At a glanceWhen a personal data breach hits, the DPDP Rules require two notifications without delay: a plain-language notice to each affected person, and an initial intimation to the Data Protection Board, followed by a detailed report to the Board within 72 hours. This page is both notifications as ready-to-fill templates, plus the checklist of what the 72-hour report must add. Fill them in during calm weather and park them in your breach-response plan: a breach is the worst possible time to start writing.
Educational resource only. This provides templates for the breach-notification requirements under India’s Digital Personal Data Protection Act, 2023 (DPDP Act) and its Rules; it is not formal legal advice: in a live breach, engage counsel alongside these notifications, not instead of them.
The situation
A breach compresses everything: systems are down, facts are half-known, and two legally required notifications are due without delay: not within 72 hours, which is the deadline for the fuller Board report, but now. Teams that draft these messages mid-incident send them late and say them badly. The fix is boring and effective: have both notifications pre-written with brackets, so the incident only has to supply facts.
What these templates are (and when the clock starts)
Two audiences, two messages, one trigger: becoming aware, not finishing the investigation. On becoming aware of a personal data breach, the Rules require you to inform each affected person, concisely and plainly, through their account or registered contact channel, and to give the Data Protection Board an initial intimation of the breach’s nature, extent, timing, location and likely impact. Both run “without delay.” The detailed report to the Board follows within 72 hours (extendable only on written request the Board grants). A cyber-incident may also start CERT-In’s separate 6-hour clock under the IT Act (a parallel track these templates don’t discharge).
Template 1: notice to affected people
Send through the person’s account or registered channel. Plain language is a legal requirement here, not a style choice: every bracket should be filled in words the person can act on.
Subject: Important: a data security incident affecting your [account / data] with [Business Name]
Dear [name],
We are writing to inform you of a data security incident at [Business Name] that affects your personal data.
What happened: On [date/time], [plain description of what occurred, and its extent].
What of yours is involved: [the specific data categories affected for this person].
What this could mean for you: [the consequences relevant to them].
What we are doing: [the mitigation and remedial measures underway].
What you can do: [specific safety steps].
Reach us: [named contact / channel] for any questions or concerns about this incident.
We will update you if the facts materially change. We apologise for this incident and are treating it with the seriousness it deserves.
[Business Name], [date]
How to fill in Template 1
[Business Name] is the only constant here: fill it in once, everything else is specific to the incident.
[Business Name]
- What it means: Your organisation’s name, exactly as this person already knows it from your other communications.
- Examples: “Confidential Dispatch Pvt Ltd”
[account / data]
- What it means: Whether what’s affected is the person’s account with you, their data, or both. Keep whichever is accurate, and drop the rest.
- Examples: “account”, “personal data”, “account and data”
[name]
- What it means: The recipient’s own name. Each notice should be personalised, not a batch “Dear Customer.”
- Examples: “Dear Priya Nair,”
[date/time]
- What it means: When the breach occurred, to the extent you know it. If the exact time isn’t established yet, say so, and note that you’ll update the person once it is.
- Examples: “14 August 2026”, “the evening of 14 August 2026”
[plain description of what occurred, and its extent]
- What it means: The nature and extent of the breach, in words an ordinary person can follow, not incident-response jargon. This is the fact the Rules require the notice to lead with.
- Examples: “An unauthorised party accessed our customer database on 14 August 2026 and viewed names, email addresses and phone numbers for around 12,000 customers.”
[the specific data categories affected for this person]
- What it means: What was exposed for this recipient specifically, not your organisation-wide list. Different people can have different data affected.
- Examples: “your name, email address and phone number”, “your PAN and bank account number”
[the consequences relevant to them]
- What it means: The likely impact on this person, so they can judge how seriously to react. Say plainly what is and isn’t at risk.
- Examples: “Your Aadhaar number was not exposed. Your email address and phone number were, which may lead to phishing attempts.”
[the mitigation and remedial measures underway]
- What it means: What you are doing in response, so the person knows this isn’t being ignored.
- Examples: “We have secured the affected system, engaged a forensic investigator, and reset all admin credentials.”
[specific safety steps]
- What it means: Concrete actions this person can take themselves to reduce their own risk. This is the field that makes the notice actionable, not just informative.
- Examples: “Reset your password”, “Watch for calls or messages referencing this incident, and don’t act on them”, “Monitor your bank statements for unusual activity.”
[named contact / channel]
- What it means: A real person or reachable channel for follow-up questions, not a no-reply address.
- Examples: “[email protected]”, “our Grievance Officer, Anita Rao, at [email protected]”
[date]
- What it means: The date this specific notice was sent (distinct from the date/time of the breach itself, above).
- Examples: “18 August 2026”
Template 2: initial intimation to the Data Protection Board
File through the Board’s prescribed channel, without delay on becoming aware.
Subject: Initial intimation of personal data breach, [Business Name]
From: [Business Name], [registration/contact details], Grievance Officer: [name, contact].
1. Nature of the breach: [what occurred].
2. Extent: [systems and data categories affected; approximate number of Data Principals].
3. Timing: [when it occurred, if known, and when we became aware].
4. Location: [systems/premises affected].
5. Likely impact: [assessment of consequences for affected Data Principals].
6. Status: Affected Data Principals [have been / are being] notified. A detailed report will follow within 72 hours.
[Authorised signatory, designation, date/time]
How to fill in Template 2
[Business Name], your registration/contact details, and your Grievance Officer’s contact are constants: fill them in once and keep them ready.
[Business Name]
- What it means: Your registered organisation name, as filed with the Board.
- Examples: “Confidential Dispatch Pvt Ltd”
[registration/contact details]
- What it means: Your organisation’s registration number and a contact the Board can use to follow up.
- Examples: “CIN U72900DL2023PTC123456, [email protected]”
[name, contact]
- What it means: Your Grievance Officer’s name and a way to reach them.
- Examples: “Anita Rao, [email protected], +91-XXXXXXXXXX”
[what occurred]
- What it means: The nature of the incident, in plain terms. This is the classification the Board’s intimation needs first.
- Examples: “Unauthorised access”, “accidental disclosure”, “ransomware”
[systems and data categories affected; approximate number of Data Principals]
- What it means: The extent of the breach: which systems, what kind of data, and roughly how many people, even if the exact count isn’t final yet.
- Examples: “Customer database (names, emails, phone numbers), approximately 12,000 Data Principals”
[when it occurred, if known, and when we became aware]
- What it means: Both dates, kept separate: when the breach happened, and when you found out. These are often different.
- Examples: “Occurred approximately 12 August 2026; became aware 14 August 2026”
[systems/premises affected]
- What it means: The specific systems or physical locations involved.
- Examples: “Primary customer database, hosted with [cloud provider] in Mumbai”
[assessment of consequences for affected Data Principals]
- What it means: Your current read on likely impact to the people affected. It can be preliminary: the fuller assessment goes in the detailed report that follows within 72 hours.
- Examples: “Risk of phishing and unsolicited contact; no financial data exposed”
[have been / are being]
- What it means: Whichever is true at the moment you file this: notifications already sent, or still going out.
- Examples: “have been”, “are being”
[Authorised signatory, designation, date/time]
- What it means: Who is filing this on the organisation’s behalf, their role, and when.
- Examples: “Anita Rao, Grievance Officer, 14 August 2026, 6:40 PM”
The 72-hour detailed report: checklist
The follow-up report to the Board must add what the intimation couldn’t yet know. Within 72 hours of becoming aware (unless the Board grants longer on written request), it covers:
- Updated and broad facts, and the circumstances that led to the breach;
- The risk-mitigation measures implemented or proposed;
- The remedial measures taken to prevent the breach recurring;
- Findings on the person who caused the breach, where established;
- Confirmation and account of the notifications sent to affected Data Principals;
- Any changes to the initial intimation’s facts (extent, numbers, impact).
What these templates don’t cover
Notification is one lane of breach response: these templates don’t run the others. They don’t contain the incident (isolation, forensics, recovery), don’t discharge CERT-In’s 6-hour reporting under the IT Act or sectoral duties (RBI, IRDAI) where those apply, and don’t decide legal strategy: penalties for notification failure reach ₹200 crore, so counsel belongs in the loop from hour one. They also assume you can tell who is affected and what was exposed, which is your processing records doing their job; without that map, no template fills itself.
FAQ
Do I notify people before I’ve finished investigating?
Yes: the duty to inform affected people and the Board runs “without delay” on becoming aware, with the fuller facts following in the 72-hour report. Notify with what you know, labelled as current understanding, and update as facts firm up.
Do I have to notify every affected person individually?
Each affected Data Principal must be informed through their account or registered contact channel, in plain language. A press statement or website banner alone doesn’t meet that.
What if 72 hours isn’t enough for the detailed report?
The Rules allow the Board to grant a longer period on a written, justified request: it’s an exception to ask for, not a default. The initial intimation still goes without delay regardless.
Does telling the Board cover my CERT-In duty too?
No: CERT-In’s 6-hour incident reporting under the IT Act is a separate, parallel obligation with its own recipient and content. A cyber-incident breach typically triggers both.