Skip to main content

Sources last verified on 17 August 2026. Methodology

DPDP data breach reporting: what Rule 7 actually requires

Breach response

By dpdprules.org editorial team · Reviewed by dpdprules.org source verificationPublished · Last reviewed

The short answer

On becoming aware of a personal data breach, a Data Fiduciary must intimate each affected Data Principal without delay, in plain language, covering the breach, its likely consequences, the mitigation under way, the safety steps they can take and a contact who can answer questions. It must also intimate the Data Protection Board: a description without delay, then updated and detailed information within seventy two hours of becoming aware, unless the Board allows longer on a written request. Rule 7 is in the group of Rules due to come into force eighteen months after publication, which computes to 13 May 2027, interpretation until confirmed.

Rule 7 of the DPDP Rules 2025 turns a breach into two parallel duties with different depths and clocks. Both start at the same moment: when the Data Fiduciary becomes aware of the breach.

Duty one: tell the affected people, without delay

Each affected Data Principal must be intimated, to the best of the Data Fiduciary's knowledge, in a concise, clear and plain manner, through their user account or a registered mode of communication. The rule lists what the intimation must cover: a description of the breach with its nature, extent and timing, the consequences likely to arise for that person, the mitigation implemented and under way, the safety measures the person can take, and business contact information of someone able to answer questions.

Notice what is absent: there is no materiality threshold in the rule's text. The duty is framed around any personal data breach and every affected Data Principal.

Duty two: tell the Board, in two stages

The Board intimation is staged.

Official requirement · verbatim

"On becoming aware of any personal data breach, the Data Fiduciary shall intimate to the Board, — (a) without delay, a description of the breach, including its nature, extent, timing and location of occurrence and the likely impact; (b) within seventy-two hours of becoming aware of the breach, or within such longer period as the Board may allow on a request made in writing in this behalf …"

Rule 7(2), truncated before items (i) to (vi), which are restated below.

The seventy two hour submission is the detailed one: updated information, the broad facts about the events, circumstances and reasons leading to the breach, mitigation, any findings about who caused the breach, remedial measures against recurrence, and a report on the intimations given to affected individuals. A longer period is possible, but only if the Board allows it on a written request.

When this starts to apply

Rule 7 sits in the eighteen month commencement group. Computed from the publication date of 13 November 2025, that group is due on 13 May 2027; the computed date is interpretation until officially confirmed. Building the workflow before the duty begins is the practical move, because the clocks in Rule 7 are short and start on awareness, not on convenience.

What to do

Decide now who detects, who drafts, who signs off and who talks to the Board. Capture the awareness moment in your incident process, prepare plain language templates for the Data Principal intimation, and rehearse the seventy two hour Board submission once. The breach response tool on this site walks the workflow step by step against the rule's own text.

Rule 7, official text with sources

Sources cited on this page

  1. [1]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 7, p. 26. Published 13 November 2025. Official source ↗ · Official requirement · Verified 16 August 2026Rule 7(2), truncated before items (i) to (vi), which are restated in the article.
  2. [2]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 1, (4), p. 24. Published 13 November 2025. Official source ↗ · Official requirement · Verified 16 August 2026As printed in Gazette No. 760. Corrigenda G.S.R. 892(E) item (i)(b) corrects the closing words to read "in the Official Gazette". The commencement periods and derived dates are unaffected.
  3. [3]Corrigenda to the Digital Personal Data Protection Rules, 2025 (G.S.R. 892(E)), (i)(b), p. 1. Published 11 December 2025. Official source ↗ · Official requirement · Verified 16 August 2026Corrects the wording of Rule 1(4) quoted above.
  4. [4]Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)), p. 1. Published 13 November 2025. Official source ↗ · Interpretation, requires judgment · Verified 16 August 202613 May 2027 is computed from the publication date printed on Gazette issue No. 760 and is presented as interpretation until officially confirmed.

data breachrule 7board intimation