DPDP Sections6 mins

Definitive Guide to Personal Data Breach Reporting Under the DPDP Act and Rules 2025

A deep dive for compliance leaders on Section 8 breach intimation obligations, 72-hour reporting timelines under the DPDP Rules 2025, and Data Protection Board penalty exposures.

Written byVipul Abhishek· Former Advocate, Supreme Court of India · ComplyDP Co-Founder

Last updated:

Personal Data Breach Reporting Under The DPDP Act

The Digital Personal Data Protection Act, 2023 establishes a strict dual notification mandate for any personal data breach. A personal data breach requires the Data Fiduciary to notify both the Data Protection Board of India and every affected Data Principal. For a Head of Compliance at a large enterprise, this shifts incident response from an IT security operational task to a primary legal exposure vector. The DPDP Rules, 2025 formalise this obligation by defining rigid timelines and specific content requirements for these intimations. This is not a best effort exercise. Your organisation must prove that it detected, contained, and reported the breach within the prescribed windows to avoid severe financial penalties.

Statutory Anchors And DPDP Rules 2025 Mechanics

Section 8 of the DPDP Act mandates that in the event of a personal data breach, the Data Fiduciary shall give the Board and each affected Data Principal intimation of such breach. The DPDP Rules, 2025 provide the critical operational specifics that transform this statutory requirement into a stopwatch. Under the Rules, you must intimate affected Data Principals without delay. Furthermore, you are required to submit a detailed report to the Data Protection Board within 72 hours of becoming aware of the breach. Section 33 of the Act outlines how the Board evaluates your response, stating it shall have regard to the nature, gravity, and duration of the breach, and whether you took action to mitigate its effects.

Who This Binds And Jurisdictional Scope

The legal burden of breach intimation falls exclusively on the Data Fiduciary. While your data processors may experience the actual technical compromise, the statute holds the Fiduciary accountable for the regulatory reporting and Data Principal communication. Section 3 dictates that this applies to the processing of digital personal data within the territory of India. It also applies to processing outside India if such processing is in connection with offering goods or services to Data Principals in India. Large enterprises must ensure their vendor oversight programs force processors to notify the Fiduciary immediately. A delay by a processor eats directly into your 72 hour window to notify the Board.

Compliance Step 1 Establish A 72 Hour Triage Workflow

1. You must design and operationalise an incident response pipeline that operates within a strict 72 hour threshold. 2. The control owner for this workflow is the Head of Compliance, working alongside the Chief Information Security Officer. 3. The required audit evidence is a time stamped incident log detailing exactly when the organisation became aware of the breach and the subsequent escalation steps. 4. Existing generic platforms often fail here because they lack the specific regulatory clock tied to DPDP Rules 2025 obligations. 5. Your workflow must trigger parallel tracks for technical containment and regulatory drafting immediately upon discovery.

Compliance Step 2 Implement Processor Notification Mandates

1. Your enterprise likely relies on dozens of third party vendors and cloud platforms. 2. The control owners for this step are Procurement and Legal. 3. The necessary evidence pack consists of updated data processing agreements that contractually bind vendors to notify you within 12 to 24 hours of a confirmed breach. 4. Since the Data Fiduciary holds the regulatory liability, you cannot wait for a processor to conduct a leisurely forensic review. 5. Vendor oversight mechanisms must include automated attestation tracking to ensure processors maintain their own rapid detection capabilities.

Compliance Step 3 Draft Regulator Ready Intimations

1. Scrambling to write a breach notice during an active crisis guarantees regulatory failure and massive team effort. 2. The Privacy Office must maintain pre approved breach intimation templates aligned with the DPDP Rules 2025. 3. The artifact here is a repository of drafted communications ready for rapid deployment to both the Board and individuals. 4. Consent is the primary basis for processing, except where Section 7 legitimate uses apply, meaning you must know exactly whose data was exposed. 5. Knowing which Data Principals are affected relies on a meticulously maintained Record of Processing Activities, or RoPA, mapping data categories to specific systems.

Compliance Step 4 Maintain A Mitigation Evidence Pack

1. Section 33 requires the Board to evaluate the timeliness and effectiveness of your mitigation actions when determining penalties. 2. The control owner is IT Security, with stringent oversight from Compliance. 3. The critical artifact is an evidence pack that documents every containment action taken from minute zero. 4. The Board will scrutinise this attestation to decide if your enterprise acted responsibly. 5. If your incident response lacks a clear audit trail showing how you mitigated the effects and consequences of the breach, the Board will treat this as an aggravating factor during their inquiry.

Penalty Exposures For Failing To Report

The financial stakes for failing to operationalise breach reporting are immense. The Schedule to the DPDP Act sets a penalty ceiling of up to 200 crore rupees for a failure to fulfil the obligation to report a personal data breach to the Board or affected Data Principals. When calculating the final monetary penalty under Section 33, the Board considers the type and nature of the personal data affected by the breach. Note that the DPDP Act does not formally classify data by sensitivity, but the volume and inherent risk of the compromised data will influence the penalty severity. The Board also weighs any repetitive nature of the breach and whether the Fiduciary realised a gain or avoided a loss.

Interactions With Other DPDP Act Sections

Breach reporting does not exist in a vacuum and impacts multiple compliance vectors. It interacts heavily with Section 33, where the Board uses the speed of your breach intimation to judge penalty mitigation. It connects to Section 8 processor obligations, requiring a seamless flow of incident data from your vendors up to your compliance office. Furthermore, your breach response relies on clear Data Protection Impact Assessment, or DPIA, documentation to rapidly understand the potential harm to Data Principals. Accurate consent artefacts dictate exactly who requires an intimation without delay.

Deadline Pressure And Evaluation Criteria

There are exactly 288 days remaining until the DPDP hard compliance deadline of 13 May 2027. For a Head of Compliance, building a resilient breach reporting architecture takes hundreds of hours of cross team coordination. You will face internal objections regarding team adoption effort and overlap with existing tools. A credible compliance solution must solve these by offering automated, regulator ready breach workflows that generate direct evidence packs for the Board, rather than just another dashboard of manual tasks. Check whether your current incident response setup satisfies this critical Section 8 obligation with a free scan at freescan.complydp.com.

Sources

Frequently asked questions

What is the specific timeline for reporting a personal data breach under the DPDP Rules 2025?

Under the DPDP Rules 2025, a Data Fiduciary must submit a detailed breach report to the Data Protection Board within 72 hours of becoming aware of the incident. Additionally, they must intimate affected Data Principals without delay. Missing these specific windows directly exposes the enterprise to severe regulatory action.

Who is legally responsible for notifying the Data Protection Board if a third party processor suffers a breach?

The statutory obligation to notify the Board and affected Data Principals rests entirely on the Data Fiduciary. Processors must inform the Fiduciary based on contractual terms, but the Fiduciary holds the ultimate regulatory liability and must execute the 72 hour reporting workflow.

What evidence will the Data Protection Board demand during a Section 33 inquiry?

The Board evaluates the nature, gravity, and duration of the breach, alongside mitigation efforts. A Head of Compliance must present a comprehensive evidence pack, including a time stamped incident log, details of technical containment actions, and proof of timely intimations to defend the enterprise.

What are the financial penalties for failing to report a personal data breach?

The Schedule to the DPDP Act establishes a penalty ceiling of up to 200 crore rupees for failing to report a breach. The final penalty amount is determined by the Board under Section 33 criteria, which heavily weighs the timeliness of reporting and the effectiveness of your mitigation steps.

Can existing generic GRC tools handle the DPDP breach reporting requirements effectively?

Generic GRC tools often struggle because they lack the specific regulatory workflows and rigid 72 hour clocks mandated by the DPDP Rules 2025. A compliant system must automatically generate regulator ready evidence packs and coordinate rapid action across procurement, IT security, and the privacy office.