Infosek
INFOSEK

What Counts as a Personal Data Breach Under DPDP?

Teams tend to picture an attacker. The definition also covers the engineer who misconfigured a bucket and the ransomware that locked you out of your own records.

What Counts as a Personal Data Breach Under DPDP?

The definition

A personal data breach means any unauthorised processing of personal data, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises the confidentiality, integrity or availability of personal data.

Three things follow that surprise most teams.

Accidental counts

The definition expressly includes accidental disclosure, acquisition, sharing, use, alteration, destruction and loss of access. No attacker is required. A public storage bucket, an email sent to the wrong distribution list, or a support export shared in the wrong channel all qualify.

In practice these are the most common real incidents, and they are the ones least likely to be escalated, because nothing felt like an attack.

Unauthorised processing counts

Processing beyond what was authorised is within the definition. An internal team using a customer data set for a purpose it was not consented for is unauthorised processing, even though the data never left the company.

The practical test is not “did someone break in”. It is whether confidentiality, integrity or availability was compromised, by anyone, deliberately or not.

Infosek Team

Why the breadth matters operationally

Rule 7 obligations trigger on becoming aware of a personal data breach. If your team's working definition is narrower than the Act's, awareness is recorded late or never, and the seventy-two hour clock is already running before anyone starts it.

This makes the escalation criteria a compliance control in their own right. An engineer who finds a misconfigured bucket needs to know that is a reportable event, not a tidy-up.

What to put in front of your team

Common questions

What is a personal data breach under the DPDP Act?

The Act defines a personal data breach as any unauthorised processing of personal data, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises the confidentiality, integrity or availability of personal data.

Is losing access to your own data a breach?

Yes. The definition covers loss of access and destruction, and compromise of availability, not only confidentiality. A ransomware event that encrypts your records is a personal data breach even if nothing was exfiltrated.

Unsure what your team should be escalating?

Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.

Book Free 30-Min Assessment