Infosek
INFOSEK

DPDP Breach Notification: The Two-Stage Rule Most Companies Miss

Almost every summary describes DPDP breach reporting as a seventy-two hour rule. That is only half of Rule 7. There are two separate intimations to the Board with two different clocks, and the first one starts immediately.

DPDP Breach Notification: The Two-Stage Rule Most Companies Miss

The short answer

Rule 7 of the DPDP Rules 2025 creates two separate intimations to the Data Protection Board, not one:

Separately, under Rule 7(1), each affected Data Principal must be intimated without delay. That obligation does not wait for the seventy-two hour report.

What the Data Principal must be told

Rule 7(1) requires the intimation to be made in a concise, clear and plain manner, through the Data Principal’s user account or any mode of communication she has registered. It must contain five specific elements:

The fifth element is easy to overlook and hard to improvise. It requires a named, reachable responder to exist before an incident, not to be nominated during one.

What the Board must be told, and when

Rule 7(2)(a) requires an intimation without delay containing a description of the breach: its nature, extent, timing and location of occurrence, and the likely impact.

Rule 7(2)(b) then requires, within seventy-two hours of becoming aware or within such longer period as the Board may allow on a written request, six further items:

The clock starts on awareness, not on confirmation

Both obligations run from becoming aware of the breach. This is a lower threshold than completing an investigation, and it is where most incident procedures fail. Teams commonly wait until they have established scope before reporting anything. Rule 7 does not permit that: the initial intimation is due without delay, and the detailed picture follows within seventy-two hours.

The Board may allow a longer period for the detailed report, but only on a request made in writing. That is an application to be made during an incident, which means the procedure for making it should exist beforehand.

Rule 7 is written on the assumption that you will not know everything early. That is why it separates the immediate description from the detailed report. An organisation that stays silent while it investigates has misread the structure of the rule.

Infosek Team

How this interacts with the CERT-In six hour direction

DPDP does not replace existing obligations. An organisation covered by the CERT-In Directions may face a six hour reporting requirement for certain cyber incidents alongside the DPDP obligations described here. The two regimes have different triggers, different recipients and different clocks.

A response plan that handles only one of them will breach the other. This is a common gap in incident procedures written before the DPDP Rules were notified.

The logging obligation that makes reporting possible

Rule 7 cannot be met without Rule 6. Rule 6(1)(c) requires visibility on the accessing of personal data through appropriate logs, monitoring and review, for detecting unauthorised access and enabling investigation. Rule 6(1)(e) requires those logs and the personal data to be retained for one year, unless another law requires otherwise.

Without that logging, the detailed report required at seventy-two hours cannot be produced, because the facts, the circumstances and the findings about who caused the breach will not be reconstructable.

What a compliant procedure needs to contain

Rule 7 commences on 14 May 2027 along with the rest of Rules 5 to 16. The procedure, the logging and the templates all need to exist before then, because none of them can be built during an incident.

Common questions

What is the DPDP breach notification timeline?

Rule 7 of the DPDP Rules 2025 requires two intimations to the Data Protection Board. On becoming aware of a personal data breach, the Data Fiduciary must intimate the Board without delay with a description of the breach, its nature, extent, timing, location and likely impact. It must then provide detailed information within seventy-two hours of becoming aware, or a longer period if the Board allows on written request. Affected Data Principals must also be intimated without delay.

Who must be told about a personal data breach under DPDP?

Both the affected Data Principals and the Data Protection Board. Under Rule 7(1) each affected Data Principal must be intimated without delay through her user account or a registered mode of communication. Under Rule 7(2) the Board must be intimated without delay and then in detail within seventy-two hours.

Topics DPDP Act CERT-In

Would your DPDP setup hold up if it were tested?

Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.

Book Free 30-Min Assessment