5 minutes

DPDP Rules 2025: Managing the 72-Hour Breach Notification Clock

An analysis of the dual-track breach notification obligations under the DPDP Act and Rules 2025, focusing on Section 8 liability and 72-hour regulator reporting timelines for enterprise legal teams.

Written byVipul Abhishek· Former Advocate, Supreme Court of India

Last updated:

Overview

Enterprise legal leaders face a strict liability allocation problem regarding data breaches. Exactly 256 days remain until the Digital Personal Data Protection Act, 2023 hard compliance deadline of 13 May 2027. The clock starts immediately when a security incident occurs. Outside counsel spend increases rapidly during an uncoordinated breach response. Defensibility requires a documented incident workflow across internal teams and external vendors. Section 1 of the Act grants the Central Government power to appoint different commencement dates for different provisions. Preparing the incident response framework takes priority before these dates take effect. A delayed response exposes the enterprise to severe regulatory scrutiny.

What the DPDP Act says about liability

Section 8(1) of the DPDP Act, 2023 assigns ultimate responsibility to the Data Fiduciary. This applies irrespective of any agreement to the contrary. It also applies despite any failure of a Data Principal to carry out their duties. If a Data Processor suffers a breach, the Fiduciary remains legally accountable for regulatory compliance. Section 8(2) restricts Fiduciaries to using Processors only under a valid contract. Legal teams draft specific indemnity clauses and turnaround times in these vendor agreements. The regulator holds the Fiduciary responsible for notifying the authorities. Any processing undertaken on behalf of the Fiduciary falls strictly under this liability shield. Fiduciaries cannot contract out of this statutory duty.

The 72-hour reporting timeline

The Act introduced the baseline obligation to report personal data breaches. The Rules 2025 operationalise this requirement with hard deadlines. Fiduciaries have to intimate affected Data Principals without delay. They are also required to submit a detailed report to the Data Protection Board of India within 72 hours of becoming aware of the breach. The Rules prescribe specific contents for these notices. Complete information is rarely available within 72 hours. The Fiduciary provides staged updates to the Board in these situations. Legal teams file an initial report to stop the clock. Subsequent filings complete the factual record as forensics teams conclude their analysis.

Dual-track notification contents

The notification obligations serve two different audiences. The intimation to Data Principals focuses on immediate risks. It outlines the remediation steps they can take to protect their accounts. The 72-hour report to the Board requires technical specifics. The Fiduciary details the breach vector and the volume of affected data. The report also lists the remedial actions taken. Legal teams do not wait for a forensic conclusion before filing this initial Board report. Staged updates establish early regulator engagement. This engagement satisfies the statutory deadline while investigations continue. The Board evaluates these filings to determine the scale of the incident.

Operational requirements for legal teams

Legal departments update their processor contracts for the new 72-hour regulatory window. A 36-hour vendor reporting target gives the Fiduciary time to assess the incident. This creates a high recurring operational burden. Tracking incident response across dozens of vendors breaks at scale when managed on spreadsheets. An in-house team drafts the initial standard operating procedure. Tooling captures time-stamped evidence trails and manages parallel notifications securely. Vendor delays directly consume the Fiduciary reporting window. Contractual terms mean nothing without automated tracking and escalation paths.

Section 33 penalties and enforcement risk

The financial exposure for failing to report a breach is severe. The Schedule to the Act specifies penalties up to Rs 200 crore for failure to notify a personal data breach. Under Section 33, the Board determines the exact penalty based on specific criteria upon the conclusion of an inquiry. Section 33(1) requires the Board to give the person an opportunity of being heard before imposing monetary penalties. Section 33(2) lists the matters the Board considers. These include the nature, gravity and duration of the breach. The Board examines the type and nature of the personal data affected. Regulators check the repetitive nature of the breach. They determine whether the person realised a gain or avoided any loss. Section 33(2)(e) directs the Board to evaluate whether the person took any action to mitigate the effects. Timeliness and effectiveness of this mitigation directly reduce the final monetary penalty.

Common misconceptions

Incorrect assumptions expose enterprises to heavy regulatory risk. Legal leaders often assume they can transfer breach liability entirely to Processors. Section 8(1) explicitly prevents this practice. The regulatory burden stays firmly on the Fiduciary. Teams also wait for complete forensics before notifying the Board. The Rules mandate an initial filing within 72 hours and explicitly permit later staged updates. Some executives believe only certain classes of data require reporting. The DPDP Act, 2023 contains no separate category for highly protected information. Any digital personal data breach triggers the notification process. Fiduciaries apply the exact same notification standard to a breached marketing list as they do to compromised financial records.

Implementation checklist

1. Revise Processor contracts to mandate incident reporting to the Fiduciary within 36 hours.

2. Map all digital personal data processing workflows to identify which vendor holds what data.

3. Draft the Board notification templates containing the mandatory fields required by the Rules 2025.

4. Deploy an incident logging system to capture exact timestamps of when the Fiduciary became aware of the breach.

5. Establish a secure communication channel for sending immediate intimations to affected Data Principals.

6. Define the internal escalation matrix linking the Chief Information Security Officer with the General Counsel.

7. Review all existing Data Processor agreements to confirm they qualify as valid contracts under Section 8(2).

8. Implement access controls to limit the blast radius of any potential network intrusion.

9. Schedule tabletop exercises to test the 72-hour reporting capability across different time zones.

How ComplyDP helps

ComplyDP provides enterprise legal teams with the infrastructure to manage DPDP Act obligations at scale. The platform automates breach response workflows and maintains privileged evidence trails. These audit logs provide defensibility during a Data Protection Board inquiry. The software translates statutory timelines into actionable alerts across your vendor ecosystem. It maps out Section 8(1) liability chains clearly. Run a confidential evaluation at freescan.complydp.com to identify gaps in your current incident response contracts. Enterprise users centralise their 72-hour notification clock management within a secure environment.

Sources

Frequently asked questions

When must a Data Fiduciary report a data breach under the DPDP Rules 2025?

The Rules require Data Fiduciaries to intimate affected Data Principals without delay. A detailed report is submitted to the Data Protection Board within 72 hours of becoming aware of the breach. Staged updates are permitted if full information is not immediately available.

Can our company transfer regulatory breach liability to our vendors?

No. Section 8(1) of the DPDP Act, 2023 makes the Data Fiduciary responsible for compliance irrespective of any agreement to the contrary. The regulator holds the Fiduciary accountable for notification failures.

Do we need to wait for complete forensic details before notifying the Board?

No. The 72-hour timeline applies to the initial intimation based on available facts. The Rules allow Fiduciaries to file staged updates as the investigation uncovers more details.

What is the penalty for failing to report a data breach to the Board?

The Schedule to the Act caps the penalty for failing to report a breach at Rs 200 crore. The Data Protection Board determines the exact amount based on factors in Section 33. Regulators check the timeliness and effectiveness of mitigation actions.