5 minutes

DPDPA 2023 Breach Reporting Timeframe: 72 Hours to the Board

Under the DPDP Act 2023 and Rules 2025, a Data Fiduciary reports a personal data breach to the Data Protection Board within 72 hours and notifies individuals without delay.

Written byVipul Abhishek· Former Advocate, Supreme Court of India

Last updated:

The timeframe to report a personal data breach under the Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025 is 72 hours. A Data Fiduciary submits this formal notice to the Data Protection Board of India. The rules also require notifying affected Data Principals without delay. These separate regulatory obligations demand concurrent incident response workflows. Fiduciaries file the initial Board disclosure even if forensic investigations remain ongoing.

Section 1(2) of the Act outlines the commencement mechanism. It specifies that provisions come into force on dates appointed by the Central Government. Different dates may apply to different sections of the legislation. Official Gazette notifications establish the exact enforcement timeline. Organizations draft their incident response playbooks before these final compliance deadlines arrive. Preparing a 72-hour reporting capability requires extensive internal coordination.

The DPDP Act establishes the baseline statutory obligation to report breaches. The accompanying DPDP Rules, 2025 define the precise timeline. A Data Fiduciary sends a detailed incident report to the Data Protection Board within 72 hours of becoming aware of the exposure. This window runs continuously. It includes weekends and public holidays. Entities gather essential facts rapidly during the initial crisis phase.

The regulatory submission details the volume of records exposed and the specific data categories compromised. Missing basic facts delays the regulatory assessment. Fiduciaries frequently rely on external cloud hosting providers and payment gateways to process data. Section 8(1) makes the Data Fiduciary responsible for compliance in respect of any processing undertaken by a Data Processor. The fiduciary bears the legal burden of the 72-hour deadline even if a vendor directly caused the incident.

The text of Section 8(1) includes a specific statutory clause regarding liability. It holds the fiduciary responsible irrespective of any agreement to the contrary. A company cannot sign away its breach reporting liability through a vendor contract. The fiduciary remains the primary target for regulatory inquiries. If a processor hides a security incident, the Board still pursues the fiduciary for missing the 72-hour window. This absolute liability applies regardless of a failure by a Data Principal to carry out their own duties under the Act.

Section 8(2) permits fiduciaries to involve processors only under a valid contract. This provision covers any activity related to offering goods or services to Data Principals. If a third-party software vendor suffers a security incident, the fiduciary holds the primary duty to notify the Board. Fiduciaries write strict breach notification clauses into their vendor agreements. These contracts compel immediate disclosure from the processor to the fiduciary. A slow vendor alert jeopardizes the fiduciarys ability to meet the 72-hour regulatory cutoff.

Failing to meet the 72-hour reporting deadline creates immediate financial risk. Section 33(1) authorizes the Board to impose monetary penalties for significant breaches following an inquiry. The maximum fine for failing to take reasonable security safeguards to prevent a personal data breach is 250 crore rupees. The Board evaluates specific statutory criteria outlined in Section 33(2) when calculating the exact penalty amount. These criteria include the nature, gravity, and duration of the breach.

The regulator examines the type and nature of the personal data affected by the incident. An exposed financial database carries a different regulatory weight than an altered public contact form. Section 33(2)(e) mandates the Board to consider whether the person took any action to mitigate the effects and consequences of the breach. The regulator evaluates the timeliness and effectiveness of those mitigation steps. A delayed report gives the Board explicit grounds for higher fines. Post-breach inquiries demand objective evidence showing exactly when the entity discovered the intrusion.

Investigators look closely at the financial impact of the data exposure. Section 33(2)(d) directs the Board to assess whether the offending party realized a gain or avoided any loss as a result of the breach. Accurate incident logging proves that the fiduciary acted quickly to minimize harm. Section 33(2)(c) requires the Board to consider the repetitive nature of the breach. A history of previous security failures amplifies the final financial penalty.

Section 33(1) outlines the procedural steps the Board takes before levying a penalty. The regulator determines on conclusion of an inquiry that a breach of the provisions of the Act or rules is significant. The Board does not issue fines automatically. The law requires giving the person an opportunity of being heard. Fiduciaries use this hearing to present their incident logs and mitigation records. They demonstrate that they met the 72-hour reporting deadline and notified consumers without delay.

Submitting the Board report satisfies only half the legal obligation. The DPDP Rules require Data Fiduciaries to communicate the breach to affected Data Principals without delay. Prompt consumer notifications allow individuals to lock their credit files or change exposed passwords. This structure creates parallel incident response tracks. One track handles the technical regulatory submission. The second manages clear public communications. Fiduciaries write communication templates in advance to save time during an active data emergency.

Section 8(3) dictates that a Data Fiduciary shall ensure the accuracy and consistency of personal data. This duty applies when the data is likely to be used to make a decision that affects the Data Principal. It also triggers when personal data is disclosed to another Data Fiduciary. A data breach that maliciously alters record integrity activates this specific clause. Fiduciaries maintain detailed system audit logs to demonstrate their data integrity controls to statutory auditors.

Organizations translate theoretical breach policies into concrete operational workflows. Data flow mapping identifies exactly where a security exposure is most likely to occur. Companies map all external tools processing their information. Knowing these network entry points accelerates threat discovery during a live incident.

Fiduciaries formalize their incident response sequences before an event happens. 1. Designate an internal officer to lead Board communications. 2. Update all vendor contracts to mandate immediate breach notification. 3. Deploy technical tools to log exact incident timelines and mitigation steps. Testing these procedures through regular tabletop exercises exposes gaps in the 72-hour reporting capability.

Sources

Frequently asked questions

Under DPDPA 2023, what is the timeframe to report a breach?

The DPDP Rules, 2025 require a Data Fiduciary to report a personal data breach to the Data Protection Board within 72 hours. The fiduciary also notifies affected Data Principals without delay.

Does the Act say to report a breach as soon as possible or within 7 days?

No. The DPDP Rules, 2025 specify a strict 72-hour window for the Board report. Relying on an undefined interpretation violates current rules.

Are startups exempt from the 72-hour breach reporting rule?

No. The 72-hour reporting requirement applies to all Data Fiduciaries processing digital personal data within the scope of the Act. Entities meet this deadline to avoid statutory penalties.

Who reports the breach if a vendor loses the data?

Under Section 8(1) of the DPDP Act, the Data Fiduciary remains responsible for compliance. If a Data Processor suffers an incident, the fiduciary holds the legal duty to report the breach to the Board within 72 hours.

What is the penalty for missing the breach reporting deadline?

Section 33(1) allows the Board to impose monetary penalties up to 250 crore rupees for significant breaches involving a failure of security safeguards. The Board considers the timeliness and effectiveness of mitigation actions when calculating fines.