Personal data breach under Rule 7: the Board, the 72 hours and the people affected
This explainer is also published on dpdpa.support. Every section, rule and date was checked against the official text on 4 Oct 2026.
Section 8(6) of the Digital Personal Data Protection Act, 2023 requires a Data Fiduciary to tell the Data Protection Board of India and each affected Data Principal about a personal data breach. (A Data Fiduciary is the person or business that decides why and how personal data is processed; a Data Principal is the person the data is about.) Rule 7 of the DPDP Rules, 2025 says how. It splits the duty into three communications: one to the people affected and two to the Board, each with its own timing and content.
What counts as a personal data breach
Section 2(u) defines a personal data breach as any unauthorised processing of personal data, or its accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access. To count, it must compromise the data’s confidentiality, integrity or availability.
So:
It is not only leaks. Losing access to personal data, or having it altered or destroyed, is a breach if it compromises availability or integrity. An incident where nothing leaves the building can still qualify.
There is no size threshold. Neither Section 8(6) nor Rule 7 sets a minimum number of people or a severity level. Rule 7 applies to “any personal data breach”.
The clock starts when you become aware
Every Rule 7 duty runs from the point of “becoming aware” of the breach. Rule 7 does not define that moment, so record it as a fact in your breach log: who learned what, and when. That timestamp drives everything below.
Telling the people affected: Rule 7(1)
On becoming aware of a breach, you must tell each affected Data Principal, to the best of your knowledge, “in a concise, clear and plain manner and without delay”. The notice goes through her user account or any mode of communication she has registered with you. It must cover:
(a) a description of the breach, including its nature, extent and the timing of its occurrence;
(b) the consequences relevant to her that are likely to arise from it;
(c) the measures you have taken and are taking, if any, to mitigate risk;
(d) the safety measures she can take to protect her interests; and
(e) business contact information of a person who can answer her questions on your behalf.
The standard for this notice is “without delay”. The 72-hour period in Rule 7(2) applies to the detailed report to the Board, not to this notice.
Telling the Board: two filings under Rule 7(2)
When
First intimation: Rule 7(2)(a): Without delay
Detailed report: Rule 7(2)(b): Within 72 hours of becoming aware, or a longer period the Board allows on a written request
Contents
First intimation: Rule 7(2)(a): A description of the breach: its nature, extent, timing and location of occurrence, and the likely impact
Detailed report: Rule 7(2)(b): (i) updated and detailed information on that description; (ii) the broad facts about the events, circumstances and reasons leading to the breach; (iii) measures implemented or proposed to mitigate risk; (iv) any findings about the person who caused it; (v) remedial measures to prevent recurrence; (vi) a report on the intimations given to affected Data Principals
In practice:
The first intimation is not held for the 72 hours. It goes without delay, with what you know.
An extension needs a written request. Only the Board can allow more time, and only on a request made in writing. Rule 7(2)(b) does not say when the request must be made; asking before the 72 hours run out is the safer course.
The detailed report covers your notices to people. Item (vi) asks for a report on the intimations you gave to affected Data Principals, so keep a record of who was told, when and how.
When a vendor causes the breach
Section 8(1) keeps a Data Fiduciary responsible for processing done on its behalf by a Data Processor, whatever the contract says. Section 8(5) extends the duty to take reasonable security safeguards to that processing too. A breach at a vendor that processes data on your behalf, such as your cloud host, is still yours to report.
Your Rule 7 clock starts when you become aware, so your processor contract should require the vendor to tell you promptly. Rule 6(1)(f) requires an appropriate provision for reasonable security safeguards in the contract. The notice period you set for the vendor is a contract choice; the Rules do not fix one.
Logs: the evidence you will need
The Board report asks for causes, findings and remediation. You can only answer with records. Rule 6(1)(c) requires visibility on access to personal data through appropriate logs, monitoring and review, so that unauthorised access can be detected, investigated and remediated. Rule 6(1)(e) requires those logs and personal data to be retained for one year for that purpose, unless another law requires otherwise. Separately, Rule 8(3) requires personal data, associated traffic data and other logs of processing to be kept for a minimum of one year from the date of processing, for the purposes in the Seventh Schedule.
What the Board can do
A breach intimation is itself one of the triggers for the Board’s powers. On receiving it, the Board may direct urgent remedial or mitigation measures, inquire into the breach and impose a penalty as the Act provides (Section 27(1)(a)). Two penalty ceilings apply most directly:
failing to take reasonable security safeguards (Section 8(5)): up to ₹250 crore, Schedule item 1;
failing to notify the Board or affected Data Principals (Section 8(6)): up to ₹200 crore, Schedule item 2.
These are maximums. Section 33(1) allows a penalty only if the Board finds, on conclusion of an inquiry, that the breach was significant. See how a Board inquiry and penalty work.
What to have ready by 13 May 2027
Section 8 and Rules 6, 7 and 8 all start on that date (clause (c) of G.S.R. 843(E); Rule 1(4)). Before then, have three things drafted and owned:
a breach register that records when you became aware and computes the 72-hour deadline;
a Board notice template with both parts; and
a plain-language letter to affected people covering items (a) to (e) of Rule 7(1).
Sources
Every section, rule and date above was checked against the official text on 4 Oct 2026.
Digital Personal Data Protection Act, 2023 (No. 22 of 2023)
Section 2(u): Personal data breach
Section 8(1): Responsible for processing by a Data Processor
Section 8(5): Security safeguards
Section 8(6): Intimation to the Board and each affected Data Principal
Section 27(1)(a): Board directions, inquiry and penalty on a breach intimation
Section 33(1): Penalty only for a significant breach, on conclusion of an inquiry
The Schedule, items 1 and 2: Up to ₹250 crore (Section 8(5)); up to ₹200 crore (Section 8(6))
DPDP Rules, 2025 (G.S.R. 846(E), 13 November 2025)
Rule 1(4): Rules 6, 7 and 8 in force eighteen months from publication
Rule 6(1): Logs and monitoring (c); one-year retention of logs (e); contract provision with processors (f)
Rule 7(1): Notice to each affected Data Principal, items (a) to (e)
Rule 7(2): Board: (a) without delay; (b) detailed report within 72 hours, items (i) to (vi)
Rule 8(3): Personal data, traffic data and logs kept for a minimum of one year
Seventh Schedule: Purposes for which Rule 8(3) retention applies
Notifications
G.S.R. 843(E), clause (c): Section 8 in force eighteen months from 13 November 2025
Have the register and both notices ready before you need them
How-to 11 gives you a breach register that works out when the detailed report is due, a two-part Board notice, and a plain-language letter to the people affected.
The how-to walkthroughs and the editable Word and Excel files are in the DPDPA Compliance Toolkit program on this site. The version of this article that we keep up to date is on dpdpa.support.
Drafting aid, not legal advice.




Comments