Under India’s Digital Personal Data Protection (DPDP) Act and Rules, a data fiduciary that suffers a personal data breach must tell the Data Protection Board of India without delay and follow up with a detailed report within 72 hours, and must also inform every affected individual. These duties are part of the 18-month phased rollout of the Rules, so most businesses should be building their breach playbook now.
This article is general information, not legal advice. Consult a qualified lawyer for your situation.
What counts as a personal data breach under the DPDP Act?
The Act defines a personal data breach broadly: any unauthorised processing of personal data, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to it, that compromises confidentiality, integrity or availability. That covers more than hacking. A misconfigured cloud bucket, a lost laptop, a ransomware lock-out or an employee emailing a spreadsheet to the wrong person can all qualify.
There is no “harm threshold” in the Act’s wording. Unlike some other regimes, the duty to notify is not limited to high-risk incidents, so teams should assume that any confirmed incident touching personal data needs to be assessed against Rule 7.
Rule 7: the DPDP breach notification timeline
Rule 7 splits the work into two audiences and, for the Board, two stages.
| Who is told | When | What they receive |
|---|---|---|
| Affected data principals | Without delay | Plain-language description, likely consequences, mitigation steps, safety measures they can take, and a business contact |
| Data Protection Board (initial) | Without delay | Nature, extent, timing, location and likely impact of the breach |
| Data Protection Board (detailed) | Within 72 hours (the Board may allow longer on a written request) | Updated facts, causes, mitigation, findings about who was responsible, preventive steps and confirmation that individuals were informed |
The clock runs from when you become aware of the breach, not from when your investigation ends. Some commentary online describes the 72-hour step as the one aimed at individuals; the Rule text as summarised by several sources places 72 hours on the detailed Board report, so read the notified Rules directly when you finalise your procedure.
When do these obligations start?
The DPDP Rules were notified in November 2025, with provisions switching on in phases. The Board’s constitution came first, consent manager registration follows at around the one-year mark (see our guide to the DPDP consent manager rules for November 2026), and the main fiduciary duties, including breach intimation, are generally expected around 18 months after notification, close to May 2027. Some blogs claim the date has been accelerated; I could not confirm that from an official source, so treat it as unverified.
Penalties for failing to report a data breach
The Schedule to the Act sets maximum penalties that matter for breach handling:
- Up to ₹250 crore for failing to take reasonable security safeguards to prevent a breach.
- Up to ₹200 crore for failing to notify the Board or affected data principals of a breach.
These are ceilings, not fixed fines, and the Board weighs the nature, gravity and duration of the failure. Still, a late or missing report is a separate violation on top of the breach itself.
DPDP breach response checklist
A workable plan turns the Rule 7 content list into templates you can fill under pressure.
- Detect and log. Rule 6 expects security controls such as encryption, access control, monitoring and retention of relevant logs, which also give you the evidence to describe what happened.
- Contain. Isolate affected systems, revoke exposed keys and stop further leakage before drafting notices.
- Assess scope. Identify which data principals and which categories of personal data were involved, and when and where it occurred.
- Notify the Board. Send the initial intimation without delay, then the detailed report inside 72 hours.
- Notify individuals. Use plain language, say what they can do to protect themselves, and name a contact who can answer questions.
- Run CERT-In in parallel. Reportable cyber incidents carry a separate six-hour reporting direction under CERT-In rules.
- Review and fix. Document root cause and preventive measures; you will need them for the Board.
AI systems and breaches: the DPDP niche most teams miss
AI products create breach paths that classic playbooks overlook. A chatbot that leaks one user’s prompt history to another, a retrieval index exposing documents to the wrong tenant, logs that store raw prompts containing personal data, or a training dataset copied to an unsecured bucket are all potential personal data breaches. If you use model APIs or third-party AI vendors, you remain the data fiduciary for that data, so your processor contracts should require prompt incident alerts and the logs you need to meet Rule 7.
If you train or fine-tune on personal data, also read our piece on AI training data under the DPDP Act, and if your product retrieves documents at query time, the access-control lessons in RAG vs fine-tuning in 2026 apply directly. For a broader starting point, see a beginner’s guide to implementing DPDP strategies.
Common mistakes when preparing a breach notification process
Most failures come from process gaps rather than technology. Teams wait for a complete forensic report before telling anyone, even though Rule 7 expects an initial intimation without delay and allows the detail to follow. Others write notices full of jargon, which defeats the plain-language requirement, or forget that user contact details must be reachable at short notice. A further trap is leaving legal, security and product teams in separate silos, so nobody owns the clock.
Run a tabletop exercise at least once a year. Pick a realistic scenario, such as an AI assistant exposing another customer’s conversation, and time how long it takes to identify affected users, draft the Board report and send individual notices. Keep the evidence: delivery logs of notices sent, timelines, and decisions made. If the Board later asks questions, a clear paper trail shows you took the obligations seriously.
Finally, align your internal severity ladder with the legal triggers. Anything involving confirmed personal data exposure should escalate to your privacy lead automatically, rather than being judged only on business impact.
Frequently asked questions
Is the 72-hour deadline for notifying the Data Protection Board already in force?
Not yet for most obligations. The DPDP Rules were notified in November 2025 and phase in over 18 months, so the core data fiduciary duties, including breach intimation, are generally expected to apply from around May 2027. Check the Rules’ commencement provisions for your exact date.
Do I have to tell every affected person about a breach?
Yes. Under Section 8(6) of the DPDP Act, a data fiduciary must inform the Board and each affected data principal, and Rule 7 asks for this to be done without delay in plain language through the person’s account or registered contact mode.
What is the maximum penalty for failing to report a breach?
The Act’s Schedule sets a penalty of up to ₹200 crore for failing to notify the Board or affected data principals, and up to ₹250 crore for failing to take reasonable security safeguards. Actual penalties depend on the Board’s assessment.
Does CERT-In reporting replace DPDP breach reporting?
No. CERT-In’s separate directions require reporting specified cyber incidents within six hours, and that duty runs in parallel with, not instead of, DPDP intimation.
Does a breach at my AI vendor or processor count as my breach?
Generally yes. The data fiduciary stays responsible for personal data processed on its behalf, so contracts with processors and AI vendors should require prompt incident alerts so you can meet your own deadlines.
Conclusion
The practical takeaway: be able to describe a breach to the Board immediately, to your users in plain words, and in detail within 72 hours. Draft the templates, assign owners, test the process with an AI-specific scenario, and tighten processor contracts well before the main obligations take effect.