AMLEGALS — Strategic Lawyering
Back to Documents
Procedure

Data Breach Response Plan

The documented framework for detecting, responding to, and reporting personal data breaches

Section 8(6)Rule 7

Breaches happen. The question is not whether you will face a breach, but whether you will respond correctly when it occurs. DPDPA gives you 72 hours to notify the Data Protection Board and affected Data Principals. That window is unforgiving. Without a documented plan, you will not meet it.

The 72-Hour Mandate

Section 8(6) and Rule 7 require notification of personal data breaches to the Data Protection Board of India and affected Data Principals within 72 hours of becoming aware. This is not 72 business hours. Not 72 hours from containment. 72 hours from awareness. The clock starts the moment anyone in your organization knows a breach has occurred.

What Constitutes a Breach

A personal data breach is any unauthorized access, disclosure, acquisition, or loss of personal data. This includes accidental exposure, not just malicious attacks. An employee emailing a customer list to the wrong recipient is a breach. A server misconfiguration exposing a database is a breach. Your plan must address the full spectrum.

Key Points
  • Unauthorized access to personal data
  • Unauthorized disclosure or sharing
  • Accidental loss or destruction
  • Data modification without authorization
  • Ransomware encryption of personal data

Detection and Escalation

The plan must define how breaches are detected and escalated. Who receives initial reports. What thresholds trigger escalation. How the response team is activated. Without clear escalation paths, critical hours are lost in confusion about who should be informed and who has authority to act.

Notification Content

Rule 7 specifies what the notification must contain: nature of the breach, approximate number of Data Principals affected, possible consequences, and measures taken or proposed. The notification to Data Principals must also include actionable steps they can take to protect themselves.

Post-Breach Documentation

Every breach must be documented regardless of whether it meets notification thresholds. This documentation serves as evidence of your compliance pulse and informs improvements to prevent recurrence. The plan should specify what records are created and how long they are retained.

Essential Clauses

Breach Definition

Section 8(6)

Clear criteria for what constitutes a notifiable breach

Detection Mechanisms

Rule 7

Technical and procedural controls for breach identification

Escalation Matrix

Rule 7

Who is notified at what severity levels

Response Team Composition

Rule 7

Roles and responsibilities during breach response

Notification Templates

Rule 7

Pre-drafted communications for Board and Data Principals

Timeline Tracking

Section 8(6)

Mechanisms to ensure 72-hour deadline compliance

Root Cause Analysis

Rule 7

Post-incident investigation requirements

Remediation Tracking

Rule 7

How corrective actions are implemented and verified

Implementation Steps

1

Assemble cross-functional breach response team

2

Define breach severity levels and escalation thresholds

3

Draft notification templates for Board and Data Principals

4

Establish communication channels for urgent escalation

5

Implement technical detection capabilities

6

Create documentation templates for breach records

7

Conduct tabletop exercises to test the plan

8

Review and update the plan annually or after each incident

Frequently Asked Questions

Need This Document Drafted?

Understanding the requirement is the first step. Having it implemented correctly is what protects your organization. Our team drafts DPDPA-compliant documents tailored to your specific operations.

Get in Touch

DPDPA Breach Response Plan: questions and answers

What must a DPDPA privacy notice contain?

Section 5 read with Rule 3 requires a notice, understandable independently of other information, that itemises the personal data and the specified purpose, and explains how the Data Principal may withdraw consent, exercise rights and complain to the Board. A Data Principal has the right to access the notice in English or any language specified in the Eighth Schedule to the Constitution. The design of translation operations is an implementation matter.

What makes consent valid under DPDPA?

Section 6 requires consent to be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action and limited to personal data necessary for the specified purpose. Withdrawal must be as easy as giving consent.

Is a Data Fiduciary responsible for its vendors under DPDPA?

Yes. Section 8(1) makes the Data Fiduciary responsible for compliance in respect of processing undertaken by it or on its behalf by a Data Processor. Section 8(2) requires a Data Fiduciary to engage a Data Processor under a valid contract. Detailed contractual clause architecture is an implementation best practice guided by Section 8(2).

Which provisions of the DPDPA and the DPDP Rules, 2025 are relevant to DPDPA Breach Response Plan?

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).

Who advises businesses on DPDPA Breach Response Plan under India's DPDPA?

AMLEGALS, an Indian law firm, advises Data Fiduciaries, Data Processors and foreign companies on DPDPA Breach Response Plan under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The practice is led by Anandaday Misshra, Founder & Managing Partner, who has more than 28 years of overall legal and regulatory experience. Enquiries: https://amlegalsdpdpa.com/contact or [email protected] or [email protected].

What should I send AMLEGALS to get a scoped proposal on DPDPA Breach Response Plan?

Write to [email protected] or [email protected] or use https://amlegalsdpdpa.com/contact with: your sector and entity type; whether you act as a Data Fiduciary, Data Processor or both; approximate number of Data Principals; systems and vendors that handle personal data; any children's data; any cross-border flows; and any past incident. With these facts a partner can propose a scope for DPDPA Breach Response Plan rather than a generic checklist.

How do I get a first view of my DPDPA exposure on DPDPA Breach Response Plan?

Use the DPDPA Exposure Assessment at https://amlegalsdpdpa.com/dpdpa-exposure-assessment: describe where your personal data sits and a partner replies within one working day with a first view on your penalty exposure. Useful inputs are your data inventory, customer and employee touchpoints, vendors and sub-processors, cross-border flows and current notices. The principal obligations commence on 13 May 2027. Content is general legal information and not legal advice.

Contact AMLEGALS about DPDPA Breach Response Plan · DPDPA Exposure Assessment