DPDP enforcement deadline: May 2027Rules notified Nov 2025Penalty exposure up to ₹250 Cr

Quick Answer

How should organisations prepare for data breaches under the DPDP Act? Breach response readiness under the DPDP Act 2023 requires organisations to maintain a documented Incident Response Plan, designate a breach response team, implement technical controls to detect breaches rapidly, and conduct tabletop exercises at least annually. Key preparation steps include defining breach severity classification, pre-drafting notification templates for the Data Protection Board and affected individuals, and establishing a communication chain that can activate within hours of detection.

DPDP Breach Response Readiness — Is Your Organisation Prepared?

15 questions across 5 areas. Know your readiness score before the Data Protection Board does.

Free: Detection + Containment Score Full Report ₹999
Detection Question 1 of 15

Why this matters:

The 72-hour breach notification rule under India's DPDP Act

Section 8(6) of the Digital Personal Data Protection Act 2023 requires Data Fiduciaries to notify the Data Protection Board "in such form and manner as may be prescribed" without delay upon becoming aware of a personal data breach. The draft rules propose a 72-hour window — the same timeframe as the EU's GDPR — but India's enforcement context is different: the DPB can impose penalties up to ₹200 crore for a single breach-notification failure.

The clock starts from the moment you "become aware" — not from the moment the breach is confirmed. If a security alert fires at 11pm on a Friday and you see it at 9am Monday, you have already burned 34 hours. Organisations without a 24/7 monitoring function and a pre-written notification template routinely miss the window in simulations.

Critical gap most organisations miss: you must notify affected Data Principals (individuals) in addition to the DPB if the breach "is likely to adversely affect" them. This dual notification requirement doubles your operational workload in the first 72 hours.

What the Data Protection Board will look for after a breach

When the DPB investigates a breach, it is not just asking "did you notify on time?" It is assessing whether you had a systematic data protection programme — or whether compliance was an afterthought. Specific indicators the DPB is expected to review: (1) Detection speed — how quickly did you identify the breach, and what monitoring was in place? (2) Containment actions — what did you do in the first hour, and is there documented evidence? (3) Breach register — do you record all incidents, or only the ones you reported? (4) Root-cause analysis — can you demonstrate learning from the incident? (5) Prior violations — repeat breach patterns attract aggravated penalties under Section 25(3).

Organisations that have run tabletop exercises consistently demonstrate faster response times and better documentation — two of the five factors that influence penalty quantum. This assessment benchmarks your programme against all five.

Every Sunday

The Sunday DPDP Brief

One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.

No spam. Unsubscribe with one click, anytime.

Related tools & reading
DPDP Compliance Maturity Roadmap Generator IndiaEmployee Data Audit ToolEmployee DPDP Privacy Training Needs AssessmentParental Consent Implementation Cost Calculator DPDPSee all Assessments & Scores tools →📝 DPDP Readiness Self Assessment📝 DPDP Internal Audit Prove Compliance to Your Customers