Checklists4 mins

DPDP Breach Tabletop Exercise Checklist for Fintech Legal Heads

A testable runbook to evaluate your fintech organisation's breach response against the 72-hour DPBI notification requirement under the DPDP Act 2023 and Rules 2025.

Written byVipul Abhishek· Former Advocate, Supreme Court of India · ComplyDP Co-Founder

Last updated:

When to use this checklist

Use this runbook to evaluate breach readiness before the hard compliance deadline in 276 days on 13 May 2027. Fintech General Counsels and Legal Heads should execute this quarterly to test incident response across rapid product cycles. This checklist applies to lending and payments platforms handling high-velocity data flows where RBI digital lending guidelines and the Digital Personal Data Protection Act, 2023 overlap.

Prerequisites

Before initiating the tabletop exercise, ensure you have a designated incident commander. Your Data Protection Officer must have a verified reporting line to the board. Compile your current data inventory, a list of third-party Data Processors under valid contracts as per Section 8 of the Act, and your draft breach notification templates.

Step-by-step checklist

1. Action: Simulate a breach alert from a third-party lending API provider. Owner: IT Security. Evidence: Timestamped alert log. Frequency: Recurring quarterly.

2. Action: Triage and confirm if the incident involves personal data processed digitally. Owner: Incident Commander. Evidence: Incident classification memo. Frequency: Recurring quarterly.

3. Action: Draft the preliminary intimation for affected Data Principals in India to be sent without delay. Owner: Legal. Evidence: Draft notice outlining the nature of the breach and mitigation steps. Frequency: Recurring quarterly.

4. Action: Prepare the detailed breach report for the Data Protection Board of India within the 72-hour window mandated by the Rules, 2025. Owner: Compliance. Evidence: DPBI notification draft with required fields. Frequency: Recurring quarterly.

5. Action: Review vendor contracts against Section 8 to verify the Data Processor notified you immediately. Owner: Legal. Evidence: Contractual indemnity audit log. Frequency: Annual.

6. Action: Execute containment protocols to mitigate effects, directly addressing Section 33 penalty mitigation factors. Owner: IT Security. Evidence: Containment action report. Frequency: Recurring quarterly.

7. Action: Log all internal decisions under legal privilege to ensure defensibility during regulatory inquiries. Owner: General Counsel. Evidence: Privileged counsel review logs. Frequency: Recurring quarterly.

8. Action: Reconcile notification logs to prove timely dispatch to both the Board and Data Principals. Owner: DPO. Evidence: Dispatch timestamp records. Frequency: Recurring quarterly.

DPBI breach intimation

The Rules, 2025 specify exact mechanics for breach notification. You must notify affected Data Principals without delay. Simultaneously, you must submit a detailed report to the Data Protection Board within 72 hours. This report must include the nature of the breach, the type of personal data affected, mitigation actions taken, and the potential impact on Data Principals. Failing this 72-hour window exposes the Data Fiduciary to significant financial penalties under Section 33.

Effort and budget reality

Executing a tabletop exercise manually requires 15 to 20 hours of cross-functional team effort per quarter, resulting in high outside counsel spend for privileged review. A tooled approach automates the 72-hour countdown, dynamically generates DPBI notification drafts, and creates an exportable audit trail. This reduces execution time to under 4 hours per simulation, allowing legal teams to focus on defensibility rather than administrative tracking.

Documentation pack

Post-exercise, update your incident response policy to align with the Rules, 2025. Revise your vendor agreements to strictly enforce immediate breach escalation from Data Processors. Update your Records of Processing Activities to reflect any newly identified data flows from the simulation. Ensure your breach intimation templates for Data Principals are drafted in clear, plain language.

Red flags

You are not ready for a DPB inquiry if your incident response plan lacks a strict 72-hour DPBI notification workflow. Relying on informal vendor communication instead of Section 8 valid contracts is a major risk. An inability to produce timestamped evidence of containment actions will nullify any penalty mitigation arguments under Section 33.

Next steps

With 276 days remaining until the deadline, manual breach workflows are a liability. Visit freescan.complydp.com to baseline which breach response steps your organisation has covered and which gaps remain.

Sources

Frequently asked questions

What is the deadline for notifying a data breach under the DPDP Rules 2025?

You must intimate affected Data Principals without delay and submit a detailed report to the Data Protection Board within 72 hours of becoming aware of the breach.

How does the DPDP Act view vendor breaches?

Under Section 8 of the Act, the Data Fiduciary remains entirely responsible for DPDP compliance, irrespective of a Data Processor's failure. You must ensure all third-party APIs and vendors operate under a valid contract.

Can we rely on outside counsel to handle the entire 72-hour breach window?

While outside counsel provides privileged review and strategic defensibility, the 72-hour timeline requires internal operational readiness. Legal review burdens can delay notifications if incident data gathering is not automated.

What factors reduce penalties under Section 33 for a breach?

The Data Protection Board considers the nature and duration of the breach, the type of personal data affected, and whether the Data Fiduciary took timely and effective action to mitigate the consequences.

Does the DPDP Act require consent to process personal data during a breach investigation?

Consent is the primary basis for processing, except where Section 7 legitimate uses apply. Investigating and containing a security incident typically falls under legitimate uses, meaning fresh consent is not required to secure the data.