AMLEGALS — Strategic Lawyering

Bank Data Breach Reporting in India: CERT-In, RBI and DPDPA Together

Bank Data Breach Reporting in India: CERT-In, RBI and DPDPA Together

The breach is one event. The reporting is three exams, sat at the same time.

The scene

The alert came at 2am. By 8am the CISO had told CERT-In, as the 2022 directions require within six hours. By noon the RBI team had filed their incident report. At four in the afternoon someone asked whether the forty thousand customers whose statements were exposed had been told. Nobody had been asked to do that.

Where the thinking breaks

The unclear thought What it breaks The clearer thought

Security reporting covers privacy reporting.

CERT-In and RBI reports go to regulators; DPDPA also requires intimation to each affected Data Principal.

Add the customer to the playbook as a recipient, with a pre-drafted notice.

The CISO owns incidents.

The CISO owns the technical response; the decision to notify under DPDPA is a legal and business call.

Name one incident commander across security, legal and communications.

Designing one playbook

Map the three regimes side by side: trigger, recipient, timeline, content. Where they overlap, draft once. Where they differ, assign an owner. Rehearse the whole thing against a single scenario, with a stopwatch.

Monday morning

01 Put CERT-In, RBI and DPDPA timelines on one page.

02 Pre-draft the customer notice in English and one regional language.

03 Run a two-hour drill where all three clocks start together.

Questions, answered plainly

Does a bank need to report a data breach to both CERT-In and the Data Protection Board? +

A cyber incident may need reporting to CERT-In under its 2022 directions, and a personal data breach must also be intimated to the Data Protection Board and each affected Data Principal under DPDPA and the Rules. Sectoral reporting to the RBI may apply as well.

What is the CERT-In reporting timeline? +

CERT-In's April 2022 directions require specified cyber security incidents to be reported within six hours of noticing them.

Sector · Banking & BFSI Banks keep everything. The law now asks why. Read →

Banking & BFSI · Deep dive The law says keep. The Act asks: keep what, exactly? Read →

Banking & BFSI · Deep dive Your DSA's phone is inside your perimeter. Read →

Tell us where your data sits. We'll show you where the exposure is.

A partner replies within one working day, with a first view on your penalty exposure.

Speak to a partner →

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).