Section 8(6) of the DPDP Act 2023 requires every Data Fiduciary to notify the Data Protection Board — and affected individuals — of a personal data breach. The DPDP Rules 2025 make this a two-part obligation to the Board: an initial intimation "without delay," followed by detailed particulars within 72 hours of becoming aware (or a longer period the Board allows). Affected individuals must also be told "without delay." Here's everything you need to know.
Quick Answer: What Is the 72-Hour Breach Rule?
Under Section 8(6) of the DPDP Act 2023 and Rule 7 of the DPDP Rules 2025, a Data Fiduciary must intimate the Data Protection Board and affected individuals "without delay" on becoming aware of a personal data breach, then give the Board detailed particulars within 72 hours (or a longer period it allows). Failing to notify carries a penalty of up to ₹200 Crore.
What Counts as a Personal Data Breach?
A personal data breach is any incident that results in the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data — one of the core obligations every business must meet. Common examples:
- A hacker gains access to your customer database
- An employee accidentally emails a spreadsheet of customer data to the wrong person
- You lose a laptop or phone containing unencrypted customer data
- A cloud storage bucket containing customer records is misconfigured as public
- A WhatsApp message with customer details is sent to the wrong contact
- An ex-employee downloads the customer list before leaving
The breach doesn't have to be a sophisticated cyberattack. Any incident that results in customer data being accessed by someone not authorised to see it qualifies.
The 72-Hour Clock: When Does It Start?
The 72-hour clock starts from the moment you become aware of the breach — not from when the breach occurred. If a breach happened three days ago but you discovered it today, the 72-hour clock started today.
This "aware" standard means you need monitoring systems that will actually detect breaches. An undetected breach that remains undetected is less of a legal risk in the immediate term — but failing to have detection systems can itself be evidence of inadequate security (the ₹250 Crore penalty provision).
Who Must Be Notified?
Two separate notification obligations:
1. The Data Protection Board
A report to the DPB portal (to be established by the government) containing:
- Description of the nature of the breach
- Categories and approximate number of Data Principals affected
- Likely consequences of the breach
- Measures taken or proposed to address the breach
- Contact details of your grievance officer
2. Affected Individuals (Data Principals)
Every person whose data was compromised must be notified without delay, in concise, clear and plain language, through their account or a registered mode of communication. The notification must describe the nature, extent and timing of the breach, its likely consequences, the measures you've taken to mitigate it, what the individual can do to protect themselves, and your contact point — enough for them to take protective action (e.g., "your email and phone number were exposed — be alert for phishing attempts").
What If You're Not Sure It's a Breach?
If you discover an incident but aren't certain whether it constitutes a "breach" — notify the DPB anyway, noting that investigation is ongoing. The penalty for not notifying (₹200 Crore) vastly outweighs any awkwardness of over-notifying. You can provide a preliminary notification within 72 hours and follow up with details.
Penalties for Missing the Deadline
Failing to notify the DPB of a breach within the prescribed time: up to ₹200 Crore. This penalty is separate from the ₹250 Crore penalty for the security failure that caused the breach. A single incident where data is breached AND you fail to notify could result in ₹450 Crore in total penalties.
Building Your Breach Response Plan Now
The time to plan for a breach is before it happens. Prepare:
- Detection: What monitoring do you have in place? (Security alerts, access logs, anomaly detection)
- Escalation: Who in your team gets called when a potential breach is detected? Who makes the notification decision?
- Documentation: A breach log template that captures incident details
- DPB Notification: A draft notification form ready to complete
- Customer Notification: A template WhatsApp/SMS/email to send to affected customers
- Containment: Steps to limit the damage (disable compromised accounts, rotate credentials, revoke access)
Your Breach-Response Checklist
When a breach is discovered, nobody has time to re-read this article. Work the sequence below — it's also the one-page PDF at the top of this post, formatted for pinning next to the server rack or billing desk.
- Note the awareness time. The legal clocks run from the moment you become aware — record it immediately.
- Contain. Revoke compromised access, isolate affected systems, stop the leak before you explain it.
- Start the incident log. What happened, what data, how discovered, who is acting — timestamped as you go.
- Notify affected customers without delay. Nature of the breach, likely consequences, your mitigation, their safety steps, a contact — in the language they consented in.
- Send the Board its initial intimation without delay — in parallel, not after, the customer notices.
- File detailed particulars with the Board within 72 hours — cause, extent, mitigation, remediation. Need longer? Request it in writing before the deadline.
- Keep proof of every notification sent — the timeline you can reconstruct is the compliance you can prove.
- Fix the root cause and update the plan — the Board's view of a repeat incident will be far harsher.
How EasyDP Handles Breach Notification
EasyDP's compliance dashboard includes a breach-reporting workflow. When you log a breach incident, the system:
- Starts the 72-hour countdown timer
- Generates a draft DPB notification from your business and incident details
- Identifies which customers are affected based on your EasyDP data records
- Drafts customer notifications in their preferred languages
- Logs every action with timestamps for your audit trail
The goal: when a breach happens at 2 AM, you're not scrambling to figure out what to do. The process is already defined.
References & Sources
- Ministry of Electronics & IT, Government of India — The Digital Personal Data Protection Act, 2023 (Section 8(6), breach intimation; the Schedule).
- The Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)) — Rule 7, "Intimation of personal data breach."
- India Code — Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023), official consolidated text.
This article is general information about the DPDP Act 2023 and DPDP Rules 2025, not legal advice. Section and rule references are cited from the official text; verify against the current notified version for your specific situation.