Email WhatsApp
Breach notification — Rule 7

DPDP breach notification: the 72-hour rule, explained properly.

Most people compress this into "72 hours to report a breach" — the reality has two separate clocks, two separate audiences, and no threshold below which it doesn't apply.

Incidents, suspected breaches, and confirmed breaches

Under DPDP, a personal data breach is any unauthorised processing, or accidental disclosure, alteration, loss, or destruction, of personal data that compromises its confidentiality, integrity, or availability. That's a deliberately broad definition. A misconfigured cloud folder left open to the public, an email sent to the wrong recipient, a lost laptop, a phishing attack that steals a password — any of these can qualify, whether malicious or accidental.

But a key distinction matters for how employees should be trained: the person spotting the problem is not usually the person qualified to classify it. A wrong email or a stolen laptop is initially a suspected incident — whether it becomes a confirmed personal data breach depends on facts an employee may not know (was the data encrypted? was it recoverable? was it actually accessed?). The employee's job is not to make that call. It's to report immediately so the response team can investigate and classify correctly.

Two stages of reporting, under Rule 7

Rule 7 of the DPDP Rules, 2025 sets out the organisation's obligation once the Data Fiduciary becomes aware of a personal data breach:

StageWho receives itTimeline
Stage 1Data Protection Board and every affected Data PrincipalWithout delay — even before the investigation is complete
Stage 2Data Protection BoardDetailed report within 72 hours. The Board may allow a longer period on written request.

These are duties of the organisation (the Data Fiduciary) — not personal duties of any individual employee. Note the Board's discretion to extend the detailed report period on written request — the 72-hour figure is a default, not an inviolable maximum.

Delays inside the organisation cost the response team time. The clock starts when the organisation becomes aware — not when an employee individually decides to escalate. If a suspected incident sits unrouted in someone's inbox for two days, that's two days the response team no longer has to investigate, contain, and meet notification duties.

What an employee should actually do

If you spot something that might be an incident — even one you may have caused yourself:

  • Report it immediately to your designated contact or IT security. Not tomorrow, not once you've looked into it.
  • Preserve the evidence — the email, the logs, the device's last known state. Don't try to quietly delete or fix anything.
  • When in doubt, report anyway. Let the response team decide whether it's a confirmed breach — that classification is their call, not yours.
  • Don't discuss it on WhatsApp groups or informal channels while it's being investigated.

A parallel obligation worth knowing about

If the incident is also a cybersecurity incident, CERT-In's separate directions may require reporting within 6 hours of discovery — a shorter, stricter window than DPDP's own timeline, and owed to a different regulator entirely. One incident may trigger obligations under more than one law. The response team handles this — but the employee needs to understand that fast internal reporting is what gives the organisation the time to meet all applicable deadlines.