Back to articles
DPDP Act

Personal Data Breaches: A 72-Hour Playbook

Every Data Fiduciary must notify the Data Protection Board and affected Data Principals of a breach. Here's the workflow to build now.

April 9, 2025 9 min read Vrushali Borade

The Notification Duty

Section 8(6) of the DPDP Act requires prompt notification of every personal data breach to both the Data Protection Board of India and each affected Data Principal. Critically — and unlike GDPR — there is no severity or risk-of-harm threshold. Any unauthorised processing, accidental disclosure, alteration, loss, destruction or loss of access to personal data triggers the duty.

The precise notification timeline will be set by the DPDP Rules, but the draft Rules published in January 2025 propose an initial notification 'without delay' and a detailed follow-up within 72 hours — mirroring GDPR's Article 33 timeline and CERT-In's 6-hour cybersecurity incident reporting requirement.

In parallel, CERT-In's 2022 directions require notification of specified cyber incidents within 6 hours. For a breach that is both a personal data breach and a reportable cyber incident, both timelines run concurrently.

The 72-Hour Playbook Workflow

A rehearsed playbook is the single highest-leverage investment a founder can make. The workflow should cover six stages: detection, containment, forensic assessment, regulator notification, user communication and post-incident review.

Detection: SIEM alerts, employee reports, third-party disclosure, and public disclosure (a security researcher's tweet is the modern equivalent of a subpoena). Assign a 24/7 on-call rotation with escalation to a named Incident Commander.

Containment: isolate the affected system, rotate credentials, revoke tokens, and preserve forensic evidence. Do not power down machines that may hold volatile memory forensic value.

Forensic assessment: within 24 hours, produce a written brief covering root cause, data categories affected, number of Data Principals affected, geographic spread and downstream exposure.

Regulator notification: file the initial notice to the Data Protection Board on the prescribed portal, and to CERT-In where applicable, within statutory timelines. Do not wait for perfect information; file what you know and update.

User communication: notify affected Data Principals directly (in-app, email, SMS) with clear language on what happened, what data was affected, what you are doing, and what they can do (password reset, credit monitoring, phishing awareness).

Post-incident review: within 30 days conduct a blameless post-mortem, log lessons learned, and update the playbook. Regulators and enterprise customers will ask to see the post-mortem.

What to Include in the Notification

The notification to the Data Protection Board should include: the nature and circumstances of the breach; the categories and approximate number of Data Principals and records affected; the likely consequences; the mitigation measures taken and proposed; and a named point of contact.

The notification to affected Data Principals should be in clear, plain language and cover: what happened, what data was involved, what you are doing about it, what they should do, and how to contact you or your DPO. Avoid legalistic hedging — regulators and users read defensiveness as an admission of poor governance.

Prepare Before You Need It

Rehearse the playbook at least twice a year with a tabletop exercise involving engineering, security, legal, communications and executive leadership. Pre-draft template notices for the Board, for users and for the press. Pre-select a forensic vendor and a crisis communications firm on retainer so procurement is not on the critical path.

A well-managed breach is a survivable event; a badly-managed one has ended companies. The difference is preparation.

BreachIncident Response

Have questions on this topic?

Book a confidential consultation with Vrushali Borade.

Book Consultation