The breach is an event. The silence is a decision.
The scene
Hour one, an engineer notices unusual exports. Hour six, a manager decides to 'confirm before escalating'. Hour thirty, Legal hears about it at lunch. Hour sixty, someone asks who writes to the Board. Hour seventy-one, nobody can say how many people were affected. Nothing in that timeline is malicious. All of it is expensive.
Where the thinking breaks
The unclear thought What it breaks The clearer thought
We'll notify once we know everything.
The Rules require intimation without delay and a detailed report within 72 hours; certainty comes later.
Notify what you know. Update what you learn.
It was the vendor's breach.
The fiduciary's duty to intimate does not transfer to the processor.
Contract for the vendor to tell you in hours, not days.
Only big breaches count.
The Act defines a personal data breach broadly, including unauthorised access and loss of access.
Define thresholds for escalation, not for notification.
Who must be told
The Board, and each affected Data Principal. The Rules specify content: a description of the breach, its likely consequences, mitigation steps, safety measures the person can take, and a contact who can answer.
Monday morning
01 Write the name of who decides to notify, and their deputy.
02 Pre-draft the notice to Data Principals in plain language.
03 Put a 'hours to notify' clause into your top five vendor contracts.
Questions, answered plainly
What is the breach notification timeline under DPDPA? +
Under the DPDP Rules, 2025 a Data Fiduciary must intimate the Board and each affected Data Principal without delay on becoming aware of a personal data breach, and give the Board a detailed report within 72 hours, or a longer period the Board allows.
What is the penalty for failing to notify a breach under DPDPA? +
Failure to give the Board or affected Data Principals intimation of a personal data breach attracts a penalty of up to ₹200 crore under the Schedule to the Act.
Argument 06 You can outsource the processing. You cannot outsource the liability. Read →
Argument 07 Privacy is not a department. It is a board decision. Read →
Argument 08 ₹250 crore is not a line item. It is a balance-sheet event. Read →
Tell us where your data sits. We'll show you where the exposure is.
A partner replies within one working day, with a first view on your penalty exposure.
Speak to a partner →
Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).