What is a personal data breach (DPDP)?
A personal data breach is any unauthorised handling — or accidental loss — of personal data that compromises its confidentiality, integrity, or availability. It covers far more than a hacker stealing a database.
Educational resource only — not legal advice.
Under India’s Digital Personal Data Protection Act, 2023 (DPDP Act), the definition is deliberately broad: unauthorised processing, or accidental disclosure, acquisition, sharing, use, alteration, destruction, or loss of access to personal data. So a spreadsheet of customer details emailed to the wrong person, a lost unencrypted laptop, or ransomware that locks you out of your own records can each be a breach.
Why it matters to you. For a business, recognising what counts as a breach is the first step — because a breach triggers a duty to notify the Data Protection Board and the affected people. Treating only “hacks” as breaches misreads the obligation and can mean a required notification is missed.
Collecting personal data from your own customers?
These are the rights your business has to honour. See where you stand with a two-minute self-check — no sign-up, no data stored.
Run the compliance self-check →