Skip to main content
Compliance Areas

DPDP Breach Notification Timeline: 72-Hour Rule (India 2026)

Miss the 72-hour window and the exposure is ₹200 crore under Section 8(6). The Board deadline, the 6-hour CERT-In rule, and the reporting steps, mapped.

By Sarthak Kalucha, Founder, CivicLayer Technologies9 min readUpdated:
On This Page

A Breach You Do Not Report Is a Violation You Have Committed

Under the DPDP Act 2023, every Data Fiduciary has a legal obligation to report personal data breaches. The notification must go to two parties: the Data Protection Board of India and every affected Data Principal. Delayed, incomplete, or suppressed breach reporting carries its own penalties, independent of the breach itself.

This obligation exists regardless of company size, industry, or the volume of data involved. A breach affecting ten records carries the same notification obligation as one affecting ten million.

The 72-Hour Notification Timeline at a Glance

The DPDP Rules, notified on November 13, 2025, set a confirmed 72-hour window. The clock starts the moment you become aware of a breach. Two notifications run in parallel: affected Data Principals and the Data Protection Board are both told without delay, and the Board receives the detailed report within 72 hours.

  1. Detection (hour 0). You become aware of a breach. The 72-hour clock starts here, not when you finish investigating.
  2. Assessment (hours 0 to 24). Scope the breach: what data, how many Data Principals, contained or ongoing.
  3. Notification (without delay, then within 72 hours). Notify affected Data Principals and give the Board its initial intimation without delay. File the detailed Board report within 72 hours.
  4. Remediation (after notification). Contain the cause, document every action with timestamps, and update your safeguards.

The detailed deadline table and the cross-jurisdiction comparison are in Timeline Requirements below. The four-phase response plan is covered in Building a Breach Response Plan.

The Two-Stage Board Notification

Rule 7 of the DPDP Rules operationalises Section 8(6) as a two-stage notification to the Data Protection Board. The two stages are not optional. The first preserves the timeline. The second carries the substance.

Stage 1: Initial intimation, without delay

The moment your incident response team confirms a personal data breach, send an initial intimation to the Board without delay. In practice this means within hours of confirmation, not days. Rule 7 requires the initial intimation to describe the breach:

  • Its nature
  • Its extent
  • Its timing
  • Its location
  • Its likely impact

Stage 2: Detailed report, within 72 hours

Within 72 hours of becoming aware of the breach, submit the full incident report. This is the substantive filing. Rule 7 requires it to cover:

Required informationDetail
Breach descriptionUpdated and detailed description of the breach
Facts and reasonsThe broad facts, circumstances and reasons leading to the breach
MitigationMeasures implemented or proposed to mitigate the risk
ResponsibilityAny findings regarding the person who caused the breach
PreventionRemedial measures taken to prevent recurrence
Data Principal intimationsA report on the intimations given to affected Data Principals

The 72-hour deadline moves only if the Board extends it on a written request. The DPDP Rules carry no “where feasible” qualifier of the kind GDPR uses. If your investigation is incomplete at the 72-hour mark, file what you have and update the Board as new information emerges.

What Constitutes a Personal Data Breach

The Act defines a personal data breach as any unauthorised processing of personal data, or any accidental disclosure, acquisition, sharing, use, alteration, destruction, or loss of access to personal data. This definition is broad by design.

Examples include:

  • External attacks: Ransomware, SQL injection, credential theft, or any unauthorised access by external actors
  • Internal incidents: An employee accessing customer records without authorisation, or sharing data with an unauthorised third party
  • Accidental exposure: A misconfigured database making personal data publicly accessible, or an email containing personal data sent to the wrong recipient
  • Data loss: Hardware failure or cloud storage corruption resulting in permanent loss of personal data without backup
  • Processor breaches: A third-party Data Processor experiencing a breach that affects personal data you entrusted to them

If personal data has been compromised in any way, the notification obligation is triggered.

Who Must Be Notified

The Data Protection Board of India

The Data Fiduciary must notify the Board under Section 8(6). Rule 7 prescribes the contents in two stages: the initial intimation without delay, and the detailed report within 72 hours. Both are set out in The Two-Stage Board Notification above.

Affected Data Principals

Every individual whose personal data was compromised must be notified without delay, in a concise, clear and plain manner, through their user account or registered mode of communication. Rule 7 requires the notice to set out:

  • A description of the breach, including its nature, extent and timing
  • The consequences relevant to the Data Principal that are likely to arise
  • The mitigation measures implemented or being implemented
  • The safety measures the Data Principal may take
  • Business contact information of a person able to respond to their queries

Vague notifications that obscure the nature or severity of the breach do not satisfy the obligation. The Act requires transparency, not damage control. The same plain-language standard that governs a privacy notice applies to breach notifications.

Timeline Requirements

The DPDP Rules, notified on November 13, 2025, establish a confirmed 72-hour notification window. A Data Fiduciary must give the Data Protection Board an initial intimation without delay and a detailed report within 72 hours of becoming aware of a personal data breach. Affected Data Principals must be notified without delay. Their notice does not wait for the Board filing.

JurisdictionNotification DeadlineRecipient
GDPR (EU)72 hoursSupervisory Authority
DPDP Act (India)72 hoursData Protection Board
DPDP Act (India)Without delayAffected Data Principals
CCPA (California)“Expedient”Affected individuals

Design your breach response procedures around two parallel tracks. Affected Data Principals and the Board both receive notice without delay. The Board then receives the detailed report within 72 hours. Rule 7 sets no order between principals and the Board; both clocks start the moment you become aware.

Dual Reporting: The Board and CERT-In

This is where many organisations are caught out. The DPDP Act’s notification requirement does not replace the older obligation to report cyber incidents to CERT-In under the IT Act 2000 and the CERT-In Directions of 2022. Most real-world breaches qualify as both a personal data breach and a cybersecurity incident. When that happens, you report to both authorities, on two different clocks.

AuthorityLegal basisDeadlineTrigger
CERT-InIT Act 2000 and CERT-In Directions 2022Within 6 hours of noticingAny cybersecurity incident, including data breaches
Data Protection BoardSection 8(6), DPDP Act 2023 and Rule 7Initial intimation without delay, detailed report within 72 hoursPersonal data breach
Affected Data PrincipalsSection 8(6), DPDP Act 2023Without delayPersonal data breach

CERT-In and the Board are parallel obligations, not alternatives. The 6-hour CERT-In window is the tightest deadline in the set, so it usually fires first. Build your detection process to start both clocks the moment an incident is confirmed.

Breach Notification vs. Erasure Notice: Two Distinct Obligations

A common point of confusion in DPDP compliance practice is the conflation of breach notification with the Rule 8 erasure notice. These are separate obligations with different triggers, recipients, and timeframes.

Breach notification (Section 8(6) of the Act) is triggered by a personal data breach: an unauthorised or accidental compromise of personal data. Notice goes to affected Data Principals and the Data Protection Board without delay, with the detailed Board report due within 72 hours.

Rule 8 erasure notice applies only to the Data Fiduciary classes listed in the Third Schedule: e-commerce entities with two crore or more registered users, and online gaming and social media intermediaries above the Schedule’s thresholds. When such an entity is about to erase personal data after the three-year window in Rule 8, it must notify the Data Principal at least 48 hours in advance. This is not a breach notification, and it is not a general pre-deletion notice for every fiduciary. Most businesses outside the Third Schedule classes are not bound by it.

ObligationTriggerRecipientTimeline
Breach notificationPersonal data breachData Protection BoardInitial intimation without delay; detailed report within 72 hours
Breach notificationPersonal data breachAffected Data PrincipalsWithout delay
Erasure notice (Rule 8)Erasure after the three-year window, Third Schedule classes onlyAffected Data PrincipalMinimum 48 hours before deletion

Both obligations must be operationalised. A breach response plan covers the first. A data lifecycle management system, with scheduled deletion and automated pre-deletion notices, covers the second.

Penalties for Non-Compliance

The penalty framework treats breach notification failures as a distinct violation category.

  • Failure to implement security safeguards to prevent breaches: up to ₹250 crore
  • Failure to notify the Data Protection Board and affected Data Principals of a breach: up to ₹200 crore

These penalties are cumulative. A business that suffers a breach due to inadequate security and then fails to report it faces enforcement on both counts. Model your own exposure with the DPDP penalty calculator.

Section 27(1) sets how a breach reaches the Board: through your own intimation under Section 8(6), a complaint from a Data Principal, a reference from the Central Government or a State Government, or the direction of a court. The Act gives the Board no power to open an inquiry on its own initiative. A breach that arrives by complaint or reference instead of by your intimation carries a second breach with it, the failure to notify. When the Board fixes a penalty, Section 33(2)(e) directs it to weigh whether you acted to mitigate the breach, and how timely and effective that action was.

Building a Breach Response Plan

Compliance requires preparation, not just reaction. Every Data Fiduciary should maintain a documented breach response plan covering four phases:

1. Detection

Establish monitoring systems that identify potential breaches in real time. This includes:

  • Intrusion detection systems on network perimeters
  • Access logging and anomaly detection on data stores
  • Regular log review processes
  • Employee reporting channels for suspected incidents

A breach that goes undetected for months is a breach that goes unreported for months.

2. Assessment

Once a potential breach is detected, assess its scope and severity:

  • What data was affected?
  • How many Data Principals are involved?
  • Is the breach contained, or is it ongoing?
  • What is the potential harm to affected individuals?

This assessment must happen within hours, not days.

3. Notification

Execute the notification procedure within the prescribed timeline:

  • Notify the Data Protection Board with all required information
  • Notify affected Data Principals through accessible channels
  • Document every notification action with timestamps

4. Remediation

After notification, address the root cause:

  • Contain the breach if it is ongoing
  • Implement corrective measures to prevent recurrence
  • Review and update security safeguards
  • Conduct a post-incident review to identify process failures

The 72-Hour Response Timeline, Hour by Hour

The four phases above describe what to do. This is when to do it. Treat the bands below as the operational companion to your response plan.

Hours 0 to 4: detect and triage. Confirm that a personal data breach has occurred, not just a security alert. Activate the incident response team across legal, security, communications, the Data Protection Officer, and engineering. Open the incident log immediately, with timestamps for every action, because it becomes your evidence for the Board. If a cybersecurity incident is confirmed, the 6-hour CERT-In clock is already running.

Hours 4 to 24: assess, contain, send the initial intimation. Scope the categories and volume of personal data affected. Block unauthorised access, isolate affected systems, revoke compromised credentials, and secure forensic logs. Send the initial intimation to the Board with what you know. Notify affected Data Principals in plain language; their notice is due without delay, not after the investigation.

Hours 24 to 48: investigate and draft the detailed report. Run the forensic analysis to establish root cause, attack vector, dwell time, and full extent of exposure. Finalise the count of affected Data Principals. Compile the detailed Board report against the Rule 7 contents above, including the record of intimations already sent to Data Principals.

Hours 48 to 72: submit, remediate, review. File the detailed report as soon as it is ready, not at the 72nd hour. Implement remediation: patch vulnerabilities, tighten access controls, raise monitoring. Notify sector regulators where they apply. Run the post-incident review and update the playbook.

BFSI: The Extra Reporting Layer

A bank, NBFC, insurer, or registered broker answers to a sector regulator as well as CERT-In and the Board, and each regulator sets its own incident reporting rules. RBI consolidated its cyber reporting rules on 31 July 2026 into entity-specific Directions and repealed the earlier circulars, including the 2016 Cyber Security Framework in Banks. Under the Reserve Bank of India (Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026, paragraph 182, a bank reports cyber incidents within six hours of detection on DAKSH, RBI’s supervisory monitoring platform, and also notifies CERT-In. The matching NBFC Directions, 2026 set the same six-hour DAKSH deadline in paragraph 141, except that Housing Finance Companies report to the National Housing Bank. Insurers report under IRDAI’s rules and brokers under SEBI’s. Map each applicable regulator’s deadline alongside the two above before an incident, not during one.

BFSI also faces a conflict the timeline does not surface. A Data Principal may request erasure under Section 12(3) while you are mid-investigation on a breach involving their data. You may not be free to delete it. Section 12(3) and Section 8(7) both carve out retention that is necessary for compliance with any law for the time being in force, such as the five-year record retention under the RBI KYC Master Direction. The breach itself can supply the legal requirement: from 13 May 2027, Rule 6(1)(e) requires a Data Fiduciary to retain logs and personal data for one year to enable detection, investigation and remediation of unauthorised access, unless another law requires otherwise. The Act does not prescribe how to evidence the carve-out. Record the specific provision relied on, keep a dated record of the decision, and erase once the retention requirement ends. How to document this clash is covered in the RBI and DPDP retention conflict guide and the DPDP compliance guide for NBFCs.

The Role of Data Processors

If your Data Processor experiences a breach affecting personal data you entrusted to them, the notification obligation falls on you as the Data Fiduciary. Your contracts with Data Processors must include:

  • An obligation for the Processor to notify you of any breach without undue delay
  • Cooperation requirements for breach investigation and assessment
  • Clear roles and responsibilities for the notification process

You cannot outsource data processing and then claim ignorance when a breach occurs. The Act holds the Data Fiduciary accountable.

Assess Your Breach Readiness

The DPDP compliance checklist includes breach notification as a core compliance area. To evaluate whether your current breach response capabilities meet the Act’s requirements, take the free DPDP Gap Assessment. To put the full obligation set on operational footing, compare ConsentOS plans, from ₹2,999 per month.

Frequently asked questions

What is the DPDP 72 hour rule?

The DPDP 72 hour rule is the deadline to report a personal data breach to the Data Protection Board of India. A Data Fiduciary must notify the Board within 72 hours of becoming aware of the breach. Affected Data Principals are informed without delay and CERT-In within 6 hours.

Does the 72-hour clock start when the breach happens or when we detect it?

It starts when the Data Fiduciary becomes aware of the breach, not when the breach occurred. The Data Protection Board will examine the gap between occurrence and detection, so weak detection is its own exposure.

Do we have to notify the Board even for a minor breach?

Yes. The DPDP Act sets no materiality threshold. Any personal data breach triggers the notification obligation regardless of scale. This is stricter than GDPR, which requires notification only where a breach is likely to cause risk to individuals.

What if our investigation is incomplete at the 72-hour mark?

File what you have within 72 hours and update the Board as the investigation progresses. A timely partial report is better than a complete late one.

If our data processor is breached, who notifies the Board?

The Data Fiduciary notifies the Board, not the processor. Your processor contracts must require the processor to alert you fast enough for you to meet your own 72-hour deadline.

Can the Data Protection Board impose penalties before full enforcement?

No. As of 1 August 2026 the Board had no appointed Chairperson and no appointed Members, and no enforcement action has been taken. Rule 7, which sets the breach notification procedure, applies from 13 May 2027. Use the interim period to build the workflow rather than wait for an enforcement action.

Know where you stand on DPDP compliance

Run the free DPDP Gap Assessment for a gap report scored against your DPDP Act 2023 obligations, work through the 26-point compliance checklist, or model your penalty exposure.

Enforcement milestones, rule notifications, and deadline analysis.

One email when it matters, no more.