On this page
- What counts as a personal data breach
- The clock starts when you become aware
- Telling the people affected: Rule 7(1)
- Telling the Board: two filings under Rule 7(2)
- When a vendor causes the breach
- Logs: the evidence you will need
- What the Board can do
- What to have ready by 13 May 2027
- Common questions
- In the news
- Sources
Section 8(6) of the Digital Personal Data Protection Act, 2023 requires a Data Fiduciary to tell the Data Protection Board of India and each affected Data Principal about a personal data breach. (A Data Fiduciary is the person or business that decides why and how personal data is processed; a Data Principal is the person the data is about.) Rule 7 of the DPDP Rules, 2025 says how. It splits the duty into three communications: one to the people affected and two to the Board, each with its own timing and content.
What counts as a personal data breach
Section 2(u) defines a personal data breach as any unauthorised processing of personal data, or its accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access. To count, it must compromise the data’s confidentiality, integrity or availability.
So:
- It is not only leaks. Losing access to personal data, or having it altered or destroyed, is a breach if it compromises availability or integrity. An incident where nothing leaves the building can still qualify.
- There is no size threshold. Neither Section 8(6) nor Rule 7 sets a minimum number of people or a severity level. Rule 7 applies to “any personal data breach”.
What the video shows
- A BREACH. WHAT NOW?
- 72 / HOURS
- From becoming aware of a breach to send the Board the details
- RULE 7 · FROM 13 MAY 2027
- Without delay, tell both
- Each affected Data Principal
- The Board
- nature, extent, timing, location, likely impact
- Within 72 hours, send the Board:
- 1 OF 6 Updated, detailed description
- 2 OF 6 Facts, events and reasons behind it
- 3 OF 6 Measures to reduce the risk
- 4 OF 6 Findings on who caused it
- 5 OF 6 Steps to prevent a repeat
- 6 OF 6 Report on notices to Data Principals
- A longer period only if the Board allows it, on a written request.
- THE BOARD DECIDES
- Rule 7 applies from 13 May 2027.
The clock starts when you become aware
Every Rule 7 duty runs from the point of “becoming aware” of the breach. Rule 7 does not define that moment, so record it as a fact in your breach log: who learned what, and when. That timestamp drives everything below.
Telling the people affected: Rule 7(1)
On becoming aware of a breach, you must tell each affected Data Principal, to the best of your knowledge, “in a concise, clear and plain manner and without delay”. The notice goes through her user account or any mode of communication she has registered with you. It must cover:

- a description of the breach, including its nature, extent and the timing of its occurrence;
- the consequences relevant to her that are likely to arise from it;
- the measures you have taken and are taking, if any, to mitigate risk;
- the safety measures she can take to protect her interests; and
- business contact information of a person who can answer her questions on your behalf.
The standard for this notice is “without delay”. The 72-hour period in Rule 7(2) applies to the detailed report to the Board, not to this notice.
Telling the Board: two filings under Rule 7(2)
| First intimation: Rule 7(2)(a) | Detailed report: Rule 7(2)(b) | |
|---|---|---|
| When | Without delay | Within 72 hours of becoming aware, or a longer period the Board allows on a written request |
| Contents | A description of the breach: its nature, extent, timing and location of occurrence, and the likely impact | (i) updated and detailed information on that description; (ii) the broad facts about the events, circumstances and reasons leading to the breach; (iii) measures implemented or proposed to mitigate risk; (iv) any findings about the person who caused it; (v) remedial measures to prevent recurrence; (vi) a report on the intimations given to affected Data Principals |
In practice:
- The first intimation is not held for the 72 hours. It goes without delay, with what you know.
- An extension needs a written request. Only the Board can allow more time, and only on a request made in writing. Rule 7(2)(b) does not say when the request must be made; asking before the 72 hours run out is the safer course.
- The detailed report covers your notices to people. Item (vi) asks for a report on the intimations you gave to affected Data Principals, so keep a record of who was told, when and how.
When a vendor causes the breach
Section 8(1) keeps a Data Fiduciary responsible for processing done on its behalf by a Data Processor, whatever the contract says. Section 8(5) extends the duty to take reasonable security safeguards to that processing too. A breach at a vendor that processes data on your behalf, such as your cloud host, is still yours to report.
Your Rule 7 clock starts when you become aware, so your processor contract should require the vendor to tell you promptly. Rule 6(1)(f) requires an appropriate provision for reasonable security safeguards in the contract. The notice period you set for the vendor is a contract choice; the Rules do not fix one.
Logs: the evidence you will need
The Board report asks for causes, findings and remediation. You can only answer with records. Rule 6(1)(c) requires visibility on access to personal data through appropriate logs, monitoring and review, so that unauthorised access can be detected, investigated and remediated. Rule 6(1)(e) requires those logs and personal data to be retained for one year for that purpose, unless another law requires otherwise. Separately, Rule 8(3) requires personal data, associated traffic data and other logs of processing to be kept for a minimum of one year from the date of processing, for the purposes in the Seventh Schedule.
What the Board can do
A breach intimation is itself one of the triggers for the Board’s powers. On receiving it, the Board may direct urgent remedial or mitigation measures, inquire into the breach and impose a penalty as the Act provides (Section 27(1)(a)). A penalty needs an inquiry that finds the breach significant, and the person must first be given an opportunity of being heard. Two penalty ceilings apply most directly:
- failing to take reasonable security safeguards (Section 8(5)): up to ₹250 crore, Schedule item 1;
- failing to notify the Board or affected Data Principals (Section 8(6)): up to ₹200 crore, Schedule item 2.
These are maximums. Section 33(1) allows a penalty only if the Board finds, on conclusion of an inquiry, that the breach was significant. See how a Board inquiry and penalty work.
What to have ready by 13 May 2027
Section 8 and Rules 6, 7 and 8 all start on that date (clause (c) of G.S.R. 843(E); Rule 1(4)). Before then, have three things drafted and owned:
- a breach register that records when you became aware and computes the 72-hour deadline;
- a Board notice template with both parts; and
- a plain-language letter to affected people covering items (a) to (e) of Rule 7(1).
Running a clinic or hospital? The DPDP Act for clinics and hospitals shows how these duties apply to patient data.
Common questions
How soon must a breach be reported to the Data Protection Board?
Without delay, with a description of what happened, how far it went, when and where, and the likely impact. A detailed report follows within 72 hours of becoming aware of the breach.
Can the 72 hours be extended?
Only by the Board. It may allow a longer period on a request made in writing.
Who else must be told about a breach?
Each affected person. They must be told in a concise, clear and plain way, without delay, through their user account or any contact method they registered with you.
What must the notice to affected people say?
What happened, including its nature, extent and timing; the consequences likely to affect them; what you are doing to reduce the risk; what they can do to protect themselves; and a business contact who can answer their questions.
What is the penalty for failing to report a breach?
Up to ₹200 crore. That is a ceiling set by the Schedule. A penalty needs an inquiry that finds a significant breach, and the person must be given an opportunity of being heard.
Next steps
- Check whether the DPDP Act applies to your business, free, in a few clicks
- How-to 11: When something goes wrong, in the toolkit
- The free duties list, every duty in plain words
In the news
- DPDP Rules: Report Breach 'Without Delay', Update Board in 72 Hrs
Explainer on the breach reporting timeline in the Rules.
- Navigating legal liabilities: Understanding DPDP execution
Question-and-answer piece from a law firm on safeguards, logs, breach reporting and retention.
Sources
Every section, rule and date above was checked against the official text on 5 Oct 2026.
Digital Personal Data Protection Act, 2023 (No. 22 of 2023)
Official text: the Digital Personal Data Protection Act, 2023 (MeitY, PDF)
- Section 2(u)Personal data breach
- Section 8(1)Responsible for processing by a Data Processor
- Section 8(5)Security safeguards
- Section 8(6)Intimation to the Board and each affected Data Principal
- Section 27(1)(a)Board directions, inquiry and penalty on a breach intimation
- Section 33(1)Penalty only for a significant breach, on conclusion of an inquiry and after giving the person an opportunity of being heard
- The Schedule, items 1 and 2Up to ₹250 crore (Section 8(5)); up to ₹200 crore (Section 8(6))
DPDP Rules, 2025 (G.S.R. 846(E), 13 November 2025)
- Rule 1(4)Rules 6, 7 and 8 in force eighteen months from publication
- Rule 6(1)Logs and monitoring (c); one-year retention of logs (e); contract provision with processors (f)
- Rule 7(1)Notice to each affected Data Principal, items (a) to (e)
- Rule 7(2)Board: (a) without delay; (b) detailed report within 72 hours of becoming aware of the breach, items (i) to (vi)
- Rule 8(3)Personal data, traffic data and logs kept for a minimum of one year
- Seventh SchedulePurposes for which Rule 8(3) retention applies
Notifications
Official text: commencement notification G.S.R. 843(E) (MeitY, PDF)
- G.S.R. 843(E), clause (c)Section 8 in force eighteen months from 13 November 2025
A drafting aid. Get legal advice for your situation. This article explains the published text of the Act and the Rules.


