DPDP Rules status: compliance window active. Read the update

Skip to content
Data Privacy · DPDP Rules 2025

Data-breach response — what to do, and the clocks that start

Two clocks start the moment you become aware of a personal data breach: an immediate 'without delay' duty to tell every affected user and to give the Board a first description, and a 72-hour deadline for the detailed report to the Board.

Educational only · not legal adviceReviewed by Sandesh Kokate, Editor

In plain English

The clock starts when you become aware of the breach. It does not start when you finish investigating it. From that moment, a Data Fiduciary must tell every affected Data Principal without delay, in plain language. You must cover five specific things:

  • What happened.
  • What it means for them.
  • What you are doing about it.
  • What they can do.
  • Who to contact.

The Board gets two messages: a first description without delay, then a detailed report within 72 hours. The Board can extend that deadline only if you make a written request and it agrees. There is no size threshold and no "minor breach" exemption — any personal data breach triggers both duties.

Think of it like

Think of a fire in an apartment block. You pull the alarm right away so residents can get out and protect themselves. You do not wait to work out which wire shorted. The fire department gets a quick call first, then a full written report once you know the cause.

Key takeaways

  • Awareness starts the clock. Both the user notice and the first Board notice are due "without delay", not after the investigation closes.
  • The user notice must cover five things under Rule 7(1)(a)–(e). One of these is a named business contact who can answer questions.
  • Notice must reach each affected user through her user account or a way she registered with you. A blog post or press release does not count as notice.
  • The Board's detailed report under Rule 7(2)(b) is due within 72 hours. It must cover:
    • The causes.
    • Mitigation steps.
    • Who caused it.
    • Remedial steps.
    • Proof you told affected users.
  • A longer period is possible only if the Board allows it on a written request. Assume 72 hours until it does.
  • Section 8(6) is the statutory hook. Rule 7 is the prescribed form and manner. Section 8(7)–(8) keeps the erasure duty running alongside.

What this means for you

Founders

Write the breach runbook and the five-point user notice template now. Name the contact person too — you cannot draft this in the middle of an incident.

Freelancers

If you process client data, your contract should require you to escalate a suspected breach to the client within hours. Their 72-hour clock runs from awareness.

Creators

If your list, membership, or community platform leaks subscriber data, you owe each subscriber a direct plain-language notice. A public post is not enough.

Status

EnforceableCore obligations enforceable 13 May 2027. On the statute book since 13 November 2025. The Data Protection Board is not yet hearing complaints, so there is currently no body receiving Rule 7(2) intimations in practice.

Primary sources

Source
MeitY — DPDP Rules, 2025 (Gazette PDF)

Status unverified — no status check recorded

Source
MeitY — DPDP Act (Gazette PDF)

Status unverified — no status check recorded

Official text

Official text — Rule 7, DPDP Rules, 2025
RULE 7 — Intimation of personal data breach (DPDP Rules, 2025) 7. (1) On becoming aware of any personal data breach, the Data Fiduciary shall, to the best of its knowledge, intimate to each affected Data Principal, in a concise, clear and plain manner and without delay, through her user account or any mode of communication registered by her with the Data Fiduciary, — (a) a description of the breach, including its nature, extent and the timing of its occurrence; (b) the consequences relevant to her, that are likely to arise from the breach; (c) the measures implemented and being implemented by the Data Fiduciary, if any, to mitigate risk; (d) the safety measures that she may take to protect her interests; and (e) business contact information of a person who is able to respond on behalf of the Data Fiduciary, to queries, if any, of the Data Principal. (2) On becoming aware of any personal data breach, the Data Fiduciary shall intimate to the Board, — (a) without delay, a description of the breach, including its nature, extent, timing and location of occurrence and the likely impact; (b) within seventy-two hours of becoming aware of the breach, or within such longer period as the Board may allow on a request made in writing in this behalf, — (i) updated and detailed information in respect of such description; (ii) the broad facts related to the events, circumstances and reasons leading to the breach; (iii) measures implemented or proposed, if any, to mitigate risk; (iv) any findings regarding the person who caused the breach; (v) remedial measures taken to prevent recurrence of such breach; and (vi) a report regarding the intimations given to affected Data Principals.
Official text — Section 8(6)–(8), DPDP Act, 2023
SECTION 8(6)–(8) — General obligations of Data Fiduciary, breach + erasure sub-sections (DPDP Act, 2023) (6) In the event of a personal data breach, the Data Fiduciary shall give the Board and each affected Data Principal, intimation of such breach in such form and manner as may be prescribed. (7) A Data Fiduciary shall, unless retention is necessary for compliance with any law for the time being in force,— (a) erase personal data, upon the Data Principal withdrawing her consent or as soon as it is reasonable to assume that the specified purpose is no longer being served, whichever is earlier; and (b) cause its Data Processor to erase any personal data that was made available by the Data Fiduciary for processing to such Data Processor. (8) The purpose referred to in clause (a) of sub-section (7) shall be deemed to no longer be served, if the Data Principal does not approach the Data Fiduciary for the performance of the specified purpose and does not exercise any of her rights in relation to such processing, for such time period as may be prescribed.
Quick self-check

DPDP readiness checklist

Check whether your breach runbook, contact point, and erasure workflow are actually in place.

Run it now

Citation

Kokate, S. (2026). Data-breach response — what to do, and the clocks that start. India AI Rulebook. Retrieved from https://indiaairulebook.com/learn/data-privacy/breach-response. Educational content, not legal advice.

The Rules are dated 13 November 2025 and were published in the Gazette on 14 November 2025. Some sources therefore give 14 May 2027. We use 13 May 2027; see Methodology.