DPDPA Breach Notification: Navigating India's Multi-Layered Compliance
As of August 21, 2026, India’s Digital Personal Data Protection Act, 2023 (DPDPA) is fully operational, bringing with it a robust framework for data protection and accountability. Among its most critical provisions is the requirement for Data Fiduciaries (DFs) to notify personal data breaches. This obligation is a cornerstone of transparency and trust, demanding meticulous attention to timelines, content, and the practicalities of reporting to the newly established Data Protection Board of India (DPBI), alongside existing sectoral regulators.
The Core Obligation and Evolving Timelines
The DPDPA places a clear mandate on Data Fiduciaries. Section 17(1) stipulates that in the event of a personal data breach, the DF must notify both the DPBI and each affected Data Principal (DP) “in such form and manner as may be prescribed.” A crucial distinction here is the condition for notifying Data Principals: it is required only “if such breach is likely to cause harm to the Data Principal.” This “likelihood of harm” threshold for individual notification offers a degree of flexibility compared to, for instance, the GDPR’s broader requirement to notify individuals unless the breach is “unlikely to result in a risk to the rights and freedoms” of natural persons.
While the DPDPA itself uses the phrase “as may be prescribed,” the Digital Personal Data Protection Rules, 202X (which we assume are now in force) have clarified the timelines. For instance, DFs are now expected to notify the DPBI “without undue delay, and in any event, within 72 hours of becoming aware of the breach.” This initial notification period allows for a preliminary assessment while ensuring prompt regulatory awareness. For Data Principals, if the “likelihood of harm” threshold is met, notification should also occur “without undue delay” after the DF has completed its assessment and identified the specific individuals affected. Section 17(2) further provides a potential exemption from notifying Data Principals if the DF has taken measures to render the personal data unintelligible or to mitigate the harm.
It’s important to note the existing landscape. CERT-In, under the IT (The Indian Computer Emergency Response Team and Manner of Performing Functions and Duties) Rules, 2013, continues to mandate reporting of certain cyber incidents within six hours. Given that many personal data breaches originate from cyber incidents, DFs must reconcile these overlapping, and sometimes stricter, pre-existing obligations with the DPDPA’s requirements.
Content of Notification: Clarity and Completeness
The “form and manner as may be prescribed” for breach notifications, outlined in the DPDPA Rules, aims to ensure consistency and provide the DPBI and Data Principals with actionable information. While the exact details are specified in the Rules, typical requirements for notification to the DPBI include:
- The nature of the personal data breach, including categories and approximate number of Data Principals concerned and categories and approximate number of personal data records concerned.
- The name and contact details of the Data Protection Officer (DPO) or other contact point where more information can be obtained.
- A description of the likely consequences of the personal data breach.
- A description of the measures taken or proposed to be taken by the Data Fiduciary to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
When notifying Data Principals, the information must be presented in clear, plain language, avoiding technical jargon. It should empower individuals to take protective measures. This typically includes the nature of the breach, the potential impact on them, and any specific steps they should take (e.g., changing passwords, monitoring accounts), along with contact information for further queries. Section 17(3) grants the power to prescribe these specifics.
Sectoral Overlays and DPBI Reporting Practicalities
The DPDPA operates as a general law, but India’s regulated sectors have long had their own stringent cybersecurity and data incident reporting norms. This creates a multi-layered compliance challenge for DFs operating in these areas.
- RBI-regulated entities: Banks and financial institutions must comply with RBI’s Master Directions on IT Governance, Risk, Controls, and Assurance Practices, which often mandate reporting of cyber incidents to the RBI and CERT-In within specific, often short, timelines (e.g., 6 hours to CERT-In, 72 hours to RBI for significant incidents).
- SEBI-regulated intermediaries: Market intermediaries have similar obligations under SEBI circulars on cyber security and cyber resilience, requiring prompt reporting of incidents to SEBI.
- IRDAI-regulated insurers: Insurers are also bound by IRDAI guidelines on information and cybersecurity, including breach notification.
For a Data Fiduciary in a regulated sector, a single personal data breach could trigger reporting obligations to CERT-In (under IT Rules), their respective sectoral regulator (RBI, SEBI, IRDAI), and now, the DPBI (under DPDPA Section 17(1)). The most stringent timeline will generally dictate the pace of initial action. The DPBI is expected to establish a dedicated online portal for breach notifications, streamlining the process, but DFs must be prepared to submit similar, yet tailored, information to multiple authorities. Harmonization efforts between the DPBI and sectoral regulators are ongoing, but DFs cannot afford to wait for perfect alignment.
Practical Takeaway
For Indian businesses, General Counsels, and DPOs, proactive preparation is paramount. Develop and regularly test a comprehensive incident response plan that integrates DPDPA requirements with existing sectoral and CERT-In reporting obligations. This plan should clearly define roles, responsibilities, communication protocols, and decision-making frameworks for assessing the “likelihood of harm” to Data Principals. Invest in robust security measures, conduct regular data protection impact assessments, and ensure continuous employee training on data handling and breach identification. Maintaining detailed records of all breaches, their assessment, and remediation efforts will be crucial for demonstrating compliance and accountability to the DPBI. Engaging legal counsel and the DPO from the outset of any suspected breach is not merely good practice but a critical safeguard in navigating India’s evolving and increasingly complex data protection landscape.