DPDP Rules 2025 · Rule 7
Intimation of personal data breach
- Status
- Not yet in force
- Commencement
- 13 May 2027 · computed date, presented as interpretation until officially confirmed (how it is computed)
- Source
- Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) · G.S.R. 846(E) · Gazette page 26
- Last verified
- 16 August 2026
What Rule 7 says, in plain English
Plain English
Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed. The summary below is what the provision says, not what is in force today. Status last checked 28 September 2026 against the MeitY library and India Code.
After becoming aware of a personal data breach, a Data Fiduciary must promptly tell each affected Data Principal, in clear and plain terms, what happened, the likely consequences, mitigation steps, safety measures and a contact person. It must also notify the Board without delay and send detailed information within 72 hours, or longer if the Board allows.
How 13 May 2027 is computed, and why it could be 1 day later
Publication date 13 November 2025 printed on Gazette issue No. 760, plus eighteen months. The eGazette portal lists this document with a code embedding 14112025 and the Government's own PIB release states 14 November 2025, which would move the computed date by 1 day; the printed masthead date is used, and the interpretation label carries that uncertainty. The corrigendum wording change does not affect this computation.
Official text of Rule 7
Rule 7. Intimation of personal data breach.(1) On becoming aware of any personal data breach, the Data Fiduciary shall, to the best of its knowledge, intimate to each affected Data Principal, in a concise, clear and plain manner and without delay, through her user account or any mode of communication registered by her with the Data Fiduciary, — (a) a description of the breach, including its nature, extent and the timing of its occurrence; (b) the consequences relevant to her, that are likely to arise from the breach; (c) the measures implemented and being implemented by the Data Fiduciary, if any, to mitigate risk; (d) the safety measures that she may take to protect her interests; and (e) business contact information of a person who is able to respond on behalf of the Data Fiduciary, to queries, if any, of the Data Principal. (2) On becoming aware of any personal data breach, the Data Fiduciary shall intimate to the Board, — (a) without delay, a description of the breach, including its nature, extent, timing and location of occurrence and the likely impact; (b) within seventy-two hours of becoming aware of the breach, or within such longer period as the Board may allow on a request made in writing in this behalf, — (i) updated and detailed information in respect of such description; (ii) the broad facts related to the events, circumstances and reasons leading to the breach; (iii) measures implemented or proposed, if any, to mitigate risk; (iv) any findings regarding the person who caused the breach; (v) remedial measures taken to prevent recurrence of such breach; and (vi) a report regarding the intimations given to affected Data Principals.
Commencement basis · Rules 3, 5 to 16, 22 and 23
“Rules 3, 5 to 16, 22 and 23 shall come into force eighteen months after the date of publication in the Official Gazette.”
Wording as corrected by corrigenda G.S.R. 892(E).
Sources cited on this page
- [1]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 7, p. 26. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Official requirement · Verified 16 August 2026Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed
- [2]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 1, (4), p. 24. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Printed text, since corrected by G.S.R. 892(E); quoted as published · Verified 16 August 2026In force since 13 November 2025
Rules 3, 5 to 16, 22 and 23 shall come into force eighteen months after the date of publication of this Gazette.
As printed. Corrigenda G.S.R. 892(E) item (i)(b) corrects the closing words to read in the Official Gazette; the computation is unaffected. - [3]Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)), p. 1. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Interpretation, requires judgment · Verified 16 August 2026Document status: published; text subject to corrigendum G.S.R. 892(E)The calendar date 13 May 2027 is computed from the printed publication date and is presented as interpretation until officially confirmed.