Who must a company notify after a personal data breach under DPDP? Under the DPDP Act 2023 and the DPDP Rules 2025, a Data Fiduciary that suffers a personal data breach must notify two audiences: the affected Data Principals (the individuals whose data was compromised) and the Data Protection Board of India (DPB). The Rules require notification without delay once the breach is known — an initial intimation with the facts available, followed by a fuller report as the investigation progresses. The individual notice must describe the breach, its likely consequences, the measures taken to mitigate harm, and what the person can do to protect themselves, in clear language. Getting the wording, timing and record-keeping right matters because a notification failure can attract penalties up to ₹200 crore. This kit generates both letters — to the DPB and to affected individuals — plus the breach timeline and internal escalation record you need alongside them.
Generate the two letters DPDP requires after a breach — a notification to the Data Protection Board and a plain-language notice to affected Data Principals — with the timeline, escalation log and record-keeping template that must sit alongside them.
The DPDP Rules 2025 require a Data Fiduciary to notify affected Data Principals and the Data Protection Board without delay once a personal data breach becomes known — the emphasis is on prompt intimation with the facts you have, not on waiting until the investigation is complete. In practice this means a two-stage flow: an initial notification made as soon as you are aware of the breach, describing its nature and the immediate steps being taken, followed by a more detailed report once the scope, root cause and remediation are established. This timeline section lays out both stages against the moment of discovery so nothing slips.
The clock that matters is the moment the breach becomes known to the organisation, not the moment leadership decides it is serious — so the timeline also covers the internal trigger: the instant any employee, vendor or monitoring system flags a suspected breach, the escalation to the DPO or Grievance Officer must start. Because you told us the breach was discovered recently, this section highlights the notifications that should already be moving and flags the follow-up report that will follow. Treat every deadline as running from discovery, and document that discovery time precisely.
Before any letter goes out, you need an internal record of what happened and who decided what — this log is both an operational tool and your evidence if the DPB later asks how you responded. It captures the discovery time and source, the initial assessment of scope and severity, the containment actions taken and when, who was notified internally and when (DPO/Grievance Officer, IT, leadership, legal), and the decision to notify the DPB and Data Principals with the reasoning behind the timing. A well-kept decision log is one of the strongest signals of good faith the DPB weighs when determining any penalty.
The log also anchors the facts that must stay consistent across every notification — the DPB letter, the individual notice and any public statement should not contradict each other or the internal record. This section gives you the log structure to complete in real time during the incident, so that when counsel or the DPO drafts the outbound letters (sections 3 and 4), they are working from a single agreed set of facts rather than reconstructing events after the fact.
Data categories affected in this breach:
The data breach notification letter DPDP India obligation flows from the Data Fiduciary's security and breach duties under the DPDP Act 2023, with the mechanics set out in the DPDP Rules 2025 notified in November 2025. When a personal data breach occurs, the Fiduciary must notify affected Data Principals and the Data Protection Board without delay — an initial intimation with available facts, followed by a fuller report. The individual notice must be in clear terms and explain the nature of the breach, its likely consequences, the mitigation measures taken, and the steps the person can take to protect themselves. This is not a formality: a failure to notify a breach can attract a penalty up to ₹200 crore, and inadequate security safeguards that led to the breach can attract up to ₹250 crore.
The practical difficulty during a live incident is that teams are firefighting the technical breach while also owing a legal notification duty on a compressed timeline. The organisations that handle this well are the ones that prepared the letters and the escalation log before an incident — so the notification is a fill-in-the-blanks exercise, not a from-scratch drafting sprint under pressure. This kit gives you exactly that pre-built pack: both letters, the timeline and the record-keeping structure, ready to deploy the moment a breach is confirmed.
The Data Protection Board weighs good faith, promptness and cooperation when determining penalties, so how you document the incident is as important as the letters themselves. A clean escalation log showing the breach was escalated the moment it was known, a consistent set of facts across the DPB letter and the individual notice, and a breach register that records your notify/no-notify reasoning together demonstrate a functioning breach-response programme rather than a scramble. The letters are the visible output; the record is what protects you if the response is ever questioned.
Breach notification is one part of a wider security and governance posture — the letters land far more credibly when they can point to safeguards, access controls and a response plan that were already in place. Niti Bharat runs fixed-price DPDP compliance engagements (₹75,000–₹3.2 lakh) that build the underlying breach-response programme, so if an incident ever happens, your notification tells the story of a prepared organisation, not an unprepared one.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.