A DPDP breach — a personal data breach under the Digital Personal Data Protection Act, 2023 — triggers two notification duties at once, and neither of them has a risk threshold. Section 8(6) requires the data fiduciary to intimate the Data Protection Board of India and each affected data principal; Rule 7 of the DPDP Rules 2025 sets the form: every affected data principal, without delay, with five items of content; the Board without delay with an initial description, and within 72 hours of becoming aware with a six-item detailed report, extendable only on a written request the Board allows.
Failure sits in the Schedule’s ₹200 crore band, one step below the ₹250 crore band for the security safeguards that should have prevented the breach. This guide sets out what counts as a DPDP breach under the Act’s definition, exactly what each notice must contain, the clocks and who starts them, how the duty compares with GDPR’s Articles 33 and 34 and with CERT-In’s incident reporting, and how to build a response that meets both notices from the first hour.

What counts as a DPDP breach
Section 2(u) of the Act defines a personal data breach as “any unauthorised processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises the confidentiality, integrity or availability of personal data”. Three consequences follow.
- Availability counts. Ransomware that encrypts data without exfiltrating it, or an outage that loses access, is a breach if availability is compromised.
- Accidental counts. A misdirected email, a misconfigured bucket, a lost device — no attacker is required.
- Unauthorised processing counts. An employee querying records without a purpose, or a processor using data beyond its instructions, is a breach even with no external actor.
There is no “risk to rights” filter as in GDPR Article 33, and no exemption for encrypted data as in Article 34(3). If the definition is met, both Rule 7 notices are due. Our guide to the DPDP Act covers the definitions.
Rule 7(1): the notice to each affected data principal
| Item | Rule 7(1) content | Drafting note |
|---|---|---|
| (a) | A description of the breach, including its nature, extent and the timing of its occurrence | What happened, what data, when — in plain language |
| (b) | The consequences relevant to her that are likely to arise from the breach | Specific to the individual’s data: fraud, phishing, exposure |
| (c) | The measures implemented and being implemented by the data fiduciary, if any, to mitigate risk | Containment done and under way |
| (d) | The safety measures that she may take to protect her interests | Password reset, monitoring, caution against phishing |
| (e) | Business contact information of a person able to respond on behalf of the data fiduciary to the data principal’s queries | A named contact route, not a generic address |
The notice must be “concise, clear and plain”, sent “without delay”, “to the best of its knowledge”, and delivered through the data principal’s user account or any mode of communication she registered with the fiduciary. There is no de minimis: one affected data principal is notified the same way as a million.
Rule 7(2): the two-stage notice to the Board
| Stage | Clock | Rule 7(2) content |
|---|---|---|
| Initial intimation | Without delay on becoming aware | A description of the breach, including its nature, extent, timing and location of occurrence, and the likely impact |
| Detailed report | Within 72 hours of becoming aware, or such longer period as the Board allows on a written request | (i) Updated and detailed information on the description · (ii) the broad facts related to the events, circumstances and reasons leading to the breach · (iii) measures implemented or proposed to mitigate risk · (iv) any findings regarding the person who caused the breach · (v) remedial measures taken to prevent recurrence · (vi) a report regarding the intimations given to affected data principals |
Item (vi) is the link between the two duties: the Board’s report must account for the data principal notices, so the individual notices cannot be deferred until the investigation is complete. Section 27 lets the Board direct urgent remedial or mitigation measures on receiving an intimation, before any inquiry. Our guide to the DPDP Rules 2025 covers Rule 7 alongside Rule 6, the security safeguards the breach will be measured against.
The DPDP breach clocks compared
| DPDP Act / Rule 7 | GDPR Articles 33–34 | CERT-In Directions (28 April 2022) | |
|---|---|---|---|
| Trigger | Any personal data breach as defined — no risk threshold | Art 33: unless unlikely to result in a risk; Art 34: high risk to individuals | Specified cyber security incidents (e.g. unauthorised access, data breach, ransomware) |
| Regulator notice | Without delay (initial) + 72 hours (detailed report), extendable on written request | Without undue delay and where feasible within 72 hours; phased information allowed | Within six hours of noticing, to CERT-In |
| Individual notice | Every affected data principal, without delay, five items | Only where high risk; exemptions for encryption, later measures, disproportionate effort | Not addressed |
| Processor duty | Contractual (Rule 6 requires security obligations in the processor contract) | Art 33(2): notify controller without undue delay | Applies to service providers and intermediaries directly |
| Penalty for failure | Up to ₹200 crore (Schedule item 2) | Up to €10m or 2% turnover | Section 70B(7) IT Act: imprisonment up to one year or fine up to ₹1 lakh, or both |
An Indian fiduciary hit by a cyber incident therefore runs three clocks: CERT-In’s six hours, the Board’s “without delay” and 72 hours, and the data principal notices “without delay”. The GDPR clock runs too where EU residents are affected. Our guide to DPDP Act vs GDPR covers the wider comparison, and DPDP penalties the Schedule bands.
Building the DPDP breach response
- Define “becoming aware” and who decides it. Both Rule 7 clocks start on awareness. A written trigger — a named incident lead confirms the section 2(u) definition is met — dates the clock and starts the record.
- Pre-draft both notices. A data principal template with the five Rule 7(1) items and a Board initial-intimation template with the Rule 7(2)(a) items, with placeholders. The 72-hour report is a structured document with six headings.
- Solve delivery before the incident. Rule 7(1) requires the user account or a registered communication mode. Confirm that in-app messaging or the registered email/SMS channel can reach every affected principal at scale, and how principals without an active account are reached.
- Make processors report to you fast. Rule 6(f) requires the processor contract to impose security obligations; add a breach-reporting clause with hours, not days, because your Board clock runs from your awareness and your processor’s silence is not a defence.
- Run CERT-In in parallel. The six-hour CERT-In report is a separate filing with its own format; assign it to the same incident lead.
- Prepare the extension request. If the 72-hour report cannot be complete, a written request to the Board for a longer period is the route — not silence. Draft the request template in advance.
- Keep the evidence for section 33(2)(e). The Board must weigh the timeliness and effectiveness of mitigation when setting a penalty; timestamps, decisions and notices sent are what prove it.
- Test annually. A tabletop that runs the three clocks against a realistic scenario finds the delivery and processor gaps before a real breach does.
Frequently asked questions
Does every DPDP breach have to be reported?
Yes. Section 8(6) and Rule 7 contain no risk threshold or de minimis: any breach meeting the section 2(u) definition must be intimated to the Board and to each affected data principal.
What is the DPDP breach notification deadline?
Each affected data principal: without delay. The Board: an initial description without delay, then a detailed six-item report within 72 hours of becoming aware, or a longer period the Board allows on a written request.
What must the notice to data principals contain?
Rule 7(1): a description of the breach (nature, extent, timing); the likely consequences for the individual; mitigation measures implemented and under way; safety measures the individual can take; and business contact details of someone able to answer queries.
Is there an exemption for encrypted data?
No. GDPR Article 34(3) excuses individual notice where data was rendered unintelligible; the DPDP Rules have no equivalent. Encryption still counts under Rule 6 and under section 33(2)(e) mitigation.
What is the penalty for failing to notify?
Schedule item 2: a penalty that may extend to ₹200 crore for breach of the section 8(6) obligation to give the Board or the affected data principal notice of a personal data breach.
Where this leaves you
Treat a DPDP breach as two notices with no threshold: the data principal notice without delay with five items, and the Board notice without delay and again within 72 hours with six. Fix the awareness trigger, pre-draft both, solve delivery, put hours into the processor contract, run CERT-In in parallel, and keep the record that section 33(2)(e) will reward — because the ₹200 crore band is for the notice you did not send, and the ₹250 crore band next to it is for the safeguards that would have made it unnecessary.
References
- The Digital Personal Data Protection Act, 2023 — Gazette text (MeitY) — Sections 2(u), 8(5)–(6), 27, 33 and the Schedule.
- The Digital Personal Data Protection Rules, 2025 — G.S.R. 846(E) (MeitY) — Rule 7, intimation of personal data breach; Rule 6, security safeguards.
- Regulation (EU) 2016/679 (GDPR), Articles 33–34 — EUR-Lex — Comparison.
More on the DPDP Act
- DPDP breach notification — you are here
- The DPDP Act: the complete guide
- The DPDP Rules 2025
- DPDP penalties: the Schedule
- DPDP Act vs GDPR
- The Significant Data Fiduciary
The Personal Data Breach Response Procedure, the Rule 7(1) data principal notice template, the Board initial intimation and 72-hour report templates, the extension request letter and the processor breach-reporting clause are in the DPDP Act Toolkit, or start with the free templates.