← Back to Knowledge Hub

An engineer notices on Monday morning that a server has been sitting open to the internet. Before anyone has worked out how long it was exposed, two legal clocks are already running, and they run at different speeds.

On becoming aware of a personal data breach, a Data Fiduciary must intimate the Data Protection Board and the affected individuals without delay, and file a detailed report with the Board within 72 hours β€” separately from CERT-In's six-hour cyber-incident rule, which still applies.

The bottom line

Who you tell: the affected Data Principals and the Data Protection Board, both without delay, with the Board's detailed report following within 72 hours.

What the notice must say: what happened, what data was exposed, the likely consequences, what the person can do about it, and how to reach you.

What it costs: up to β‚Ή200 crore for failing to notify, and up to β‚Ή250 crore for the weak security underneath. One incident can trigger both.

What counts as a breach

A personal data breach is any unauthorised processing, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data that compromises its confidentiality, integrity or availability.

That definition is broad on purpose. It reaches well past a hacker stealing a database: an employee emailing a customer list to the wrong address, a misconfigured cloud bucket left public, a laptop left in a taxi, ransomware locking you out of your own records. If the security of personal data has been compromised, the duty to notify has been triggered.

Who you notify, and how fast

Two duties start at the moment you become aware.

  1. The affected Data Principals β€” intimate them without delay, individually.
  2. The Data Protection Board β€” an initial intimation without delay, followed by a detailed report within 72 hours. The Board may allow longer on request.

There is no severity threshold letting you stay quiet. The framework is built on prompt transparency rather than on your own judgment about whether a breach was serious enough to mention.

What the notice to individuals must say

The notice has to be useful to the person reading it, which rules out most legal boilerplate. In plain language it must describe:

  • what happened β€” the nature and broad cause of the breach;
  • what data was exposed β€” the categories of personal data involved;
  • the likely consequences for that individual;
  • the protective steps available to them, such as resetting passwords or watching for fraudulent transactions; and
  • your contact details, and the safeguards you have since put in place.

The detailed report to the Board goes further, covering timing, circumstances, mitigation already carried out and remedial measures planned.

Two regulators, two clocks

Here is the part that catches businesses out. The DPDP duty runs in parallel with CERT-In's 2022 direction, which requires specified cyber incidents to be reported within six hours.

The same incident may therefore need reporting to two regulators, on two different timelines, through two different channels: CERT-In within six hours, the Board without delay with the detailed report at 72 hours. An incident-response plan that only wires in one of them will meet a deadline and miss a deadline in the same afternoon.

The penalties

FailureMaximum penalty
Failure to notify a personal data breachβ‚Ή200 crore
Failure to implement reasonable security safeguardsβ‚Ή250 crore

Penalties apply per contravention, so a single incident can attract both β€” the weak security that allowed the breach, and the failure to report it properly. Before fixing an amount the Board weighs the statutory factors: the nature and gravity of the breach, the steps taken to mitigate it, and so on.

The Board can also publish the violation. For most businesses that power is the one worth planning around, because the fine is paid once and the search result stays.

The playbook, and what to have ready first

None of this can be drafted during a live incident. Some of it has to exist beforehand: a written decision on who is authorised to declare a breach and who notifies whom, pre-drafted notice templates for individuals and for the Board, monitoring that flags anomalous access early, and a map of which systems hold personal data so that scoping takes minutes rather than days.

With that in place the response runs in sequence:

  1. Detect and contain β€” isolate the affected systems.
  2. Assess β€” what data, whose data, how much, and the likely impact.
  3. Notify on both clocks β€” CERT-In within six hours, the Board without delay, the detailed report within 72 hours.
  4. Notify individuals β€” plain-language notices carrying the protective steps.
  5. Mitigate and remediate β€” close the hole, rotate credentials, document as you go.
  6. Review β€” root-cause analysis and a fix that stops the recurrence.

Run a tabletop drill against it at least once before May 2027, so the timeline is familiar rather than novel on the day it matters.

A worked example

A health-tech app discovers at 9 a.m. on a Monday that a misconfigured server exposed 40,000 users' names, phone numbers and appointment histories.

  • By 3 p.m. Monday, six hours in: the cyber-incident report goes to CERT-In.
  • The same day, without delay: initial intimation to the Data Protection Board, and notification to the 40,000 affected users β€” what leaked, what to watch for, who to contact.
  • By 9 a.m. Thursday, at 72 hours: the detailed report to the Board, covering cause, scope, mitigation and remedial measures.
  • Throughout: contain the server, rotate credentials, start the root-cause fix.

A company with this written down executes it. A company without it spends the first day deciding who is in charge.

Common mistakes

  • Holding a breach back to investigate it properly first. The duty is prompt notification, not a finished investigation.
  • Forgetting CERT-In. The six-hour rule is separate from DPDP and it expires much sooner.
  • Writing the notice in legal language. The person reading it needs to know what to do next.
  • Having no written playbook. Drafting under pressure is how a clock gets missed.
  • Treating breach response as an IT matter. It is legal, communications and engineering at the same time.

Frequently asked questions

What is the breach notification timeline under the DPDP Act? Intimate the Board and the affected individuals without delay, and file a detailed report with the Board within 72 hours.

What is the penalty for not reporting a data breach? Up to β‚Ή200 crore for failing to notify, and up to β‚Ή250 crore for failing the underlying security safeguards, per contravention.

How does DPDP interact with CERT-In's six-hour rule? They apply in parallel. The same incident may need a CERT-In report within six hours and a DPDP report to the Board within 72 hours, through different channels.

Do I have to tell affected users about every breach? Yes. The Act requires intimating affected Data Principals without delay, in plain language, with the protective steps they can take.

Who must report a breach? Every Data Fiduciary β€” the business determining the purpose and means of processing β€” even where a processor was handling the data when it went wrong.

What if we are still not sure how bad it is? Notify anyway. The initial intimation is not the detailed report, and the 72-hour report is where the fuller picture goes.