Email WhatsApp
Breach notification — Rule 7

DPDPA data breach notification requirements in India: the 72-hour rule.

For data breach notification under DPDPA (the DPDP Act), “72 hours” is only part of the requirement. Rule 7 creates an immediate notification duty and a second, more detailed report to the Board within 72 hours.

Incidents, suspected breaches, and confirmed breaches

Under DPDP, a personal data breach is any unauthorised processing, or accidental disclosure, alteration, loss, or destruction, of personal data that compromises its confidentiality, integrity, or availability. That's a deliberately broad definition. A misconfigured cloud folder left open to the public, an email sent to the wrong recipient, a lost laptop, a phishing attack that steals a password — any of these can qualify, whether malicious or accidental.

But a key distinction matters for how employees should be trained: the person spotting the problem is not usually the person qualified to classify it. A wrong email or a stolen laptop is initially a suspected incident — whether it becomes a confirmed personal data breach depends on facts an employee may not know (was the data encrypted? was it recoverable? was it actually accessed?). The employee's job is not to make that call. It's to report immediately so the response team can investigate and classify correctly.

DPDP breach notification requirements under Rule 7

Rule 7 of the DPDP Rules, 2025 sets out the organisation's obligation once the Data Fiduciary becomes aware of a personal data breach:

StageWho receives itTimeline
Stage 1Data Protection Board and every affected Data PrincipalWithout delay — even before the investigation is complete
Stage 2Data Protection BoardDetailed report within 72 hours. The Board may allow a longer period on written request.

These are duties of the organisation (the Data Fiduciary) — not personal duties of any individual employee. Note the Board's discretion to extend the detailed report period on written request — the 72-hour figure is a default, not an inviolable maximum.

Delays inside the organisation cost the response team time. The clock starts when the organisation becomes aware — not when an employee individually decides to escalate. If a suspected incident sits unrouted in someone's inbox for two days, that's two days the response team no longer has to investigate, contain, and meet notification duties.

Why organisations miss the 72-hour DPDP deadline

When data breach notifications fail to meet the 72-hour DPDP deadline, the bottleneck is often internal rather than legal: the incident is not escalated promptly, ownership is unclear, evidence is altered while someone tries to “fix” the problem, or teams wait for certainty before alerting the response function. Clear reporting routes and DPDPA employee awareness training help reduce that avoidable delay by teaching staff to recognise a suspected incident and report it immediately.

What an employee should actually do

If you spot something that might be an incident — even one you may have caused yourself:

  • Report it immediately to your designated contact or IT security. Not tomorrow, not once you've looked into it.
  • Preserve the evidence — the email, the logs, the device's last known state. Don't try to quietly delete or fix anything.
  • When in doubt, report anyway. Let the response team decide whether it's a confirmed breach — that classification is their call, not yours.
  • Don't discuss it on WhatsApp groups or informal channels while it's being investigated.

A parallel obligation worth knowing about

If the incident is also a cybersecurity incident, CERT-In's separate directions may require reporting within 6 hours of discovery — a shorter, stricter window than DPDP's own timeline, and owed to a different regulator entirely. One incident may trigger obligations under more than one law. The response team handles this — but the employee needs to understand that fast internal reporting is what gives the organisation the time to meet all applicable deadlines. See also the DPDP penalty framework for breach-related contraventions.