Skip to main content

The 3rd and main DPDP commencement date is computed as 13 May 2027, which is interpretation until officially confirmed.

Sources last verified on 23 September 2026. Methodology

Tool

Data breach response playbook

Your organisation just became aware of a personal data breach. Work this page top to bottom: contain and anchor the clock, run the 2 without delay duties in parallel, file the detailed Board submission inside 72 hours, then stabilise. Required steps carry the official source; recommended steps are marked as practice.

Commencement note: Rules 3, 5 to 16, 22 and 23 are not yet in force. The computed date is 13 May 2027, which is interpretation until officially confirmed. Basis of the computation: Publication date 13 November 2025 printed on Gazette issue No. 760, plus eighteen months. The eGazette portal lists this document with a code embedding 14112025 and the Government's own PIB release states 14 November 2025, which would move the computed date by 1 day; the printed masthead date is used, and the interpretation label carries that uncertainty. The corrigendum wording change does not affect this computation. Building ahead of the duty is the practical move. See Rule 7, official text.

Loading your saved progress from this browser…

The provisions this tool rests on

The provisions below are the sources for the legal statements on this page. Each links to the official document it was verified against, and to the provision on this site wherever this site publishes that provision. The label says whether the site is reporting a requirement, explaining it, reading it, recommending something, or pointing at a text it does not restate.

  • DPDP Rules 2025, r. 7, (1)

    Official requirement · Verified 16 August 2026

    Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed

    (1) On becoming aware of any personal data breach, the Data Fiduciary shall, to the best of its knowledge, intimate to each affected Data Principal, in a concise, clear and plain manner and without delay, through her user account or any mode of communication registered by her with the Data Fiduciary, — (a) a description of the breach, including its nature, extent and the timing of its occurrence; (b) the consequences relevant to her, that are likely to arise from the breach; (c) the measures implemented and being implemented by the Data Fiduciary, if any, to mitigate risk; (d) the safety measures that she may take to protect her interests; and (e) business contact information of a person who is able to respond on behalf of the Data Fiduciary, to queries, if any, of the Data Principal.

    Rule 7 on this site Official source ↗ Also on MeitY (byte identical) ↗

  • DPDP Rules 2025, r. 7, (2)

    Official requirement · Verified 16 August 2026

    Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed

    (2) On becoming aware of any personal data breach, the Data Fiduciary shall intimate to the Board, — (a) without delay, a description of the breach, including its nature, extent, timing and location of occurrence and the likely impact; (b) within seventy-two hours of becoming aware of the breach, or within such longer period as the Board may allow on a request made in writing in this behalf, — (i) updated and detailed information in respect of such description; (ii) the broad facts related to the events, circumstances and reasons leading to the breach; (iii) measures implemented or proposed, if any, to mitigate risk; (iv) any findings regarding the person who caused the breach; (v) remedial measures taken to prevent recurrence of such breach; and (vi) a report regarding the intimations given to affected Data Principals.

    Rule 7 on this site Official source ↗ Also on MeitY (byte identical) ↗

  • DPDP Act 2023, s. 8, (1)

    Official requirement · Verified 17 August 2026

    Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed

    (1) A Data Fiduciary shall, irrespective of any agreement to the contrary or failure of a Data Principal to carry out the duties provided under this Act, be responsible for complying with the provisions of this Act and the rules made thereunder in respect of any processing undertaken by it or on its behalf by a Data Processor.

    Section 8 on this site Official source ↗

  • DPDP Act 2023, s. 8, (5)

    Official requirement · Verified 17 August 2026

    Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed

    (5) A Data Fiduciary shall protect personal data in its possession or under its control, including in respect of any processing undertaken by it or on its behalf by a Data Processor, by taking reasonable security safeguards to prevent personal data breach.

    Section 8 on this site Official source ↗

  • DPDP Act 2023, s. 27

    Official requirement · Verified 17 August 2026

    Phased commencement; it commences in 2 parts, on the computed date 13 November 2026, which is interpretation until officially confirmed, then the computed date 13 May 2027, which is interpretation until officially confirmed

    (1) The Board shall exercise and perform the following powers and functions, namely:— (a) on receipt of an intimation of personal data breach under sub-section (6) of section 8, to direct any urgent remedial or mitigation measures in the event of a personal data breach, and to inquire into such personal data breach and impose penalty as provided in this Act;

    Section 27 on this site Official source ↗

    Quoted here is clause (a) of sub-section (1) alone, the breach intimation limb this step rests on. Sub-section (1) runs to clause (e) on the same Gazette page, covering complaints by a Data Principal, complaints about a Consent Manager, breach of a condition of registration and a section 37(2) reference; sub-sections (2) and (3) carry the Board's power to issue directions and to modify, suspend, withdraw or cancel them.

  • DPDP Act 2023, s. 32

    Official requirement · Verified 17 August 2026

    Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed

    (1) The Board may accept a voluntary undertaking in respect of any matter related to observance of the provisions of this Act from any person at any stage of a proceeding under section 28.

    Section 32 on this site Official source ↗

  • Notification establishing the Data Protection Board of India, p. 2

    Official requirement · Verified 20 August 2026

    Document status: published; in effect

    In exercise of the powers conferred by sub-sections (1) and (3) of section 18 of the Digital Personal Data Protection Act, 2023 (22 of 2023), the Central Government hereby establishes, the Data Protection Board of India, to exercise the powers conferred on, and to perform the functions assigned to it under the said Act, with effect from the date of publication of this notification in the Official Gazette. 2. The head office of the Data Protection Board of India shall be in the National Capital Region of India.

    Official source ↗ Also on MeitY (byte identical) ↗

  • DPDP Act 2023, s. 28

    Official requirement · Verified 20 August 2026

    Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed

    (1) The Board shall function as an independent body and shall, as far as practicable, function as a digital office, with the receipt of complaints and the allocation, hearing and pronouncement of decisions in respect of the same being digital by design, and adopt such techno-legal measures as may be prescribed.

    Section 28 on this site Official source ↗

Sources cited on this page

  1. [1]
    Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 7, (1), p. 26. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Official requirement · Verified 16 August 2026
  2. [2]
    Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 7, (2), p. 26. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Official requirement · Verified 16 August 2026
  3. [3]
    The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 8, (1), p. 7. Published 11 August 2023. Official source ↗ · Official requirement · Verified 17 August 2026
  4. [4]
    The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 8, (5), p. 7. Published 11 August 2023. Official source ↗ · Official requirement · Verified 17 August 2026
  5. [5]
    The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 27, p. 14. Published 11 August 2023. Official source ↗ · Official requirement · Verified 17 August 2026Quoted here is clause (a) of sub-section (1) alone, the breach intimation limb this step rests on. Sub-section (1) runs to clause (e) on the same Gazette page, covering complaints by a Data Principal, complaints about a Consent Manager, breach of a condition of registration and a section 37(2) reference; sub-sections (2) and (3) carry the Board's power to issue directions and to modify, suspend, withdraw or cancel them.
  6. [6]
    The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 32, p. 16. Published 11 August 2023. Official source ↗ · Official requirement · Verified 17 August 2026
  7. [7]
    Notification establishing the Data Protection Board of India (G.S.R. 844(E)), p. 2. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Official requirement · Verified 20 August 2026
  8. [8]
    The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 28, p. 14. Published 11 August 2023. Official source ↗ · Official requirement · Verified 20 August 2026

Read the guide

DPDP breach reporting under Rule 7 Rule 7 read line by line, including what the intimation must contain and the myth about affected numbers.