DPDP Data Breach Response: Board and Data Principal Notification Workflow
By Ravi Sisodia · Reviewed by CA Divyanshu Sengar · Updated 5 October 2026
Final Rule 7 requires affected Data Principals to be informed without delay and the Board to receive detailed breach information within 72 hours, but that future-dated breach rule is not yet operative on 4 October 2026.
Finin2min 2-Minute Summary
- Rule 7 requires affected Data Principals to receive clear breach information without delay once the Data Fiduciary becomes aware.
- The Board must be informed without delay, with detailed information within 72 hours unless a longer period is permitted.
- Rule 6 also specifies minimum reasonable-security safeguards and processor-contract security provisions.
- Rules 6 and 7 sit on the 18-month commencement track and are scheduled for May 2027.
- Organisations should test breach detection, legal triage, evidence preservation and notification drafting before commencement.
Current status: build the machine before the clock starts
Define the breach-decision point
Incident-response teams should distinguish a security event from a personal-data breach and document when the organisation becomes aware of facts sufficient to trigger the notification workflow. That timestamp will matter once Rule 7 is operative.
Security, privacy, legal, product and communications teams need one severity and escalation matrix.
Prepare two different notifications
The Data Principal notice should explain nature/extent/timing, likely consequences, mitigation, protective steps and contact details in clear language. The Board report needs the event sequence, mitigation, cause/actor information where known, remedial steps and notification details.
Do not wait for perfect forensic certainty before starting the regulatory workflow; maintain updates as facts develop.
October 2026 status: rehearse Rule 7 without starting a false statutory clock
Rules 6 and 7 are final but remain scheduled for the 18-month commencement point in May 2027. Organisations can nevertheless run tabletop exercises using the final notification fields now. Label exercises clearly as readiness work so incident teams do not confuse an internal rehearsal with a statutory notice made under an operative rule.
The most valuable exercise starts from an imperfect alert: for example a processor reports unusual access but cannot yet confirm exfiltration. Teams should decide who records awareness time, who determines whether personal data is affected, who contacts the processor, and what information can be sent to users and the Board while forensics continues.
After each exercise, update processor SLAs and contact lists. A breach plan with outdated vendor escalation contacts will fail even if the legal template is excellent.
- Run processor-inclusive tabletop exercises.
- Define who records the awareness timestamp.
- Separate initial Board notice from later detailed report.
- Version-control templates for the May 2027 commencement.
72-hour readiness pack
- Incident intake and breach-classification form.
- Awareness timestamp and decision log.
- Affected-data/user scoping method.
- Data Principal notice template.
- Board initial and detailed report templates.
- Processor escalation contract/SLA.
- Evidence preservation and post-incident remediation.
Questions readers commonly ask
Is the 72-hour DPDP rule already binding in October 2026?
No. Final Rule 7 is notified but scheduled to commence in May 2027.
When does the 72-hour clock matter under the final rule?
The detailed Board information is due within 72 hours of becoming aware, unless a longer period is permitted.
Must affected users be told too?
Yes, the final rule requires notice to each affected Data Principal without delay.
Should processor contracts address breaches?
Yes. Security and escalation obligations should be built into processor contracts and operations.
Official / primary sources
- DPDP Rules, 2025 - Rules 6-7: security safeguards and breach notification
- DPDP Act, 2023 - Data Fiduciary responsibility and breach obligation
- DPDP enforcement timeline - Core sections/rules commence after 18 months
Disclaimer
Important: General educational and professional-reference material. Apply the current Code, Rules, insurance contract/regulatory instrument or DPDP commencement status to the exact facts before acting. Educational and professional reference only; confirm the current law, rates and the facts of your case before relying on this page.