Data Breach Notification Under DPDP: The 72-Hour Drill
What counts as a personal data breach under DPDP, who must be notified and how fast, and how to build a breach-response drill your team can actually run.
Under the DPDP Act, a personal data breach triggers an obligation to notify both the Data Protection Board and the affected individuals - and the practical discipline every organisation should build now is a drill that gets from detection to notification fast.
Key facts at a glance
- A personal data breach covers unauthorised access, disclosure, alteration, loss or destruction of personal data.
- Notification is owed to both the Data Protection Board of India and the affected data principals.
- Many organisations plan around a 72-hour internal response target as good breach-response practice.
- Penalties for inadequate security safeguards can reach up to Rs 250 crore per instance.
- Full DPDP obligations, including breach notification, become enforceable from 13 May 2027.
- The data fiduciary stays accountable even if a third-party processor caused the breach.
- The Data Protection Board provisions are already active ahead of the full 2027 enforcement date.
What Counts as a Breach
DPDP defines a personal data breach broadly. It is not limited to a hacker stealing a database - it includes:
- Accidental exposure of data (e.g. a misconfigured cloud storage bucket left public)
- Loss of a device containing unencrypted personal data
- Unauthorised access by an employee outside their role
- Ransomware or malware incidents affecting systems that hold personal data
- Sending personal data to the wrong recipient at scale
The common thread is any compromise of confidentiality, integrity or availability of personal data - not just theft.
Who Needs to Know, and In What Order
| Recipient | What they need | Why |
|---|---|---|
| Data Protection Board of India | Details of the breach, scope, and remedial steps | Regulatory oversight and potential inquiry |
| Affected data principals | Notice that their data was compromised and what to do | Lets individuals protect themselves (e.g. change passwords, monitor accounts) |
| Internal leadership/board | Incident summary and business impact | Governance and disclosure obligations |
| Vendors/processors involved | Coordination on containment and root cause | Shared responsibility for fixing the issue |
Building a 72-Hour Drill
Many organisations use a 72-hour internal target - a widely recognised benchmark from other data-protection regimes - as the pace to aim for, even while confirming exact prescribed timelines under the applicable DPDP Rules. A workable drill breaks into four phases:
Hour 0-4: Detect and Contain
- Identify the system or data affected.
- Isolate affected systems to stop further exposure.
- Assign an incident owner (not necessarily the most senior person - the one who can act fastest).
Hour 4-24: Assess Scope
- Determine what data categories were involved (e.g. names and emails vs. financial or health data).
- Estimate how many data principals are affected.
- Check whether a third-party processor was involved and pull them into the response.
Hour 24-48: Prepare Notifications
- Draft the notification to the Data Protection Board with a factual, non-speculative account of what is known so far.
- Draft a plain-language notice for affected individuals - what happened, what data, what they should do.
- Loop in legal/compliance advisors if available.
Hour 48-72: Notify and Remediate
- Send notifications.
- Begin remediation: patch the vulnerability, rotate credentials, review access logs.
- Document the entire timeline - what was detected when, and what actions were taken - since this record matters if the Board asks questions later.
Why the Drill Matters Even Before 2027
Full DPDP obligations are enforceable from 13 May 2027, but breaches do not wait for enforcement dates. A business that has never rehearsed this process will lose critical hours figuring out who does what, while a business with even a one-page runbook can move immediately. Waiting until an actual incident to design the process is the most common and costly mistake.
Practical Steps to Prepare Now
- Write a one-page breach-response runbook naming who does what in the first 72 hours.
- Identify your Data Protection Board contact point and process in advance, so you are not searching for it during an incident.
- Pre-draft a notification template for affected individuals that can be filled in quickly.
- Review vendor contracts to ensure processors are contractually required to notify you promptly of any incident on their end.
- Run a tabletop exercise at least once a year with the team that would actually respond.
If you are not sure how ready your business is to handle a breach notification under DPDP, ComplianceCheck's DPDP assessment gives you a clear picture in a few minutes.
Sources
- Ministry of Electronics and Information Technology, DPDP Act and Rules - meity.gov.in
- Data Protection Board of India
This guide is general information, not legal advice. Requirements vary by state, sector and headcount - confirm specifics with a compliance professional or the relevant authority.
Frequently Asked Questions
- What is a personal data breach under DPDP?
- A personal data breach is any unauthorised processing of personal data, or any accidental or unauthorised loss, disclosure, alteration, destruction or acquisition of it, that compromises confidentiality, integrity or availability.
- Who has to be notified after a data breach under DPDP?
- A data fiduciary must notify the Data Protection Board of India and the affected data principals whose personal data was compromised.
- How fast must a breach be reported under DPDP?
- The DPDP framework expects prompt notification without undue delay; many organisations plan around a 72-hour internal response target as good practice, similar to other global data-protection regimes, though businesses should confirm the exact prescribed timeline under the applicable Rules.
- What is the penalty for failing to report a breach or secure data adequately under DPDP?
- Penalties for failing to implement reasonable security safeguards, which includes breach-related failures, can reach up to Rs 250 crore per instance.
- Is a data fiduciary liable for a breach caused by its vendor?
- Yes, the data fiduciary remains accountable to data principals and the Data Protection Board even when a third-party data processor is the direct cause of the breach.
- When does breach notification become a fully enforceable obligation?
- Full substantive DPDP obligations, including breach notification, become enforceable from 13 May 2027, with no stated grace period after that date.
- Should a small business without a dedicated IT team worry about breach notification?
- Yes - the DPDP Act does not exempt small businesses from breach-notification obligations, so even a small team handling customer or employee data should have a basic response plan.
Check your status
DPDP Gap Assessment
A 45-question gap assessment for the Digital Personal Data Protection (DPDP) Act 2023, scoring data-protection maturity across 6 phases.