---
title: "Rule 7: Intimation of personal data breach"
url: https://dpdp.myndsolution.com/wiki/rules/rule-7-intimation-of-personal-data-breach/
description: "Rule 7 of the Digital Personal Data Protection Rules, 2025 (Intimation of personal data breach). Official text verbatim, comes into force on 13 may 2027…"
kind: rule
updated: 2026-09-09
official_source: https://egazette.gov.in/WriteReadData/2025/267650.pdf
text_type: official-text-plus-interpretation
publisher: MYND Integrated Solutions
license: Official Government of India texts are reproduced verbatim (public domain / open government data). Interpretation is CC BY 4.0, MYND Integrated Solutions.
disclaimer: Not legal advice. Official text prevails over any interpretation.
html_version: https://dpdp.myndsolution.com/wiki/rules/rule-7-intimation-of-personal-data-breach/
---
# Rule 7: Intimation of personal data breach

*The Digital Personal Data Protection Rules, 2025, G.S.R. 846(E) dated 13 November 2025. Comes into force on 13 May 2027.*

## Official text

- **(1)** On becoming aware of any personal data breach, the Data Fiduciary shall, to the best of its knowledge, intimate to each affected Data Principal, in a concise, clear and plain manner and without delay, through her user account or any mode of communication registered by her with the Data Fiduciary, —
  - **(a)** a description of the breach, including its nature, extent and the timing of its occurrence;
  - **(b)** the consequences relevant to her, that are likely to arise from the breach;
  - **(c)** the measures implemented and being implemented by the Data Fiduciary, if any, to mitigate risk;
  - **(d)** the safety measures that she may take to protect her interests; and
  - **(e)** business contact information of a person who is able to respond on behalf of the Data Fiduciary, to queries, if any, of the Data Principal.

- **(2)** On becoming aware of any personal data breach, the Data Fiduciary shall intimate to the Board, —
  - **(a)** without delay, a description of the breach, including its nature, extent, timing and location of occurrence and the likely impact;
  - **(b)** within seventy-two hours of becoming aware of the breach, or within such longer period as the Board may allow on a request made in writing in this behalf, —
    - **(i)** updated and detailed information in respect of such description;
    - **(ii)** the broad facts related to the events, circumstances and reasons leading to the breach;
    - **(iii)** measures implemented or proposed, if any, to mitigate risk;
    - **(iv)** any findings regarding the person who caused the breach;
    - **(v)** remedial measures taken to prevent recurrence of such breach; and
    - **(vi)** a report regarding the intimations given to affected Data Principals.


## Made under

- [s. 8 General obligations of Data Fiduciary](https://dpdp.myndsolution.com/wiki/act/section-8-general-obligations-of-data-fiduciary/)

## Interpretation in plain English (not legal advice)

> This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation.

When a Data Fiduciary (the entity determining the purpose and means of processing data) discovers a personal data breach, it must notify each affected Data Principal (the individual to whom the data relates) without delay. This notice must be clear, concise, and sent through the individual's user account or registered communication method. The notice must describe the breach, its timing, the likely consequences for the individual, what the Data Fiduciary is doing to mitigate the risk, steps the individual can take to protect themselves, and business contact information for any questions. The Data Fiduciary must also notify the Board (the regulatory authority) about the breach. An initial report describing the breach, its location, and its likely impact must be sent to the Board without delay. Within seventy-two hours of discovering the breach, the Data Fiduciary must send the Board a more detailed update. This detailed update must include the facts and reasons behind the breach, mitigation steps, any findings about who caused it, remedial measures taken to prevent it from happening again, and a report showing that the affected Data Principals were notified. The Board may allow more time for this detailed seventy-two-hour report if the Data Fiduciary submits a written request.

### Key points

- A Data Fiduciary must notify affected Data Principals about a personal data breach without delay through their user account or registered contact method. [(1)]
- The notice to the Data Principal must include details of the breach, likely consequences, mitigation measures, and contact information. [(1)(a)-(e)]
- The Data Fiduciary must also notify the Board about the breach without delay, providing its nature, extent, timing, location, and likely impact. [(2)(a)]
- Within seventy-two hours of becoming aware of the breach, the Data Fiduciary must provide the Board with detailed information, including causes, remedial measures, and a report on user notifications. [(2)(b)]
- The Board may extend the seventy-two-hour deadline if the Data Fiduciary makes a written request. [(2)(b)]

### Common misreadings

- People might think the seventy-two-hour deadline applies to notifying the Data Principal, but the rule requires notifying the Data Principal without delay, while the seventy-two-hour limit applies to the detailed report sent to the Board.
- People might assume the Data Fiduciary only needs to report a breach to the Board, but the rule explicitly requires notifying both the Board and each affected Data Principal.

*Interpretation prepared 2026-09-09 from the official text only; the official text prevails.*

---
Cite as: DPDP Rules, 2025, r. 7. Official source: https://egazette.gov.in/WriteReadData/2025/267650.pdf
