The two-stage notification process
Section 8(6) creates the obligation; Rule 7 provides the procedure:
- 01
Stage 1: Intimation without delay
The Data Fiduciary must intimate the Data Protection Board and each affected Data Principal about the breach as soon as it becomes aware of it. “Without delay” means without unreasonable delay—the clock starts when the organisation has credible evidence of a breach, not when the forensic investigation is complete.
- 02
Stage 2: Detailed report within 72 hours
Rule 7 requires a detailed report to the Board within 72 hours. The report must describe the nature of the breach, the categories and approximate number of Data Principals affected, the likely consequences, the measures taken or proposed to address the breach and to mitigate its effects.
CERT-In parallel obligation: six-hour reporting
The Indian Computer Emergency Response Team (CERT-In) Directions issued in April 2022 under the IT Act 2000 require organisations to report specified cyber-security incidents to CERT-In within six hours of noticing or being brought to notice of the incident. “Specified incidents” include data breaches, ransomware attacks, phishing and unauthorised access.
The CERT-In six-hour clock and the DPDPA 72-hour clock run in parallel—they are separate obligations under different statutes. A personal data breach that is also a cyber-security incident must be reported to both CERT-In (within 6 hours) and the Data Protection Board (detailed report within 72 hours). Compliance with one does not satisfy the other.
| Parameter | DPDPA (S.8(6), Rule 7) | CERT-In Directions (2022) |
|---|---|---|
| Timeline | Intimation without delay + detailed report in 72 hours | 6 hours from awareness |
| Recipient | Data Protection Board + affected Data Principals | CERT-In |
| Scope | Personal data breaches | Cyber-security incidents (broader) |
| Governing law | DPDPA 2023 | IT Act 2000, S.70B |
| Penalty | Up to ₹200 crore | IT Act penalties + CERT-In enforcement |
What the detailed report must contain
Rule 7 specifies the content of the detailed breach report to the Board:
- Nature and circumstances of the personal data breach
- Categories of personal data affected (e.g. identity data, financial data, health data)
- Approximate number of Data Principals affected
- Likely consequences of the breach for the affected Data Principals
- Measures taken or proposed to address the breach
- Measures taken or proposed to mitigate the adverse effects on Data Principals
- Contact details of the Data Protection Officer or other point of contact
Penalties for non-notification
The DPDPA Schedule sets the penalty ceiling for non-compliance with Section 8(6) at up to ₹200 crore, as determined by the Data Protection Board after inquiry. Section 33(2) lists the factors the Board considers: the nature, gravity and duration of the breach; whether the Data Fiduciary took prompt action to mitigate; whether there was a pattern of contravention; and any gain made or loss avoided.
Separately, failure to implement the security safeguards that should have prevented the breach (Section 8(5)) carries a ceiling of up to ₹250 crore. In a breach scenario, both provisions may be engaged—the Board can assess the security failure and the notification failure independently.
How AMLEGALS assists with breach response
AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder and Managing Partner, with Rohit Lalwani, Associate Partner, working on DPDPA compliance. The firm assists organisations in building breach-response playbooks, managing the dual DPDPA/CERT-In notification process under time pressure, drafting Board notifications and representing Data Fiduciaries in Board proceedings following a breach.

