6 min
What is the DPDP breach clock to the Board and to customers, and who owns the runbook?
Understand the 72 hour DPDP breach notification deadline, vendor liability under Section 8, and how General Counsel should structure incident runbooks.
Last updated:
Under the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025, a personal data breach triggers two separate notification obligations. A Data Fiduciary must submit a detailed report to the Data Protection Board of India within 72 hours of discovering the breach. The same entity must inform affected Data Principals without delay. The Data Fiduciary owns the incident response runbook. This entity retains primary legal liability even if a third party vendor caused the exposure. The law does not allow companies to point fingers at software providers to escape regulatory scrutiny. The Fiduciary answers to the Board.
Section 8(1) of the Act establishes that the Data Fiduciary holds sole responsibility for compliance. The statute states this applies irrespective of any agreement to the contrary. If a Data Processor suffers a breach while handling your enterprise data, the regulator looks directly at the Fiduciary. Engaging a processor requires a valid contract under Section 8(2). General Counsel need these contracts to contain immediate notification clauses. Vendor agreements should force processors to report anomalies to the Fiduciary well before the 72 hour regulatory window expires. You cannot meet your 72 hour deadline if your vendor takes four days to notify your security team.
Traditional limitation of liability caps in legacy master service agreements rarely cover statutory fines introduced by the DPDP Act. Legacy contracts focus on data confidentiality rather than strict statutory reporting timelines. Legal teams face a hard compliance deadline of 13 May 2027 to finalize processor contracts. Updating indemnity clauses and documenting liability allocation for breach scenarios takes time. Outside counsel spend will spike if organizations attempt to negotiate these clauses without an established data processing agreement framework. The contract defines the internal clock. Vendors must give the Fiduciary enough time to assess the situation before the statutory limit hits. A 12 hour or 24 hour vendor reporting requirement gives the Fiduciary a necessary buffer.
When a breach occurs, the clock starts on gathering forensic evidence. You have 72 hours to compile the facts and notify the Data Protection Board. The report requires specifics about the data affected, the scale of the exposure, and the initial containment measures. Failing to hit this deadline severely weakens regulatory defensibility. The Board wants to see an organized response. Fragmented emails and unstructured spreadsheets fail under regulatory scrutiny during an active breach inquiry. If a Fiduciary lacks complete information at the 72 hour mark, they must still file the initial notification and provide updates as the forensic investigation progresses. Concealing an incident violates the core provisions of the Act.
The DPDP Rules 2025 specify that notification to Data Principals must occur without delay. This timeline runs concurrently with the Board notification. The Fiduciary must tell the affected individuals what happened and what steps they should take to protect themselves. A credible compliance platform automates this workflow. The system must map breach reports directly to the itemised notices and verifiable consent records held for each person. Timely intimation allows individuals to secure their accounts, change passwords, and monitor for identity theft. Delays in notifying individuals compound the severity of the breach in the eyes of the regulator.
Under Section 33, the Board determines monetary penalties by evaluating specific factors. Section 33(2)(e) directs the Board to consider whether the person took any action to mitigate the effects and consequences of the breach. The timeliness and effectiveness of your actions directly influence the final fine. The Board also examines the nature, gravity, and duration of the breach. Section 33(2)(c) allows the regulator to increase penalties for the repetitive nature of the breach. Fines for failing to implement reasonable security safeguards can reach up to 250 crore rupees per instance. Proper incident response minimizes this exposure.
A data breach often triggers a wave of user complaints. Section 13(1) gives the Data Principal the right to readily available means of grievance redressal. The Fiduciary or Consent Manager must respond to these grievances within the prescribed period. If individuals suffer from a breach and cannot get answers from the Fiduciary, they will escalate their complaints. Section 13(3) requires individuals to exhaust the Fiduciary grievance process before approaching the Board. A poorly executed breach response guarantees an unmanageable spike in formal grievances. The legal team must equip the grievance officer with accurate talking points based on the incident response runbook.
The Legal Head and the Data Protection Officer jointly own the breach runbook. They direct the technical teams to contain the incident while managing legal exposure. An auditor or the Board will ask for a timestamped evidence trail. You must show exactly when the breach was detected, how the data was secured, and who received notifications. The runbook defines who talks to the regulator and who drafts the customer emails. Roles must be explicit. Information security teams handle the technical containment, but legal teams must dictate the external communication strategy. Misaligned communication during the first 48 hours of an incident often creates contradictory records. The Board will use these contradictions against the Fiduciary during a Section 33 inquiry.
Organizations must take three specific actions to prepare for a breach inquiry.
1. Audit existing master service agreements to confirm vendors are required to report suspected breaches within 12 to 24 hours. This buffer gives the Fiduciary time to evaluate the exposure, draft the necessary paperwork, and meet the 72 hour Board deadline without rushing incomplete data.
2. Draft a standardized DPDP incident response runbook that assigns explicit roles. Assign specific internal stakeholders for technical containment, regulatory reporting, and customer intimation. Cross functional alignment prevents delays when the clock starts ticking.
3. Implement a dedicated system of record for incident tracking. This central repository guarantees privileged review and defensible regulator engagement. It replaces scattered chat logs with a formal audit trail.
Run a gap analysis of your current incident readiness using freescan.complydp.com to identify vendor contract exposures before the enforcement deadline.
Sources
Frequently asked questions
Does a Data Processor have to notify the Board directly?
No. The Data Fiduciary holds the statutory obligation to notify the Data Protection Board and the Data Principals. The processor must notify the Fiduciary based on the terms established in their valid contract under Section 8.
What qualifies as without delay for notifying affected customers?
The DPDP Rules 2025 require intimation to Data Principals without delay. While the Board report has a hard 72 hour ceiling, customer notification should occur as soon as the Fiduciary verifies the scope and identifies the affected individuals.
Can we contractually shift regulatory liability to our vendors?
Section 8(1) prevents a Data Fiduciary from contracting away its statutory liability. You can negotiate indemnities to recover costs after the fact, but the regulator will penalize the Fiduciary directly for the breach.
What happens if we miss the 72 hour deadline?
Under Section 33, the Board assesses the timeliness of your response when calculating fines. Missing the 72 hour window documented in the Rules 2025 drastically increases your exposure to maximum penalties.
ComplyDP