DPDP Rules status: compliance window active. Read the update

Skip to content
Data Privacy · For Government

Data breach response for government departments

A citizen-data breach in a government system starts not one clock but several — and the fastest is measured in hours. Here's what a department actually has to do, in what order, and who to tell.

Educational only · not legal adviceLast reviewed: 17 August 2026Reviewed by Sandesh Kokate, Editor

Does this apply to your department?

When a department collects or processes citizens' personal data, it acts as a Data Fiduciary under the DPDP Act, with duties to keep that data secure and to report breaches. The Act allows the government to exempt certain State bodies from some provisions by notification — but those exemptions are narrow and conditional, and they don't remove the practical need to be breach-ready. Assume these duties apply unless a specific notification says otherwise.

The clocks you're actually racing

One incident can trigger several parallel deadlines:

6 hours

CERT-In

Cyber-security incidents must be reported to CERT-In within 6 hours under its 2022 Directions (IT Act, Section 70B). This applies now, today.

Rule 7

DPDP Board + affected citizens

On becoming aware of a personal data breach, notify the Data Protection Board and every affected individual without delay, with a fuller report to the Board due within 72 hours. The clock starts at AWARENESS, not when the breach happened. There is no materiality threshold — every breach is reportable, regardless of size.

Varies

Sector overlays

If your department works with banking, insurance, or securities data, RBI / IRDAI / SEBI breach rules may add their own timelines on top.

Three other CERT-In duties people miss

The six-hour reporting rule is the famous one. The 2022 Directions actually impose four duties, and the other three catch organisations out.

Set your clocks by the government's. Every computer system you run must sync its clock to the Network Time Protocol servers of the National Informatics Centre or the National Physical Laboratory, or to a server that traces back to them.

Keep your logs for 180 days, in India. All ICT system logs, on a rolling 180-day basis, stored inside the country. This is a localisation rule, and it sits outside the DPDP Act entirely.

Answer CERT-In within six hours too. If CERT-In asks you for information, you have six hours to respond. This is a second clock, separate from the incident one. A team built only for incident reporting will miss it.

One thing about the first clock: it starts when someone notices the incident, or when it is brought to their attention. Not when you work out what caused it.

What the notice to citizens must contain

Plain-language notices, not legal boilerplate: what happened, what data was involved, the likely consequences, what the department is doing about it, what the individual can do to protect themselves, and a contact point for questions.

The catch — which clock is actually live today

Watch

Rule 7's breach-notification duty becomes fully enforceable at the 18-month mark, on 13 May 2027. And the Data Protection Board you would report to under Rule 7 is not yet operational as a reporting channel. The practical position for a department right now: your live, enforceable obligation is the 6-hour CERT-In report. Build, document, and rehearse your DPB-and-citizen notification process now, so it's ready the day the Board stands up and full enforcement lands.

The Board was legally established on 13 November 2025, and will consist of a Chairperson and four Members (G.S.R. 845(E), 13 November 2025). MeitY began the appointment process on 6 May 2026, writing to all Union Ministries and Departments and all State and UT Chief Secretaries seeking nominations, and advertised one Chairperson post and four Member posts. A further notification followed on 6 June 2026. As at 4 Sep 2026, no appointment has been notified. Until the Board is staffed there is no active regulator to adjudicate complaints, register Consent Managers, or issue the standards the Rules assume it will issue.

The Rules are dated 13 November 2025 and were published in the Gazette on 14 November 2025. Some sources therefore give 14 May 2027. We use 13 May 2027; see Methodology.

Track the Board's status in what's still pending →

First-hours checklist for a department

  1. Log the time you became aware — this starts the DPDP clock.
  2. Contain the incident and preserve evidence.
  3. Convene your incident-response team and loop in your CISO / IT security and legal cell.
  4. Report to CERT-In within 6 hours.
  5. Scope it: what data, whose, how many, still ongoing or contained.
  6. Prepare the Board intimation and the 72-hour detailed report (for when the DPB channel is live; document it regardless).
  7. Notify affected citizens in plain language, with protective steps and a contact point.
  8. Document every step and timestamp; run a post-incident review.

Penalties

The statutory maximums are steep — up to ₹200 crore for failing to notify a breach, and up to ₹250 crore for failing to maintain reasonable security safeguards. Beyond penalties, the accountability and public-trust stakes for a government system are their own reason to get this right.

Sources

Source
MeitY — DPDP Act (Gazette PDF)

DPDP Act, 2023 — Sections 8(5) & 8(6)

Status unverified — no status check recorded

Source
MeitY — DPDP Rules, 2025 (Gazette PDF)

DPDP Rules, 2025 — Rule 7 (breach notification)

Status unverified — no status check recorded

Source
MeitY — Appointment to the post of Chairperson and Other Members, DPBI (6 May 2026)

Board appointment process — nominations invited, 6 May 2026

Status unverified — no status check recorded

Source
CERT-In — Directions under Section 70B(6), 28 April 2022

6-hour cyber-incident reporting; 180-day log retention; time-sync and information-request duties.

Last updated: 4 Sep 2026 · Reviewed by Sandesh Kokate, Editor

Educational only, not legal advice. Departments should also follow their own ministry and CERT-In protocols and take advice on their specific situation. Re-verify against the Gazette of India before relying on anything here.