5 mins

DPDP Act 2023 Breach Reporting Timeframe: 72 Hours Explained

Under the DPDP Rules 2025, Data Fiduciaries must report a personal data breach to the Board within 72 hours and notify affected individuals.

Written byVipul Abhishek· Former Advocate, Supreme Court of India

Last updated:

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, a Data Fiduciary faces strict deadlines for incident reporting. The organization must report a personal data breach to the Data Protection Board of India within 72 hours. Section 8(6) of the Act establishes this dual notification duty. It requires the fiduciary to intimate both the Board and the affected Data Principals. A personal data breach includes unauthorized processing, accidental disclosure, or loss of access that compromises digital personal data. You cannot wait for a complete technical investigation. The initial 72 hour window requires rapid disclosure of basic facts. You submit supplemental information later as the investigation progresses.

For Seed to Series B founders, this 72 hour window operates as a rigid operational test. Enterprise buyers evaluating your startup during due diligence examine breach readiness closely. If your team cannot detect an incident, notify the Board within 72 hours, and email users promptly, you fail standard security questionnaires. A breach response failure acts as an immediate deal blocker for B2B sales. Security audits demand concrete proof of your notification workflows. Delayed compliance implementation threatens upcoming funding rounds.

The Legal Framework and Fiduciary Liability

Section 8(1) of the DPDP Act holds the Data Fiduciary responsible for compliance. This liability applies irrespective of any agreement to the contrary. The Data Fiduciary assumes full responsibility for any processing undertaken by it directly. It bears equal responsibility for processing undertaken on its behalf by a Data Processor. A startup cannot contract away its liability to report a security incident. Section 8(2) limits how a fiduciary engages a Data Processor. The fiduciary may involve a processor to process personal data only under a valid contract. This contract dictates the speed of incident reporting from the vendor to you. If an offshore cloud provider suffers an outage that exposes data, the legal burden rests on your organization. Your startup holds the ultimate liability to execute notifications.

Compliance teams must navigate two overlapping reporting timelines. Section 8(6) of the DPDP Act requires the Data Fiduciary to intimate the Board and affected individuals in the event of a personal data breach. The DPDP Rules set this Board reporting window at 72 hours. India imposes an even tighter deadline under the Information Technology Act. The Indian Computer Emergency Response Team mandates a 6 hour reporting window for severe cybersecurity incidents. Legal teams consider this 6 hour CERT-In overlap a critical compliance factor. A startup might need to file a preliminary technical report with CERT-In hours before finalizing the Data Protection Board notification. Failing to coordinate these parallel reporting duties creates significant legal exposure.

What Happens If You Miss the Window

Missing the 72 hour notification deadline triggers enforcement action. Section 33(1) allows the Board to impose monetary penalties if it determines that a breach of the provisions of this Act is significant. A breach of the provisions differs legally from a personal data breach. Experiencing a security incident is a personal data breach. Failing to report that incident under Section 8(6), or failing to implement reasonable security safeguards under Section 8(5), constitutes a breach of the provisions. Section 33(2) lists the exact matters examined to calculate the fine amount. Regulators review the nature, gravity, and duration of the non-compliance. They assess the type and nature of the personal data affected. Mitigation efforts play a direct role in the final calculation. Fines reach up to 250 crore rupees for failing to take reasonable security safeguards.

Steps to Build a Compliant Breach Workflow

Building a compliant incident response workflow requires technical and legal coordination. 1. Define internal escalation paths so engineering teams alert the compliance lead immediately upon detecting a data leak. Speed determines your ability to meet parallel regulatory deadlines. 2. Amend vendor agreements to mandate that Data Processors notify you within 24 hours of an incident. This buffer gives your legal team time to review the facts and meet the 72 hour Board timeline. 3. Draft notification templates for the Data Protection Board and the affected Data Principals ahead of time. Pre-approved messaging prevents panic during a live incident. 4. Integrate a compliance platform to log the exact time of discovery, the timeline of actions, and the transmission of the required notices. This audit trail defends your company during regulatory inquiries. 5. Conduct tabletop exercises with your executive team. Simulating an incident ensures every department understands the communication hierarchy. 6. Review external communication channels. You need a reliable method to contact all affected individuals to satisfy Section 8(6).

Common Misconceptions Regarding Breach Reporting

Founders often misunderstand the legal mechanics of incident reporting. Many believe they should wait for a complete forensic investigation before filing. The DPDP Rules 2025 dictate initial notification within 72 hours even if all facts remain unknown. You provide available details first and update the regulators as new data surfaces. Another common error involves ignoring the CERT-In requirements. Startups often prepare for the 72 hour DPDP window while missing the 6 hour cybersecurity incident deadline. Some companies attempt to hide minor breaches from users to protect brand reputation. This omission violates Section 8(6) directly and increases the risk of severe penalties under Section 33. Relying on manual spreadsheets to track incident timelines causes missed deadlines. Spreadsheets fail to provide automated alerts or locked audit logs.

Commercial Evaluation and Readiness

Enterprise readiness requires proving to buyers that your startup handles data securely. A credible compliance system centralizes vendor contracts. It maintains immutable logs and tracks the 72 hour reporting window automatically. This automation prevents your core team from losing focus on product development during an incident. Startups that manage breaches efficiently pass due diligence and secure enterprise contract renewals. Assess your current incident response posture and identify functional gaps before an external auditor does. Run an evaluation at https://www.complydp.com/audit-preview to clear enterprise deals and prepare your operations for regulatory scrutiny.

Sources

Frequently asked questions

When does the 72-hour breach reporting clock start under the DPDP Rules?

The 72 hour timeframe begins the moment the Data Fiduciary becomes aware of the personal data breach. You must report initial details to the Board within this window.

Do startups need to notify both the Data Protection Board and users?

Yes. Section 8(6) requires the Data Fiduciary to intimate both the Board and affected Data Principals in the event of a personal data breach.

Does the DPDP Act override CERT-In reporting rules?

No. Compliance teams must manage both. The Indian Computer Emergency Response Team mandates a 6 hour reporting window for severe cybersecurity incidents, running parallel to the 72 hour DPDP timeline.

What happens if a Data Processor causes the breach?

Under Section 8(1), the Data Fiduciary remains fully responsible for compliance. Startups must ensure their vendor contracts mandate immediate incident notification to meet regulatory deadlines.

What is the penalty for failing to report a personal data breach?

Failing to report violates the Act. Under Section 33(1), the Board assesses monetary penalties for a breach of the provisions. Fines reach 250 crore rupees for failing to maintain reasonable security safeguards.