Skip to content

Personal Data Breach Response

Personal Data Breach Response: current Indian law, practical example, evidence checklist, risks and Finin2min summary.

Current-law position: As at 4 July 2026, institutional and enabling DPDP provisions are in force. Section 6(9) and section 27(1)(d) are scheduled for 13 November 2026; most substantive processing obligations are scheduled for 13 May 2027. Readiness work should distinguish current duties from future commencement.

Finin2min crux

DPDP and CERT-In may require parallel assessment, communications and records with different triggers.

Legal anchors

DPDP Act and DPDP Rules; CERT-In overlay

The legal conclusion must be read with the current rules, notifications, portal instructions and binding judgments applicable to the event date.

How to analyse it

1. Applicability

Identify the person, activity, location, transaction date, threshold and regulator before applying the rule.

2. Statutory condition

Separate mandatory legal conditions from portal fields, industry practice and contractual preference.

3. Evidence

Link each conclusion to contemporaneous documents, approvals, filings and accounting records.

4. Action

Activate legal, security, communications and evidence tracks immediately.

Practical illustration

A ransomware incident affects customer personal data and business systems.

Decision point: Reperform the analysis if a material fact, date, location or legal status changes.

Evidence pack

What can go wrong?

Waiting for perfect facts can miss a short cyber-reporting window.

Additional risks include stale source use, incomplete authority, inconsistent portal data, weak contemporaneous evidence and failure to consider linked tax, accounting, contract or sector rules.

Finin2min action workflow

StageControlOutput
FactsFreeze transaction, party, date and locationFact sheet
LawRead Act, Rules and later instrumentsLegal map
EvidenceReconcile filings, books and documentsEvidence index
DecisionApprove, remediate, disclose or escalateSigned action note

Quick Q&A

What is the direct answer?

DPDP and CERT-In may require parallel assessment, communications and records with different triggers.

Which provision should be opened first?

DPDP Act and DPDP Rules; CERT-In overlay

What should be preserved?

data inventory and processing register, privacy notice and consent artefacts, processor contracts and security schedules.

What is the immediate next step?

Activate legal, security, communications and evidence tracks immediately.

Official sources

Digital Personal Data Protection Act, 2023

MeitY

Open official source

Source reviewed 4 July 2026

Digital Personal Data Protection Rules, 2025

MeitY

Open official source

Source reviewed 4 July 2026

DPDP phased commencement notification, 13 November 2025

MeitY

Open official source

Source reviewed 4 July 2026

Data Protection Board establishment and appointment material

MeitY

Open official source

Source reviewed 4 July 2026

CERT-In directions under section 70B

CERT-In

Open official source

Source reviewed 4 July 2026

Information Technology Intermediary Guidelines and Digital Media Ethics Code Rules

MeitY

Open official source

Source reviewed 4 July 2026

Law, portal and source review: 4 July 2026. Case law and transaction-specific conditions should be checked immediately before professional reliance.