DPDP data breach reporting: what Rule 7 actually requires
By Abhijeet Singh · Primary sources verified by dpdprules.orgPublished · Last reviewed 5 min read
What does DPDP Rule 7 require after a personal data breach?
The short answer
Once Rule 7 of the DPDP Rules 2025 is in force, a Data Fiduciary that becomes aware of a personal data breach must intimate each affected Data Principal without delay, in plain language, covering the breach, its likely consequences, the mitigation under way, the safety steps they can take and a contact who can answer questions. It must also intimate the Data Protection Board: a description without delay, then updated and detailed information within 72 hours of becoming aware, unless the Board allows longer on a written request. Rule 7 is in the group of Rules due to come into force 18 months after publication, which computes to 13 May 2027, interpretation until officially confirmed.

Once it is in force, Rule 7 of the DPDP Rules 2025 turns a breach into 2 parallel duties with different depths and clocks. Both start at the same moment: when the Data Fiduciary becomes aware of the breach. Rule 7 is not in force yet: Rule 1(4) brings it into force 18 months after the Rules were published in the Official Gazette, which computes to 13 May 2027, a date that is interpretation until officially confirmed.
Duty one: tell the affected people, without delay
Each affected Data Principal must be intimated, to the best of the Data Fiduciary's knowledge, in a concise, clear and plain manner, through their user account or a registered mode of communication. The rule lists what the intimation must cover: a description of the breach with its nature, extent and timing, the consequences likely to arise for that person, the mitigation implemented and under way, the safety measures the person can take, and business contact information of someone able to answer questions.
Notice what is absent: there is no materiality threshold in the rule's text. The duty is framed around any personal data breach and every affected Data Principal.
Duty two: tell the Board, in 2 stages
The Board intimation is staged.
"On becoming aware of any personal data breach, the Data Fiduciary shall intimate to the Board, — (a) without delay, a description of the breach, including its nature, extent, timing and location of occurrence and the likely impact; (b) within seventy-two hours of becoming aware of the breach, or within such longer period as the Board may allow on a request made in writing in this behalf …"
Rule 7(2), truncated before items (i) to (vi), which are restated below.
The 72 hour submission is the detailed one: updated information, the broad facts about the events, circumstances and reasons leading to the breach, mitigation, any findings about who caused the breach, remedial measures against recurrence, and a report on the intimations given to affected individuals. A longer period is possible, but only if the Board allows it on a written request.
What Rule 7 does not require
Search engine and chatbot answers for this question, sampled in August 2026, routinely add a requirement that is not in the rule: that the Board submission must state the categories and approximate number of affected Data Principals. It is worth being precise, because a team building a template from one of those answers will collect information the rule never asks for and may believe it has a duty it does not have.
Rule 7(2)(b) prints 6 items, quoted in full in the sources below, and none of them mentions a category, a count or an approximate number:
| Item | What the rule asks for |
|---|---|
| (i) | Updated and detailed information in respect of the description already given |
| (ii) | The broad facts related to the events, circumstances and reasons leading to the breach |
| (iii) | Measures implemented or proposed, if any, to mitigate risk |
| (iv) | Any findings regarding the person who caused the breach |
| (v) | Remedial measures taken to prevent recurrence of such breach |
| (vi) | A report regarding the intimations given to affected Data Principals |
The wording comes from the GDPR, where Article 33(3)(a) requires a controller to "describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned". That is EU law. It has no counterpart in Rule 7.
Item (vi) is the one most easily misread as the same thing, and it deserves care rather than a flat answer. On the printed words, the object of the report is the intimations given, not the people affected: item (vi) asks for a report regarding the intimations, and nothing in Rule 7 uses the words category, number or approximate. That is how far the text goes. It does not follow that a figure sits outside item (vi). A report regarding the intimations given can fairly be read to require the Data Fiduciary to account for the intimations it sent, which in practice means saying how many went out, and since Rule 7(1) requires an intimation to each affected Data Principal, that figure will usually be the number of people affected. Which of the 2 readings the Board takes is interpretation, not text. Rule 7 is not yet in force, and as at 24 August 2026 we have located no Board order or official guidance construing item (vi), so nothing here should be read as an assurance that a submission without a figure is complete.
The safe conclusion is the narrow one: Rule 7(2)(b) does not carry the GDPR formula, and section 8(6) of the Act leaves the form and manner of breach intimation to what is prescribed, which is Rule 7 and nothing more. A template that collects categories and approximate numbers of affected Data Principals and of records because it believes Rule 7 demands them is built on the wrong law. As a practical matter rather than a requirement: hold the figure anyway. A fiduciary that intimated each affected person under Rule 7(1) will have it, and nothing in Rule 7 stops you giving the Board a number. Hold it for 2 further reasons: section 36 of the Act lets the Central Government, for the purposes of the Act, require a Data Fiduciary to furnish such information as it may call for, and section 33(2)(b) makes the type and nature of the personal data affected by the breach a matter the Board must have regard to when it determines a penalty. If you give a number early, give it as an estimate and correct it in the updated information under item (i).
When this starts to apply
Rule 7 sits in the 18 month commencement group. Computed from the publication date of 13 November 2025, that group is due on 13 May 2027; the computed date is interpretation until officially confirmed. Building the workflow before the duty begins is the practical move, because the clocks in Rule 7 are short and start on awareness, not on convenience.
What to do
Decide now who detects, who drafts, who signs off and who talks to the Board. Capture the awareness moment in your incident process, prepare plain language templates for the Data Principal intimation, and rehearse the 72 hour Board submission once. The breach response tool on this site walks the workflow step by step against the rule's own text, and the security team guide covers the detection and containment work that usually sits with security.