Choose Language
Google Translate
Skip to content
Facebook X-twitter Instagram Linkedin Youtube
  • sales@cybernx.com
  • +91 90823 52813
CyberNX Logo
  • Home
  • About
    • About Us
    • CERT-In Empanelled Cybersecurity Auditor
    • Awards & Recognition
    • Our Customers
  • Services

    Peregrine

    • Managed Detection & Response
    • AI Managed SOC Services
    • Elastic Stack Consulting
    • CrowdStrike Consulting 
    • Threat Hunting Services
    • Digital Risk Protection Services
    • Threat Intelligence Services
    • Digital Forensics Services
    • Brand Risk & Dark Web Monitoring
    • Full Stack Observability

    Pinpoint

    • Red Teaming Services
    • Vulnerability Assessment
    • Penetration Testing Services
    • Secure Code Review Services
    • Cloud Security Assessment
    • Phishing Simulation Services
    • Breach and Attack Simulation Services

    nCompass

    • Cybersecurity Audit Services
    • Virtual CISO Services
    • DPDP Act Consulting
    • ISO 27001 Consulting
    • RBI Master Direction Compliance
    • SEBI CSCRF Framework Consulting
    • SEBI Cloud Framework Consulting
    • Security Awareness Training
    • Cybersecurity Staffing Services

    NXRadar

    • SBOM Solutions
    • CBOM Solutions
    • AIBOM Solutions
  • Industries
    • Banking
    • Financial Services
    • Insurance
  • Resources
    Blogs
    Case Studies
    Downloads
    Whitepapers
    Buyer’s Guide
    Research & Guides
  • Careers
  • English (US)
    • English
Contact Us
CyberNX Logo
  • English (US)
    • English
  • Home
  • About
    • About Us
    • CERT-In Empanelled Cybersecurity Auditor
    • Awards & Recognition
    • Our Customers
  • Services

    Peregrine

    • Managed Detection & Response
    • AI Managed SOC Services
    • Elastic Stack Consulting
    • CrowdStrike Consulting
    • Threat Hunting Services
    • Digital Risk Protection Services
    • Threat Intelligence Services
    • Digital Forensics Services
    • Brand Risk & Dark Web Monitoring
    • Full Stack Observability

    Pinpoint

    • Red Teaming Services
    • Vulnerability Assessment
    • Penetration Testing Services 
    • Secure Code Review Services
    • Cloud Security Assessment
    • Phishing Simulation Services
    • Breach and Attack Simulation Services

    nCompass

    • Cybersecurity Audit Services
    • Virtual CISO Services
    • DPDP Act Consulting
    • ISO 27001 Consulting
    • RBI Master Direction Compliance
    • SEBI CSCRF Framework Consulting
    • SEBI Cloud Framework Consulting
    • Security Awareness Training
    • Cybersecurity Staffing Services

    NXRadar

    • SBOM Solutions
    • CBOM Solutions
    • AIBOM Solutions
  • Industries
    • Banking
    • Financial Services
    • Insurance
  • Resources
    Blogs
    Case Studies
    Downloads
    Whitepapers
    Buyer’s Guide
    Research & Guides
  • Careers
  • Contact

DPDPA vs CERT-In Directions: What Changes for Your Breach Response

4 min read
8 Views
  • DPDPA

A breach is never just one problem. It is a technical problem and a people problem at the same time. For many Indian companies, a breach can trigger separate cybersecurity and data-protection duties – with different deadlines, recipients and information requirements.

Think of it this way. The CERT-In Directions ask what happened to your systems. The DPDPA asks what happened to your customers’ data. Answer only the first and you leave a privacy gap behind a clean security filing. Answer only the second and you have missed the tighter of the two deadlines.

This guide breaks down DPDPA vs CERT-In Directions across four things: the trigger, the timeline, the recipients and the evidence. You will also see which duty is enforceable today.

Table of Contents

Two rulebooks, one incident

The CERT-In Directions were issued on Apr 28, 2022 under Section 70B of the Information Technology Act, 2000. They apply to service providers, intermediaries, data centres, body corporates and government organisations. The purpose is national cyber resilience.

The Digital Personal Data Protection Act, 2023 (DPDPA) works from the opposite end. Section 8(6) requires every Data Fiduciary to inform the Data Protection Board of India and each affected Data Principal about a personal data breach. Rule 7 of the DPDP Rules, 2025 sets out the manner and the timelines.

DPDPA vs CERT-In directions: Key differences

Both duties can start from the same alert. What they demand after that diverges quickly.

DPDPA vs CERT-In directions: Two Reporting Clocks

Trigger

CERT-In responds to a notified cyber security incident: unauthorised access, ransomware, data leaks, denial of service attacks and attacks on critical systems. Personal data does not have to be involved.

DPDPA responds to a personal data breach, meaning any unauthorised processing, accidental disclosure, loss or destruction of personal data. No attacker is required.

Timelines

CERT-In requires covered entities to report specified cyber incidents within six hours of noticing the incident or being informed of it.

DPDPA works in two stages: an initial intimation to the Board without delay, then a detailed report within 72 hours of becoming aware. Affected individuals must be told without delay as well.

Recipients

CERT-In reporting goes to one government team in a prescribed format. It stays between you and the regulator.

DPDPA reporting goes to the Board and to every affected Data Principal. Rule 7 does not establish a minimum number of affected individuals or a separate materiality threshold for triggering the breach-intimation duty.

Evidence

CERT-In is oriented toward the technical incident: its category, affected systems, indicators of compromise and logs on request. The Directions also require ICT system clocks to be synchronised with NIC/NPL or traceable NTP servers.

DPDPA wants a data narrative: what was affected, roughly how many people, the likely consequences, what you did about it and how you reached those people.

Overlaps and exceptions

This is where response plans usually break. One filing does not cover both, and a privacy breach is not always a security incident. Four examples show why:

  • Denial of service attack on your customer portal: Service drops, no data is exposed. CERT-In incident reporting applies. DPDPA does not
  • Employee sends a customer list to the wrong recipient: DPDPA breach notification may apply, and CERT-In reporting should also be assessed because the CERT-In Directions include data breaches and data leaks among reportable cyber incidents
  • Ransomware on a database holding customer KYC records: Both may apply. Their respective reporting clocks should be calculated from the awareness/notice trigger applicable under each framework.
  • Vendor misconfigures a cloud bucket holding your customer data: Both apply, and as the Data Fiduciary you stay accountable for the notification

So triage needs two questions, not one. Was this a notifiable cyber incident? Was personal data touched? The answers are independent.

Compliance timeline for Indian enterprises

Timing is where a lot of published guidance has gone stale. CERT-In incident reporting has been enforceable since Jun 2022. It applies to you right now.

The DPDP Rules, 2025 were notified in Nov 2025 with a phased rollout. Governance provisions took effect immediately, Consent Manager registration follows at 12 months, and the core Data Fiduciary obligations, including Rule 7 breach reporting, take effect 18 months from notification in May 2027. Until then, Section 43A of the IT Act and the SPDI Rules, 2011 continue to apply.

Regulated entities have less breathing room. For RBI-regulated entities, the RBI’s revised Guidelines on Reporting of Unusual Cyber Incidents, effective February 1, 2024, require initial reporting of applicable unusual cyber incidents to RBI within six hours of detection, with reporting through the DAKSH portal for entities onboarded to it.

Building a single breach response

The answer is not two playbooks. It is one intake process with two outputs. Five things make that work:

  • A precise incident timeline: Record detection, escalation and awareness timestamps so each regulatory deadline can be calculated from the trigger applicable to that framework.
  • Evidence that survives scrutiny: The 180-day log retention and clock synchronisation CERT-In already requires are what let you reconstruct scope for a DPDP breach notification
  • Pre-approved templates: A technical filing for CERT-In and a plain language notice for individuals, both written before the incident
  • Named owners with deputies: Security, legal, compliance and communications, with cover for weekends and leave
  • Rehearsal: A tabletop exercise that ends with both filings drafted, not just with containment

Conclusion

DPDPA and the CERT-In Directions are not competing frameworks. They create distinct reporting obligations that can overlap during the same incident. Six-hour reporting requirements already apply under CERT-In and, where applicable, while the DPDP breach-notification regime adds another layer when Rule 7 takes effect in May 2027.

As a CERT-In empanelled cybersecurity auditor, we help Indian enterprises align detection, logging and reporting across both regimes. If DPDPA vs CERT-In Directions has become a board level question for your organisation, our DPDP Act consulting team can assess your readiness and build the playbook with you. Talk to our experts and let us help you build a process you trust.

DPDPA vs CERT-In Directions FAQs

What is the difference between DPDPA and CERT-In Directions?

CERT-In Directions cover cyber security incidents and require reporting within six hours of detection. DPDPA covers personal data breaches and requires reporting to the Data Protection Board of India plus every affected individual.

Does DPDP breach notification replace CERT-In reporting?

No. The duties run in parallel under different laws. CERT-In reporting sits under Section 70B of the IT Act, 2000. DPDP breach notification sits under Section 8(6) of the DPDPA read with Rule 7 of the DPDP Rules, 2025.

When do DPDPA breach reporting duties become enforceable?

The DPDP Rules, 2025 follow a phased timeline. Data Fiduciary obligations, including Rule 7 breach reporting, take effect 18 months from notification in May 2027. CERT-In reporting has been enforceable since Jun 2022.

What counts as a personal data breach under DPDPA?

Any unauthorised processing, accidental disclosure, sharing, alteration, loss or destruction of personal data that compromises its confidentiality, integrity or availability. Human error, a misconfigured system or an insider action all qualify.

Author
Krishnakant Mathuria
LinkedIn

With 12+ years in the ICT & cybersecurity ecosystem, Krishnakant has built high-performance security teams and strengthened organisational resilience by leading effective initiatives. His expertise spans regulatory and compliance frameworks, security engineering and secure software practices. Known for uniting technical depth with strategic clarity, he advises enterprises on how to modernise their security posture, align with evolving regulations, and drive measurable, long-term security outcomes.

Share on

WhatsApp
LinkedIn
Facebook
X
Pinterest

For Customized Plans Tailored to Your Needs, Get in Touch Today!

Connect with us

RESOURCES

Related Blogs

Explore our resources section for insightful blogs, articles, infographics and case studies, covering everything in Cyber Security.
DPDPA and ISO 27001: What an ISMS Certificate Leaves Out

DPDPA and ISO 27001: What Your Certificate Does Not Cover

Picture your last board review: the ISO 27001 certificate is renewed and the audit closed without a major non-conformity. But

pharmaceutical manufacturing environment with connected clinical

CrowdStrike Falcon for Healthcare and Pharma: Compliance Alignment

A compliance officer at a hospital group asked us a question last year: she wanted to know which specific clause

How to Conduct a DPIA under DPDPA: A Practical Methodology

How to Conduct a DPIA under DPDPA: A Step-by-Step Methodology

Picture a bank two weeks from launching a lending app. To score applicants faster, it will pull income records, location

RESOURCES

Cyber Security Knowledge Hub

Explore our resources section for insightful blogs, articles, infographics and case studies, covering everything in Cyber Security.

BLOGS

Stay informed with the latest cybersecurity trends, insights, and expert tips to keep your organization protected.

CASE STUDIES

Explore real-world examples of how CyberNX has successfully defended businesses and delivered measurable security improvements.

DOWNLOADS

Learn about our wide range of cybersecurity solutions designed to safeguard your business against evolving threats.
CyberNX Footer Logo
Book a Free Call

Peregrine

  • Managed Detection & Response
  • AI Managed SOC Services
  • Elastic Stack Consulting
  • CrowdStrike Consulting
  • Threat Hunting Services
  • Digital Risk Protection Services
  • Threat Intelligence Services
  • Digital Forensics Services
  • Brand Risk & Dark Web Monitoring
  • Full Stack Observability

Pinpoint

  • Red Teaming Services
  • Vulnerability Assessment
  • Penetration Testing Services
  • Secure Code Review Services
  • Cloud Security Assessment
  • Phishing Simulation Services
  • Breach and Attack Simulation Services

nCompass

  • Cybersecurity Audit Services
  • Virtual CISO Services
  • DPDP Act Consulting
  • ISO 27001 Consulting
  • RBI Master Direction Compliance
  • SEBI CSCRF Framework Consulting
  • SEBI Cloud Framework Consulting
  • Security Awareness Training
  • Cybersecurity Staffing Services

NXRadar

  • SBOM Solutions
  • CBOM Solutions
  • AIBOM Solutions
  • About
  • CERT-In
  • Awards
  • Careers
  • Sitemap
Facebook Twitter Instagram Youtube

Copyright © 2026 CyberNX | All Rights Reserved | Terms and Conditions | Privacy Policy

  • English (US)
    • English
Copyright © 2026 CyberNX | All Rights Reserved | Terms and Conditions | Privacy Policy
Scroll to Top

WhatsApp us

Not Sure Where to Start with Cybersecurity?

We value your privacy. Your personal information is collected and used only for legitimate business purposes in accordance with our Privacy Policy.