DPDP enforcement deadline: May 2027Rules notified Nov 2025Penalty exposure up to ₹250 Cr
⚡ DPDP Act enforcement begins May 2026 — Check your readiness score

Quick Answer

Under the DPDP Act 2023, a data fiduciary must notify the Data Protection Board and affected Data Principals of a personal data breach, and the DPDP Rules 2025 shape how and when. A DPDP-ready breach log records each confirmed breach, the data and individuals affected, the timeline from detection to notification, the content of the notification, and the remediation. The log is the evidence that you notified on time and acted properly. Because breach-notification failures can attract penalties up to ₹200 crore, a defensible breach log is a direct risk control.

Data Breach Log Tracker — Breach Logging and Notification Readiness

If you had a breach today, could you prove you notified the right people on time? This checks whether your breach log and notification tracking hold up.

How notification-ready is your breach log?

What a DPDP-ready breach log must record

Why a breach log is different from an incident log

An incident log captures everything that might affect personal data. A breach log is narrower and higher-stakes: it records the incidents that crossed the threshold into a notifiable personal data breach and therefore triggered obligations under the DPDP Act 2023. Keeping the two distinct matters, because a breach carries specific duties — notifying the Data Protection Board and the affected Data Principals — that a routine incident does not. When breaches are buried inside a general incident list, the ones that carry legal deadlines are the easiest to miss.

The breach log is fundamentally an evidence artefact. If your notification is ever questioned, the log is what proves you detected the breach, assessed it, and notified the right parties within the expected timeframe. Given that breach-notification failures can attract penalties up to ₹200 crore, this is not paperwork for its own sake. Niti Bharat helps companies stand up a dedicated breach log wired to their notification process, so the evidence exists before it is ever needed.

Proving timely notification under the DPDP Rules 2025

The DPDP Rules 2025 shape the expectations around breach notification — how, to whom, and within what timeframe. The single most important thing your log can capture is the timeline: when the breach was detected, when it was assessed as a breach, when the Board was notified, and when affected individuals were told. This chain is what demonstrates timeliness, and timeliness is exactly what an adjudication process scrutinises. A log with vague or missing dates cannot prove you acted in time even if you did.

Equally important is having a notification process that has been rehearsed before a real breach occurs. Deciding who drafts the notification, who approves it, and how it reaches the Board and individuals — in the middle of a live incident — is how deadlines slip. Niti Bharat runs privacy governance programmes that include breach-response readiness, so the log, the process and the notification templates are all in place and tested ahead of the May 2027 enforcement horizon.

Get the breach log and notification tracker (free)

A dedicated breach-log template with timeline fields, plus a notification tracker so you can prove who was told, what was sent, and when.

Frequently Asked Questions

What must a breach notification under DPDP contain?+
It should describe the breach, the personal data and Data Principals affected, the likely consequences, the measures taken or proposed to address it, and how affected individuals can protect themselves or seek help. Your log should capture that the notification carried this content and when it was sent.
How quickly must we notify a breach?+
The DPDP Rules 2025 set the expectations for breach notification to the Data Protection Board and affected individuals. The practical rule is to notify promptly — which is why your log must capture the detection and notification times so timeliness can be demonstrated.
Should every incident go in the breach log?+
No — only incidents assessed as notifiable personal data breaches belong in the breach log. Everything else stays in the general incident log. The assessment decision that separates the two should itself be recorded, in the incident log.
What penalty applies to a breach-notification failure?+
Under the DPDP Act, failure to notify a breach as required can attract a penalty of up to ₹200 crore. This is a ceiling, not a fixed amount, but it underlines why a defensible, timely breach log is a serious risk control rather than administrative detail.

Related Tools

Every Sunday

The Sunday DPDP Brief

One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.

No spam. Unsubscribe with one click, anytime.

Related tools & reading
Data Fiduciary vs Data Processor Under DPDP IndiaData Incident Log TrackerData Lakehouse & Warehouse DPDP Compliance in IndiaRetail Customer Data Under DPDPSee all Reference & Checklists tools →📝 Can Employees Refuse Biometric Data DPDP📝 Answer Your Next Client DPDP Questionnaire Faster