DPDP Wiki Talk to us

/The Rules · 2025

Rule 7: Intimation of personal data breach

DPDP Rules, 2025, G.S.R. 846(E) dated 13 November 2025. Comes into force on 13 May 2027.

UpcomingOfficial textComes into force on 13 May 2027 (phase 3) · rule 1(4)
Provision
Rule 7 of The Digital Personal Data Protection Rules, 2025
Status
Comes into force on 13 May 2027 (phase 3)
Made under
s. 8 General obligations of Data Fiduciary
Source
Ministry of Electronics and Information Technology · G.S.R. 846(E) · 13 November 2025 · Official PDF

Rule 7. Intimation of personal data breach

Verbatim from the Gazette of India
(1)

On becoming aware of any personal data breach, the Data Fiduciary shall, to the best of its knowledge, intimate to each affected Data Principal, in a concise, clear and plain manner and without delay, through her user account or any mode of communication registered by her with the Data Fiduciary, —

(a)

a description of the breach, including its nature, extent and the timing of its occurrence;

(b)

the consequences relevant to her, that are likely to arise from the breach;

(c)

the measures implemented and being implemented by the Data Fiduciary, if any, to mitigate risk;

(d)

the safety measures that she may take to protect her interests; and

(e)

business contact information of a person who is able to respond on behalf of the Data Fiduciary, to queries, if any, of the Data Principal.

(2)

On becoming aware of any personal data breach, the Data Fiduciary shall intimate to the Board, —

(a)

without delay, a description of the breach, including its nature, extent, timing and location of occurrence and the likely impact;

(b)

within seventy-two hours of becoming aware of the breach, or within such longer period as the Board may allow on a request made in writing in this behalf, —

(i)

updated and detailed information in respect of such description;

(ii)

the broad facts related to the events, circumstances and reasons leading to the breach;

(iii)

measures implemented or proposed, if any, to mitigate risk;

(iv)

any findings regarding the person who caused the breach;

(v)

remedial measures taken to prevent recurrence of such breach; and

(vi)

a report regarding the intimations given to affected Data Principals.

Interpretation in plain English

Interpretation · not legal advice
Interpretation, not legal advice. This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation.
Data FiduciaryData PrincipalBoard

When a Data Fiduciary (the entity determining the purpose and means of processing data) discovers a personal data breach, it must notify each affected Data Principal (the individual to whom the data relates) without delay. This notice must be clear, concise, and sent through the individual's user account or registered communication method. The notice must describe the breach, its timing, the likely consequences for the individual, what the Data Fiduciary is doing to mitigate the risk, steps the individual can take to protect themselves, and business contact information for any questions. The Data Fiduciary must also notify the Board (the regulatory authority) about the breach. An initial report describing the breach, its location, and its likely impact must be sent to the Board without delay. Within seventy-two hours of discovering the breach, the Data Fiduciary must send the Board a more detailed update. This detailed update must include the facts and reasons behind the breach, mitigation steps, any findings about who caused it, remedial measures taken to prevent it from happening again, and a report showing that the affected Data Principals were notified. The Board may allow more time for this detailed seventy-two-hour report if the Data Fiduciary submits a written request.

Key points

  • A Data Fiduciary must notify affected Data Principals about a personal data breach without delay through their user account or registered contact method. [(1)]
  • The notice to the Data Principal must include details of the breach, likely consequences, mitigation measures, and contact information. [(1)(a)-(e)]
  • The Data Fiduciary must also notify the Board about the breach without delay, providing its nature, extent, timing, location, and likely impact. [(2)(a)]
  • Within seventy-two hours of becoming aware of the breach, the Data Fiduciary must provide the Board with detailed information, including causes, remedial measures, and a report on user notifications. [(2)(b)]
  • The Board may extend the seventy-two-hour deadline if the Data Fiduciary makes a written request. [(2)(b)]

Common misreadings

  • People might think the seventy-two-hour deadline applies to notifying the Data Principal, but the rule requires notifying the Data Principal without delay, while the seventy-two-hour limit applies to the detailed report sent to the Board.
  • People might assume the Data Fiduciary only needs to report a breach to the Board, but the rule explicitly requires notifying both the Board and each affected Data Principal.

Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.

/MYND · DPDP practice

Putting this into practice?

MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.

How we use these details: only to respond to you. Withdraw any time by writing to sales@myndsol.com. This form is protected against automated submissions.