Confidential Dispatch

DPDP breach notification: what the 72-hour rule actually requires

6 min readUpdated 2026-07-02
On this page
  1. 01What counts as a personal data breach?
  2. 02The rule people get wrong
  3. 03What you must tell the Data Protection Board
  4. 04What you must tell affected people
  5. 05DPDP is not your only breach clock: CERT-In’s 6 hours
  6. 06What happens if you don’t notify
  7. 07FAQ
At a glance

The “72-hour rule” is widely misread. Under India’s DPDP Rules, if you suffer a personal data breach you must inform the Data Protection Board without delay and tell affected people without delay in plain language — then give the Board a detailed report within 72 hours (circumstances, what you’ve done about it, and who was responsible). The 72 hours is the deadline for the full report to the Board, not permission to wait three days before acting.

Educational resource only. This explains how breach notification works under India’s Digital Personal Data Protection Act, 2023 (DPDP Act), and its Rules; it is not formal legal advice.

What counts as a personal data breach?

A breach is any unauthorised handling — or accidental loss — of personal data that compromises its confidentiality, integrity or availability. The DPDP Act defines it broadly: unauthorised processing, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data.

That breadth is deliberate and worth sitting with. It’s not only the dramatic case of a hacker dumping your customer database. A staff member emailing a spreadsheet of client PANs to the wrong address, a lost laptop with unencrypted KYC files, or ransomware that locks you out of your own records — all of these can be personal data breaches under the definition.

The rule people get wrong

“72 hours” is not how long you have before you do anything — it’s the deadline for the complete report to the Board. A lot of published summaries flatten the rule into “report a breach within 72 hours,” and that gets the timing wrong in a way that matters.

The DPDP Rules actually stage it:

  1. On becoming aware — without delay: give the Data Protection Board an initial intimation (the nature, extent, timing and location of the breach, and its likely impact), and inform the affected people without delay as well.
  2. Within 72 hours (or a longer period if the Board permits on written request): give the Board an updated, detailed report — the broad facts and circumstances, the remedial and mitigation measures you’ve taken, and your findings about who caused it — plus confirmation of the notifications you sent to affected people.

So the honest reading is: act immediately on discovery, then complete the fuller Board report within 72 hours. Treating 72 hours as a grace period is the mistake.

What you must tell the Data Protection Board

Two communications: an immediate first intimation, then a detailed follow-up within 72 hours. The first, without delay, describes the breach — its nature, extent, timing and location, and likely impact. The second, within 72 hours, adds:

  • the broad facts and the circumstances that led to the breach;
  • the remedial and mitigation measures you have implemented;
  • your findings on the person who caused the breach (where known); and
  • an account of the notifications you sent to affected Data Principals.

If you genuinely need longer for the detailed report, the Rules let you ask the Board in writing, with justification — but that’s an exception to request, not a default to assume.

Use the template

DPDP breach notification template — a ready-to-fill report covering both the initial intimation and the detailed 72-hour follow-up.

What you must tell affected people

Each affected person must be told directly, without delay, in a concise and plain manner they can actually act on. You notify them through their account with you or another channel they’ve registered, and the message has to give them enough to protect themselves:

  • a description of the breach — its nature, extent and timing;
  • the consequences relevant to them;
  • the mitigation measures you’re taking;
  • safety measures they can take themselves to reduce their risk; and
  • business contact details — a person or channel they can reach for more.

The framing rule is plain language. A dense, lawyerly notice that leaves an ordinary person unsure whether their Aadhaar or bank details are at risk doesn’t meet the intent of telling them “in a concise, clear and plain manner.”

DPDP is not your only breach clock: CERT-In’s 6 hours

This is the caveat that trips businesses up: a cyber-incident can trigger CERT-In’s 6-hour rule and the DPDP Act’s timeline at the same time. Separate from the DPDP Act, the Indian Computer Emergency Response Team (CERT-In) must be told of cybersecurity incidents within 6 hours of detection, under the Information Technology Act, 2000 (IT Act). These are parallel obligations, not alternatives — most real personal data breaches that involve a cyber-incident will trigger both.

That means the same event can start two clocks with different deadlines (6 hours to CERT-In, “without delay” then 72 hours to the Data Protection Board), different recipients and different report contents — and, in regulated sectors, possibly an RBI or IRDAI (Insurance Regulatory and Development Authority of India) obligation on top. A workable incident-response plan treats these as parallel tracks from the first hour, not one after the other.

What happens if you don’t notify

Failure to notify a breach carries a penalty of up to ₹200 crore — and weak security that let it happen can cost up to ₹250 crore. The DPDP Act’s penalty schedule puts failure to give the required breach notifications in the up-to-₹200 crore band, and failure to take reasonable security safeguards to prevent a breach in the highest, up-to-₹250 crore band.

The practical takeaway is that breach response and breach prevention are penalised separately: doing the notifications correctly does not cure a failure to have had reasonable safeguards in the first place. Both matter, and DPDP compliance requires both.

Note on timing: the breach-notification and security provisions come into force on the staggered DPDP schedule (the operational Rules apply eighteen months from the 13 November 2025 notification — around mid-May 2027), so the window to build the response process is now, before the duty bites.

FAQ

Do I really have to report every breach, even a small one?

The definition is broad and doesn’t carve out small incidents, so the safe reading is to treat any unauthorised handling or loss of personal data as reportable. When unsure, document your assessment.

Is the deadline 72 hours to report a breach?

Not quite. You must inform the Board and affected people without delay on becoming aware; the 72 hours is the deadline for the detailed follow-up report to the Board.

If I report to CERT-In, have I met the DPDP Act’s requirement?

No. CERT-In (6 hours, under the IT Act) and the Data Protection Board (under the DPDP Act) are separate obligations with different recipients, contents and timelines. A breach can require both.

What can it cost if I don’t notify?

Failure to give the required breach notifications can attract a penalty of up to ₹200 crore; failure to have reasonable security safeguards, up to ₹250 crore.

Reviewed by Confidential Dispatch Editorial Team
Last updated 2 July 2026
Not legal advice.

Collecting personal data from your own customers?

These are the rights your business has to honour. See where you stand with a two-minute self-check — no sign-up, no data stored.

Run the compliance self-check →