Skip to main content
Finin2minAction Guide · source-controlled
DPDP, Privacy & DataUpdated 5 October 2026

DPDP Data Breach Response: Board and Data Principal Notification Workflow

By Ravi Sisodia · Reviewed by CA Divyanshu Sengar · Updated 5 October 2026

Final Rule 7 requires affected Data Principals to be informed without delay and the Board to receive detailed breach information within 72 hours, but that future-dated breach rule is not yet operative on 4 October 2026.

Finin2min 2-Minute Summary

Current status: build the machine before the clock starts

Define the breach-decision point

Incident-response teams should distinguish a security event from a personal-data breach and document when the organisation becomes aware of facts sufficient to trigger the notification workflow. That timestamp will matter once Rule 7 is operative.

Security, privacy, legal, product and communications teams need one severity and escalation matrix.

Prepare two different notifications

The Data Principal notice should explain nature/extent/timing, likely consequences, mitigation, protective steps and contact details in clear language. The Board report needs the event sequence, mitigation, cause/actor information where known, remedial steps and notification details.

Do not wait for perfect forensic certainty before starting the regulatory workflow; maintain updates as facts develop.

October 2026 status: rehearse Rule 7 without starting a false statutory clock

Rules 6 and 7 are final but remain scheduled for the 18-month commencement point in May 2027. Organisations can nevertheless run tabletop exercises using the final notification fields now. Label exercises clearly as readiness work so incident teams do not confuse an internal rehearsal with a statutory notice made under an operative rule.

The most valuable exercise starts from an imperfect alert: for example a processor reports unusual access but cannot yet confirm exfiltration. Teams should decide who records awareness time, who determines whether personal data is affected, who contacts the processor, and what information can be sent to users and the Board while forensics continues.

After each exercise, update processor SLAs and contact lists. A breach plan with outdated vendor escalation contacts will fail even if the legal template is excellent.

72-hour readiness pack

Questions readers commonly ask

Is the 72-hour DPDP rule already binding in October 2026?

No. Final Rule 7 is notified but scheduled to commence in May 2027.

When does the 72-hour clock matter under the final rule?

The detailed Board information is due within 72 hours of becoming aware, unless a longer period is permitted.

Must affected users be told too?

Yes, the final rule requires notice to each affected Data Principal without delay.

Should processor contracts address breaches?

Yes. Security and escalation obligations should be built into processor contracts and operations.

Official / primary sources

Disclaimer

Important: General educational and professional-reference material. Apply the current Code, Rules, insurance contract/regulatory instrument or DPDP commencement status to the exact facts before acting. Educational and professional reference only; confirm the current law, rates and the facts of your case before relying on this page.

Educational and professional reference only — not financial, tax or legal advice. Verify the current official position from the primary source before relying on any figure, rate, provision or deadline.