Two clocks, not one
A data breach at an Indian business usually triggers at least two obligations to two different bodies, on different timelines, under different laws. Treating them as one report is the most common failure in incident response.
| To whom | Trigger | Timing | Source |
|---|---|---|---|
| CERT-In | Any reportable cyber incident in the Annexure, including data breach and data leak | 6 hours of noticing | CERT-In Directions, 28 April 2022 |
| Data Protection Board and each affected Data Principal | Personal data breach | As prescribed by the Rules under the Act | DPDP Act, 2023, Section 8(6) |
| Sector regulator (RBI, SEBI, IRDAI, TRAI as applicable) | As defined by that regulator's directions | Varies by regulator | Sector-specific directions |
What a personal data breach means
Section 2(u) of the DPDP Act defines a personal data breach as any unauthorised processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises its confidentiality, integrity or availability. Loss of availability — ransomware encrypting your own database — is included, even where no data left the organisation.
Sequence to follow
- Contain and preserve. Do not wipe systems before logs and images are captured; Rule 3(1)(h) of the IT Rules, 2021 and the CERT-In directions both anticipate records being available.
- Start the six-hour CERT-In clock the moment the incident is noticed, and file with what is known. A first report is not a final report.
- Assess scope: which Data Principals, which categories of data, what the likely consequences are.
- Notify the Data Protection Board and the affected Data Principals as required under Section 8(6) and the Rules.
- Notify the sector regulator if one applies, and the insurer if there is cyber cover.
- Record every step with a timestamp. The record is the evidence of reasonable security safeguards under Section 8(5).
Status of the DPDP notification timeline
The Digital Personal Data Protection Act, 2023 received Presidential assent on 11 August 2023. Its provisions are brought into force, and its operational detail supplied, through Rules notified by the Central Government; a draft of those Rules was published for public consultation in January 2025. Confirm the commencement status of the specific section and the current text of the Rules before relying on any date or timeline.
