When a breach happens, the clock is already running.

Under Section 8(6) of the DPDP Act and Rule 7 of the DPDP Rules 2025, a business that becomes aware of a personal data breach must inform every affected customer and the Data Protection Board without delay — and file the detailed breach particulars with the Board within 72 hours. EasyDP turns that legal sequence into a guided workflow your team can execute under pressure.

DPDP Act 2023, Section 8(6) · DPDP Rules 2025, Rule 7 · Updated July 2026

The obligation, in the Act's own terms.

No.ObligationWhat the Act saysCitation
01 Notify affected customers without delay Each affected Data Principal must be told the nature of the breach, its likely consequences, what you are doing about it, what they can do to protect themselves, and who to contact. Rules · R.7
02 Notify the Board without delay The Data Protection Board gets an initial intimation as soon as you become aware — before you have all the answers. Rules · R.7
03 Detailed Board filing within 72 hours Within 72 hours of becoming aware (or a longer period the Board allows on request), you must file the detailed particulars: cause, extent, mitigation, and remediation. Rules · R.7
04 Penalties compound Failing to give breach intimation carries a penalty of up to ₹200 crore — separate from the up-to-₹250 crore penalty for the security failure that caused the breach. Act · Schedule

The obligation, handled.

SPEC. 03 · DPDP ACT 2023
CL. 01
A guided incident flow

Declare an incident and EasyDP walks your team through the legal sequence — affected-customer notice, initial Board intimation, 72-hour detailed filing — with the deadline visible at every step.

CL. 02
Customer notifications in their language

Affected customers get the required notice in the language they consented in, across the channel you reach them on — email, SMS or WhatsApp.

CL. 03
Pre-drafted, legally structured content

Notification templates already carry the fields Rule 7 requires, so the person on call fills in facts instead of drafting legal text at 2 a.m.

CL. 04
An incident record that survives scrutiny

Every action — discovery time, notifications sent, Board filings — is timestamped into the audit log, establishing exactly when you became aware and what you did.

The long-form guides behind this feature.

Breach reporting, answered.

Twice over: affected Data Principals and the Data Protection Board must be informed without delay on becoming aware of the breach, and the detailed breach information must reach the Board within 72 hours (Rule 7, DPDP Rules 2025). The clock runs from awareness, not from when the breach occurred.

Built on India's official DPDP framework.

DPDP Act 2023No. 22 of 2023 · In force Nov 13, 2025
DPDP Rules 2025G.S.R. 846(E) · staged: 2025 → May 2027
MeitY governedMinistry of Electronics & Information Technology