Data Breach & Incident Response

A personal data breach is any unauthorised access to, or accidental disclosure, alteration or loss of, personal data. Under the Digital Personal Data Protection Act, 2023, a business that suffers one must inform the Data Protection Board of India and every affected person. Certain cyber incidents must also be reported to the Indian Computer Emergency Response Team (CERT-In) within six hours.

The two duties are separate. The CERT-In directions of April 2022 apply now. The duty under the DPDP Act and Rule 7 of the 2025 Rules applies from 13 May 2027. A business in a regulated sector, such as banking, insurance or securities, also has to report to its own regulator.

When you need it

  • When a breach has just been discovered

    The first hours decide whether the deadlines can be met and what is said to customers.

  • When there is no written plan

    A plan agreed in advance names who decides, who is called and what is sent, so that time is not lost.

  • When a vendor reports an incident

    A breach at a processor is the business’s breach to report. The contract decides how much information the vendor has to give.

  • When customers ask about breach procedures

    Enterprise customers ask for the incident response plan and notification commitments before signing.

  • After an incident

    A written record of what happened and what was done is needed for regulators, insurers and any later claim.

How the process works

Six stages. The first four run in parallel in the first three days.

  1. 1

    Contain and preserve

    Immediately

    Stop the incident from spreading, and keep the logs and affected systems intact for investigation. The technical work is led by the security team; legal input at this point is about what to preserve and who to tell.

  2. 2

    Establish the facts

    The first 24 to 72 hours

    Find out what happened, when, which personal data and how many people are affected, and whether the incident is continuing. The notifications depend on these facts.

    Documents

    • The incident log and timeline
    • A list of affected systems and data
    • Contracts with any vendor involved
  3. 3

    Work out who must be told

    Within hours

    Identify each duty that applies: CERT-In, the Data Protection Board, a sector regulator, affected individuals, customers whose data the business processes, and insurers.

  4. 4

    Notify

    Within the legal deadlines

    Send each notification in the form and time required. The notice to individuals has to be clear and say what happened, the likely consequences, what the business is doing and what they can do to protect themselves.

  5. 5

    Handle the consequences

    The following weeks

    Respond to questions from regulators, customers and the press, deal with contractual claims and consider claims against a vendor at fault.

  6. 6

    Review and repair

    Within a month or two

    Record the cause and the response, fix the weakness, and update the plan, the contracts and the training.

Common questions

The Act defines it widely: any unauthorised processing of personal data, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to it, that compromises its confidentiality, integrity or availability. A lost laptop or a misdirected email can qualify.

To discuss a data breach, write to info@ireniclegal.com or call +91 96547 47331. Written by Adv. Kanika Marwaha Bindal; last updated 7 October 2026.