In an increasingly digital economy, organisations collect and process significant volumes of personal data. While businesses may implement security measures to protect this information, data breaches can still occur through cyberattacks, unauthorised access, accidental disclosure, system vulnerabilities or human error. The Digital Personal Data Protection Act, 2023 (DPDP Act) therefore places specific responsibilities on Data Fiduciaries when a personal data breach occurs.
The Digital Personal Data Protection Rules, 2025 (DPDP Rules) provide greater detail on how such breaches are to be communicated and managed. The Rules were notified in November 2025 and are being brought into force through a phased implementation framework.
What is a Personal Data Breach?
A personal data breach broadly refers to any unauthorised processing of personal data, including accidental or unlawful loss, disclosure, alteration or access that compromises the security of such data.
A breach may involve different forms of incidents—for example, a database being hacked, confidential customer information being accidentally emailed to the wrong recipient, or an unauthorised person gaining access to an organisation’s systems.
The DPDP framework treats breach management as an important part of a Data Fiduciary’s overall responsibility for protecting personal data.
What Does the DPDP Act Require?
Under Section 8(6) of the DPDP Act, where a personal data breach occurs, the Data Fiduciary is required to intimate the Data Protection Board of India and each affected Data Principal in the prescribed manner and form. The Board may, upon receiving information regarding a breach, direct urgent remedial or mitigation measures and inquire into the breach.
This means that responding to a breach is not limited to internally containing the incident. The organisation must also consider its regulatory and communication obligations.
What Do the DPDP Rules, 2025 Provide?
Rule 7 of the DPDP Rules, 2025 provides a more detailed framework for breach notifications.
When a Data Fiduciary becomes aware of a personal data breach, it must promptly inform affected Data Principals. The communication should be clear and understandable and should explain important information, including the nature, extent and timing of the breach and its likely consequences for the affected individual.
The notification should also identify measures taken by the organisation to mitigate the effects of the breach and provide practical recommendations to help affected individuals protect themselves. Contact details of a person who can respond to questions relating to the breach must also be provided.
The Data Fiduciary must additionally inform the Data Protection Board without delay. Within 72 hours, or such longer period as may be allowed by the Board, it must provide detailed information regarding the breach, including the circumstances leading to it, the measures taken to mitigate its effects, remedial measures adopted to prevent recurrence and details of notifications issued to affected Data Principals.
Why is Timely Notification Important?
A data breach can expose individuals to risks such as identity theft, financial fraud, phishing and other forms of misuse. Prompt notification allows affected individuals to take protective measures at an early stage.
For businesses, timely reporting also forms part of regulatory compliance. Failure to maintain appropriate security safeguards or comply with breach-related obligations can attract significant penalties under the DPDP framework.
How Should Businesses Prepare?
Organisations should have a documented data breach response plan covering detection, internal escalation, investigation, containment, regulatory notification and communication with affected individuals.
Businesses should also maintain appropriate security safeguards, monitor systems for unauthorised access, maintain relevant logs and ensure that Data Processor contracts contain appropriate security requirements.
Conclusion
The DPDP Act and Rules make data breach management an important element of privacy governance. Organisations must be prepared not only to prevent breaches but also to respond quickly and transparently when incidents occur.
Effective breach preparedness therefore requires a combination of technical safeguards, internal response procedures, contractual controls and timely communication. As the DPDP framework moves through its phased implementation, organisations should use this period to strengthen their incident-response mechanisms and build a culture of responsible data protection.
