---
title: "Data breaches and security"
url: https://dpdp.myndsolution.com/wiki/faq/breach-and-security/
description: "What a personal data breach is, the 72 hour report to the Board, what affected people must be told, minimum security safeguards, logs and penalties."
kind: faq
updated: 2026-09-09
text_type: analysis
publisher: MYND Integrated Solutions
license: Official Government of India texts are reproduced verbatim (public domain / open government data). Interpretation is CC BY 4.0, MYND Integrated Solutions.
disclaimer: Not legal advice. Official text prevails over any interpretation.
html_version: https://dpdp.myndsolution.com/wiki/faq/breach-and-security/
---
# Data breaches and security

> This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation.

## What counts as a personal data breach?

The definition is wide. A personal data breach means "any unauthorised processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises the confidentiality, integrity or availability of personal data" ([section 2(u)](/wiki/act/section-2/)). Three points follow from the words. It is not limited to hacking or theft: an accident counts. It is not limited to data getting out: losing access to your own data counts, so ransomware or a destroyed backup is a breach. And availability sits alongside confidentiality and integrity, so an outage that makes personal data unavailable can fall inside the definition.

## Within how many hours must a data breach be reported to the Board?

Seventy-two hours for the detailed report, but the first intimation is due immediately. On becoming aware of a breach the Data Fiduciary must intimate the Board "without delay" with a description of the breach, "including its nature, extent, timing and location of occurrence and the likely impact" ([rule 7(2)(a)](/wiki/rules/rule-7/)). It must then follow up "within seventy-two hours of becoming aware of the breach, or within such longer period as the Board may allow on a request made in writing in this behalf" ([rule 7(2)(b)](/wiki/rules/rule-7/)). The clock runs from awareness, not from the breach itself, and an extension has to be asked for in writing.

## Who must be told about a data breach?

Both the Board and every affected person. The Act requires the Data Fiduciary, in the event of a personal data breach, to give the Board and each affected Data Principal intimation of the breach in the prescribed form and manner ([section 8(6)](/wiki/act/section-8/)). The Rules put the individual first: on becoming aware of a breach, the Data Fiduciary shall, "to the best of its knowledge, intimate to each affected Data Principal, in a concise, clear and plain manner and without delay, through her user account or any mode of communication registered by her with the Data Fiduciary" ([rule 7(1)](/wiki/rules/rule-7/)). There is no threshold of severity or number of records below which the duty falls away.

## What must the breach notice to affected individuals say?

Five things, listed in [rule 7(1)](/wiki/rules/rule-7/). A description of the breach, including its nature, extent and the timing of its occurrence. The consequences relevant to that person that are likely to arise from the breach. The measures implemented and being implemented by the Data Fiduciary, if any, to mitigate risk. The safety measures she may take to protect her own interests. And the business contact information of a person who can respond on behalf of the Data Fiduciary to any queries she has. It is written for the individual, not for a regulator, which is why the Rules insist on "concise, clear and plain".

## What goes into the 72 hour report to the Board?

Six items, on top of the first intimation. Under [rule 7(2)(b)](/wiki/rules/rule-7/) the Data Fiduciary must give updated and detailed information in respect of the earlier description; the broad facts related to the events, circumstances and reasons leading to the breach; measures implemented or proposed, if any, to mitigate risk; any findings regarding the person who caused the breach; remedial measures taken to prevent recurrence; and a report regarding the intimations given to affected Data Principals. That last item matters: the Board is told not only what happened but whether the people affected were actually informed.

## What are "reasonable security safeguards"?

The Act imposes the duty ([section 8(5)](/wiki/act/section-8/)) and [rule 6(1)](/wiki/rules/rule-6/) lists the minimum. Appropriate data security measures, "such as securing of personal data through encryption, obfuscation, masking or the use of virtual tokens mapped to that personal data". Appropriate measures to control access to computer resources. Visibility on access to personal data through appropriate logs, monitoring and review. Reasonable measures for continued processing if data is destroyed or access is lost, such as data backups. Retention of logs and personal data for one year. Appropriate provision in the contract with any Data Processor for taking reasonable security safeguards. And appropriate technical and organisational measures to ensure effective observance of those safeguards.

## How long must access logs be kept?

One year, under two separate provisions. For detection of unauthorised access, investigation, remediation and continued processing, a Data Fiduciary must "retain such logs and personal data for a period of one year, unless compliance with any law for the time being in force requires otherwise" ([rule 6(1)(e)](/wiki/rules/rule-6/)). Independently, for the purposes set out in the [Seventh Schedule](/wiki/rules/schedule-7/), a Data Fiduciary must retain personal data, associated traffic data and other logs of the processing "for a minimum period of one year from the date of such processing", after which they must be erased unless another law or a government notification requires longer ([rule 8(3)](/wiki/rules/rule-8/)).

## What is the penalty for a security failure or a late breach report?

They are separate line items. Failure to take reasonable security safeguards to prevent a personal data breach under section 8(5) carries a penalty that "may extend to two hundred and fifty crore rupees", the highest in the Act. Failure to give the Board or an affected Data Principal notice of a breach under section 8(6) "may extend to two hundred crore rupees". Any other breach of the Act or the Rules "may extend to fifty crore rupees" ([the Schedule](/wiki/act/schedule/)). These are ceilings, not fixed amounts: the Board may impose a penalty only if it determines after an inquiry that the breach is "significant" ([section 33(1)](/wiki/act/section-33/)).

## Are the breach reporting duties in force today?

Not yet. [Section 8](/wiki/act/section-8/), which carries both the security duty and the intimation duty, comes into force eighteen months after publication of [G.S.R. 843(E)](/wiki/notifications/gsr-843e-2025/), that is on 13 May 2027. [Rule 6](/wiki/rules/rule-6/) and [rule 7](/wiki/rules/rule-7/) are in the same group under [rule 1(4)](/wiki/rules/rule-1/), which brings rules 3, 5 to 16, 22 and 23 into force eighteen months after the Rules were published. [Section 27](/wiki/act/section-27/), which gives the Board power to act on a breach intimation, and [section 28](/wiki/act/section-28/), which sets out its procedure, commence on the same date, with the single exception of section 27(1)(d).
