Skip to main content

The 3rd and main DPDP commencement date is computed as 13 May 2027, which is interpretation until officially confirmed.

Sources last verified on 23 September 2026. Methodology

DPDP breach notification: 72 hours to the Board, 6 hours to CERT In

Breach response

By · Primary sources verified by dpdprules.orgPublished · Last reviewed 8 min read

Is the data breach reporting deadline in India 72 hours or 6 hours?

The short answer

Both, because they are 2 separate legal regimes with different recipients. Under Rule 7 of the DPDP Rules 2025, once it is in force, a Data Fiduciary must intimate each affected Data Principal and send the Data Protection Board a description of the breach without delay, then file detailed information with the Board within 72 hours of becoming aware, or any longer period the Board allows on a written request. Separately, under the CERT In directions of 28 April 2022 issued under the IT Act, service providers, intermediaries, data centres, body corporates and government organisations must report cyber incidents listed in Annexure I, which includes data breach and data leak, to CERT In within 6 hours of noticing them. The DPDP duty is in the commencement group computed to 13 May 2027, interpretation until officially confirmed; the CERT In duty is already in effect: the directions took effect 60 days after issue, and on 25 September 2022 for MSMEs.

More answered questions →

Diagram: 2 breach clocks, 2 regimes, and only 1 of them is running today, as at 3 September 2026. The same diagram appears further down this article, where it is described in full.
Both statuses read as at 3 September 2026: the Rule 7 clock is not in force today, computed 13 May 2027 and interpretation until officially confirmed, while the CERT In 6 hour clock is in force today and binds only the entities those directions name.

Search for the Indian data breach reporting deadline and you will find 2 different numbers: 72 hours and 6 hours. Both are real, and they belong to 2 separate legal regimes with different recipients, different triggers and different coverage. They are not both running, though. Only the CERT In clock is in force as at 3 September 2026, and the DPDP clock joins it when Rule 7 commences, so a breach this week engages 1 of the 2 and a breach after that date can engage both.

Diagram comparing the 2 Indian breach reporting regimes and showing that only 1 of them is running today. The left column, Rule 7 of the DPDP Rules 2025, is marked not in force today as at 3 September 2026: the Data Fiduciary, on becoming aware, intimates every affected person and the Data Protection Board, covering any personal data breach at any Data Fiduciary, with both intimations without delay and the detailed Board submission within 72 hours, or a longer period the Board allows on a written request under Rule 7(2)(b). The right column, the CERT In directions 2022, is marked in force today as at 3 September 2026: service providers, intermediaries, data centres, body corporates and Government organisations report the cyber incidents in Annexure I, including data breach and data leak, to CERT In within 6 hours of noticing or being brought to notice. A panel below is split in 2. Under the heading giving each instrument's own words it quotes Rule 1(4), as corrected by corrigenda G.S.R. 892(E), reading “Rules 3, 5 to 16, 22 and 23 shall come into force eighteen months after the date of publication in the Official Gazette”, with Rule 7 sitting inside 5 to 16; and it quotes the CERT In directions at page 4, “This direction will become effective after 60 days from the date on which it is issued”, noting that they were issued on 28 April 2022 and moved to 25 September 2022 for MSMEs by CERT In's extension of 27 June 2022. Under the heading marking this site's reading it says that section 8(6) is the Act duty behind Rule 7, that section 40(2)(f) empowers rules on the form and manner of breach intimation to the Board under section 8(6), that section 8 is in the Act's own 18 month group, that 13 May 2027 is computed from the publication date printed on Gazette issue No. 760 and is interpretation until officially confirmed, and that both statuses are read as at 3 September 2026. The footer cites Rule 7 of the DPDP Rules 2025 and CERT In directions No. 20(3)/2022 of 28 April 2022, direction (ii), issued under section 70B(6) of the IT Act 2000.

The 2 clocks side by side

DPDP Rule 7CERT In directions
Legal basisDPDP Act 2023 and DPDP Rules 2025Section 70B(6) of the IT Act 2000, direction No. 20(3)/2022 CERT In
Who reportsThe Data FiduciaryService providers, intermediaries, data centres, body corporates and government organisations
Reports toEach affected Data Principal, and the Data Protection Board of IndiaCERT In
What triggers itAny personal data breachCyber incidents listed in Annexure I, including data breach and data leak
The clockWithout delay to affected people and the Board; detailed Board submission within 72 hours of awarenessWithin 6 hours of noticing or being brought to notice
Status todayIn the commencement group computed to 13 May 2027, interpretation until confirmedIn effect

The DPDP clock: 72 hours to the Board

Rule 7 of the DPDP Rules 2025 sets the personal data breach intimation duties. On becoming aware of any personal data breach, the Data Fiduciary must intimate each affected Data Principal without delay in a concise, clear and plain manner, and must intimate the Board in 2 stages:

DPDP Rules 2025, r. 7 · Intimation of personal data breach · verbatim

"On becoming aware of any personal data breach, the Data Fiduciary shall intimate to the Board, — (a) without delay, a description of the breach, including its nature, extent, timing and location of occurrence and the likely impact; (b) within seventy-two hours of becoming aware of the breach, or within such longer period as the Board may allow on a request made in writing in this behalf …"

Rule 7(2), truncated before items (i) to (vi).

The trigger is awareness of any personal data breach, with no materiality threshold in the rule's text, and the only route to more time sits inside Rule 7(2)(b) itself: the 72 hours runs "or within such longer period as the Board may allow on a request made in writing in this behalf". So the 72 hours is a ceiling the Board can lift on a written request, not a hard stop. What each of the 6 items in that 72 hour submission asks for, and why the GDPR formula of categories and approximate numbers is not one of them, is in what a Rule 7 breach report must contain. A working playbook for the whole response is in the hour by hour breach response article.

The CERT In clock: 6 hours

Entirely separately, the CERT In directions of 28 April 2022, issued under section 70B(6) of the Information Technology Act 2000, set a cyber incident reporting duty that has been in effect since 2022:

Official requirement · CERT-In directions under section 70B(6) of the Information Technology Act, 2000 on reporting of cyber incidents, (ii)

"Any service provider, intermediary, data centre, body corporate and Government organisation shall mandatorily report cyber incidents as mentioned in Annexure I to CERT-In within 6 hours of noticing such incidents or being brought to notice about such incidents."

Direction (ii) of No. 20(3)/2022 CERT In.

Annexure I of the directions lists the reportable incident types, and items xi and xii are data breach and data leak. So a personal data breach at a body corporate is typically also a reportable cyber incident, and the CERT In clock is much shorter: 6 hours from noticing, not 72.

The consequence attached to that clock is also larger than most runbooks record. Section 70B(7) of the same Act is what follows a failure to provide information called for or to comply with a direction under section 70B(6), and its fine ceiling was raised from one lakh rupees to one crore with effect from 30 November 2023, which is set out with the Gazette print in what the Jan Vishwas Act changed in the IT Act.

Which clock is running today

The 2 numbers do not carry the same weight today, and this is the part a side by side table hides. The CERT In duty is live and the DPDP duty is not.

Rule 1(4) of the DPDP Rules 2025 fixes the DPDP side. It is quoted inline rather than as a captioned figure, because its closing words are the ones corrigenda G.S.R. 892(E) substituted at line 24 of Gazette page 24, so this is the operative reading of the sub rule and not the wording the Gazette printed: "Rules 3, 5 to 16, 22 and 23 shall come into force eighteen months after the date of publication in the Official Gazette."

Rule 7 sits inside that range, so the breach intimation duties commence 18 months after publication, computed at 13 May 2027 and presented as interpretation until officially confirmed. The Act provision behind them travels with them. Section 8(6) requires the Data Fiduciary to give the Board and each affected Data Principal intimation of a breach "in such form and manner as may be prescribed", and section 40(2)(f) empowers the Central Government to make rules for "the form and manner of intimation of personal data breach to the Board under sub-section (6) of section 8", which is what Rule 7 does. Section 8 is inside "sections 7 to 10" in paragraph (c) of the commencement notification, the paragraph that commences its group 18 months after that Gazette was published, so the Act duty and the rule that fills it in start together.

The CERT In directions commenced on their own terms and long ago. Their closing paragraph, on page 4, is quoted inline rather than as a captioned figure, because a sentence fixing when an instrument takes effect imposes no requirement on anybody and should not be labelled as one: "This direction will become effective after 60 days from the date on which it is issued."

They were issued on 28 April 2022, so the 6 hour duty applied from late June 2022 for the entities they cover. CERT In then moved 2 of its own dates, which is easy to miss because the further document carries the same number, No. 20(3)/2022 CERT In. Issued on 27 June 2022, it provides that the directions "will become effective on 25 th September, 2022 for Micro, Small & Medium Enterprises (MSMEs)", and that the subscriber and customer validation requirements at paragraph (v) a. and f. take effect on the same date for data centres, VPS providers, cloud service providers and VPN service providers. It leaves the 6 hour clock in direction (ii) untouched for everybody who is not an MSME. Every one of those dates is nearly 4 years past, so the conclusion does not move: the CERT In duty is in force as at 3 September 2026.

If your organisation suffers a personal data breach this week, the reportable clock is the CERT In one.

What this means in practice

Treat the 2 duties as parallel tracks with different owners. The CERT In report is a security team action on the 6 hour clock, already in force today. The DPDP intimations are a compliance and legal action on the without delay and 72 hour clocks, due when Rule 7 commences on the computed date of 13 May 2027, interpretation until confirmed. They go to different recipients and neither substitutes for the other: reporting to CERT In does not intimate the Data Protection Board or the affected people, and the DPDP intimations do not discharge the CERT In duty.

One more difference worth noting: the DPDP duty runs from becoming aware, while the CERT In duty runs from noticing or being brought to notice. In an incident, record one timestamped awareness moment and treat it as the anchor for both.

The data breach response playbook on this site runs the DPDP side step by step with a live 72 hour countdown; add the CERT In report to phase one of your own runbook.

Rule 7, official text with sources →The hour by hour breach response playbook article →What a Rule 7 breach report must contain →

Data breachRule 7Indian Computer Emergency Response Team72 hours6 hours

Share this: