Data Breach Notification
Rule 7 of DPDP Rules 2025 mandates timely notification of personal data breaches to the Data Protection Board and affected Data Principals.
Breach Response Process
Detect & Assess
Identify the breach and assess its scope, impact, and the personal data affected
Contain & Mitigate
Take immediate steps to contain the breach and prevent further unauthorized access
Notify the Board
Intimate the Data Protection Board about the breach in prescribed form and manner
Notify Data Principals
Inform affected Data Principals about the breach and remedial actions
Notification Timeline
To Data Protection Board
Notify without unreasonable delay, and in any case within 72 hours of becoming aware of the breach.
To Affected Data Principals
Notify as directed by the Board, typically without undue delay after Board notification.
What to Include in Notifications
Board Notification
Data Principal Notification
Strengthen Your Compliance Posture
Explore complementary certifications that work together to provide comprehensive security and compliance coverage.