DPDP Act Breach Notification: What Applies Now and What Starts in 2027
The DPDP Act's breach duty commences in May 2027. CERT-In's six-hour report is live today. This guide separates the two and says what to build now.
17 min readBy Sachin Shirish, Director
Reviewed by Pragya Dwivedi, Associate Director, CISM, eWPTX
There are two breach-reporting clocks in Indian law, and today only one of them is running. That single fact decides what you owe after an incident this week, what you will owe after one in 2027, and what is worth building in between. Get it wrong in either direction and you either miss a live statutory duty or spend a quarter preparing for one that has not started. This guide separates the two, names the dates, and says what to put in place now.
CERT-In's six-hour incident report is a live legal duty: the Directions were issued 28 April 2022 and effective 60 days later, in June 2022. The DPDP Act's duty to intimate the Data Protection Board and every affected Data Principal is not in force: section 8(6) of the Act and Rule 7 of the Digital Personal Data Protection Rules, 2025 sit in the eighteen-month tranche of the phased commencement and take effect in May 2027.
Most breach-response plans we read get that backwards — a detailed Rule 7 workflow no law yet requires, and a thin paragraph on the duty enforceable for four years. This guide takes the opposite order.
What a breach obliges you to do today
The live obligation is CERT-In's. Direction (ii) of the CERT-In Directions of 28 April 2022, issued under section 70B(6) of the Information Technology Act, 2000, requires service providers, intermediaries, data centres, body corporate and Government organisations to report cyber incidents of the types listed in its Annexure I within six hours of noticing them or being brought to notice about such incidents.
Three features shape any runbook written for 2026. The trigger is the incident type, not the data: Annexure I lists categories — targeted scanning, unauthorised access to IT systems or data, identity theft, ransomware, attacks on servers and network appliances, data breach and data leak among them — so an incident touching no personal data can be reportable. The clock starts at noticing, and six hours is barely a triage window. And there is no individual-notification duty anywhere in the Directions — precisely the gap the DPDP Act closes in 2027.
If you are breached this afternoon, the enforceable reporting question is a CERT-In question; our guide to CERT-In Directions compliance covers that side in detail.
What commences in May 2027
The definition that will trigger it
Section 2 of the Digital Personal Data Protection Act, 2023 defines a personal data breach as "any unauthorised processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises the confidentiality, integrity or availability of personal data". Those definitions are in force already; the duties they feed are not.
Three features determine how wide the 2027 duty will be. Loss of access counts: ransomware that encrypts a customer database and exfiltrates nothing is a personal data breach, because availability was compromised. Accidental counts: no attacker is required, just a support agent attaching the wrong export to an email. And there is no severity qualifier — section 8(6) requires intimation in the event of a personal data breach, and Rule 7 prescribes the form and manner. Neither carves out small or low-harm events.
Notice to each affected Data Principal, from May 2027
On becoming aware of a breach, Rule 7(1) of the DPDP Rules, 2025 will require the Data Fiduciary to intimate each affected Data Principal "in a concise, clear and plain manner and without delay", through her user account or any mode of communication she registered. The notice must carry five things:
- a description of the breach, including its nature, extent and the timing of its occurrence;
- the consequences relevant to her that are likely to arise from the breach;
- the measures implemented and being implemented by the Data Fiduciary, if any, to mitigate risk;
- the safety measures she may take to protect her interests; and
- business contact information of a person able to respond on behalf of the Data Fiduciary to her queries.
Item 2 is the demanding one: not a generic bulletin, but the consequences relevant to her — which you cannot write without knowing which data about which person sat in the affected system. Item 5 is the quiet one: a staffed contact who can answer.
Notice to the Data Protection Board, from May 2027
Rule 7(2) of the same Rules sets a two-stage sequence to the Board.
Stage one, without delay. A description of the breach — nature, extent, timing and location of occurrence, and likely impact. Due on awareness, not after investigation.
Stage two, within seventy-two hours of becoming aware, or within such longer period as the Board may allow on a written request, six items:
- updated and detailed information in respect of that description;
- the broad facts related to the events, circumstances and reasons leading to the breach;
- measures implemented or proposed, if any, to mitigate risk;
- any findings regarding the person who caused the breach;
- remedial measures taken to prevent recurrence; and
- a report regarding the intimations given to affected Data Principals.
The last item catches teams: the 72-hour report must account for the notices sent to individuals, so the two tracks run in parallel, not in a queue. Start principal notifications late and the report is incomplete.
Two regulators, two clocks — but not yet at the same time
Once the DPDP duties commence, one intrusion can generate a six-hour report to CERT-In and a seventy-two hour report to the Board on different triggers, and compliance in one is no defence to the other. Today the right-hand column is a design target.
| CERT-In Directions, 28 April 2022 — in force now | DPDP Act 2023 and DPDP Rules 2025 — from 13 May 2027 | |
|---|---|---|
| Legal basis | Section 70B(6), IT Act, 2000 | Section 8(6) of the Act; Rule 7 of the Rules |
| Status today | Live | Not in force |
| Who must report | Service providers, intermediaries, data centres, body corporate and Government organisations | Data Fiduciaries |
| Extension | None provided | Board may allow longer, on written request |
| What triggers it | A cyber incident of a type listed in Annexure I, noticed or brought to notice | A personal data breach as defined in the Act, on becoming aware |
| Is personal data required? | No — the trigger is the incident type, not the data | Yes — the definition turns on personal data |
| Who you tell | CERT-In | The Data Protection Board of India, and every affected Data Principal |
| Clock | 6 hours of noticing | Without delay to both; detailed report to the Board within 72 hours |
| Individual notice? | Not required by the Directions | Required, to each affected Data Principal, with five prescribed contents |
The fan-out that matters from 2027 is one detection event, two independent assessments: is this an Annexure I incident type, and was personal data compromised, whose? A defaced microsite holding no personal data is reportable to CERT-In and is not a personal data breach. A payroll file emailed to the wrong recipient will be a personal data breach from 2027, and may be no Annexure I incident at all. Where the answer is close, it is a lawyer's call.
The commencement picture, stated accurately
The Act and the Rules were not switched on; they were phased, in three tranches, from a November 2025 notification. Both notifications carry 13 November 2025 on their face — G.S.R. 843(E) and G.S.R. 846(E) are each headed "New Delhi, the 13th November, 2025" — while the Government's backgrounder says 14 November (PIB backgrounder). Month, year and tranche lengths are settled; only the day differs, and a date derived from it moves by one day with it.
The phasing itself is not in dispute. The section-level detail below comes from the commencement notifications published in the Gazette of India: G.S.R. 843(E) for the Act and G.S.R. 846(E) for the Rules.
Notification G.S.R. 843(E) brought into force on publication section 1(2), section 2, sections 18 to 26, section 35, sections 38 to 43 and parts of section 44 of the Act — broader than the Board provisions alone: it includes the definitions and the rule-making power. One year brings in section 6(9) and section 27(1)(d). Eighteen months brings in the substantive core: sections 3 to 5, section 6 apart from sub-section (9), sections 7 to 17, section 27 apart from clause (1)(d), sections 28 to 34, sections 36 and 37, and section 44(2) — including section 8, carrying the security-safeguards and breach-intimation duties, and section 33, carrying the penalties.
Rule 1(2) to (4) of the Rules, notified as G.S.R. 846(E), follows the same shape: rule 1(2) commences rules 1, 2 and 17 to 21 on publication, rule 1(3) brings in rule 4 — Consent Manager registration — after one year, and rule 1(4) brings in rules 3, 5 to 16, 22 and 23 at eighteen months. Rule 7 is in that last group.
The eighteen-month date is computed from that November notification, so the divergence carries straight through: the substantive duties commence in May 2027, read as the 13th or the 14th depending on which day the notification is taken to bear. SecureRoot's compliance pages state 13 May 2027, the earlier reading; if a contractual deadline turns on the day, take it.
The penalty exposure, and why it is not the notice
Penalties sit in the Schedule to the DPDP Act, 2023, read with section 33, which G.S.R. 843(E) commences in the eighteen-month tranche. The notification appoints dates for sections rather than for the Schedule, so treat the Schedule as biting when section 33 does. Three entries matter, and the largest is not the notification failure:
- Breach of the obligation under section 8(5) to take reasonable security safeguards to prevent a personal data breach — may extend to ₹250 crore.
- Breach of the obligation under section 8(6) to give the Board or affected Data Principal notice of a personal data breach — may extend to ₹200 crore.
- Breach of the additional obligations of a Significant Data Fiduciary under section 10 — may extend to ₹150 crore.
These are ceilings, not tariffs; the Board determines the amount. The ordering carries a planning message: the heavier exposure attaches to the controls, not the paperwork, so the months before commencement are better spent on the section 8(5) safeguards — work that also reduces the number of notices you ever send.
If the Central Government notifies you as a Significant Data Fiduciary under section 10, more arrives in the same tranche: a Data Protection Officer based in India, an independent data auditor, and under Rule 13(1) of the DPDP Rules, 2025 a Data Protection Impact Assessment and an audit once in every period of twelve months, with the assessor required by Rule 13(2) to furnish the Board a report of significant observations. That changes who signs rather than what the clocks are. Our guide to Data Protection Officer services in India sets out whether you need that role.
What to build in the meantime
Four artefacts decide whether the 2027 duty is a configuration change or a crisis, and each earns its keep before commencement.
1. A data map that tells you who was affected. Rule 7(1) will demand a notice describing consequences relevant to a specific individual, so you need to know, per system, which categories of personal data sit there and whose. It is the long-lead item — months to build, quick to go stale — and it pays off now, because it also tells you which systems deserve testing first.
2. A named decision owner. One person decides whether an event is a personal data breach and starts the clock, with a named deputy. The failure mode is never a wrong decision; it is that nobody decides while awareness ages. Give them the CERT-In call today, so the DPDP call in 2027 lands on someone practised.
3. Notification templates, pre-drafted and counsel-reviewed. The principal notice with all five Rule 7(1) elements, the stage-one Board alert, and the stage-two report with its six headings. Drafting a regulator-facing document mid-containment produces the errors you would expect.
4. A tested playbook. One timed alert producing a CERT-In assessment, a DPDP assessment and both sets of drafts — run against the live CERT-In duty now, with the DPDP branch as rehearsal. Our DPDP Act compliance checklist covers the surrounding programme; a DPDP compliance audit is where it is tested against evidence rather than intention.
Where SecureRoot fits, and where it does not
On incident-reporting topics vagueness is worse than useless, so: SecureRoot is not CERT-In empanelled, and we do not file reports on a client's behalf — not to CERT-In, not to the Data Protection Board. Those filings are yours, as are the judgement calls behind them.
What we do is the section 8(5) side: manual, exploit-driven penetration testing that finds the exposures a breach notice would otherwise be written about, with a proof of concept for each finding, critical findings reported within three hours of discovery, and a retest to show the fix held. We hold ISO/IEC 27001:2022 (certificate IN60432E) and ISO 9001:2015, with a registered office in Kanpur and a branch in Greater Noida West. Our DPDP Act compliance services page sets out the wider engagement model.
Nothing here is legal advice. Whether an event meets the statutory definition, or how the commencement dates apply to you, is a question for a lawyer.
Frequently asked questions
Do we have to notify the Data Protection Board if we are breached today?
No. Section 8(6) of the DPDP Act and Rule 7 of the DPDP Rules, 2025 sit in the eighteen-month tranche and take effect in May 2027. Until then there is no statutory duty to intimate the Board or affected Data Principals, and the penalty provisions are not in force either. What is live today is CERT-In's duty: six hours from noticing an Annexure I incident, under the Directions of 28 April 2022 and section 70B(6) of the IT Act, 2000. Sector regulators add their own — RBI, SEBI and IRDAI each run incident-reporting regimes for the entities they supervise — and customer contracts routinely set a shorter clock than any of them. You almost certainly owe someone a report today. It is simply not the Data Protection Board, and a runbook that only names the Board will fail you this afternoon.
When does the 72-hour clock start once the duty is live?
It starts when the Data Fiduciary becomes aware of the personal data breach — the same trigger as the notice to Data Principals and the stage-one alert to the Board. Rule 7(2)(b) measures seventy-two hours from that awareness, not from the intrusion, the end of containment or the completion of forensics. That matters because awareness usually arrives as an ambiguous signal — an alert, a customer complaint, a researcher's email — and organisations lose a day deciding whether it is real. Record in writing the moment your named decision owner concluded a personal data breach had occurred, and what they knew then. The Board may allow longer, but only on a written request, so design to seventy-two hours and treat any extension as a windfall. The practical consequence is that triage, not legal review, sets the clock: whoever reads the alerts needs a route to the decision owner that does not wait for Monday.
Will every personal data breach have to be reported, however small?
As the rules are written, yes. Rule 7 is triggered by becoming aware of a personal data breach, and neither it nor section 8(6) contains a severity threshold, materiality test or risk qualifier. There is no Indian equivalent of the European carve-out for breaches unlikely to risk individuals. A single misdirected email containing one customer's personal data falls within the definition and, on the face of the text, attracts both the notice to that individual and the intimation to the Board. The Board may issue proportionality guidance once it begins operating, but that guidance does not exist yet. Plan for the text as notified, treat any narrowing as a bonus, and remember that whether a specific event meets the definition is a question for your counsel rather than your security team. The practical answer is to write the threshold question down before you need it, so a Tuesday-afternoon misdirected email is judged against a rule you agreed in advance rather than against the mood of the room.
Can one report satisfy both CERT-In and the Board?
No, and it will not once both duties are live. They are separate obligations to separate bodies under separate statutes, on different clocks and in different formats: CERT-In under section 70B(6) of the IT Act, 2000 and the Directions of 28 April 2022, with six hours from noticing a listed incident; the DPDP intimations under section 8(6) and Rule 7, running to the Board and to every affected Data Principal. The triggers do not overlap cleanly: an incident can be reportable to CERT-In without involving personal data, and a personal data breach can occur without meeting any Annexure I type. Build one detection process that fans out into two assessments and two sets of documents; what can be shared is the underlying material — evidence, incident timeline and forensic findings. Assume the two tracks will disagree about urgency, because six hours and seventy-two hours pull in different directions, and decide now which one your first hour serves.
We are a processor, not the fiduciary. Does any of this reach us?
The Rule 7 duties will fall on the Data Fiduciary — the person who determines the purpose and means of processing. A Data Processor acting on a fiduciary's instructions will not itself intimate the Board or affected individuals. That is not the same as having no exposure. Section 8(5) makes the fiduciary responsible for personal data even where a processor handles it on its behalf, so fiduciaries will push notification timelines into your contract — they must, since they cannot meet a seventy-two hour deadline if they learn of your incident on day five. Those clauses are appearing in Indian contracts now, well ahead of commencement, and are negotiated in hours rather than days. If you process for Indian fiduciaries, your incident-response service level is already a commercial term — worth pricing before a customer sets the number for you.
Next step
If your last penetration test predates the systems that now hold your personal data, the notification template is not your weakest link. Request an assessment: a 30 to 45 minute scoping call, then a written scope with timeline and fixed price before any testing begins.
Related reading: the DPDP Act compliance checklist, CERT-In Directions compliance, the DPDP compliance audit, Data Protection Officer services, and our DPDP Act compliance services.
Have a Question About This?
If this raised something specific to your environment, a scoping call is the fastest way to get a direct answer.
We reply within one business day.


