DPDP Breach Notification: The Two-Stage Rule Most Companies Miss
Almost every summary describes DPDP breach reporting as a seventy-two hour rule. That is only half of Rule 7. There are two separate intimations to the Board with two different clocks, and the first one starts immediately.
The short answer
Rule 7 of the DPDP Rules 2025 creates two separate intimations to the Data Protection Board, not one:
- Without delay — a description of the breach including its nature, extent, timing and location of occurrence, and the likely impact.
- Within seventy-two hours of becoming aware — updated and detailed information, the broad facts and circumstances, mitigation measures, findings on who caused it, remedial measures, and a report on what affected Data Principals were told.
Separately, under Rule 7(1), each affected Data Principal must be intimated without delay. That obligation does not wait for the seventy-two hour report.
What the Data Principal must be told
Rule 7(1) requires the intimation to be made in a concise, clear and plain manner, through the Data Principal’s user account or any mode of communication she has registered. It must contain five specific elements:
- A description of the breach, including its nature, extent and the timing of its occurrence.
- The consequences relevant to her that are likely to arise from the breach.
- The measures implemented and being implemented to mitigate risk, if any.
- The safety measures she may take to protect her own interests.
- Business contact information of a person able to respond to her queries on behalf of the Data Fiduciary.
The fifth element is easy to overlook and hard to improvise. It requires a named, reachable responder to exist before an incident, not to be nominated during one.
What the Board must be told, and when
Rule 7(2)(a) requires an intimation without delay containing a description of the breach: its nature, extent, timing and location of occurrence, and the likely impact.
Rule 7(2)(b) then requires, within seventy-two hours of becoming aware or within such longer period as the Board may allow on a written request, six further items:
- Updated and detailed information in respect of the description already given.
- The broad facts related to the events, circumstances and reasons leading to the breach.
- Measures implemented or proposed to mitigate risk, if any.
- Any findings regarding the person who caused the breach.
- Remedial measures taken to prevent recurrence.
- A report regarding the intimations given to affected Data Principals.
The clock starts on awareness, not on confirmation
Both obligations run from becoming aware of the breach. This is a lower threshold than completing an investigation, and it is where most incident procedures fail. Teams commonly wait until they have established scope before reporting anything. Rule 7 does not permit that: the initial intimation is due without delay, and the detailed picture follows within seventy-two hours.
The Board may allow a longer period for the detailed report, but only on a request made in writing. That is an application to be made during an incident, which means the procedure for making it should exist beforehand.
Rule 7 is written on the assumption that you will not know everything early. That is why it separates the immediate description from the detailed report. An organisation that stays silent while it investigates has misread the structure of the rule.
Infosek Team
How this interacts with the CERT-In six hour direction
DPDP does not replace existing obligations. An organisation covered by the CERT-In Directions may face a six hour reporting requirement for certain cyber incidents alongside the DPDP obligations described here. The two regimes have different triggers, different recipients and different clocks.
A response plan that handles only one of them will breach the other. This is a common gap in incident procedures written before the DPDP Rules were notified.
The logging obligation that makes reporting possible
Rule 7 cannot be met without Rule 6. Rule 6(1)(c) requires visibility on the accessing of personal data through appropriate logs, monitoring and review, for detecting unauthorised access and enabling investigation. Rule 6(1)(e) requires those logs and the personal data to be retained for one year, unless another law requires otherwise.
Without that logging, the detailed report required at seventy-two hours cannot be produced, because the facts, the circumstances and the findings about who caused the breach will not be reconstructable.
What a compliant procedure needs to contain
- A defined trigger for “becoming aware”, and who is authorised to declare it.
- A named responder with business contact information, ready to be published to affected Data Principals.
- A pre-drafted Data Principal intimation template covering all five elements of Rule 7(1).
- A path to intimate the Board immediately, separate from the seventy-two hour report.
- A prepared written request for extension, in case the detailed report cannot be completed in time.
- Logging that satisfies Rule 6(1)(c) and the one year retention in Rule 6(1)(e).
- A parallel assessment of whether CERT-In obligations are also triggered.
Rule 7 commences on 14 May 2027 along with the rest of Rules 5 to 16. The procedure, the logging and the templates all need to exist before then, because none of them can be built during an incident.
Common questions
What is the DPDP breach notification timeline?
Rule 7 of the DPDP Rules 2025 requires two intimations to the Data Protection Board. On becoming aware of a personal data breach, the Data Fiduciary must intimate the Board without delay with a description of the breach, its nature, extent, timing, location and likely impact. It must then provide detailed information within seventy-two hours of becoming aware, or a longer period if the Board allows on written request. Affected Data Principals must also be intimated without delay.
Who must be told about a personal data breach under DPDP?
Both the affected Data Principals and the Data Protection Board. Under Rule 7(1) each affected Data Principal must be intimated without delay through her user account or a registered mode of communication. Under Rule 7(2) the Board must be intimated without delay and then in detail within seventy-two hours.
Would your DPDP setup hold up if it were tested?
Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.
Book Free 30-Min Assessment