Under Section 8(6) of the DPDP Act and Rule 7 of the DPDP Rules 2025, a business that becomes aware of a personal data breach must inform every affected customer and the Data Protection Board without delay — and file the detailed breach particulars with the Board within 72 hours. EasyDP turns that legal sequence into a guided workflow your team can execute under pressure.
DPDP Act 2023, Section 8(6) · DPDP Rules 2025, Rule 7 · Updated July 2026
| No. | Obligation | What the Act says | Citation |
|---|---|---|---|
| 01 | Notify affected customers without delay | Each affected Data Principal must be told the nature of the breach, its likely consequences, what you are doing about it, what they can do to protect themselves, and who to contact. | Rules · R.7 |
| 02 | Notify the Board without delay | The Data Protection Board gets an initial intimation as soon as you become aware — before you have all the answers. | Rules · R.7 |
| 03 | Detailed Board filing within 72 hours | Within 72 hours of becoming aware (or a longer period the Board allows on request), you must file the detailed particulars: cause, extent, mitigation, and remediation. | Rules · R.7 |
| 04 | Penalties compound | Failing to give breach intimation carries a penalty of up to ₹200 crore — separate from the up-to-₹250 crore penalty for the security failure that caused the breach. | Act · Schedule |
Declare an incident and EasyDP walks your team through the legal sequence — affected-customer notice, initial Board intimation, 72-hour detailed filing — with the deadline visible at every step.
Affected customers get the required notice in the language they consented in, across the channel you reach them on — email, SMS or WhatsApp.
Notification templates already carry the fields Rule 7 requires, so the person on call fills in facts instead of drafting legal text at 2 a.m.
Every action — discovery time, notifications sent, Board filings — is timestamped into the audit log, establishing exactly when you became aware and what you did.
Twice over: affected Data Principals and the Data Protection Board must be informed without delay on becoming aware of the breach, and the detailed breach information must reach the Board within 72 hours (Rule 7, DPDP Rules 2025). The clock runs from awareness, not from when the breach occurred.