A breach is never just one problem. It is a technical problem and a people problem at the same time. For many Indian companies, a breach can trigger separate cybersecurity and data-protection duties – with different deadlines, recipients and information requirements.
Think of it this way. The CERT-In Directions ask what happened to your systems. The DPDPA asks what happened to your customers’ data. Answer only the first and you leave a privacy gap behind a clean security filing. Answer only the second and you have missed the tighter of the two deadlines.
This guide breaks down DPDPA vs CERT-In Directions across four things: the trigger, the timeline, the recipients and the evidence. You will also see which duty is enforceable today.
Two rulebooks, one incident
The CERT-In Directions were issued on Apr 28, 2022 under Section 70B of the Information Technology Act, 2000. They apply to service providers, intermediaries, data centres, body corporates and government organisations. The purpose is national cyber resilience.
The Digital Personal Data Protection Act, 2023 (DPDPA) works from the opposite end. Section 8(6) requires every Data Fiduciary to inform the Data Protection Board of India and each affected Data Principal about a personal data breach. Rule 7 of the DPDP Rules, 2025 sets out the manner and the timelines.
DPDPA vs CERT-In directions: Key differences
Both duties can start from the same alert. What they demand after that diverges quickly.
Trigger
CERT-In responds to a notified cyber security incident: unauthorised access, ransomware, data leaks, denial of service attacks and attacks on critical systems. Personal data does not have to be involved.
DPDPA responds to a personal data breach, meaning any unauthorised processing, accidental disclosure, loss or destruction of personal data. No attacker is required.
Timelines
CERT-In requires covered entities to report specified cyber incidents within six hours of noticing the incident or being informed of it.
DPDPA works in two stages: an initial intimation to the Board without delay, then a detailed report within 72 hours of becoming aware. Affected individuals must be told without delay as well.
Recipients
CERT-In reporting goes to one government team in a prescribed format. It stays between you and the regulator.
DPDPA reporting goes to the Board and to every affected Data Principal. Rule 7 does not establish a minimum number of affected individuals or a separate materiality threshold for triggering the breach-intimation duty.
Evidence
CERT-In is oriented toward the technical incident: its category, affected systems, indicators of compromise and logs on request. The Directions also require ICT system clocks to be synchronised with NIC/NPL or traceable NTP servers.
DPDPA wants a data narrative: what was affected, roughly how many people, the likely consequences, what you did about it and how you reached those people.
Overlaps and exceptions
This is where response plans usually break. One filing does not cover both, and a privacy breach is not always a security incident. Four examples show why:
- Denial of service attack on your customer portal: Service drops, no data is exposed. CERT-In incident reporting applies. DPDPA does not
- Employee sends a customer list to the wrong recipient: DPDPA breach notification may apply, and CERT-In reporting should also be assessed because the CERT-In Directions include data breaches and data leaks among reportable cyber incidents
- Ransomware on a database holding customer KYC records: Both may apply. Their respective reporting clocks should be calculated from the awareness/notice trigger applicable under each framework.
- Vendor misconfigures a cloud bucket holding your customer data: Both apply, and as the Data Fiduciary you stay accountable for the notification
So triage needs two questions, not one. Was this a notifiable cyber incident? Was personal data touched? The answers are independent.
Compliance timeline for Indian enterprises
Timing is where a lot of published guidance has gone stale. CERT-In incident reporting has been enforceable since Jun 2022. It applies to you right now.
The DPDP Rules, 2025 were notified in Nov 2025 with a phased rollout. Governance provisions took effect immediately, Consent Manager registration follows at 12 months, and the core Data Fiduciary obligations, including Rule 7 breach reporting, take effect 18 months from notification in May 2027. Until then, Section 43A of the IT Act and the SPDI Rules, 2011 continue to apply.
Regulated entities have less breathing room. For RBI-regulated entities, the RBI’s revised Guidelines on Reporting of Unusual Cyber Incidents, effective February 1, 2024, require initial reporting of applicable unusual cyber incidents to RBI within six hours of detection, with reporting through the DAKSH portal for entities onboarded to it.
Building a single breach response
The answer is not two playbooks. It is one intake process with two outputs. Five things make that work:
- A precise incident timeline: Record detection, escalation and awareness timestamps so each regulatory deadline can be calculated from the trigger applicable to that framework.
- Evidence that survives scrutiny: The 180-day log retention and clock synchronisation CERT-In already requires are what let you reconstruct scope for a DPDP breach notification
- Pre-approved templates: A technical filing for CERT-In and a plain language notice for individuals, both written before the incident
- Named owners with deputies: Security, legal, compliance and communications, with cover for weekends and leave
- Rehearsal: A tabletop exercise that ends with both filings drafted, not just with containment
Conclusion
DPDPA and the CERT-In Directions are not competing frameworks. They create distinct reporting obligations that can overlap during the same incident. Six-hour reporting requirements already apply under CERT-In and, where applicable, while the DPDP breach-notification regime adds another layer when Rule 7 takes effect in May 2027.
As a CERT-In empanelled cybersecurity auditor, we help Indian enterprises align detection, logging and reporting across both regimes. If DPDPA vs CERT-In Directions has become a board level question for your organisation, our DPDP Act consulting team can assess your readiness and build the playbook with you. Talk to our experts and let us help you build a process you trust.
DPDPA vs CERT-In Directions FAQs
What is the difference between DPDPA and CERT-In Directions?
CERT-In Directions cover cyber security incidents and require reporting within six hours of detection. DPDPA covers personal data breaches and requires reporting to the Data Protection Board of India plus every affected individual.
Does DPDP breach notification replace CERT-In reporting?
No. The duties run in parallel under different laws. CERT-In reporting sits under Section 70B of the IT Act, 2000. DPDP breach notification sits under Section 8(6) of the DPDPA read with Rule 7 of the DPDP Rules, 2025.
When do DPDPA breach reporting duties become enforceable?
The DPDP Rules, 2025 follow a phased timeline. Data Fiduciary obligations, including Rule 7 breach reporting, take effect 18 months from notification in May 2027. CERT-In reporting has been enforceable since Jun 2022.
What counts as a personal data breach under DPDPA?
Any unauthorised processing, accidental disclosure, sharing, alteration, loss or destruction of personal data that compromises its confidentiality, integrity or availability. Human error, a misconfigured system or an insider action all qualify.




