Data-breach response — what to do, and the clocks that start
Two clocks start the moment you become aware of a personal data breach: an immediate 'without delay' duty to tell every affected user and to give the Board a first description, and a 72-hour deadline for the detailed report to the Board.
In plain English
The clock starts when you become aware of the breach. It does not start when you finish investigating it. From that moment, a Data Fiduciary must tell every affected Data Principal without delay, in plain language. You must cover five specific things:
- What happened.
- What it means for them.
- What you are doing about it.
- What they can do.
- Who to contact.
The Board gets two messages: a first description without delay, then a detailed report within 72 hours. The Board can extend that deadline only if you make a written request and it agrees. There is no size threshold and no "minor breach" exemption — any personal data breach triggers both duties.
Think of it like
Think of a fire in an apartment block. You pull the alarm right away so residents can get out and protect themselves. You do not wait to work out which wire shorted. The fire department gets a quick call first, then a full written report once you know the cause.
Key takeaways
- Awareness starts the clock. Both the user notice and the first Board notice are due "without delay", not after the investigation closes.
- The user notice must cover five things under Rule 7(1)(a)–(e). One of these is a named business contact who can answer questions.
- Notice must reach each affected user through her user account or a way she registered with you. A blog post or press release does not count as notice.
- The Board's detailed report under Rule 7(2)(b) is due within 72 hours. It must cover:
- The causes.
- Mitigation steps.
- Who caused it.
- Remedial steps.
- Proof you told affected users.
- A longer period is possible only if the Board allows it on a written request. Assume 72 hours until it does.
- Section 8(6) is the statutory hook. Rule 7 is the prescribed form and manner. Section 8(7)–(8) keeps the erasure duty running alongside.
What this means for you
Write the breach runbook and the five-point user notice template now. Name the contact person too — you cannot draft this in the middle of an incident.
If you process client data, your contract should require you to escalate a suspected breach to the client within hours. Their 72-hour clock runs from awareness.
If your list, membership, or community platform leaks subscriber data, you owe each subscriber a direct plain-language notice. A public post is not enough.
Status
Primary sources
Official text
Official text — Rule 7, DPDP Rules, 2025
Official text — Section 8(6)–(8), DPDP Act, 2023
DPDP readiness checklist
Check whether your breach runbook, contact point, and erasure workflow are actually in place.
Run it nowCitation
Kokate, S. (2026). Data-breach response — what to do, and the clocks that start. India AI Rulebook. Retrieved from https://indiaairulebook.com/learn/data-privacy/breach-response. Educational content, not legal advice.
The Rules are dated 13 November 2025 and were published in the Gazette on 14 November 2025. Some sources therefore give 14 May 2027. We use 13 May 2027; see Methodology.