DPDP breach notification: 72 hours to the Board, 6 hours to CERT In
By Abhijeet Singh · Primary sources verified by dpdprules.orgPublished · Last reviewed 8 min read
Is the data breach reporting deadline in India 72 hours or 6 hours?
The short answer
Both, because they are 2 separate legal regimes with different recipients. Under Rule 7 of the DPDP Rules 2025, once it is in force, a Data Fiduciary must intimate each affected Data Principal and send the Data Protection Board a description of the breach without delay, then file detailed information with the Board within 72 hours of becoming aware, or any longer period the Board allows on a written request. Separately, under the CERT In directions of 28 April 2022 issued under the IT Act, service providers, intermediaries, data centres, body corporates and government organisations must report cyber incidents listed in Annexure I, which includes data breach and data leak, to CERT In within 6 hours of noticing them. The DPDP duty is in the commencement group computed to 13 May 2027, interpretation until officially confirmed; the CERT In duty is already in effect: the directions took effect 60 days after issue, and on 25 September 2022 for MSMEs.

Search for the Indian data breach reporting deadline and you will find 2 different numbers: 72 hours and 6 hours. Both are real, and they belong to 2 separate legal regimes with different recipients, different triggers and different coverage. They are not both running, though. Only the CERT In clock is in force as at 3 September 2026, and the DPDP clock joins it when Rule 7 commences, so a breach this week engages 1 of the 2 and a breach after that date can engage both.
The 2 clocks side by side
| DPDP Rule 7 | CERT In directions | |
|---|---|---|
| Legal basis | DPDP Act 2023 and DPDP Rules 2025 | Section 70B(6) of the IT Act 2000, direction No. 20(3)/2022 CERT In |
| Who reports | The Data Fiduciary | Service providers, intermediaries, data centres, body corporates and government organisations |
| Reports to | Each affected Data Principal, and the Data Protection Board of India | CERT In |
| What triggers it | Any personal data breach | Cyber incidents listed in Annexure I, including data breach and data leak |
| The clock | Without delay to affected people and the Board; detailed Board submission within 72 hours of awareness | Within 6 hours of noticing or being brought to notice |
| Status today | In the commencement group computed to 13 May 2027, interpretation until confirmed | In effect |
The DPDP clock: 72 hours to the Board
Rule 7 of the DPDP Rules 2025 sets the personal data breach intimation duties. On becoming aware of any personal data breach, the Data Fiduciary must intimate each affected Data Principal without delay in a concise, clear and plain manner, and must intimate the Board in 2 stages:
"On becoming aware of any personal data breach, the Data Fiduciary shall intimate to the Board, — (a) without delay, a description of the breach, including its nature, extent, timing and location of occurrence and the likely impact; (b) within seventy-two hours of becoming aware of the breach, or within such longer period as the Board may allow on a request made in writing in this behalf …"
Rule 7(2), truncated before items (i) to (vi).
The trigger is awareness of any personal data breach, with no materiality threshold in the rule's text, and the only route to more time sits inside Rule 7(2)(b) itself: the 72 hours runs "or within such longer period as the Board may allow on a request made in writing in this behalf". So the 72 hours is a ceiling the Board can lift on a written request, not a hard stop. What each of the 6 items in that 72 hour submission asks for, and why the GDPR formula of categories and approximate numbers is not one of them, is in what a Rule 7 breach report must contain. A working playbook for the whole response is in the hour by hour breach response article.
The CERT In clock: 6 hours
Entirely separately, the CERT In directions of 28 April 2022, issued under section 70B(6) of the Information Technology Act 2000, set a cyber incident reporting duty that has been in effect since 2022:
"Any service provider, intermediary, data centre, body corporate and Government organisation shall mandatorily report cyber incidents as mentioned in Annexure I to CERT-In within 6 hours of noticing such incidents or being brought to notice about such incidents."
Direction (ii) of No. 20(3)/2022 CERT In.
Annexure I of the directions lists the reportable incident types, and items xi and xii are data breach and data leak. So a personal data breach at a body corporate is typically also a reportable cyber incident, and the CERT In clock is much shorter: 6 hours from noticing, not 72.
The consequence attached to that clock is also larger than most runbooks record. Section 70B(7) of the same Act is what follows a failure to provide information called for or to comply with a direction under section 70B(6), and its fine ceiling was raised from one lakh rupees to one crore with effect from 30 November 2023, which is set out with the Gazette print in what the Jan Vishwas Act changed in the IT Act.
Which clock is running today
The 2 numbers do not carry the same weight today, and this is the part a side by side table hides. The CERT In duty is live and the DPDP duty is not.
Rule 1(4) of the DPDP Rules 2025 fixes the DPDP side. It is quoted inline rather than as a captioned figure, because its closing words are the ones corrigenda G.S.R. 892(E) substituted at line 24 of Gazette page 24, so this is the operative reading of the sub rule and not the wording the Gazette printed: "Rules 3, 5 to 16, 22 and 23 shall come into force eighteen months after the date of publication in the Official Gazette."
Rule 7 sits inside that range, so the breach intimation duties commence 18 months after publication, computed at 13 May 2027 and presented as interpretation until officially confirmed. The Act provision behind them travels with them. Section 8(6) requires the Data Fiduciary to give the Board and each affected Data Principal intimation of a breach "in such form and manner as may be prescribed", and section 40(2)(f) empowers the Central Government to make rules for "the form and manner of intimation of personal data breach to the Board under sub-section (6) of section 8", which is what Rule 7 does. Section 8 is inside "sections 7 to 10" in paragraph (c) of the commencement notification, the paragraph that commences its group 18 months after that Gazette was published, so the Act duty and the rule that fills it in start together.
The CERT In directions commenced on their own terms and long ago. Their closing paragraph, on page 4, is quoted inline rather than as a captioned figure, because a sentence fixing when an instrument takes effect imposes no requirement on anybody and should not be labelled as one: "This direction will become effective after 60 days from the date on which it is issued."
They were issued on 28 April 2022, so the 6 hour duty applied from late June 2022 for the entities they cover. CERT In then moved 2 of its own dates, which is easy to miss because the further document carries the same number, No. 20(3)/2022 CERT In. Issued on 27 June 2022, it provides that the directions "will become effective on 25 th September, 2022 for Micro, Small & Medium Enterprises (MSMEs)", and that the subscriber and customer validation requirements at paragraph (v) a. and f. take effect on the same date for data centres, VPS providers, cloud service providers and VPN service providers. It leaves the 6 hour clock in direction (ii) untouched for everybody who is not an MSME. Every one of those dates is nearly 4 years past, so the conclusion does not move: the CERT In duty is in force as at 3 September 2026.
If your organisation suffers a personal data breach this week, the reportable clock is the CERT In one.
What this means in practice
Treat the 2 duties as parallel tracks with different owners. The CERT In report is a security team action on the 6 hour clock, already in force today. The DPDP intimations are a compliance and legal action on the without delay and 72 hour clocks, due when Rule 7 commences on the computed date of 13 May 2027, interpretation until confirmed. They go to different recipients and neither substitutes for the other: reporting to CERT In does not intimate the Data Protection Board or the affected people, and the DPDP intimations do not discharge the CERT In duty.
One more difference worth noting: the DPDP duty runs from becoming aware, while the CERT In duty runs from noticing or being brought to notice. In an incident, record one timestamped awareness moment and treat it as the anchor for both.
The data breach response playbook on this site runs the DPDP side step by step with a live 72 hour countdown; add the CERT In report to phase one of your own runbook.
Rule 7, official text with sources →The hour by hour breach response playbook article →What a Rule 7 breach report must contain →
Data breachRule 7Indian Computer Emergency Response Team72 hours6 hours