DPDP glossary
What is Personal Data Breach?
A personal data breach is any unauthorised access, disclosure, acquisition, sharing, use, alteration, destruction, or loss of personal data that compromises confidentiality, integrity, or availability. Accidental misconfigurations and insider errors count—not only hacking.
Key requirements
- Detect and contain the incident promptly
- Assess scope using a data inventory where possible
- Notify the DPBI within the prescribed timeline
- Notify affected Data Principals separately
- Document containment steps and retain evidence for the Board