DPDP Basics · July 2026 · 8 min read
Breach notification is where DPDP compliance becomes a stopwatch. Most obligations under the Act can be built calmly over months. This one is tested during the worst week your IT team will have — and failing it carries a penalty of up to ₹200 crore, separate from and additional to the penalty for the breach itself. Here is what the framework requires and how to build a response that actually works under pressure.
What counts as a personal data breach
The Act defines it broadly: any unauthorised processing of personal data, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access, that compromises the confidentiality, integrity or availability of personal data.
Three consequences of that breadth are routinely missed:
- No harm threshold. There is no "only if it's serious" filter for notification to individuals, unlike GDPR's high-risk test.
- Availability counts. A ransomware event that encrypts your own data — with no exfiltration at all — is a breach, because you lost access.
- Accidents count. An email with a student list sent to the wrong parent group, a misconfigured cloud bucket, a lost laptop, an employee taking a customer list on exit — all breaches.
Who you must notify
Every affected data principal — without delay
In plain language, concise and understandable, covering: the nature and extent of the breach, when and where it occurred, the likely consequences relevant to that individual, the measures being taken to mitigate risk, safety measures the individual should consider taking, and the contact details of a person able to answer their questions.
The Data Protection Board — promptly, then in detail
An initial intimation on becoming aware of the breach, followed within 72 hours by a detailed report covering: the events and circumstances leading to the breach, its broad facts and the reasons for it; the mitigation measures implemented; the findings on the person who caused it, if determined; remedial measures to prevent recurrence; and a report on the intimations given to affected data principals.
The clock starts when you become aware — not when your investigation concludes.
Don't forget parallel obligations
DPDP notification does not replace sectoral duties. CERT-In directions require reporting specified cyber incidents within their own tight window; RBI, IRDAI and SEBI impose their own timelines on regulated entities. Your playbook needs all applicable clocks running in parallel, not sequentially.
The hour-by-hour playbook
Hours 0–4: Detect, convene, contain
- Trigger the incident response team; assign a single incident commander with decision authority.
- Start the evidence log immediately — every action, with timestamp and owner. This becomes your submission to the Board and your defence on the "mitigation" factor in penalty assessment.
- Contain: isolate affected systems, revoke compromised credentials, block exfiltration paths. Preserve forensic evidence — don't wipe and rebuild before imaging.
Hours 4–24: Scope — the hard part
You must answer: which personal data, of which individuals, was affected? This is where most organisations fail, because they discover mid-incident that no one knows what was on that file share. Organisations with a current data inventory and classification answer in hours; organisations without spend days and still submit an estimate to the regulator.
- Identify affected data stores and map them to data categories and individuals.
- Determine attack vector and dwell time from logs — which is why log retention is a safeguard requirement, not housekeeping.
- Draft the initial intimation to the Board in parallel; do not wait for perfect scoping.
Hours 24–48: Notify individuals
- Send plain-language intimations to affected principals — email, SMS or in-app as appropriate, in accessible language.
- Stand up a response channel: a named contact, FAQ page and staff briefed with consistent answers. Expect questions from customers, parents, employees and media simultaneously.
- Record proof of every intimation sent — the Board's 72-hour report requires an account of these notifications.
Hours 48–72: The detailed report
- Compile: circumstances and cause, broad facts, mitigation taken, findings on who caused it (if known), remedial measures to prevent recurrence, and the intimation report.
- Have counsel review before submission — this document will be read as your admission of facts.
- File within the window, even if the forensic investigation continues; note what remains under investigation rather than missing the deadline.
After 72 hours
Complete forensics, implement the remedial measures you committed to, update the risk register, and run a post-incident review. If the Board opens an inquiry, your evidence log and remediation record are the two documents that most influence the outcome.
Build it before you need it
Three investments turn this from a crisis into a procedure: a current data inventory so you can scope fast; logging and monitoring so you can detect and reconstruct; and a rehearsed playbook with named roles and pre-drafted notification templates. Run a tabletop exercise once a year — the first time you test the 72-hour clock should not be the day it is running.
Frequently asked questions
What is the DPDP breach notification deadline in India?
Affected data principals must be intimated without delay in plain language, and the Data Protection Board must receive an initial intimation on becoming aware of the breach followed by a detailed report within 72 hours covering cause, mitigation, remedial measures and the intimations given.
Does a ransomware attack count as a personal data breach under the DPDP Act?
Yes. The Act's definition includes loss of access to personal data, so a ransomware event that encrypts data and denies availability is a personal data breach even if no data was exfiltrated.
Do we have to notify every affected individual, even for a minor breach?
Yes. Unlike GDPR, the DPDP framework does not apply a high-risk threshold for notifying individuals — each affected data principal must be intimated about the breach.
What is the penalty for failing to report a data breach in India?
Up to ₹200 crore for failure to notify the Board or affected data principals — separate from and additional to the penalty of up to ₹250 crore for failing to take reasonable security safeguards.
Privonta Shield helps Companies, Government, SMEs and Education Institutes meet every DPDP obligation — data discovery, consent management, rights workflows and audit trails, deployed inside your own boundary. Book a free DPDP assessment →