Buyer Questions • 6 minutes
How long do I have to report a personal data breach under the DPDP Act?
The DPDP Rules, 2025 require data fiduciaries to report a personal data breach to the Data Protection Board within 72 hours and to affected Data Principals without delay. Missing this deadline carries penalties up to Rs. 200 crore, making swift incident response protocols a statutory necessity.
Last updated:
Under the Digital Personal Data Protection Act, 2023 (DPDP Act) and the notified DPDP Rules, 2025, a Data Fiduciary must submit a detailed breach report to the Data Protection Board within 72 hours. Alongside this mandatory regulatory filing, you must notify the affected Data Principals without delay. Missing this reporting clock under Section 8(6) exposes your enterprise to penalties extending to Rs. 200 crore. Because time is of the essence, modern enterprises must completely overhaul their incident response playbooks to prevent regulatory delays and subsequent financial exposure.
The Dual Notification Standard
The DPDP Rules mandate that incident response is a simultaneous, dual-track process. The initial 72-hour report to the Board must detail the nature of the breach, the volume of data involved, and the immediate mitigation steps your internal security team has taken. Simultaneously, the notification to Data Principals in India must occur without delay, ensuring affected individuals can take protective measures promptly, such as changing their passwords or monitoring their financial statements. The law treats both these obligations seriously, meaning failing to notify the individuals is just as detrimental as failing to notify the regulator.
Separating the Penalties: Security vs. Reporting
It is critical to separate the reporting penalty from the underlying security failure penalty. The Act Schedule explicitly divides these non-compliances. While failing to notify the Board or affected Data Principals under Section 8(6) costs up to Rs. 200 crore, failing to implement reasonable security safeguards under Section 8(5) carries a separate penalty extending up to Rs. 250 crore. This means a single cyber incident could theoretically attract compounding regulatory fines if both your preventive security and your reactive reporting protocols fail. Therefore, discovering a breach is only the beginning of your legal risk management process.
How the Board Determines the Penalty
Under Section 33(2) of the DPDP Act, the Board does not arbitrarily impose the maximum Rs. 200 crore penalty for a missed deadline. Instead, it must have regard to specific statutory factors during its inquiry. These include the nature, gravity, and duration of the breach, as well as the type and nature of the personal data affected. The Board will also investigate whether the breach is of a repetitive nature, and whether the Data Fiduciary realised a financial gain or avoided any loss as a result. Crucially, the Board will closely evaluate whether the person took any action to mitigate the effects and consequences of the breach, and the timeliness and effectiveness of those mitigation efforts. A documented, swift response can dramatically reduce your final monetary penalty.
Strategic Defensibility For The General Counsel
For a General Counsel or Legal Head, a 72-hour reporting window drastically alters how you manage vendor liability and regulator engagement. You can no longer wait for a lengthy outside counsel review or a comprehensive third-party forensic report before initiating a regulatory filing. The DPDP Act covers digital personal data processing within India and processing outside India connected to offering goods or services to Data Principals in India. This means cross-border breaches impacting this data trigger the exact same rapid timelines. As soon as you confirm a breach has occurred, the clock starts ticking.
Furthermore, the DPDP Act assesses risk based on actual volume and impact. The DPDP Act 2023 does not create distinct statutory classifications based on data sensitivity, meaning you must treat all personal data breaches with equal urgency and uniform incident response protocols. Whether the compromised data involves basic contact information or highly detailed financial transaction logs, the 72-hour clock applies universally. There is no legal exception that allows you to delay reporting merely because you believe the data carries a lower risk profile.
Managing Vendor Liability and the Supply Chain
Your primary legal exposure often lies deeply embedded in the supply chain. Data Processors are not directly liable to the Board for breach notification, meaning the Data Fiduciary holds the entire regulatory risk. You must enforce strict 24-hour breach reporting Service Level Agreements (SLAs) in all vendor contracts. Review your limitation of liability and indemnity clauses immediately to ensure you can recover the potential Rs. 200 crore penalty if a Data Processor delays your ability to notify the Board. If your vendor waits 48 hours to inform you of an incident, your legal team is left with merely 24 hours to draft and file the complex regulatory notification.
What Happens If We Miss The 72-Hour Deadline?
If you fail to notify the Board within 72 hours or fail to inform Data Principals without delay, the Board may initiate an official inquiry. Under the penalty schedule, this specific failure exposes the company to a fine of up to Rs. 200 crore. As part of this inquiry, the Board will closely examine whether your delay led to exacerbated harm for the Data Principals, or if your organization deliberately avoided taking prompt action to protect its public reputation.
Does The Obligation Apply To Third-Party Vendors?
The legal obligation to notify the Board and Data Principals rests entirely on the Data Fiduciary. Your third-party processors must notify you when a breach occurs, but they do not report directly to the regulator. This architecture of the law makes back-to-back contractual indemnities and strict vendor reporting timelines absolutely essential for your organizational defensibility. Processors must be contractually bound to cooperate fully with your investigation and provide real-time updates.
Do We Need To Report Every Minor Security Incident?
The DPDP Act, 2023 defines a personal data breach broadly as any unauthorised processing that compromises the confidentiality, integrity, or availability of personal data. The Rules require reporting once a breach is confirmed. Building a robust evidence trail of your mitigation efforts is vital for reducing potential penalties during a regulatory inquiry. Even if you suspect a breach is minor, documenting your internal review and mitigation steps satisfies the Section 33(2) requirement to demonstrate timely and effective action.
Can We Process Data To Investigate Breaches?
Consent is the primary basis for processing, except where Section 7 legitimate uses apply. Investigating a security incident or responding to a corporate emergency often falls under these legitimate uses, allowing your internal cyber forensics team to conduct rapid response and data review without seeking fresh consent from the affected individuals. This statutory allowance ensures that privacy requirements do not inadvertently cripple your cybersecurity operations during a live threat.
Action Plan For Legal Teams
1. Audit your current incident response plan to ensure it unambiguously mandates notifying the Data Protection Board within 72 hours and affected Data Principals without delay. 2. Revise vendor processing agreements to require breach notification to your legal team within 24 hours of discovery, backed by clear, uncapped indemnity provisions for regulatory fines. 3. Conduct regular tabletop exercises with your executive suite, IT, and legal teams to simulate a 72-hour reporting timeline under regulatory pressure. 4. With exactly 288 days remaining until the 13 May 2027 DPDP compliance deadline, secure your compliance posture. Use freescan.complydp.com to identify vendor vulnerabilities and build a defensible, automated breach management workflow today.
Sources
Frequently asked questions
How long do we have to report a data breach to the Data Protection Board?
Under the DPDP Rules, 2025, a Data Fiduciary must submit a detailed breach report to the Data Protection Board within 72 hours of identifying the incident. In addition to this regulatory filing, you must also notify the affected Data Principals without delay so they can take protective measures against potential harm.
What is the penalty for failing to report a personal data breach under DPDP?
Failing to give the Board or affected Data Principals notice of a personal data breach under Section 8(6) carries a penalty that may extend to Rs. 200 crore. This is legally separate from the Rs. 250 crore maximum penalty for failing to maintain reasonable security safeguards under Section 8(5).
Are our data processors responsible for reporting breaches to the Board?
No. The DPDP Act places the obligation to notify the regulator and the Data Principals exclusively on the Data Fiduciary. Processors do not directly interact with the Board. You must ensure your processor contracts include strict 24-hour reporting SLAs and strong indemnities so you can meet your 72-hour regulatory window.
Does the reporting timeline change depending on the type of data breached?
No, the timeline remains exactly the same for all personal data. The DPDP Act, 2023 does not create distinct statutory classifications based on data sensitivity. All personal data breaches must be reported to the Board within 72 hours, although the Board will consider the type and nature of the compromised data when determining any ultimate penalty.
ComplyDP