DPDP Breach Notification Timeline: 72-Hour Rule (India 2026)
Miss the 72-hour window and the exposure is ₹200 crore under Section 8(6). The Board deadline, the 6-hour CERT-In rule, and the reporting steps, mapped.
On This Page
- A Breach You Do Not Report Is a Violation You Have Committed
- The 72-Hour Notification Timeline at a Glance
- The Two-Stage Board Notification
- Stage 1: Initial intimation, without delay
- Stage 2: Detailed report, within 72 hours
- What Constitutes a Personal Data Breach
- Who Must Be Notified
- The Data Protection Board of India
- Affected Data Principals
- Timeline Requirements
- Dual Reporting: The Board and CERT-In
- Breach Notification vs. Erasure Notice: Two Distinct Obligations
- Penalties for Non-Compliance
- Building a Breach Response Plan
- 1. Detection
- 2. Assessment
- 3. Notification
- 4. Remediation
- The 72-Hour Response Timeline, Hour by Hour
- BFSI: The Extra Reporting Layer
- The Role of Data Processors
- Assess Your Breach Readiness
A Breach You Do Not Report Is a Violation You Have Committed
Under the DPDP Act 2023, every Data Fiduciary has a legal obligation to report personal data breaches. The notification must go to two parties: the Data Protection Board of India and every affected Data Principal. Delayed, incomplete, or suppressed breach reporting carries its own penalties, independent of the breach itself.
This obligation exists regardless of company size, industry, or the volume of data involved. A breach affecting ten records carries the same notification obligation as one affecting ten million.
The 72-Hour Notification Timeline at a Glance
The DPDP Rules, notified on November 13, 2025, set a confirmed 72-hour window. The clock starts the moment you become aware of a breach. Two notifications run in parallel: affected Data Principals and the Data Protection Board are both told without delay, and the Board receives the detailed report within 72 hours.
- Detection (hour 0). You become aware of a breach. The 72-hour clock starts here, not when you finish investigating.
- Assessment (hours 0 to 24). Scope the breach: what data, how many Data Principals, contained or ongoing.
- Notification (without delay, then within 72 hours). Notify affected Data Principals and give the Board its initial intimation without delay. File the detailed Board report within 72 hours.
- Remediation (after notification). Contain the cause, document every action with timestamps, and update your safeguards.
The detailed deadline table and the cross-jurisdiction comparison are in Timeline Requirements below. The four-phase response plan is covered in Building a Breach Response Plan.
The Two-Stage Board Notification
Rule 7 of the DPDP Rules operationalises Section 8(6) as a two-stage notification to the Data Protection Board. The two stages are not optional. The first preserves the timeline. The second carries the substance.
Stage 1: Initial intimation, without delay
The moment your incident response team confirms a personal data breach, send an initial intimation to the Board without delay. In practice this means within hours of confirmation, not days. Rule 7 requires the initial intimation to describe the breach:
- Its nature
- Its extent
- Its timing
- Its location
- Its likely impact
Stage 2: Detailed report, within 72 hours
Within 72 hours of becoming aware of the breach, submit the full incident report. This is the substantive filing. Rule 7 requires it to cover:
| Required information | Detail |
|---|---|
| Breach description | Updated and detailed description of the breach |
| Facts and reasons | The broad facts, circumstances and reasons leading to the breach |
| Mitigation | Measures implemented or proposed to mitigate the risk |
| Responsibility | Any findings regarding the person who caused the breach |
| Prevention | Remedial measures taken to prevent recurrence |
| Data Principal intimations | A report on the intimations given to affected Data Principals |
The 72-hour deadline moves only if the Board extends it on a written request. The DPDP Rules carry no “where feasible” qualifier of the kind GDPR uses. If your investigation is incomplete at the 72-hour mark, file what you have and update the Board as new information emerges.
What Constitutes a Personal Data Breach
The Act defines a personal data breach as any unauthorised processing of personal data, or any accidental disclosure, acquisition, sharing, use, alteration, destruction, or loss of access to personal data. This definition is broad by design.
Examples include:
- External attacks: Ransomware, SQL injection, credential theft, or any unauthorised access by external actors
- Internal incidents: An employee accessing customer records without authorisation, or sharing data with an unauthorised third party
- Accidental exposure: A misconfigured database making personal data publicly accessible, or an email containing personal data sent to the wrong recipient
- Data loss: Hardware failure or cloud storage corruption resulting in permanent loss of personal data without backup
- Processor breaches: A third-party Data Processor experiencing a breach that affects personal data you entrusted to them
If personal data has been compromised in any way, the notification obligation is triggered.
Who Must Be Notified
The Data Protection Board of India
The Data Fiduciary must notify the Board under Section 8(6). Rule 7 prescribes the contents in two stages: the initial intimation without delay, and the detailed report within 72 hours. Both are set out in The Two-Stage Board Notification above.
Affected Data Principals
Every individual whose personal data was compromised must be notified without delay, in a concise, clear and plain manner, through their user account or registered mode of communication. Rule 7 requires the notice to set out:
- A description of the breach, including its nature, extent and timing
- The consequences relevant to the Data Principal that are likely to arise
- The mitigation measures implemented or being implemented
- The safety measures the Data Principal may take
- Business contact information of a person able to respond to their queries
Vague notifications that obscure the nature or severity of the breach do not satisfy the obligation. The Act requires transparency, not damage control. The same plain-language standard that governs a privacy notice applies to breach notifications.
Timeline Requirements
The DPDP Rules, notified on November 13, 2025, establish a confirmed 72-hour notification window. A Data Fiduciary must give the Data Protection Board an initial intimation without delay and a detailed report within 72 hours of becoming aware of a personal data breach. Affected Data Principals must be notified without delay. Their notice does not wait for the Board filing.
| Jurisdiction | Notification Deadline | Recipient |
|---|---|---|
| GDPR (EU) | 72 hours | Supervisory Authority |
| DPDP Act (India) | 72 hours | Data Protection Board |
| DPDP Act (India) | Without delay | Affected Data Principals |
| CCPA (California) | “Expedient” | Affected individuals |
Design your breach response procedures around two parallel tracks. Affected Data Principals and the Board both receive notice without delay. The Board then receives the detailed report within 72 hours. Rule 7 sets no order between principals and the Board; both clocks start the moment you become aware.
Dual Reporting: The Board and CERT-In
This is where many organisations are caught out. The DPDP Act’s notification requirement does not replace the older obligation to report cyber incidents to CERT-In under the IT Act 2000 and the CERT-In Directions of 2022. Most real-world breaches qualify as both a personal data breach and a cybersecurity incident. When that happens, you report to both authorities, on two different clocks.
| Authority | Legal basis | Deadline | Trigger |
|---|---|---|---|
| CERT-In | IT Act 2000 and CERT-In Directions 2022 | Within 6 hours of noticing | Any cybersecurity incident, including data breaches |
| Data Protection Board | Section 8(6), DPDP Act 2023 and Rule 7 | Initial intimation without delay, detailed report within 72 hours | Personal data breach |
| Affected Data Principals | Section 8(6), DPDP Act 2023 | Without delay | Personal data breach |
CERT-In and the Board are parallel obligations, not alternatives. The 6-hour CERT-In window is the tightest deadline in the set, so it usually fires first. Build your detection process to start both clocks the moment an incident is confirmed.
Breach Notification vs. Erasure Notice: Two Distinct Obligations
A common point of confusion in DPDP compliance practice is the conflation of breach notification with the Rule 8 erasure notice. These are separate obligations with different triggers, recipients, and timeframes.
Breach notification (Section 8(6) of the Act) is triggered by a personal data breach: an unauthorised or accidental compromise of personal data. Notice goes to affected Data Principals and the Data Protection Board without delay, with the detailed Board report due within 72 hours.
Rule 8 erasure notice applies only to the Data Fiduciary classes listed in the Third Schedule: e-commerce entities with two crore or more registered users, and online gaming and social media intermediaries above the Schedule’s thresholds. When such an entity is about to erase personal data after the three-year window in Rule 8, it must notify the Data Principal at least 48 hours in advance. This is not a breach notification, and it is not a general pre-deletion notice for every fiduciary. Most businesses outside the Third Schedule classes are not bound by it.
| Obligation | Trigger | Recipient | Timeline |
|---|---|---|---|
| Breach notification | Personal data breach | Data Protection Board | Initial intimation without delay; detailed report within 72 hours |
| Breach notification | Personal data breach | Affected Data Principals | Without delay |
| Erasure notice (Rule 8) | Erasure after the three-year window, Third Schedule classes only | Affected Data Principal | Minimum 48 hours before deletion |
Both obligations must be operationalised. A breach response plan covers the first. A data lifecycle management system, with scheduled deletion and automated pre-deletion notices, covers the second.
Penalties for Non-Compliance
The penalty framework treats breach notification failures as a distinct violation category.
- Failure to implement security safeguards to prevent breaches: up to ₹250 crore
- Failure to notify the Data Protection Board and affected Data Principals of a breach: up to ₹200 crore
These penalties are cumulative. A business that suffers a breach due to inadequate security and then fails to report it faces enforcement on both counts. Model your own exposure with the DPDP penalty calculator.
Section 27(1) sets how a breach reaches the Board: through your own intimation under Section 8(6), a complaint from a Data Principal, a reference from the Central Government or a State Government, or the direction of a court. The Act gives the Board no power to open an inquiry on its own initiative. A breach that arrives by complaint or reference instead of by your intimation carries a second breach with it, the failure to notify. When the Board fixes a penalty, Section 33(2)(e) directs it to weigh whether you acted to mitigate the breach, and how timely and effective that action was.
Building a Breach Response Plan
Compliance requires preparation, not just reaction. Every Data Fiduciary should maintain a documented breach response plan covering four phases:
1. Detection
Establish monitoring systems that identify potential breaches in real time. This includes:
- Intrusion detection systems on network perimeters
- Access logging and anomaly detection on data stores
- Regular log review processes
- Employee reporting channels for suspected incidents
A breach that goes undetected for months is a breach that goes unreported for months.
2. Assessment
Once a potential breach is detected, assess its scope and severity:
- What data was affected?
- How many Data Principals are involved?
- Is the breach contained, or is it ongoing?
- What is the potential harm to affected individuals?
This assessment must happen within hours, not days.
3. Notification
Execute the notification procedure within the prescribed timeline:
- Notify the Data Protection Board with all required information
- Notify affected Data Principals through accessible channels
- Document every notification action with timestamps
4. Remediation
After notification, address the root cause:
- Contain the breach if it is ongoing
- Implement corrective measures to prevent recurrence
- Review and update security safeguards
- Conduct a post-incident review to identify process failures
The 72-Hour Response Timeline, Hour by Hour
The four phases above describe what to do. This is when to do it. Treat the bands below as the operational companion to your response plan.
Hours 0 to 4: detect and triage. Confirm that a personal data breach has occurred, not just a security alert. Activate the incident response team across legal, security, communications, the Data Protection Officer, and engineering. Open the incident log immediately, with timestamps for every action, because it becomes your evidence for the Board. If a cybersecurity incident is confirmed, the 6-hour CERT-In clock is already running.
Hours 4 to 24: assess, contain, send the initial intimation. Scope the categories and volume of personal data affected. Block unauthorised access, isolate affected systems, revoke compromised credentials, and secure forensic logs. Send the initial intimation to the Board with what you know. Notify affected Data Principals in plain language; their notice is due without delay, not after the investigation.
Hours 24 to 48: investigate and draft the detailed report. Run the forensic analysis to establish root cause, attack vector, dwell time, and full extent of exposure. Finalise the count of affected Data Principals. Compile the detailed Board report against the Rule 7 contents above, including the record of intimations already sent to Data Principals.
Hours 48 to 72: submit, remediate, review. File the detailed report as soon as it is ready, not at the 72nd hour. Implement remediation: patch vulnerabilities, tighten access controls, raise monitoring. Notify sector regulators where they apply. Run the post-incident review and update the playbook.
BFSI: The Extra Reporting Layer
A bank, NBFC, insurer, or registered broker answers to a sector regulator as well as CERT-In and the Board, and each regulator sets its own incident reporting rules. RBI consolidated its cyber reporting rules on 31 July 2026 into entity-specific Directions and repealed the earlier circulars, including the 2016 Cyber Security Framework in Banks. Under the Reserve Bank of India (Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026, paragraph 182, a bank reports cyber incidents within six hours of detection on DAKSH, RBI’s supervisory monitoring platform, and also notifies CERT-In. The matching NBFC Directions, 2026 set the same six-hour DAKSH deadline in paragraph 141, except that Housing Finance Companies report to the National Housing Bank. Insurers report under IRDAI’s rules and brokers under SEBI’s. Map each applicable regulator’s deadline alongside the two above before an incident, not during one.
BFSI also faces a conflict the timeline does not surface. A Data Principal may request erasure under Section 12(3) while you are mid-investigation on a breach involving their data. You may not be free to delete it. Section 12(3) and Section 8(7) both carve out retention that is necessary for compliance with any law for the time being in force, such as the five-year record retention under the RBI KYC Master Direction. The breach itself can supply the legal requirement: from 13 May 2027, Rule 6(1)(e) requires a Data Fiduciary to retain logs and personal data for one year to enable detection, investigation and remediation of unauthorised access, unless another law requires otherwise. The Act does not prescribe how to evidence the carve-out. Record the specific provision relied on, keep a dated record of the decision, and erase once the retention requirement ends. How to document this clash is covered in the RBI and DPDP retention conflict guide and the DPDP compliance guide for NBFCs.
The Role of Data Processors
If your Data Processor experiences a breach affecting personal data you entrusted to them, the notification obligation falls on you as the Data Fiduciary. Your contracts with Data Processors must include:
- An obligation for the Processor to notify you of any breach without undue delay
- Cooperation requirements for breach investigation and assessment
- Clear roles and responsibilities for the notification process
You cannot outsource data processing and then claim ignorance when a breach occurs. The Act holds the Data Fiduciary accountable.
Assess Your Breach Readiness
The DPDP compliance checklist includes breach notification as a core compliance area. To evaluate whether your current breach response capabilities meet the Act’s requirements, take the free DPDP Gap Assessment. To put the full obligation set on operational footing, compare ConsentOS plans, from ₹2,999 per month.
Frequently asked questions
What is the DPDP 72 hour rule?
The DPDP 72 hour rule is the deadline to report a personal data breach to the Data Protection Board of India. A Data Fiduciary must notify the Board within 72 hours of becoming aware of the breach. Affected Data Principals are informed without delay and CERT-In within 6 hours.
Does the 72-hour clock start when the breach happens or when we detect it?
It starts when the Data Fiduciary becomes aware of the breach, not when the breach occurred. The Data Protection Board will examine the gap between occurrence and detection, so weak detection is its own exposure.
Do we have to notify the Board even for a minor breach?
Yes. The DPDP Act sets no materiality threshold. Any personal data breach triggers the notification obligation regardless of scale. This is stricter than GDPR, which requires notification only where a breach is likely to cause risk to individuals.
What if our investigation is incomplete at the 72-hour mark?
File what you have within 72 hours and update the Board as the investigation progresses. A timely partial report is better than a complete late one.
If our data processor is breached, who notifies the Board?
The Data Fiduciary notifies the Board, not the processor. Your processor contracts must require the processor to alert you fast enough for you to meet your own 72-hour deadline.
Can the Data Protection Board impose penalties before full enforcement?
No. As of 1 August 2026 the Board had no appointed Chairperson and no appointed Members, and no enforcement action has been taken. Rule 7, which sets the breach notification procedure, applies from 13 May 2027. Use the interim period to build the workflow rather than wait for an enforcement action.
Know where you stand on DPDP compliance
Run the free DPDP Gap Assessment for a gap report scored against your DPDP Act 2023 obligations, work through the 26-point compliance checklist, or model your penalty exposure.
Enforcement milestones, rule notifications, and deadline analysis.
One email when it matters, no more.
Resources
Continue Reading
Related DPDP Act 2023 guidance from the ConsentOS knowledge base.
What Is the DPDP Act 2023? Guide for Indian Business Compliance
India's Digital Personal Data Protection Act 2023 decoded: 7 obligations for every Data Fiduciary, 8 rights for Data Principals, penalties up to ₹250 crore.
6 min read
Regulatory UpdatesDPDP Act 2023 Compliance Deadlines & Enforcement Dates (India)
Every DPDP Act date: Rules notified Nov 2025, Consent Manager registration Nov 2026, penalty enforcement May 2027. Plan your compliance timeline.
5 min read
Regulatory UpdatesDPDP Penalties: ₹250 Crore Risk and Enforcement Tiers in India
A breakdown of every penalty provision in the DPDP Act 2023. Understand the financial exposure, the enforcement mechanism, and what triggers each penalty tier.
7 min read