DPDP Breach Notification Checklist
Section 8(6) of the DPDP Act and Rule 7 of the DPDP Rules 2025 require a data fiduciary, on becoming aware of a personal data breach, to notify the Data Protection Board of India and every affected data principal without delay, with a comprehensive report to the Board within 72 hours. The clock starts at awareness, not at occurrence. CERT-In Directions 2022 require reporting of cyber security incidents within 6 hours of detection through a separate channel — this clock runs in parallel, not as an alternative. Sectoral regulators — RBI, SEBI, IRDAI — impose their own incident-reporting timelines that also run in parallel for regulated entities. For a regulated Indian financial entity that suffers a single breach involving personal data, four to six regulatory notifications may be due within the first 72 hours, each in its own prescribed format, each requiring specific content, each with its own clock. The checklist below covers the DPB and data-principal track end to end, and signposts the parallel obligations that the CISO function owns separately.