger: on becoming aware. There is no materiality threshold in the rule's text and no waiting period to confirm the details. The single most valuable thing you can do in the first minutes is record the exact date and time of awareness in your incident log, because every deadline that follows is measured from it.
The first hour: contain and anchor
Before any notification, stop the bleeding. Isolate the affected systems, revoke exposed credentials, close the entry point, and preserve evidence while you do it. Assemble the response team in one room or one channel: an incident lead, security, engineering, legal, communications and support. Open a timestamped incident log that records events, circumstances and reasons as they become known; the 72 hour Board submission will ask for exactly those facts, so a disciplined log writes most of it for you.
One legal point matters immediately: if a Data Processor holds or touches the affected data, instruct it to contain on its side and report what it knows to you. Section 8 of the Act keeps the Data Fiduciary responsible for complying with the framework, including in respect of processing undertaken on its behalf by a Data Processor. The breach happening inside a vendor does not move the duty.
Duty one: tell each affected person, without delay
Rule 7(1) requires an intimation to each affected Data Principal, to the best of your knowledge, in a concise, clear and plain manner, through the person's user account or a registered mode of communication. The rule fixes 5 contents:
- a description of the breach, including its nature, extent and the timing of its occurrence;
- the consequences relevant to that person that are likely to arise;
- the measures implemented and being implemented to mitigate risk;
- the safety measures the person may take to protect their interests;
- business contact information of a person able to respond to their queries.
Write it like a human being. The people receiving this message did nothing wrong, and the rule's plain manner requirement is on your side: no legal boilerplate, no burying the point. Log every send, with recipient, time and channel, because the Board submission must include a report on these intimations.
Duty two: tell the Board, twice
The Board intimation is staged, and the official text carries both clocks:
"On becoming aware of any personal data breach, the Data Fiduciary shall intimate to the Board, — (a) without delay, a description of the breach, including its nature, extent, timing and location of occurrence and the likely impact; (b) within seventy-two hours of becoming aware of the breach, or within such longer period as the Board may allow on a request made in writing in this behalf …"
Rule 7(2), truncated before items (i) to (vi), which are restated below.
Stage one, Rule 7(2)(a), is a description, sent without delay on the facts you have. Do not hold it back for the full picture; stage two exists to update and complete it. Stage two, Rule 7(2)(b), due within 72 hours of awareness, carries 6 required contents: updated and detailed information on the description already sent; the broad facts related to the events, circumstances and reasons leading to the breach; measures implemented or proposed to mitigate risk; any findings regarding the person who caused the breach; remedial measures taken to prevent recurrence; and a report regarding the intimations given to affected Data Principals. If 72 hours is genuinely not enough, the only lawful route to more time is a request to the Board made in writing; send it before the deadline passes.
A practical note on where to send it: as of our last verification, the Board has not published a dedicated intimation channel in any primary source we track. What is official so far is that notification G.S.R. 844(E) establishes the Data Protection Board of India with its head office in the National Capital Region, and the Act has the Board function, as far as practicable, as a digital office. Watch the MeitY website for the channel; this site will add it, with its source, the day it is published.
After the deadline: what the Board can do
The intimation is not a formality that disappears into a mailbox. Under section 27(1)(a), the Board's powers switch on the moment it receives one:
"on receipt of an intimation of personal data breach under sub-section (6) of section 8, to direct any urgent remedial or mitigation measures in the event of a personal data breach, and to inquire into such personal data breach and impose penalty as provided in this Act;"
Section 27(1)(a) of the DPDP Act 2023.
Read as at 3 September 2026, none of that is live either: clause (c) of the Act's commencement notification puts section 27, except clause (d) of sub section (1), and sections 28 to 34 in the same 18 month group as section 8, so the Board's power to act on an intimation, the section 33 power to impose any of the Schedule's amounts and the section 32 settlement track all begin when the duty does. Those powers are why phase 4 of a good response is unglamorous but essential: verify that the remedial measures actually closed the gap, run a post incident review, and preserve the incident log, both intimations and the send records in one place. The Schedule's numbers explain the stakes: failing reasonable security safeguards carries a cap of 250 crore rupees, and failing the breach notice duty carries 200 crore rupees. If proceedings do begin, the Act also has a settlement track: under section 32, the Board may accept a voluntary undertaking at any stage of a section 28 proceeding, and acceptance bars proceedings under the Act as regards the undertaking's contents, except where a term of the undertaking is not adhered to.
The 4 phases at a glance
Prepare on a calm day
Every step above is easier if 4 things exist before any incident: named owners for each track with deputies, the 2 intimation drafts kept ready with your standing details, a current list of Data Processors with breach contacts, and 1 tabletop rehearsal from awareness to the 72 hour submission. The downloadable starting templates cover both intimations.
When this becomes law, and what to do now
Read as at 3 September 2026, Rule 7 is not in force. Rule 1(4) puts "Rules 3, 5 to 16, 22 and 23" into force "eighteen months after the date of publication in the Official Gazette", with those closing words as corrigenda G.S.R. 892(E) corrected them, and Rule 7 sits inside 5 to 16. Computed from the publication date of 13 November 2025, the group is due on 13 May 2027, and that calendar date is interpretation until officially confirmed. Section 8(6) is the Act duty behind Rule 7, and section 8 is itself in the Act's own 18 month group, so on this site's reading the Act duty and the rule that gives it form and manner begin together. The clocks in Rule 7 are short and start on awareness, which makes building the workflow before the duty begins the entire point.
One boundary is worth stating plainly, because both diagrams on this page now draw it: Rule 7 prescribes only the 2 intimations and their contents. Nothing in it requires an incident log, a named response team, a post incident review or a rehearsal. Logs of a different kind are required elsewhere: Rule 6(1)(c) requires visibility on the accessing of personal data through appropriate logs, monitoring and review, and Rule 6(1)(e) requires such logs and personal data to be retained for one year unless compliance with any law for the time being in force requires otherwise. Neither of those is the incident log described above, and both sit in the same 18 month group as Rule 7, so they are no more in force today than it is. Phases 1 and 4 of the playbook are therefore this site's recommended practice rather than a requirement of Rule 7, and the diagram labels them that way.
A Hindi explainer of the same 2 clocks, quoting Rule 7 from the Hindi Gazette rather than translating the English, is at डेटा ब्रीच होने पर क्या करें.
The interactive version of everything in this article is the data breach response playbook: enter your awareness time and it runs the live 72 hour countdown, lays out the phases with parallel tracks, tracks your progress in your browser, previews and downloads sample intimations, and exports the whole plan to Excel.
Rule 7, official text with sources →Section 8, official text with sources →Downloadable intimation templates →