Confidential Dispatch

What a company must tell you after a data breach

4 min readUpdated 2026-07-03
On this page
  1. 01You have a right to be told — directly
  2. 02The five things the notice must contain
  3. 03How and when they must tell you
  4. 04What to do if the notice is vague or never comes
  5. 05FAQ
At a glance

If a company suffers a breach involving your personal data, India’s DPDP Act requires it to tell you — the affected person — without delay and in plain language. The notice must describe what happened, the likely consequences for you, what the company is doing about it, what you can do to protect yourself, and who to contact. A vague “we take your privacy seriously” email that hides the facts doesn’t meet that bar.

Educational resource only. This explains what a business must tell affected people after a breach under India’s Digital Personal Data Protection Act, 2023 (DPDP Act) and its Rules; it is not formal legal advice.

You have a right to be told — directly

A breach of your data isn’t the company’s private problem to quietly manage — the law says you must be informed.

Under the DPDP Act, when a business suffers a personal data breach — any unauthorised access, disclosure, loss or alteration of personal data — it must notify the people affected, not just the regulator. That’s a deliberate design choice: you can’t protect yourself against a leak you don’t know about. So the notice to you isn’t a courtesy; it’s an obligation the company owes you.

The five things the notice must contain

A proper breach notice has to give you enough to actually act — not just admit something went wrong.

The DPDP Rules set out what the message to affected people must cover. Look for all five:

  • What happened — a description of the breach: its nature, extent and timing.
  • The consequences for you — the likely impact, so you can gauge your risk (is your Aadhaar exposed? your card? just your email?).
  • What the company is doing — the mitigation measures it’s taking in response.
  • What you can do — the safety measures you can take yourself to reduce your risk (for example, change a password, watch for fraud).
  • Who to contact — business contact details, so you can reach a person or channel for more information.

If a notice tells you a breach occurred but leaves out the consequences or what you can do, it’s missing the parts that actually help you.

How and when they must tell you

The rule is “without delay,” in plain language, through a channel that reaches you.

Two things govern the timing and form. First, without delay — the company can’t sit on the news while it manages the fallout; you’re meant to be told promptly on the company becoming aware. (Separately, the business also has to report a detailed account to the Data Protection Board within 72 hours — but that Board deadline is not a licence to delay telling you.) Second, plain language — the notice has to be concise and clear enough for an ordinary person to understand, delivered through your account with them or another channel you’ve registered. A dense, lawyerly message that leaves you unsure whether your bank details are at risk doesn’t meet the intent.

What to do if the notice is vague or never comes

A missing or evasive breach notice is itself a failure you can escalate.

If you learn about a breach but got no notice, or the notice was so vague it told you nothing useful, you’re not without recourse:

FAQ

Does a company have to tell me personally, or just announce it?

It must notify affected people — you — through your account or a channel you’ve registered, not merely post a general notice. The message has to reach you and be understandable.

How quickly must they tell me?

Without delay, on becoming aware of the breach. The separate 72-hour deadline is for the company’s detailed report to the Data Protection Board, and doesn’t justify delaying your notice.

What if the notice doesn’t say what data of mine was affected?

That’s a gap. You can use your right of access to ask directly, and press for the consequences and safety steps the notice should have included.

What can I do if a company hides a breach?

Complain to the company’s grievance channel, then the Data Protection Board of India. Failure to notify a breach can attract significant penalties for the business.

Reviewed by Confidential Dispatch Editorial Team
Last updated 3 July 2026
Not legal advice.

Collecting personal data from your own customers?

These are the rights your business has to honour. See where you stand with a two-minute self-check — no sign-up, no data stored.

Run the compliance self-check →