/The Rules · 2025
Rule 7: Intimation of personal data breach
DPDP Rules, 2025, G.S.R. 846(E) dated 13 November 2025. Comes into force on 13 May 2027.
- Provision
- Rule 7 of The Digital Personal Data Protection Rules, 2025
- Status
- Comes into force on 13 May 2027 (phase 3)
- Made under
- s. 8 General obligations of Data Fiduciary
- Source
- Ministry of Electronics and Information Technology · G.S.R. 846(E) · 13 November 2025 · Official PDF
On becoming aware of any personal data breach, the Data Fiduciary shall, to the best of its knowledge, intimate to each affected Data Principal, in a concise, clear and plain manner and without delay, through her user account or any mode of communication registered by her with the Data Fiduciary, —
On becoming aware of any personal data breach, the Data Fiduciary shall intimate to the Board, —
without delay, a description of the breach, including its nature, extent, timing and location of occurrence and the likely impact;
within seventy-two hours of becoming aware of the breach, or within such longer period as the Board may allow on a request made in writing in this behalf, —
When a Data Fiduciary (the entity determining the purpose and means of processing data) discovers a personal data breach, it must notify each affected Data Principal (the individual to whom the data relates) without delay. This notice must be clear, concise, and sent through the individual's user account or registered communication method. The notice must describe the breach, its timing, the likely consequences for the individual, what the Data Fiduciary is doing to mitigate the risk, steps the individual can take to protect themselves, and business contact information for any questions. The Data Fiduciary must also notify the Board (the regulatory authority) about the breach. An initial report describing the breach, its location, and its likely impact must be sent to the Board without delay. Within seventy-two hours of discovering the breach, the Data Fiduciary must send the Board a more detailed update. This detailed update must include the facts and reasons behind the breach, mitigation steps, any findings about who caused it, remedial measures taken to prevent it from happening again, and a report showing that the affected Data Principals were notified. The Board may allow more time for this detailed seventy-two-hour report if the Data Fiduciary submits a written request.
Key points
- A Data Fiduciary must notify affected Data Principals about a personal data breach without delay through their user account or registered contact method. [(1)]
- The notice to the Data Principal must include details of the breach, likely consequences, mitigation measures, and contact information. [(1)(a)-(e)]
- The Data Fiduciary must also notify the Board about the breach without delay, providing its nature, extent, timing, location, and likely impact. [(2)(a)]
- Within seventy-two hours of becoming aware of the breach, the Data Fiduciary must provide the Board with detailed information, including causes, remedial measures, and a report on user notifications. [(2)(b)]
- The Board may extend the seventy-two-hour deadline if the Data Fiduciary makes a written request. [(2)(b)]
Common misreadings
- People might think the seventy-two-hour deadline applies to notifying the Data Principal, but the rule requires notifying the Data Principal without delay, while the seventy-two-hour limit applies to the detailed report sent to the Board.
- People might assume the Data Fiduciary only needs to report a breach to the Board, but the rule explicitly requires notifying both the Board and each affected Data Principal.
Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.
/MYND · DPDP practice
Putting this into practice?
MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.