Compliance 6 min read 2 February 2026

The 72-Hour Breach Notification Rule: DPDP Act Explained

A personal data breach must reach the Data Protection Board within 72 hours. What triggers the obligation, how to report, and the cost of missing it.

PDF ↓ Download the free one-page guide Branded PDF summary with a QR code back to this guide — print it for your desk or team. PDF →

Section 8(6) of the DPDP Act 2023 requires every Data Fiduciary to notify the Data Protection Board — and affected individuals — of a personal data breach. The DPDP Rules 2025 make this a two-part obligation to the Board: an initial intimation "without delay," followed by detailed particulars within 72 hours of becoming aware (or a longer period the Board allows). Affected individuals must also be told "without delay." Here's everything you need to know.

Quick Answer: What Is the 72-Hour Breach Rule?

Under Section 8(6) of the DPDP Act 2023 and Rule 7 of the DPDP Rules 2025, a Data Fiduciary must intimate the Data Protection Board and affected individuals "without delay" on becoming aware of a personal data breach, then give the Board detailed particulars within 72 hours (or a longer period it allows). Failing to notify carries a penalty of up to ₹200 Crore.

What Counts as a Personal Data Breach?

A personal data breach is any incident that results in the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data — one of the core obligations every business must meet. Common examples:

The breach doesn't have to be a sophisticated cyberattack. Any incident that results in customer data being accessed by someone not authorised to see it qualifies.

The 72-Hour Clock: When Does It Start?

The 72-hour clock starts from the moment you become aware of the breach — not from when the breach occurred. If a breach happened three days ago but you discovered it today, the 72-hour clock started today.

This "aware" standard means you need monitoring systems that will actually detect breaches. An undetected breach that remains undetected is less of a legal risk in the immediate term — but failing to have detection systems can itself be evidence of inadequate security (the ₹250 Crore penalty provision).

Who Must Be Notified?

Two separate notification obligations:

1. The Data Protection Board

A report to the DPB portal (to be established by the government) containing:

2. Affected Individuals (Data Principals)

Every person whose data was compromised must be notified without delay, in concise, clear and plain language, through their account or a registered mode of communication. The notification must describe the nature, extent and timing of the breach, its likely consequences, the measures you've taken to mitigate it, what the individual can do to protect themselves, and your contact point — enough for them to take protective action (e.g., "your email and phone number were exposed — be alert for phishing attempts").

What If You're Not Sure It's a Breach?

If you discover an incident but aren't certain whether it constitutes a "breach" — notify the DPB anyway, noting that investigation is ongoing. The penalty for not notifying (₹200 Crore) vastly outweighs any awkwardness of over-notifying. You can provide a preliminary notification within 72 hours and follow up with details.

Penalties for Missing the Deadline

Failing to notify the DPB of a breach within the prescribed time: up to ₹200 Crore. This penalty is separate from the ₹250 Crore penalty for the security failure that caused the breach. A single incident where data is breached AND you fail to notify could result in ₹450 Crore in total penalties.

Building Your Breach Response Plan Now

The time to plan for a breach is before it happens. Prepare:

Your Breach-Response Checklist

When a breach is discovered, nobody has time to re-read this article. Work the sequence below — it's also the one-page PDF at the top of this post, formatted for pinning next to the server rack or billing desk.

  1. Note the awareness time. The legal clocks run from the moment you become aware — record it immediately.
  2. Contain. Revoke compromised access, isolate affected systems, stop the leak before you explain it.
  3. Start the incident log. What happened, what data, how discovered, who is acting — timestamped as you go.
  4. Notify affected customers without delay. Nature of the breach, likely consequences, your mitigation, their safety steps, a contact — in the language they consented in.
  5. Send the Board its initial intimation without delay — in parallel, not after, the customer notices.
  6. File detailed particulars with the Board within 72 hours — cause, extent, mitigation, remediation. Need longer? Request it in writing before the deadline.
  7. Keep proof of every notification sent — the timeline you can reconstruct is the compliance you can prove.
  8. Fix the root cause and update the plan — the Board's view of a repeat incident will be far harsher.

How EasyDP Handles Breach Notification

EasyDP's compliance dashboard includes a breach-reporting workflow. When you log a breach incident, the system:

The goal: when a breach happens at 2 AM, you're not scrambling to figure out what to do. The process is already defined.

References & Sources

  1. Ministry of Electronics & IT, Government of India — The Digital Personal Data Protection Act, 2023 (Section 8(6), breach intimation; the Schedule).
  2. The Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)) — Rule 7, "Intimation of personal data breach."
  3. India Code — Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023), official consolidated text.

This article is general information about the DPDP Act 2023 and DPDP Rules 2025, not legal advice. Section and rule references are cited from the official text; verify against the current notified version for your specific situation.

Data BreachBreach Notification72 HoursDPDP

Check Your DPDP Compliance

Free 2-minute checker — get your specific obligations and penalty exposure.

Related Articles

← All Blog Posts