4 mins

Incident Reporting Clocks and Vendor Liability Under DPDP Act 2023

An analysis of overlapping cyber incident reporting timelines in India, focusing on Rule 7 DPDP Rules obligations and Fiduciary liability for third-party Data Processor failures.

Written byVipul Abhishek· Former Advocate, Supreme Court of India

Last updated:

What happened

Veloxx Media recently published an advisory on incident reporting and third-party risk management under the Digital Personal Data Protection Act, 2023. The report outlines overlapping regulatory clocks for data breaches in India. Organizations face a six-hour window to report cyber incidents to CERT-In. Under Rule 7 of the DPDP Rules, 2025, a Fiduciary has 72 hours to submit detailed breach particulars to the Data Protection Board of India. Affected Data Principals require intimation without delay. The analysis observes that the DPDP regime imposes no risk threshold for breach reporting. Any personal data breach triggers these obligations, regardless of perceived severity. Veloxx Media also states that Data Fiduciaries retain primary liability for breaches caused by their third-party Data Processors.

Does the DPDP Act apply here?

Section 3 of the Act covers digital personal data processed within India. It also applies to processing outside India connected to offering goods or services to Data Principals in India. Fintech operations routinely process digital lending histories, payment records, and account-aggregator API outputs. This information qualifies as personal data. Corporate intellectual property and anonymised datasets fall outside this scope. The zero-threshold reporting mandate applies strictly to personal data breaches. Employee data processed by the Fiduciary is also subject to the Act, though Section 7 legitimate uses cover specific employment processing purposes.

Legal implications under DPDP

The allocation of liability between parties shifts fundamentally under this framework. A Data Fiduciary holds primary accountability for data breaches, even when a Data Processor causes the failure. You cannot transfer statutory liability downstream through contract clauses. Indemnities provide financial recovery mechanisms, but regulatory defensibility rests entirely on the Fiduciary. Consent is the primary basis for processing, except where Section 7 legitimate uses apply. RBI digital lending guidelines and anti-money laundering mandates often intersect with these processing grounds. Every vendor failure puts the Fiduciary at risk of penalties reaching up to Rs 250 crore for failing to take reasonable security safeguards.

Could this happen to you

A payments or lending startup routinely relies on external APIs for credit scoring and customer onboarding. If a KYC verification vendor suffers an exposure, the regulatory clock starts immediately. The Board will expect the Fiduciary to produce an incident report within 72 hours. Your legal team needs instant access to the vendor's audit logs to draft this notification under privileged review. If a vendor contract lacks rigid notification timelines, the resulting delay forces you into a compliance failure. Failing to manage this supply chain risk directly threatens enterprise deals and drives up outside counsel spend during an incident. A regulatory penalty at this stage severely impacts board confidence.

What companies should do in the next 30 days

1. Revise processor contracts to require vendor incident notification to your legal team within 24 hours.

2. Adjust limitation of liability clauses to account for the Rs 250 crore DPDP penalty ceiling regarding breach response failures.

3. Document a unified incident playbook that satisfies the 6-hour CERT-In mandate alongside the 72-hour DPBI requirement.

4. Audit existing consent records to ensure data shared with processors maps correctly to the original collection purpose.

To evaluate your current third-party risk exposure and processor contract gaps, run a gap assessment at freescan.complydp.com.

What to watch

Regulator engagement will increase as the Data Protection Board scales its enforcement operations. Fintech General Counsels should monitor how the Board interprets the Rule 7 intimation timelines in practice alongside RBI reporting formats. Early enforcement actions will likely target Fiduciaries lacking documented vendor oversight programs. Exactly 252 days remain until the DPDP hard compliance deadline of 13 May 2027.

Sources

Frequently asked questions

Do we have to report minor data breaches under the DPDP Act?

Yes. The DPDP Act and Rules 2025 do not feature a risk threshold for reporting. Any occurrence of a personal data breach requires notifying the Data Protection Board and affected Data Principals.

Who is legally responsible if our SaaS vendor loses customer data?

The Data Fiduciary bears primary liability under the Act. While you can seek financial recovery through indemnities, regulatory penalties up to Rs 250 crore for failing to protect personal data fall directly on the Fiduciary.

How long do we have to report a data breach to the Board?

Rule 7 of the DPDP Rules, 2025 mandates that Fiduciaries submit detailed particulars of a data breach to the Data Protection Board within 72 hours. Affected Data Principals require intimation without delay.

Can we rely entirely on vendor indemnities for DPDP compliance?

No. Indemnities are financial recovery tools. They do not prevent regulatory enforcement actions or repair the Fiduciary's defensibility before the Data Protection Board.

When is the deadline to comply with the DPDP Act?

The hard compliance deadline is 13 May 2027. Companies have exactly 252 days remaining to finalize their vendor governance and incident reporting playbooks.