Executive Summary
Data breach notification is a critical obligation under India's data protection framework:
- Statutory basis: DPDP Act Section 8(6)
- Trigger: Personal data breach
- Reporting to: Data Protection Board
- Timeline: As prescribed (expected 72 hours)
- Notification content: Nature, impact, remedial measures
- Penalty: Up to Rs. 200 crores for non-compliance
This guide examines breach notification requirements and compliance strategies.
1. Statutory Framework
DPDP Act Provisions
| Section |
Requirement |
| Section 8(6) |
Intimate DPB of breach |
| Section 8(7) |
Notify affected Data Principals |
| Section 15 |
Penalty for breach of obligations |
CERT-In Requirements (Parallel)
| Requirement |
Specification |
| Direction 2022 |
6-hour reporting for cyber incidents |
| Scope |
Cyber security incidents |
| Overlap |
May apply alongside DPDP |
2. What Constitutes a Personal Data Breach
Types of Breaches
| Type |
Example |
| Confidentiality breach |
Unauthorized disclosure |
| Integrity breach |
Unauthorized alteration |
| Availability breach |
Loss of access |
3. Breach Assessment
Risk Assessment
| Risk Level |
Indicators |
| High |
Financial data, health records, identity theft risk |
| Medium |
Contact details, preferences |
| Low |
Already public information |
4. Notification Requirements
To Data Protection Board
| Element |
Requirement |
| Trigger |
Personal data breach |
| Timeline |
As prescribed by rules |
| Format |
Prescribed form |
| Content |
Nature, categories, measures taken |
To Data Principals
| Condition |
Notification |
| High risk |
When breach poses high risk |
| DPB direction |
As directed by Board |
| Plain language |
Clear and understandable |
5. Internal Breach Response Process
Phase 1: Detection and Containment
| Step |
Action |
| Detection |
Identify the breach |
| Containment |
Stop ongoing breach |
| Preservation |
Secure evidence |
Phase 2: Investigation and Notification
| Recipient |
Timeline |
| Internal escalation |
Immediate |
| DPB notification |
Within prescribed period |
| Data Principal notification |
As required |
6. Penalties for Non-Compliance
DPDP Act Penalties
| Violation |
Maximum Penalty |
| Failure to notify DPB |
Rs. 200 crores |
| Failure to notify individuals |
Rs. 200 crores |
| Inadequate security |
Rs. 250 crores |
7. Compliance Checklist
Pre-Breach Preparedness
During Breach
8. Key Takeaways
- Preparation is Key: Have incident response plans ready.
- Quick Detection: Invest in monitoring capabilities.
- Timeline Critical: Notification deadlines are strict.
- Documentation: Maintain comprehensive breach records.
- Dual Reporting: Consider CERT-In and sector regulators.
Conclusion
Data breach notification requires robust detection, assessment, and notification processes. Proactive preparation is essential for compliance.