Silence after a breachis the most expensive sound.

Failure to intimate a breach carries its own penalty of up to ₹200 crore, separate from the breach itself.

In one line: Under the DPDP Rules, 2025 a Data Fiduciary must intimate the Board and each affected Data Principal without delay on becoming aware of a personal data breach, and give the Board a detailed report within 72 hours, or a longer period the Board allows.

The estate · The first 72 hoursHover to inspect

The breach is an event. The silence is a decision.

The scene

Hour one, an engineer notices unusual exports. Hour six, a manager decides to 'confirm before escalating'. Hour thirty, Legal hears about it at lunch. Hour sixty, someone asks who writes to the Board. Hour seventy-one, nobody can say how many people were affected. Nothing in that timeline is malicious. All of it is expensive.

Where the thinking breaks

The unclear thoughtWhat it breaksThe clearer thought
We'll notify once we know everything. The Rules require intimation without delay and a detailed report within 72 hours; certainty comes later. Notify what you know. Update what you learn.
It was the vendor's breach. The fiduciary's duty to intimate does not transfer to the processor. Contract for the vendor to tell you in hours, not days.
Only big breaches count. The Act defines a personal data breach broadly, including unauthorised access and loss of access. Define thresholds for escalation, not for notification.

Who must be told

The Board, and each affected Data Principal. The Rules specify content: a description of the breach, its likely consequences, mitigation steps, safety measures the person can take, and a contact who can answer.

Monday morning

  1. 01Write the name of who decides to notify, and their deputy.
  2. 02Pre-draft the notice to Data Principals in plain language.
  3. 03Put a 'hours to notify' clause into your top five vendor contracts.

Questions, answered plainly

What is the breach notification timeline under DPDPA?

Under the DPDP Rules, 2025 a Data Fiduciary must intimate the Board and each affected Data Principal without delay on becoming aware of a personal data breach, and give the Board a detailed report within 72 hours, or a longer period the Board allows.

What is the penalty for failing to notify a breach under DPDPA?

Failure to give the Board or affected Data Principals intimation of a personal data breach attracts a penalty of up to ₹200 crore under the Schedule to the Act.

Argument 06You can outsource the processing. You cannot outsource the liability.Read → Argument 07Privacy is not a department. It is a board decision.Read → Argument 08₹250 crore is not a line item. It is a balance-sheet event.Read →

Tell us where your data sits.We'll show you where the exposure is.

A partner replies within one working day, with a first view on your penalty exposure.

Speak to a partner