Choose Language
Google Translate
Skip to content
Facebook X-twitter Instagram Linkedin Youtube
  • sales@cybernx.com
  • +91 90823 52813
CyberNX Logo
  • Home
  • About
    • About Us
    • CERT-In Empanelled Cybersecurity Auditor
    • Awards & Recognition
    • Our Customers
  • Services

    Peregrine

    • Managed Detection & Response
    • AI Managed SOC Services
    • Elastic Stack Consulting
    • CrowdStrike Consulting 
    • Threat Hunting Services
    • Digital Risk Protection Services
    • Threat Intelligence Services
    • Digital Forensics Services
    • Brand Risk & Dark Web Monitoring
    • Full Stack Observability

    Pinpoint

    • Red Teaming Services
    • Vulnerability Assessment
    • Penetration Testing Services
    • Secure Code Review Services
    • Cloud Security Assessment
    • Phishing Simulation Services
    • Breach and Attack Simulation Services

    MSP247

    • 24 X 7 Managed Cloud Services
    • Cloud Security Implementation
    • Disaster Recovery Consulting
    • Security Patching Services
    • WAF Services

    nCompass

    • SBOM Management Tool
    • Cybersecurity Audit Services
    • Virtual CISO Services
    • DPDP Act Consulting
    • ISO 27001 Consulting
    • RBI Master Direction Compliance
    • SEBI CSCRF Framework Consulting
    • SEBI Cloud Framework Consulting
    • Security Awareness Training
    • Cybersecurity Staffing Services
  • Industries
    • Banking
    • Financial Services
    • Insurance
  • Resources
    Blogs
    Case Studies
    Downloads
    Whitepapers
    Buyer’s Guide
    Research & Guides
  • Careers
  • English
Contact Us
CyberNX Logo
  • English
  • Home
  • About
    • About Us
    • CERT-In Empanelled Cybersecurity Auditor
    • Awards & Recognition
    • Our Customers
  • Services

    Peregrine

    • Managed Detection & Response
    • AI Managed SOC Services
    • Elastic Stack Consulting
    • CrowdStrike Consulting
    • Threat Hunting Services
    • Digital Risk Protection Services
    • Threat Intelligence Services
    • Digital Forensics Services
    • Brand Risk & Dark Web Monitoring
    • Full Stack Observability

    Pinpoint

    • Red Teaming Services
    • Vulnerability Assessment
    • Penetration Testing Services 
    • Secure Code Review Services
    • Cloud Security Assessment
    • Phishing Simulation Services
    • Breach and Attack Simulation Services

    MSP247

    • 24 X 7 Managed Cloud Services
    • Cloud Security Implementation
    • Disaster Recovery Consulting
    • Security Patching Services
    • WAF Services

    nCompass

    • SBOM Management Tool
    • Cybersecurity Audit Services
    • Virtual CISO Services
    • DPDP Act Consulting
    • ISO 27001 Consulting
    • RBI Master Direction Compliance
    • SEBI CSCRF Framework Consulting
    • SEBI Cloud Framework Consulting
    • Security Awareness Training
    • Cybersecurity Staffing Services
  • Industries
    • Banking
    • Financial Services
    • Insurance
  • Resources
    Blogs
    Case Studies
    Downloads
    Whitepapers
    Buyer’s Guide
    Research & Guides
  • Careers
  • Contact

Data Breach Notification under DPDPA: Rule 7 Timelines, DPB Reporting and Penalties

4 min read
2 Views
  • DPDPA

In September 2024, a hacker using the alias “xenZen” made the personal data of approximately 31 million Star Health policyholders accessible through Telegram chatbots, as reported by Reuters. Medical reports, insurance claims, ID cards and tax details were being distributed freely. Affected individuals found out when journalists showed them their own records. Star Health had not notified them.

Under India’s DPDP Rules, 2025, that silence now carries a penalty of up to ₹200 crore. Data breach notification under DPDPA is a structured legal obligation with two recipients, defined timelines and no threshold below which reporting is not required. Every personal data breach, regardless of scale or severity, triggers the same dual obligation: notify the Data Protection Board of India (DPB) and notify affected individuals.

This blog breaks down exactly what Rule 7 requires, what each notification must contain and what your team needs to build before enforcement begins.

Table of Contents

What is a personal data breach under DPDPA?

Section 2 of the DPDP Act defines a personal data breach as any unauthorised processing or accidental disclosure, alteration, loss or destruction of personal data that compromises its confidentiality, integrity or availability.

The scope is broad. A misconfigured cloud storage bucket, a ransomware attack encrypting customer records or a phishing compromise exposing employee data – all of these qualify. Deliberate attacks and accidental exposure are treated equally. There is no distinction based on how the breach occurred.

How Rule 7 structures the data breach notification India obligation

Rule 7 of the DPDP Rules, 2025 divides your notification process into two parallel streams: one directed at the DPB, and one directed at affected Data Principals (individuals whose personal data was breached). The five steps below capture the full operational flow for completing data breach notification under DPDPA.

5 Steps to Complete Data Breach Notification under DPDPA

Detect and confirm the breach

Identify the nature, scope and affected systems as quickly as possible. Record the exact detection timestamp. This is the moment the regulatory clock starts for all downstream obligations.

Send initial intimation to the DPB/Notify the DPB

Notify the Data Protection Board without delay upon confirmation. This is a preliminary report, not a full investigation output. It must include a description of the breach, the categories and approximate number of affected Data Principals, likely consequences and the initial steps taken to contain the incident.

Notify affected Data Principals

Without any delay, inform each affected individual through their registered communication channel – email, SMS or in-app notification. The notice must be written in plain language. It must describe what happened, which data was involved and what protective steps the individual should take immediately.

Submit the 72-hour detailed report to the DPB

Within 72 hours of becoming aware of the breach, submit a complete report to the DPB. This expands on the initial intimation and must include root cause, affected systems, data categories involved, detection timeline, volume of records, remediation actions taken and steps to prevent recurrence.

Update the DPB as the investigation develops

If new facts emerge, additional affected records, revised timelines or newly identified responsible parties, the filed report must be updated to reflect current findings.

Why no materiality threshold changes your compliance posture

Most global frameworks, including GDPR – require breach notification only when an incident is likely to pose risk to individuals. DPDPA removes that filter entirely.

Every unauthorised or accidental personal data exposure is reportable under the Act. A single-record incident carries the same notification obligation as a large-scale exfiltration. This shifts the operational question from “is this significant enough to report?” to “how fast can we detect, assess and notify?”

Continuous detection capability becomes the foundation of any data breach notification framework and not just a reactive breach response capability activated after the damage is done.

Penalties for failing to notify

The DPDP Act Schedule sets the penalty for non-compliance with Section 8(6) at up to ₹200 crore per incident. This covers both the failure to notify the DPB and the failure to notify affected Data Principals.

Unjustified delays may be treated as non-compliance and attract regulatory action. Incomplete or inaccurate notifications attract additional regulatory scrutiny from the DPB. The penalty framework applies regardless of whether the failure was deliberate or not – there is no intent-based defence.

Conclusion

The Star Health incident showed what a notification gap looks like in practice: millions of individuals whose most sensitive data was circulating publicly and who had no idea. Under DPDPA, that gap is now a defined legal violation with a ₹200 crore penalty attached.

Data breach notification under DPDPA requires immediate DPB intimation, parallel Data Principal notification and a full detailed report within 72 hours – for every breach, at every scale. Meeting the data breach reporting requirements under this framework requires detection infrastructure, documentation workflows and notification readiness built well ahead of May 13, 2027.

At CyberNX, our DPDPA consulting team helps organisations design and operationalise end-to-end breach response frameworks – from detection architecture and SIEM configuration to DPB submission workflows and Data Principal notification systems. Connect with our experts to build your data breach notification under DPDPA programme before enforcement begins.

Data breach notification under DPDPA FAQs

Does every breach need to be reported under DPDPA, even minor ones?

Yes. The DPDP Act carries no materiality threshold. Every personal data breach-regardless of the number of individuals affected or the severity of the exposure – triggers the full dual notification obligation under Rule 7. You must notify the DPB and affected Data Principals for every qualifying incident without exception.

What is the timeline for data breach notification under DPDPA?

Rule 7 requires an initial intimation to the DPB without delay upon detection. A detailed report must follow within 72 hours. Affected data principals must be notified without undue delay, in parallel with the DPB process. There is no fixed hour count for Data Principal notification, but any delay is subject to regulatory scrutiny.

What are the penalties for failing to meet data breach reporting requirements India mandates under DPDPA?

Under Section 8(6) of the DPDP Act, failure to notify the Data Protection Board or affected Data Principals can attract a penalty of up to ₹200 crore per incident. Delay and incomplete notifications are treated as non-compliance and attract direct scrutiny from the DPB.

Author
Krishnakant Mathuria
LinkedIn

With 12+ years in the ICT & cybersecurity ecosystem, Krishnakant has built high-performance security teams and strengthened organisational resilience by leading effective initiatives. His expertise spans regulatory and compliance frameworks, security engineering and secure software practices. Known for uniting technical depth with strategic clarity, he advises enterprises on how to modernise their security posture, align with evolving regulations, and drive measurable, long-term security outcomes.

Share on

WhatsApp
LinkedIn
Facebook
X
Pinterest

For Customized Plans Tailored to Your Needs, Get in Touch Today!

Connect with us

RESOURCES

Related Blogs

Explore our resources section for insightful blogs, articles, infographics and case studies, covering everything in Cyber Security.
DPDPA Compliance for GCCs and IT/ITES Companies

DPDPA Compliance for GCCs and IT/ITES Companies: What You Need to Know

Conversations about the Digital Personal Data Protection Act (DPDPA) usually orbit around banks, fintechs and e-commerce platforms. That’s understandable because

DPDP Act 2023 Logging Solution: Rule 6 and Rule 8 Requirements

Logging Solution as per DPDP Act 2023: What Rule 6 and Rule 8 Require

With the DPDP Rules now in effect, every organisation that processes personal data of Indian citizens carries active compliance obligations

Building a DPDPA Reporting Template That Holds Up Under Audit

Your DPDPA Reporting Template Is Not Ready – Here’s How to Fix

The DPDP Rules, 2025 are now in force. Reporting obligations are real, and as you might know, penalties are steep.

RESOURCES

Cyber Security Knowledge Hub

Explore our resources section for insightful blogs, articles, infographics and case studies, covering everything in Cyber Security.

BLOGS

Stay informed with the latest cybersecurity trends, insights, and expert tips to keep your organization protected.

CASE STUDIES

Explore real-world examples of how CyberNX has successfully defended businesses and delivered measurable security improvements.

DOWNLOADS

Learn about our wide range of cybersecurity solutions designed to safeguard your business against evolving threats.
CyberNX Footer Logo
Book a Free Call

Peregrine

  • Managed Detection & Response
  • AI Managed SOC Services
  • Elastic Stack Consulting
  • CrowdStrike Consulting
  • Threat Hunting Services
  • Digital Risk Protection Services
  • Threat Intelligence Services
  • Digital Forensics Services
  • Brand Risk & Dark Web Monitoring
  • Full Stack Observability

Pinpoint

  • Red Teaming Services
  • Vulnerability Assessment
  • Penetration Testing Services
  • Secure Code Review Services
  • Cloud Security Assessment
  • Phishing Simulation Services
  • Breach and Attack Simulation Services

MSP247

  • 24 X 7 Managed Cloud Services
  • Cloud Security Implementation
  • Disaster Recovery Consulting
  • Security Patching Services
  • WAF Services

nCompass

  • SBOM Management Tool
  • Cybersecurity Audit Services
  • Virtual CISO Services
  • DPDP Act Consulting
  • ISO 27001 Consulting
  • RBI Master Direction Compliance
  • SEBI CSCRF Framework Consulting
  • SEBI Cloud Framework Consulting
  • Security Awareness Training
  • Cybersecurity Staffing Services
  • About
  • CERT-In
  • Awards
  • Careers
  • Sitemap
Facebook Twitter Instagram Youtube

Copyright © 2026 CyberNX | All Rights Reserved | Terms and Conditions | Privacy Policy

  • English
Copyright © 2026 CyberNX | All Rights Reserved | Terms and Conditions | Privacy Policy
Scroll to Top

WhatsApp us

Not Sure Where to Start with Cybersecurity?

We value your privacy. Your personal information is collected and used only for legitimate business purposes in accordance with our Privacy Policy.