Buyer Questions6 mins

What Are DPDP Breach Notification Rules?

Discover the 72-hour DPBI reporting timeline, Data Principal intimation requirements, and vendor oversight strategies for HealthTech General Counsels navigating the DPDP Act and Rules 2025.

Written bySanket Sharma· Former Advocate, Supreme Court of India · ComplyDP Co-Founder

Last updated:

Under the Digital Personal Data Protection Act, 2023 and the anticipated procedural frameworks under the DPDP Rules, a Data Fiduciary must notify the Data Protection Board of India and affected Data Principals in the event of a personal data breach. The rules prescribe a detailed report submitted to the Board within 72 hours of becoming aware of the breach, alongside intimation to affected Data Principals without delay. This dual notification requirement fundamentally shifts how corporate legal teams must manage their immediate incident response protocols. Navigating this strict timeline means that cross-functional teams, including IT, security, and legal, must be closely aligned before a crisis even occurs.

Section 8(1) of the DPDP Act stipulates an uncompromising standard for enterprise accountability. It explicitly states that a Data Fiduciary shall be responsible for complying with the Act and its rules "irrespective of any agreement to the contrary or failure of a Data Principal to carry out the duties provided under this Act." This statutory language means that if a vendor or Data Processor suffers a breach that compromises patient data, the primary legal, financial, and regulatory liability securely rests with the Fiduciary.

General Counsels can no longer rely solely on paper indemnification clauses or shifting blame to third-party processors to protect the enterprise from regulatory scrutiny. The Fiduciary ultimately owns the risk for any processing undertaken on its behalf by a Data Processor.

Furthermore, Section 8(2) mandates that a Data Fiduciary may only engage, appoint, use or otherwise involve a Data Processor to process personal data on its behalf for any activity related to offering of goods or services to Data Principals under a valid contract. Additionally, Section 8(3) requires that where personal data processed by a Data Fiduciary is likely to be used to make a decision that affects the Data Principal or disclosed to another Data Fiduciary, the Fiduciary must ensure its accuracy and completeness. In the chaos of a data breach, attempting to notify Data Principals using inaccurate or outdated contact information could be viewed by the Board as a compounding failure in statutory compliance.

The 72-hour notification to the Board must detail the nature of the breach, the volume of affected Data Principals, and the mitigation steps taken. If your legal team cannot gather these facts rapidly due to fragmented clinic systems or uncooperative vendors, outside counsel spend will spike just to manage regulator engagement. Administrative delays directly increase your exposure under the Section 33 penalty provisions.

The notice to Data Principals must be dispatched without delay, serving to inform them of the risk and the actions they should take. For a healthtech enterprise or hospital network, this communication carries significant weight. Although the DPDP Act does not create a distinct statutory classification for medical records, the high risk of harm associated with patient data means the Board will closely evaluate the timeliness and effectiveness of this notice.

Managing Vendor Liability and Contracts

General Counsels must immediately prioritize vendor oversight and contract remediation. Section 8 requires a valid contract for engaging Data Processors. Your indemnity clauses, limitation of liability, and breach notification flow-down provisions must compel processors to notify your legal department within 24 hours of an incident.

Mandating a 24-hour processor turnaround ensures your internal teams have the remaining 48 hours to draft a defensible statutory filing. Relying on legacy contracts that lack specific timelines exposes the business to severe regulatory risk, as the Board will not accept vendor delays as a valid excuse for missing the 72-hour reporting window.

The Regulator Evaluation Factors

When assessing the imposition of monetary penalties on conclusion of an inquiry, Section 33(2) of the DPDP Act dictates a specific set of criteria that the Data Protection Board of India shall have regard to. These factors include: (a) the nature, gravity and duration of the breach; (b) the type and nature of the personal data affected by the breach; (c) the repetitive nature of the breach; (d) whether the person, as a result of the breach, has realised a gain or avoided any loss; and (e) whether the person took any action to mitigate the effects and consequences of the breach, including the timeliness and effectiveness of such action.

Defensibility in front of the Data Protection Board of India requires an ironclad evidence trail of your internal response workflow, proving that legal and security teams moved decisively. Large hospitals and healthtech platforms process substantial volumes of personal data, making them prime candidates for Significant Data Fiduciary designation. Significant Data Fiduciaries face stricter regulatory obligations. When an incident occurs, these entities must prove that their foundational security practices were robust enough to prevent foreseeable risks.

Preempting the Legal Review Burden

Corporate legal teams often resist automated compliance tools, fearing unclear accountability if the software errs during a high-stakes incident. However, managing breach workflows manually across disparate clinical databases virtually guarantees missed 72-hour deadlines and incomplete regulatory filings.

A credible compliance solution maps patient data flows securely and maintains comprehensive consent records, so outside counsel can conduct a privileged review and focus on strategy rather than frantic fact-finding. Consent is the primary basis for processing, except where Section 7 legitimate uses apply, and proving you had a valid lawful basis for the breached data is a core component of regulatory defensibility.

The Financial Risks of Non-Compliance

Section 33 allows the Board to impose significant monetary penalties, capping at up to 250 crore rupees for failure to observe reasonable security safeguards or fulfill breach notification duties. As explicitly noted in Section 33(2), the Board will consider if the breached entity realized a gain or avoided a loss due to their non-compliance. Investing in proactive breach management tooling is fundamentally a risk mitigation strategy to avoid catastrophic regulatory fines.

Under Section 1(2) of the DPDP Act, the Central Government has the authority to appoint different dates for the coming into force of different provisions of the Act. Any reference to the commencement of the Act shall be construed as a reference to the coming into force of that specific provision. This phased implementation means that enterprise legal teams cannot passively wait for a single universal compliance date.

General Counsels must transition from theoretical risk assessments to operationalizing incident response immediately. You must update your standard operating procedures to align with the anticipated rules and establish reliable reporting workflows across all departments, ensuring absolute readiness before specific breach notification rules are formally published in the Official Gazette.

Related Questions

What To Do Next

Step 1 Audit processor contracts. Execute amendments with all Data Processors to ensure flow-down clauses mandate immediate breach notification to your legal team, paired with strict limitation of liability carve-outs for DPDP fines. Ensure all engagements are under a valid contract as required by Section 8.

Step 2 Establish a defensible evidence trail. Implement tracking for consent records and data flows so that if an incident occurs, the volume of affected Data Principals and the type of data compromised can be quantified instantly for the Board filing, directly addressing Section 33(2) evaluation criteria.

Step 3 Automate the regulatory response. Adopt a platform that standardizes the intake of incident details and prepares the necessary regulatory frameworks for your final privileged review. To assess how your current vendor contracts and incident response plans align with the notified rules, run a compliance evaluation at freescan.complydp.com.

Sources

Frequently asked questions

Do Data Processors have to notify the Board directly in a breach?

No. Under Section 8 of the Act, the Data Fiduciary remains responsible for all compliance obligations in respect of any processing undertaken by it or on its behalf. Processors must notify the Fiduciary, who then submits the statutory 72-hour report to the Data Protection Board of India and intimates the affected Data Principals without delay.

What is the maximum penalty for failing to report a breach?

Under Section 33, failure to fulfill breach notification duties or implement reasonable security safeguards can result in significant monetary penalties up to 250 crore rupees. The Board considers the nature, gravity, duration, repetitive nature of the breach, the type of data affected, and whether any gain was realized or loss avoided when calculating these statutory fines.

Are there exceptions to notifying Data Principals under the Rules?

The DPDP Act requires intimation to affected Data Principals in the event of a personal data breach. While specific mitigation measures like encryption might be considered by the Board under Section 33(2)(e) regarding the timeliness and effectiveness of mitigating effects, the fundamental obligation to intimate affected Data Principals without delay remains a statutory requirement for the Data Fiduciary.

How do we handle breaches affecting offshore patient data?

The Act applies to digital personal data processed within India, and processing outside India if connected to offering goods or services to Data Principals within the territory of India. If the breach affects these Data Principals, the full statutory notification obligations and timelines apply to the Data Fiduciary, regardless of where the physical server or the Data Processor is located.