5 mins
DPDPA 2023 Breach Reporting Timeframe: 72 Hours to the Board
Under the DPDPA 2023 and Rules 2025, a Data Fiduciary must report a personal data breach to the Data Protection Board within 72 hours and to affected individuals without delay.
Last updated:
Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, a Data Fiduciary must report a personal data breach to the Data Protection Board of India within 72 hours. Notification to the affected Data Principals must happen without delay. This dual reporting requirement forces organizations to identify, assess, and report security incidents rapidly. Section 8 of the Act establishes that a Data Fiduciary remains responsible for compliance irrespective of any agreement to the contrary. If a Data Processor experiences the unauthorized access, the legal duty to notify the Board still rests entirely on the Data Fiduciary.
Many early stage startups treat compliance as a delayed priority. Enterprise buyers assess risk differently. When a software provider signs a business contract, the enterprise client expects a tested incident response plan. Section 33 allows the Board to fine organizations up to 250 crore rupees for failing to report a personal data breach or failing to implement reasonable security safeguards. The Board calculates these penalties based on specific criteria outlined in Section 33(2). It examines the nature, gravity, and duration of the breach. It assesses the type of personal data affected and the repetitive nature of the incident. It also determines whether the organization realized a gain or avoided a loss due to the breach. Investors reviewing a data room during Series A funding look for exact procedures mapping to these statutory sections.
The 72-hour reporting window to the Data Protection Board begins the moment the organization becomes aware of the incident. The Rules, 2025 define the specific information required in this report. A response team needs to document the nature of the unauthorized access, estimate the number of affected individuals, and list immediate mitigation steps. Gathering these details manually takes days of engineering effort. Staff members have to trace audit logs, identify the compromised database rows, and draft legal notices simultaneously. Enterprise due diligence checklists now ask exactly how a vendor meets this 72-hour timeline. Relying on scattered spreadsheets and unstructured chat channels risks failing investor scrutiny.
The timeframe to notify affected individuals is defined as without delay. Startups cannot wait for a complete forensic audit before warning their users. The notice informs the Data Principal about the incident, explains the compromised data points, and provides grievance redressal details. Section 13(1) gives individuals the right to readily available means of grievance redressal. The Fiduciary has a prescribed period to respond to these inquiries from the date of receipt. Section 13(3) requires the Data Principal to exhaust this opportunity for internal redressal before approaching the Board. A structured system to mass email affected users and track their responses keeps the organization compliant. Preparing notice templates in advance cuts down the response time expected by regulatory bodies and enterprise clients.
Assessing the financial impact of a breach goes beyond the headline regulatory fines. A delayed response burns internal runway as leadership abandons normal operations for crisis management. Section 33(2)(e) directs the Board to consider whether the person took any action to mitigate the effects and consequences of the breach. The Board evaluates the timeliness and effectiveness of these mitigation efforts. Rapid notification proves active mitigation. Prolonged silence signals negligence. Operating with lean budgets means startups cannot absorb the operational drag of a disorganized breach response. Every hour spent manually drafting notices is an hour lost to shipping features. Preconfigured compliance workflows turn an unpredictable legal scramble into a structured operational routine.
Operationalizing breach response early unblocks enterprise deals. Follow these concrete steps to build readiness and meet the statutory deadlines.
1. Map all third party vendors and update contracts to require immediate notification upon a breach detection.
2. Designate an internal owner to oversee incident response and gather facts required for the Data Protection Board submission.
3. Draft notification templates for both the Board and affected Data Principals to avoid starting from scratch during a crisis.
4. Implement audit logs to capture when a breach occurred, the specific data affected, and the exact timestamp when notices were sent.
5. Test the internal reporting workflow against the 72-hour limit to verify a small team can actually execute it.
6. Establish a dedicated grievance redressal channel under Section 13 to handle the immediate influx of user inquiries following a breach notification.
7. Review the penalty criteria in Section 33 to understand how the Board evaluates the duration of the breach and the timeliness of mitigation.
A frequent mistake is assuming the timeline applies only after a full investigation concludes. The clock starts at awareness. Another common error is treating the final compliance deadline as the date to begin preparations. Delaying implementation puts upcoming funding rounds at risk. Enterprise buyers refuse to sign annual contracts if a vendor lacks a validated breach response protocol. Founders often assume their cloud provider handles breach reporting automatically. A Data Processor might detect the unauthorized access, but Section 8(1) assigns the legal reporting duty strictly to the Data Fiduciary. Blaming a third party vendor does not shield the primary organization from regulatory penalties.
Managing a 72-hour reporting window manually consumes excessive engineering bandwidth. Credible compliance solutions automate evidence collection and vendor oversight. A platform triggers workflows the moment a breach is flagged. It compiles the required data for the Data Protection Board report directly from system logs. The tool also tracks the status of user notifications and centralizes Section 13 grievance tickets in one dashboard. This specific posture demonstrates maturity to enterprise clients. It drastically cuts down security questionnaire completion time. Fast growing companies scale compliance by removing manual legal reviews from routine incident response.
Evaluate your breach reporting readiness and identify gaps in your incident response plan. Review your current posture and unblock enterprise deals at https://www.complydp.com/audit-preview before the deadline.
Sources
Frequently asked questions
Does a startup have to report all data breaches under DPDP 2023?
Yes, the DPDP Act requires a Data Fiduciary to report any personal data breach to both the Data Protection Board and the affected Data Principals. There is no risk threshold or exemption for small businesses in the 2023 Act.
When does the 72 hour clock start for DPDP breach reporting?
The 72 hour timeline to notify the Data Protection Board begins the moment the Data Fiduciary becomes aware of the personal data breach. You cannot pause the clock to complete a full internal investigation.
What happens if a third party vendor causes the data breach?
Under Section 8, the Data Fiduciary remains entirely responsible for reporting the breach. Startups must require their Data Processors to notify them immediately so they can meet the 72 hour regulatory window.
What is the penalty for failing to report a personal data breach?
Section 33 of the DPDP Act establishes a maximum penalty of up to 250 crore rupees for failing to take reasonable security safeguards or failing to report a personal data breach to the Board and affected individuals.
Can we delay notifying affected users until our investigation is complete?
No, the DPDP Rules, 2025 mandate that Data Principals must be notified without delay. You cannot wait for a comprehensive forensic audit to issue the initial warning to affected users.
ComplyDP