LEGALWEBSITE.inEvery page. Every law. No surprises. All articles
Security 5 min readReviewed 5 September 2026

A personal data breach in India: who you must tell, and how fast

Two separate reporting duties run in parallel — CERT-In within six hours and the Data Protection Board under the DPDP Act — plus sector rules for regulated entities.

Two clocks, not one

A data breach at an Indian business usually triggers at least two obligations to two different bodies, on different timelines, under different laws. Treating them as one report is the most common failure in incident response.

To whomTriggerTimingSource
CERT-InAny reportable cyber incident in the Annexure, including data breach and data leak6 hours of noticingCERT-In Directions, 28 April 2022
Data Protection Board and each affected Data PrincipalPersonal data breachAs prescribed by the Rules under the ActDPDP Act, 2023, Section 8(6)
Sector regulator (RBI, SEBI, IRDAI, TRAI as applicable)As defined by that regulator's directionsVaries by regulatorSector-specific directions

What a personal data breach means

Section 2(u) of the DPDP Act defines a personal data breach as any unauthorised processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises its confidentiality, integrity or availability. Loss of availability — ransomware encrypting your own database — is included, even where no data left the organisation.

Sequence to follow

  • Contain and preserve. Do not wipe systems before logs and images are captured; Rule 3(1)(h) of the IT Rules, 2021 and the CERT-In directions both anticipate records being available.
  • Start the six-hour CERT-In clock the moment the incident is noticed, and file with what is known. A first report is not a final report.
  • Assess scope: which Data Principals, which categories of data, what the likely consequences are.
  • Notify the Data Protection Board and the affected Data Principals as required under Section 8(6) and the Rules.
  • Notify the sector regulator if one applies, and the insurer if there is cyber cover.
  • Record every step with a timestamp. The record is the evidence of reasonable security safeguards under Section 8(5).

Status of the DPDP notification timeline

The Digital Personal Data Protection Act, 2023 received Presidential assent on 11 August 2023. Its provisions are brought into force, and its operational detail supplied, through Rules notified by the Central Government; a draft of those Rules was published for public consultation in January 2025. Confirm the commencement status of the specific section and the current text of the Rules before relying on any date or timeline.

Sources

  • The Digital Personal Data Protection Act, 2023 — Sections 2(u), 8(5) and 8(6)
  • CERT-In Directions No. 20(3)/2022-CERT-In dated 28 April 2022
  • The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 — Rule 3(1)(h)

This note is general information about published law, not legal advice on your facts. For advice, speak to our team.

Check your own site against this

The audit reads your live pages and grades them provision by provision.

Run a free audit

Read next