
Law
Data breach under DPDP: who to tell, what to tell them and when
· 6 min read
Reviewed by Adv. Mahir Gupta, Advocate, Delhi High Court ·
A company discovers that a customer database has been copied, or that an employee's mailbox has been taken over. Within hours, three different audiences need to hear about it: the national incident-response agency, the Data Protection Board and the people whose data was exposed. Each has its own clock. Confusing them is the most common mistake we see in breach planning, so this post sets them out side by side.
First, the dates. The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025. The Data Protection Board came into being at once, and the main duties of Data Fiduciaries, including breach notification, apply after an 18-month phase-in, on 13 May 2027 (counted from the Rules' publication; confirm the exact date against the Gazette text for your compliance calendar). Until then, the breach duty that binds almost every Indian company is not the DPDP one. It is CERT-In's.
CERT-In, the Indian Computer Emergency Response Team, issued directions under Section 70B(6) of the Information Technology Act, 2000 on 28 April 2022, effective 27 June 2022. They require a service provider, intermediary, data centre, body corporate or government organisation to report specified cyber incidents within 6 hours of noticing them or being told of them. The list of reportable incidents has 20 categories, and data breach and data leak are both on it, alongside targeted scanning, website defacement and unauthorised access to social media accounts. Reports may be made by email, phone or fax, and the published guidance points to incident@cert-in.org.in.
The CERT-In direction does not wait for May 2027, and it does not ask whether personal data is involved. A ransomware attack on a server with no customer records is still reportable. The same directions also require logs of ICT systems to be kept for a rolling 180 days within India, so that an investigation has something to work with. Failing to provide information called for by CERT-In, or to comply with its directions, is punishable under Section 70B(7) of the IT Act with imprisonment of up to one year, or a fine of up to ₹1 lakh, or both.
Now the DPDP side. Rule 7 of the DPDP Rules, 2025 deals with intimation of a personal data breach. It applies to any personal data breach. Analysts have pointed out that, unlike the laws of the EU, UK or Australia, there is no harm threshold that lets a company decide a minor incident need not be reported.
Rule 7 has three parts. First, the Data Fiduciary must inform each affected Data Principal without delay, in a concise, clear and plain manner, through the person's user account or registered mode of communication. The message must describe the nature, extent and timing of the breach, its likely consequences for that person, the mitigation steps taken, safety measures the person can take, and business contact details of someone who can answer questions.
Second, the Data Fiduciary must inform the Data Protection Board without delay, with a description of the breach covering its nature, extent, timing, location and likely impact. Third, within 72 hours, or a longer period if the Board allows, it must give the Board a detailed report: the facts and circumstances that led to the breach, the mitigation measures taken or proposed, findings about who caused it, the steps to prevent recurrence, and a report on the notices sent to Data Principals. The 72 hours is therefore the second report to the Board, not the first and not the deadline for telling individuals.
The consequences of getting this wrong are significant. Under the Schedule to the Digital Personal Data Protection Act, 2023, as reported in law-firm commentary, failing to give the required breach intimation (Section 8(6)) can attract a penalty of up to ₹200 crore, and failing to maintain reasonable security safeguards (Section 8(5)) can attract up to ₹250 crore. Penalties are imposed by the Board after an inquiry.
How do the two clocks fit together? In practice, CERT-In's 6 hours is the short fuse and the DPDP duties are the longer chain. Hour 0 is when anyone in the organisation notices the incident. By hour 6, a first CERT-In report should be in, even if facts are incomplete. If personal data is involved, the Board intimation and the notices to Data Principals follow without delay, and the detailed Board report is due within 72 hours of the Data Fiduciary becoming aware of the breach. Awareness may be argued to come later than the first notice inside the organisation, but planning on a single hour 0 is the safer course. Since the DPDP duties start only in May 2027, treat the next several months as rehearsal time: companies that already run the 6-hour drill have most of the machinery needed.
Here is a first-24-hours action list. One: record the time the incident was first noticed and who noticed it. Two: appoint one incident lead and one person who talks to regulators. Three: contain without destroying evidence, which means isolating systems, rotating credentials and preserving logs rather than wiping machines. Four: file the first CERT-In report within 6 hours. Five: establish what personal data, and whose, may be involved. Six: draft the Data Principal notice in plain language with a named contact. Seven: prepare the Board intimation and, once DPDP duties apply, send it without delay. Eight: brief the board, your counsel and any affected business partners, and keep a written timeline. Nine: set a calendar alert for hour 72.
Two cautions. Do not wait for a full forensic picture before you notify; both regimes are built around early, partial reports followed by detail. And do not let a notice to customers go out before the facts have been checked by someone who can say what is and is not known, because an inaccurate notice creates its own problems.
If you are an individual rather than a company, and an organisation tells you your data was exposed, change the passwords on that account and anywhere you reused them, watch for phishing that uses the leaked details, and if money has been lost, call 1930 and file a complaint at cybercrime.gov.in at once.
Organisations that want help preparing for these clocks should work with their own legal counsel and security team. Useful preparation includes tabletop drills for the first 24 hours, log and evidence preservation, and draft CERT-In and Board report templates that the organisation's own counsel and officers approve. The aim is simple: when an incident happens, nobody should be working out who to call while the hours run.
Sources
- Alston & Bird: New Cybersecurity Rules In India Impose Strict Reporting Requirements and Steep Penalties
- Siri Law LLP: A comprehensive guide to India's CERT-In 6-hour cyber incident reporting mandate
- dpdprules.org: Rule 7 DPDP Rules 2025, Intimation of personal data breach
- K&S Partners: Data Breach Response Under India's DPDP Act
- Privacy World: India Passes the Digital Personal Data Protection Rules
Need help with a cyber crime? Cyber Surety is a cyber-safety membership by Codesnag × VirtualVakil: ethical hackers and lawyers on your case, 24×7 on WhatsApp. Or read how to file a cyber crime complaint.

