Consent & Obligations

Data Breach Notification Under the DPDP Act and Rules 2025

Rule 7 of the DPDP Rules 2025 (under the DPDP Act 2023, or DPDPA) requires every Data Fiduciary to notify affected individuals and the Data Protection Board when a personal data breach occurs — without delay — and to file a detailed report to the Board within 72 hours. This duty sits alongside the separate CERT-In 6-hour incident reporting requirement.

~4 min readLast updated: June 2026

What Must You Do After a Data Breach?

Rule 7 of the DPDP Rules 2025

After a personal data breach, you must notify affected Data Principals without delay and report to the Data Protection Board in two stages: an initial notification without delay, followed by a detailed report within 72 hours.

Rule 7 sets out the breach notification process in two tracks: one for the Data Principal and one for the Data Protection Board.

Notification to the Data Principal must happen without delay. It must be sent through the Data Principal's user account or via a registered communication channel. The notification must include: a description of the breach, the consequences that may result from it, the measures the Data Fiduciary has taken in response, the safety measures the Data Principal can take on their end, and the contact information of the person the Data Principal can reach for more information.

Notification to the Board follows a two-stage process. The first stage, without delay, must include a description of the breach, the nature and extent of the data affected, the timing of the breach, and the likely impact. The second stage, within 72 hours, requires a more detailed submission: updated and comprehensive information about the breach, the facts, circumstances, and reasons behind it, the mitigation measures taken, findings about who or what caused the breach, the remedial measures put in place, and a report on how affected Data Principals have been notified.

The 72-hour window is significant. It starts from the time the Data Fiduciary becomes aware of the breach, not from when the breach occurred. Given that a detailed investigation, root cause analysis, and Data Principal notification report must all be ready within this window, organisations need a pre-established breach response plan to meet this deadline.

Key Points

  • Notify affected Data Principals without delay, via their user account or registered communication channel.
  • Data Principal notification must cover: breach description, consequences, measures taken, safety steps for the individual, and contact details.
  • First report to the Board (without delay): description, nature, extent, timing, and likely impact of the breach.
  • Second report to the Board (within 72 hours): detailed facts, circumstances, root cause findings, mitigation and remedial measures, and a report on Data Principal notifications.
  • The 72-hour clock starts from when the Data Fiduciary becomes aware of the breach.
  • A pre-established incident response plan is essential to meet these timelines.

Frequently Asked Questions

What is the breach notification timeline under the DPDP Act?

Under Rule 7 of the DPDP Rules 2025, a Data Fiduciary must notify each affected Data Principal and the Data Protection Board without delay on becoming aware of a personal data breach, then file a detailed report to the Board within 72 hours (or a longer period the Board allows). A separate CERT-In 6-hour cyber-incident report can apply in parallel.

Related: DPDP enforcement timeline

Who must you notify after a personal data breach?

Both the affected Data Principals and the Data Protection Board of India. Each affected individual must be told, in clear language, the nature and extent of the breach, its likely consequences, the measures you are taking, and the steps they can take to protect themselves.

Related: The Data Protection Board

Is there a harm threshold for reporting a DPDP breach?

No. The DPDP Act has no harm or severity threshold and no exemption for encrypted data — every personal data breach is reportable to the Board and to the affected Data Principals, regardless of how minor it appears.

How is DPDP breach notification different from CERT-In reporting?

They are separate, parallel duties. CERT-In requires reporting certain cyber incidents within 6 hours under the IT Act. DPDP breach notification under Rule 7 requires notifying the Board and affected individuals, with a detailed Board report within 72 hours. A single incident can trigger both clocks at once.

What is the penalty for failing to report a data breach?

Failing to notify a personal data breach can attract a penalty of up to ₹200 crore under the Act's Schedule. This is a standalone penalty, separate from any penalty for the security failure that caused the breach.

Related: DPDP Act penalties

Not sure if you meet these requirements?

Take the free DPDP Readiness Assessment to get an instant compliance score and a detailed gap analysis report.

Download the full guide as PDF

Disclaimer: This guide is for informational purposes only and does not constitute legal advice. It is a plain-English interpretation of the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The official gazette text is the only authoritative source. Consult qualified legal counsel before making compliance decisions.