Data Breach & Incident Response
A personal data breach is any unauthorised access to, or accidental disclosure, alteration or loss of, personal data. Under the Digital Personal Data Protection Act, 2023, a business that suffers one must inform the Data Protection Board of India and every affected person. Certain cyber incidents must also be reported to the Indian Computer Emergency Response Team (CERT-In) within six hours.
The two duties are separate. The CERT-In directions of April 2022 apply now. The duty under the DPDP Act and Rule 7 of the 2025 Rules applies from 13 May 2027. A business in a regulated sector, such as banking, insurance or securities, also has to report to its own regulator.
When you need it
When a breach has just been discovered
The first hours decide whether the deadlines can be met and what is said to customers.
When there is no written plan
A plan agreed in advance names who decides, who is called and what is sent, so that time is not lost.
When a vendor reports an incident
A breach at a processor is the business’s breach to report. The contract decides how much information the vendor has to give.
When customers ask about breach procedures
Enterprise customers ask for the incident response plan and notification commitments before signing.
After an incident
A written record of what happened and what was done is needed for regulators, insurers and any later claim.
How the process works
Six stages. The first four run in parallel in the first three days.
- 1
Contain and preserve
ImmediatelyStop the incident from spreading, and keep the logs and affected systems intact for investigation. The technical work is led by the security team; legal input at this point is about what to preserve and who to tell.
- 2
Establish the facts
The first 24 to 72 hoursFind out what happened, when, which personal data and how many people are affected, and whether the incident is continuing. The notifications depend on these facts.
Documents
- The incident log and timeline
- A list of affected systems and data
- Contracts with any vendor involved
- 3
Work out who must be told
Within hoursIdentify each duty that applies: CERT-In, the Data Protection Board, a sector regulator, affected individuals, customers whose data the business processes, and insurers.
- 4
Notify
Within the legal deadlinesSend each notification in the form and time required. The notice to individuals has to be clear and say what happened, the likely consequences, what the business is doing and what they can do to protect themselves.
- 5
Handle the consequences
The following weeksRespond to questions from regulators, customers and the press, deal with contractual claims and consider claims against a vendor at fault.
- 6
Review and repair
Within a month or twoRecord the cause and the response, fix the weakness, and update the plan, the contracts and the training.
Common questions
The Act defines it widely: any unauthorised processing of personal data, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to it, that compromises its confidentiality, integrity or availability. A lost laptop or a misdirected email can qualify.
The Data Protection Board of India and each affected person. Rule 7 requires the business to inform affected individuals without delay, and to give the Board a first intimation without delay and detailed information within 72 hours of becoming aware.
No. The Act and the Rules do not set a threshold of harm or of numbers. Every personal data breach is to be notified once the duty is in force.
The directions of 28 April 2022 require specified cyber security incidents, including data breaches and data leaks, to be reported to CERT-In within six hours of noticing them. This applies now, to service providers, intermediaries, data centres and body corporates.
The Schedule to the DPDP Act allows a penalty of up to ₹200 crore for failing to notify the Board or affected individuals, and up to ₹250 crore for failing to take reasonable security safeguards to prevent the breach.
The business that decided to collect the data, the Data Fiduciary. The vendor’s contract should require it to tell the business immediately and to supply the facts needed for the notifications.
The team and who decides, how incidents are graded, the reporting duties and deadlines, draft notices, contact details for regulators, vendors, insurers and advisers, and a record-keeping template. It should be tested at least once a year.
Related
To discuss a data breach, write to info@ireniclegal.com or call +91 96547 47331. Written by Adv. Kanika Marwaha Bindal; last updated 7 October 2026.

