AMLEGALS — Strategic Lawyering
HomeDPDPA InsightsData Breach Notification Under DPDPA
Inviolum™

Data Breach Notification Under DPDPA

Compliance Protocols for Incident Response

"In the event of a personal data breach, the Data Fiduciary shall give the Board and each affected Data Principal intimation of such breach."

— DPDPA Section 8(6)

The Breach Response Imperative

Section 8(6) establishes a dual notification obligation: intimation to the Data Protection Board of India and to each affected Data Principal. Rule 7 prescribes the manner and content of this intimation. The phrase "without undue delay" sets an ambiguous but urgent standard that organisations must operationalise through pre-established protocols.

The breach notification regime intersects with CERT-In Directions 2022, which mandates 6-hour reporting for cyber incidents. Organisations must maintain parallel notification pathways: one to CERT-In for cyber security incidents and another to DPBI for personal data breaches. The classification of an incident as both cyber incident and personal data breach triggers concurrent obligations.

Delayed notification constitutes an independent violation carrying separate penalties under The Schedule. Organisations cannot await complete forensic analysis before notification. The statutory expectation is prompt intimation with subsequent updates as investigation progresses.

Key Provisions

Section 8(6)

Dual Notification Obligation

Data Fiduciaries must notify both the Data Protection Board and each affected Data Principal. The dual obligation ensures regulatory oversight and individual awareness concurrently.

Rule 7

Notification Content

Intimation must include: nature and extent of breach, personal data categories affected, likely consequences, remedial measures undertaken, and contact information for further queries.

Section 8(6) read with Rule 7

Timing Standard

Notification must be "without undue delay." This standard requires organisations to notify promptly upon becoming aware of a breach, not upon completing investigation.

Section 8(2) read with Section 8(6)

Processor Notification

Data Processors must notify Data Fiduciaries of breaches occurring in their processing environment, enabling the Fiduciary to fulfil notification obligations.

Incident Response Architecture

Pre-drafted notification templates reduce response time. Templates must be customisable for breach-specific details while maintaining statutory content requirements.

Escalation matrices must define authority for breach classification and notification decisions. Delays in internal escalation translate to notification delays.

Data Principal notification at scale requires infrastructure for mass communication with personalisation capability.

Forensic investigation and notification must proceed in parallel. Organisations cannot defer notification pending investigation completion.

Post-breach remediation documentation supports regulatory engagement and demonstrates good faith compliance efforts.

Implementation Challenges

Breach Detection Latency

Practice Note: Many breaches remain undetected for extended periods. Organisations must invest in detection capabilities to minimise the gap between occurrence and awareness, which defines the notification timeline start.

Affected Principal Identification

Practice Note: Determining which Data Principals are affected requires data mapping and forensic analysis. The tension between thoroughness and speed must be managed through staged notification approaches.

Multi-Regulator Coordination

Practice Note: Breaches may trigger CERT-In, DPBI, and sector regulator notifications. Coordination mechanisms must ensure consistent messaging while meeting different reporting requirements.

Inviolum Framework Application

V

Verification

Conduct tabletop exercises simulating breach scenarios. Audit notification templates against Rule 7 content requirements.

I

Implementation

Establish 24x7 incident response teams with defined escalation paths. Deploy mass notification systems with Data Principal contact databases.

B

Benchmarking

Measure time from detection to notification, affected principal coverage rate, and regulatory response outcomes.

E

Enforcement

Implement automated breach classification triggers. Establish mandatory notification review checkpoints before external communication.

Statutory References

DPDPA Section 8(6)DPDP Rules 2025 Rule 7CERT-In Directions 2022DPDPA The Schedule

Compliance Assessment

This analysis represents general guidance. Your organisation's compliance pulse requires assessment against specific processing activities.

Get in Touch

Data Breach Notification DPDPA: questions and answers

What is the legal framework for data protection in India?

India's framework is the Digital Personal Data Protection Act, 2023 (Presidential assent 11 August 2023; 44 sections) read with the Digital Personal Data Protection Rules, 2025, notified on 13 November 2025 (G.S.R. 846(E)) with 23 Rules and 7 Schedules.

When do DPDPA obligations apply to businesses?

The Act and Rules follow phased commencement. Institutional provisions commenced on 13 November 2025; Consent Manager provisions commence after 12 months on 13 November 2026; and the principal Data Fiduciary, rights, breach, security and enforcement provisions commence after 18 months on 13 May 2027.

What rights do individuals have under DPDPA?

Data Principals have the right to access information about processing (Section 11), correction, completion, updating and erasure (Section 12), grievance redressal (Section 13) and nomination (Section 14). Rule 14 governs the manner in which these rights are exercised.

Which provisions of the DPDPA and the DPDP Rules, 2025 are relevant to Data Breach Notification DPDPA?

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).

Who advises businesses on Data Breach Notification DPDPA under India's DPDPA?

AMLEGALS, an Indian law firm, advises Data Fiduciaries, Data Processors and foreign companies on Data Breach Notification DPDPA under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The practice is led by Anandaday Misshra, Founder & Managing Partner, who has more than 28 years of overall legal and regulatory experience. Enquiries: https://amlegalsdpdpa.com/contact or [email protected] or [email protected].

What should I send AMLEGALS to get a scoped proposal on Data Breach Notification DPDPA?

Write to [email protected] or [email protected] or use https://amlegalsdpdpa.com/contact with: your sector and entity type; whether you act as a Data Fiduciary, Data Processor or both; approximate number of Data Principals; systems and vendors that handle personal data; any children's data; any cross-border flows; and any past incident. With these facts a partner can propose a scope for Data Breach Notification DPDPA rather than a generic checklist.

How do I get a first view of my DPDPA exposure on Data Breach Notification DPDPA?

Use the DPDPA Exposure Assessment at https://amlegalsdpdpa.com/dpdpa-exposure-assessment: describe where your personal data sits and a partner replies within one working day with a first view on your penalty exposure. Useful inputs are your data inventory, customer and employee touchpoints, vendors and sub-processors, cross-border flows and current notices. The principal obligations commence on 13 May 2027. Content is general legal information and not legal advice.

Contact AMLEGALS about Data Breach Notification DPDPA · DPDPA Exposure Assessment