Skip to main content

Sources last verified on 20 August 2026. Methodology

DPDP breach notification: 72 hours to the Board, 6 hours to CERT In

Breach response

By dpdprules.org editorial team · Reviewed by dpdprules.org source verificationPublished · Last reviewed 3 min read

The short answer

Both, because they are two separate legal regimes with different recipients. Under Rule 7 of the DPDP Rules 2025, a Data Fiduciary must intimate each affected Data Principal and send the Data Protection Board a description of the breach without delay, then file detailed information with the Board within seventy two hours of becoming aware. Separately, under the CERT In directions of 28 April 2022 issued under the IT Act, service providers, intermediaries, data centres, body corporates and government organisations must report cyber incidents listed in Annexure I, which includes data breach and data leak, to CERT In within six hours of noticing them. The DPDP duty is in the commencement group computed to 13 May 2027, interpretation until confirmed; the CERT In duty is already in effect.

Search for the Indian data breach reporting deadline and you will find two different numbers: seventy two hours and six hours. Both are real, and they belong to two separate legal regimes with different recipients, different triggers and different coverage. If your organisation suffers a breach, you may owe both.

The two clocks side by side

DPDP Rule 7CERT In directions
Legal basisDPDP Act 2023 and DPDP Rules 2025Section 70B(6) of the IT Act 2000, direction No. 20(3)/2022 CERT In
Who reportsThe Data FiduciaryService providers, intermediaries, data centres, body corporates and government organisations
Reports toEach affected Data Principal, and the Data Protection Board of IndiaCERT In
What triggers itAny personal data breachCyber incidents listed in Annexure I, including data breach and data leak
The clockWithout delay to affected people and the Board; detailed Board submission within seventy two hours of awarenessWithin six hours of noticing or being brought to notice
Status todayIn the commencement group computed to 13 May 2027, interpretation until confirmedIn effect

The DPDP clock: seventy two hours to the Board

Rule 7 of the DPDP Rules 2025 sets the personal data breach intimation duties. On becoming aware of any personal data breach, the Data Fiduciary must intimate each affected Data Principal without delay in a concise, clear and plain manner, and must intimate the Board in two stages:

Official requirement · verbatim

"On becoming aware of any personal data breach, the Data Fiduciary shall intimate to the Board, — (a) without delay, a description of the breach, including its nature, extent, timing and location of occurrence and the likely impact; (b) within seventy-two hours of becoming aware of the breach, or within such longer period as the Board may allow on a request made in writing in this behalf …"

Rule 7(2), truncated before items (i) to (vi).

The trigger is awareness of any personal data breach, with no materiality threshold in the rule's text, and the only route to more time is a written request the Board allows. The full anatomy of this duty, the required contents and a working playbook are in the hour by hour breach response article.

The CERT In clock: six hours

Entirely separately, the CERT In directions of 28 April 2022, issued under section 70B(6) of the Information Technology Act 2000, set a cyber incident reporting duty that has been in effect since 2022:

Official requirement · verbatim

"Any service provider, intermediary, data centre, body corporate and Government organisation shall mandatorily report cyber incidents as mentioned in Annexure I to CERT-In within 6 hours of noticing such incidents or being brought to notice about such incidents."

Direction (ii) of No. 20(3)/2022 CERT In.

Annexure I of the directions lists the reportable incident types, and items xi and xii are data breach and data leak. So a personal data breach at a body corporate is typically also a reportable cyber incident, and the CERT In clock is much shorter: six hours from noticing, not seventy two.

What this means in practice

Treat the two duties as parallel tracks with different owners. The CERT In report is a security team action on the six hour clock, already in force today. The DPDP intimations are a compliance and legal action on the without delay and seventy two hour clocks, due when Rule 7 commences on the computed date of 13 May 2027, interpretation until confirmed. They go to different recipients and neither substitutes for the other: reporting to CERT In does not intimate the Data Protection Board or the affected people, and the DPDP intimations do not discharge the CERT In duty.

One more difference worth noting: the DPDP duty runs from becoming aware, while the CERT In duty runs from noticing or being brought to notice. In an incident, record one timestamped awareness moment and treat it as the anchor for both.

The data breach response playbook on this site runs the DPDP side step by step with a live seventy two hour countdown; add the CERT In report to phase one of your own runbook.

Rule 7, official text with sourcesThe hour by hour breach response playbook article

Sources cited on this page

  1. [1]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 7, p. 26. Published 13 November 2025. Official source ↗ · Official requirement · Verified 20 August 2026Rule 7(2), truncated before items (i) to (vi).
  2. [2]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 7, (1), p. 26. Published 13 November 2025. Official source ↗ · Official requirement · Verified 20 August 2026Rule 7(1) requires intimation to each affected Data Principal without delay, in a concise, clear and plain manner.
  3. [3]CERT-In directions under section 70B(6) of the Information Technology Act, 2000 on reporting of cyber incidents (No. 20(3)/2022-CERT-In), (ii), p. 2. Published 28 April 2022. Official source ↗ · Official requirement · Verified 20 August 2026Direction (ii) of No. 20(3)/2022-CERT-In dated 28 April 2022, issued under section 70B(6) of the Information Technology Act, 2000. Annexure I items xi and xii are Data Breach and Data Leak.
  4. [4]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 1, (4), p. 24. Published 13 November 2025. Official source ↗ · Official requirement · Verified 20 August 2026Rule 7 is in the eighteen month commencement group under Rule 1(4).
  5. [5]Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)), p. 1. Published 13 November 2025. Official source ↗ · Interpretation, requires judgment · Verified 20 August 2026The calendar date 13 May 2027 is computed from the publication date printed on Gazette issue No. 760 and is presented as interpretation until officially confirmed.

data breachrule 7cert in72 hours6 hours

Share this: