AMLEGALS — Strategic Lawyering
Security

How to Respond to Data Breaches Within 72 Hours

Building incident response capabilities for timely breach notification under DPDPA

Updated 16 January 2025

Executive Summary

A personal data breach triggers notification obligations under Section 8(6) of the DPDPA. The practical reality of breach response demands preparation long before any incident occurs. This guide addresses the technical, procedural, and communication aspects of breach response that enable timely and effective notification.

Key Takeaways

  • 1
    Pre-establish incident response teams, procedures, and communication templates
  • 2
    Implement detection capabilities that identify breaches promptly
  • 3
    Document all response actions contemporaneously for regulatory demonstration
  • 4
    Notify the Data Protection Board within prescribed timelines with required particulars
  • 5
    Consider Data Principal notification where the breach poses significant risk

1Understanding Breach Notification Obligations

Section 8(6) requires Data Fiduciaries to inform the Data Protection Board and affected Data Principals of any personal data breach. The Rules prescribe the form and manner of notification. The clock starts when the organisation becomes aware of the breach, making detection capabilities as important as response procedures.

2Establishing the Incident Response Team

Effective breach response requires coordinated action across multiple functions. Establish the team and define roles before any incident occurs.

1

Identify Team Members

Include representatives from IT security, legal, communications, customer service, and senior management. Define primary and backup contacts for each function.

2

Define Roles and Responsibilities

Specify who leads the response, who handles technical containment, who manages legal assessment, who coordinates communications, and who liaises with regulators.

3

Establish Escalation Paths

Define criteria for escalating incidents to senior leadership and the board. Not all incidents require board involvement, but significant breaches demand executive attention.

4

Conduct Regular Training

Run tabletop exercises simulating breach scenarios. Practice improves response speed and quality when real incidents occur.

3Detecting Breaches

You cannot respond to what you do not know about. Detection capabilities directly impact notification timeliness.

1

Technical Monitoring

Deploy intrusion detection systems, security information and event management platforms, and data loss prevention tools. Configure alerting for suspicious activities.

2

Log Analysis

Maintain comprehensive logs and conduct regular analysis for anomalies that might indicate unauthorised access.

3

Employee Reporting

Train employees to recognise and report potential incidents. Suspicious emails, unexpected system behaviour, and customer reports of fraud may indicate breaches.

4

Third Party Notifications

Establish procedures for receiving and acting on breach notifications from processors and partners. Contractual provisions should require prompt notification.

4Initial Response and Containment

Once a potential breach is identified, immediate actions focus on limiting damage while preserving evidence.

1

Activate the Incident Response Team

Notify team members and establish a command structure. Begin logging all actions with timestamps.

2

Assess the Situation

Determine what happened, what systems are affected, what data may be compromised, and whether the incident is ongoing.

3

Contain the Breach

Take immediate steps to stop ongoing unauthorised access. This may include isolating affected systems, revoking compromised credentials, or blocking malicious IP addresses.

4

Preserve Evidence

Capture forensic images of affected systems before remediation. Evidence preservation is essential for investigation and may be required for regulatory proceedings.

Important Warnings

  • •Hasty containment actions can destroy evidence. Coordinate containment with forensic requirements.
  • •Do not assume the breach is contained without verification. Attackers often maintain persistent access.

5Assessing Notification Requirements

Not every security incident triggers notification obligations. Assess whether the incident constitutes a personal data breach and what notification is required.

1

Identify Affected Data

Determine what personal data was or may have been accessed, acquired, disclosed, or destroyed. Consider both confirmed and potential exposure.

2

Assess Impact

Evaluate the likely consequences for affected Data Principals. Consider the nature of the data, the number of individuals affected, and the circumstances of the breach.

3

Document the Assessment

Record the analysis supporting notification decisions. If notification is not required, document the justification.

6Notifying the Data Protection Board

Notification to the Board must be made in prescribed form within required timelines.

1

Prepare the Notification

Include the nature of the breach, categories and approximate number of Data Principals affected, likely consequences, and measures taken or proposed to address the breach.

2

Submit Within Timelines

Submit the notification within the prescribed period. If full details are not yet available, provide initial notification with commitment to supplement.

3

Maintain Communication

Respond promptly to any Board inquiries. Be prepared to provide additional information as the investigation progresses.

7Notifying Affected Data Principals

Where the breach is likely to result in significant harm to Data Principals, direct notification enables them to take protective measures.

1

Determine Notification Scope

Identify which Data Principals must be notified based on breach impact assessment.

2

Prepare Clear Communication

Explain what happened, what data was affected, what the organisation is doing, and what steps the individual should take. Avoid technical jargon and legal disclaimers that obscure the message.

3

Select Appropriate Channels

Use reliable contact methods. For large scale breaches, multiple channels may be necessary including email, postal mail, and public announcement.

4

Provide Support Resources

Offer assistance such as credit monitoring, identity protection services, or dedicated support channels where appropriate to the breach type.

8Post Incident Activities

After immediate response, conduct thorough review to improve future preparedness.

1

Root Cause Analysis

Determine how the breach occurred and why existing controls failed to prevent or detect it.

2

Remediation Implementation

Address identified vulnerabilities and control gaps. Verify remediation effectiveness.

3

Process Improvement

Update incident response procedures based on lessons learned. Revise training materials and conduct refresher exercises.

4

Documentation Retention

Maintain comprehensive records of the incident and response for regulatory compliance and potential litigation defence.

Frequently Asked Questions

Need Implementation Support?

Our data protection team can help translate these guidelines into organisation-specific policies, procedures, and technical implementations.

Get Expert Guidance

Respond Data Breaches: questions and answers

When do DPDPA obligations apply to businesses?

The Act and Rules follow phased commencement. Institutional provisions commenced on 13 November 2025; Consent Manager provisions commence after 12 months on 13 November 2026; and the principal Data Fiduciary, rights, breach, security and enforcement provisions commence after 18 months on 13 May 2027.

What must a DPDPA privacy notice contain?

Section 5 read with Rule 3 requires a notice, understandable independently of other information, that itemises the personal data and the specified purpose, and explains how the Data Principal may withdraw consent, exercise rights and complain to the Board. A Data Principal has the right to access the notice in English or any language specified in the Eighth Schedule to the Constitution. The design of translation operations is an implementation matter.

When must personal data be erased under DPDPA?

Section 8(7) requires erasure once the specified purpose is no longer served or consent is withdrawn, unless retention is required by law. Rule 8 and the Third Schedule prescribe time periods for specified classes of Data Fiduciaries, with prior intimation to the Data Principal before erasure.

Which provisions of the DPDPA and the DPDP Rules, 2025 are relevant to Respond Data Breaches?

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).

Who advises businesses on Respond Data Breaches under India's DPDPA?

AMLEGALS, an Indian law firm, advises Data Fiduciaries, Data Processors and foreign companies on Respond Data Breaches under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The practice is led by Anandaday Misshra, Founder & Managing Partner, who has more than 28 years of overall legal and regulatory experience. Enquiries: https://amlegalsdpdpa.com/contact or [email protected] or [email protected].

What should I send AMLEGALS to get a scoped proposal on Respond Data Breaches?

Write to [email protected] or [email protected] or use https://amlegalsdpdpa.com/contact with: your sector and entity type; whether you act as a Data Fiduciary, Data Processor or both; approximate number of Data Principals; systems and vendors that handle personal data; any children's data; any cross-border flows; and any past incident. With these facts a partner can propose a scope for Respond Data Breaches rather than a generic checklist.

How do I get a first view of my DPDPA exposure on Respond Data Breaches?

Use the DPDPA Exposure Assessment at https://amlegalsdpdpa.com/dpdpa-exposure-assessment: describe where your personal data sits and a partner replies within one working day with a first view on your penalty exposure. Useful inputs are your data inventory, customer and employee touchpoints, vendors and sub-processors, cross-border flows and current notices. The principal obligations commence on 13 May 2027. Content is general legal information and not legal advice.

Contact AMLEGALS about Respond Data Breaches · DPDPA Exposure Assessment