India's DPDP Breach Rule Has No Harm Threshold and a 72-Hour Report, and It Does Not Start Until 2027
Key Takeaways
- Section 8(5), section 8(6) and rules 6 and 7 all commence eighteen months after 13 November 2025, which puts them in May 2027; as at 21 September 2026 they are not in force
- The Act attaches no harm or risk threshold: section 8(6) reaches every personal data breach and each affected Data Principal
- Rule 7(2) requires two reports to the Board, one without delay and a detailed one within 72 hours of becoming aware, extendable only on a written request
- Section 17(1) keeps the security duty in section 8(5) for its exempt categories but switches off the breach intimation duty in section 8(6)
- CERT-In's April 2022 directions under the IT Act already require data breaches and data leaks to be reported within six hours, on a separate legal basis
Commencement Status, Stated First
Nothing described in this post is an obligation under the DPDP Act today. The Central Government's commencement notification, G.S.R. 843(E) of 13 November 2025, brought only section 1(2), the definitions in section 2, the Board provisions in sections 18 to 26, and sections 35, 38 to 43 and 44(1) and (3) into force on publication. Section 8 as a whole, including the security duty in section 8(5) and the breach intimation duty in section 8(6), falls in the third tranche, which commences "eighteen months from the date of publication".
The Digital Personal Data Protection Rules, 2025, notified the same day as G.S.R. 846(E), follow the same pattern. Rule 1(4) brings rules 3, 5 to 16, 22 and 23 into force eighteen months after publication in the Gazette, and that list includes rule 6 (security safeguards) and rule 7 (breach intimation). Read against the 13 November 2025 publication date, both instruments put the start in May 2027, on 13 May 2027 on a plain count.
This publication searched for a notification amending G.S.R. 843(E) or rule 1 of the Rules and found none as at 21 September 2026, so this post treats the published dates as current.
Two consequences follow for the months in between. The definition of a personal data breach in section 2(u) is already in force, because all of section 2 commenced in November 2025, but the duty it attaches to is not. And section 43A of the Information Technology Act, 2000 stays on the books until section 44(2)(a) omits it in the same May 2027 tranche, as this publication's DPDP Act guide records.
What Section 8(6) of the Act Requires
The operative sentence in the Act as published in the Gazette is short:
In the event of a personal data breach, the Data Fiduciary shall give the Board and each affected Data Principal, intimation of such breach in such form and manner as may be prescribed.
Digital Personal Data Protection Act, 2023, section 8(6)
Three features stand out on its face. It names two recipients and treats them identically at the level of the Act. It contains no qualifier about likelihood of harm, risk to rights or number of people affected, so every breach and every affected person is in scope. And it contains no deadline; the timing is left entirely to the Rules.
Section 8(1) makes the Data Fiduciary responsible for compliance "irrespective of any agreement to the contrary", including for processing done on its behalf by a Data Processor. The intimation duty sits on the fiduciary, not on the processor.
How the Act Defines a Personal Data Breach
Section 2(u) defines the term:
"personal data breach" means any unauthorised processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises the confidentiality, integrity or availability of personal data;
Digital Personal Data Protection Act, 2023, section 2(u)
The definition covers all three security properties. A breach need not involve anyone seeing the data: "loss of access" that compromises availability is enough, which on the text's own terms brings an incident where data is encrypted or made unavailable, with nothing copied out, within section 8(6). The first limb is also broad, since "unauthorised processing" is not confined to outside attackers.
Intimation to Each Affected Data Principal
Rule 7(1) sets the individual notice. On becoming aware of any personal data breach, the Data Fiduciary must, to the best of its knowledge, intimate each affected Data Principal "in a concise, clear and plain manner and without delay", through her user account or any mode of communication she has registered with the fiduciary. The intimation must contain five items:
- a description of the breach, including its nature, extent and the timing of its occurrence
- the consequences relevant to her that are likely to arise from the breach
- the measures the fiduciary has implemented and is implementing, if any, to mitigate risk
- the safety measures she may take to protect her interests
- business contact information of a person able to respond to her queries on the fiduciary's behalf
The rule names no exception for encrypted data, no substitute public notice where contact details are missing, and no delay at the request of law enforcement. The Press Information Bureau's background note on the Rules summarises the rule the same way: affected individuals are to be informed without delay, in plain language, with contact details for help.
The Initial and Detailed Reports to the Board
Rule 7(2) splits the Board notice in two.
| Report | When | Contents |
|---|---|---|
| Initial, rule 7(2)(a) | Without delay | A description of the breach, including its nature, extent, timing and location of occurrence, and the likely impact |
| Detailed, rule 7(2)(b) | Within 72 hours of becoming aware, or a longer period the Board allows on a written request | Updated and detailed information on the description; the broad facts on the events, circumstances and reasons leading to the breach; mitigation measures implemented or proposed; any findings about the person who caused it; remedial measures to prevent recurrence; and a report on the intimations given to affected Data Principals |
Two details differ from the individual notice. The Board's initial report must include the location of occurrence, which the individual's does not. And the detailed report closes the loop by requiring an account of the individual intimations, so the fiduciary reports to the regulator on its own notices.
The trigger for both clocks is the same phrase, "on becoming aware". The Rules do not define awareness.
What the Board does with an intimation is set by section 27(1)(a): direct urgent remedial or mitigation measures, inquire into the breach and impose a penalty. That clause is in the same eighteen-month tranche. The Board's own procedure is the subject of this publication's post on the Data Protection Board.
Security Safeguards the Rules Specify
Section 8(5) requires reasonable security safeguards to prevent a personal data breach, and rule 6(1) lists what they must include "at the minimum":
- (a) data security measures such as encryption, obfuscation, masking or virtual tokens mapped to the personal data
- (b) access controls on the computer resources the fiduciary or its processor uses
- (c) visibility of access through logs, monitoring and review, to detect, investigate and remediate unauthorised access
- (d) measures for continued processing if confidentiality, integrity or availability is compromised, such as data backups
- (e) retention of those logs and personal data for one year, unless another law requires otherwise
- (f) a provision in the contract with any Data Processor for reasonable security safeguards
- (g) technical and organisational measures to ensure the safeguards are effectively observed
Item (e) connects the two duties. The logs the fiduciary must keep for a year are what the detailed report under rule 7(2)(b) draws on. Rule 8(3) adds a separate minimum one-year retention of personal data, traffic data and processing logs for the purposes in the Seventh Schedule.
Who Falls Outside the Intimation Duty
Section 17(1) disapplies Chapter II "except sub-sections (1) and (5) of section 8" in six situations, among them processing necessary to enforce a legal right or claim, processing by courts, tribunals and regulators in their functions, processing for the prevention, detection, investigation or prosecution of offences, and processing of non-residents' data in India under a contract with a person outside India.
The exception is drawn precisely. Section 8(5), the security duty, survives in those situations. Section 8(6), the breach intimation duty, does not. An Indian service provider processing foreign customers' data under an offshore contract, for example, keeps the safeguards obligation and loses the duty to intimate the Board or the individuals. Section 17(2)(a) goes further for any State instrumentality the Central Government notifies: the Act does not apply to it at all.
The Parallel CERT-In Clock
The DPDP regime is not India's first breach reporting rule, and it does not displace the existing one. On 28 April 2022 the Indian Computer Emergency Response Team issued directions under section 70B(6) of the Information Technology Act, 2000. Direction (ii) requires service providers, intermediaries, data centres, body corporates and government organisations to report the cyber incidents listed in Annexure I to CERT-In within six hours of noticing them or being told of them. Annexure I includes "Data Breach" and "Data Leak".
Direction (iv) requires logs of all ICT systems to be kept securely for a rolling 180 days within Indian jurisdiction. The directions state that they become effective 60 days from the date of issue.
The two regimes rest on different statutes, run to different clocks and go to different bodies: CERT-In within six hours, and from May 2027 the Board without delay and within 72 hours, plus each affected individual. Neither the DPDP Act nor the DPDP Rules refers to the CERT-In directions, and nothing in either instrument states that one report satisfies the other.
Penalty Exposure
The Schedule to the Act gives failure to notify under section 8(6) a ceiling of ₹200 crore, and failure to keep reasonable security safeguards under section 8(5) a ceiling of ₹250 crore, the highest in the Schedule. Section 33(1) permits a penalty only where the Board finds, on conclusion of an inquiry, that the breach of the Act is "significant", and section 33(2) lists the factors the Board must weigh, including the nature, gravity and duration of the breach, whether the person took action to mitigate its effects and how timely and effective that action was, and whether the penalty is proportionate.
Section 42(1) lets the Central Government amend the Schedule by notification, but no amendment may raise any penalty to more than twice the amount in the Act as originally enacted. Sections 27 and 33, through which the Board would impose those penalties, are themselves in the May 2027 tranche.
Frequently Asked Questions
Is India's DPDP breach notification requirement in force?
How quickly must the Data Protection Board be told about a breach?
Does every breach have to be notified to individuals, or only serious ones?
Does a ransomware incident with no data theft count as a personal data breach?
How does DPDP breach intimation relate to CERT-In reporting?
Sources
Everything above is reported from these documents. Follow them to verify.
- The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023), as published in the Gazette of India (MeitY) (August 11, 2023) statute
- Digital Personal Data Protection Rules, 2025, G.S.R. 846(E), Gazette of India, Extraordinary, 13 November 2025 (November 13, 2025) regulation
- G.S.R. 843(E), notification appointing commencement dates for the Digital Personal Data Protection Act, 2023, 13 November 2025 (November 13, 2025) regulation
- CERT-In, Directions under sub-section (6) of section 70B of the Information Technology Act, 2000, No. 20(3)/2022-CERT-In (April 28, 2022) agency guidance
- Press Information Bureau, DPDP Rules, 2025 Notified: background note (November 17, 2025) agency release
Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.