Hands of a compliance lead resting on an open blank notebook beside a steel cup of chai on a dark meeting room table late in the evening

DPDP breach notification India: the 72-hour drill that failed

A 190-person diagnostics chain in Hyderabad ran a breach drill on a Thursday morning. They contained the incident in eleven minutes. They still could not have filed the report.

Hands of a compliance lead resting on an open blank notebook beside a cup of chai on a dark meeting room table late in the evening
The drill was not about stopping the breach. It was about what you write down afterwards, and how fast.
The short version

DPDP breach notification in India gives you 72 hours to file a report, not to repair the breach. Rule 7 of the Digital Personal Data Protection Rules, 2025 asks for the facts and causes, the mitigation you ran, your findings on who or what was responsible, the steps taken against a repeat, and a summary of what you told the affected people.

Two things break this for mid-market firms. The clock starts when you become aware, and almost nobody has written down what awareness means or who is allowed to declare it. And the report needs scope, whose data and how many people and which fields, which is an inventory question rather than a security one.

A separate CERT-In reporting clock runs ahead of all of it, at six hours from noticing. Most firms learn that ordering during the incident, which is the wrong afternoon to learn it.

10:05 AM on a Thursday, and the scenario I handed across the table was one page long. A diagnostics chain in Hyderabad, 190 staff, eleven collection centres, patient test reports scanned into a shared folder so referring doctors could pull them without ringing the lab. The scenario said the sharing link on that folder had been sitting at anyone-with-the-link, and someone outside the company had opened it. That was all. No attacker, no ransom note.

Sandhya, who runs IT there, read the page twice and asked whether that was the whole thing. Achha, I said. That is the whole thing. Now show me the seventy-two hours.

We have run this drill with enough Indian mid-market teams now that I can predict the shape of the failure before the room starts. The security part goes fine. The paperwork is where it falls over, because the paperwork rests on a list nobody built.

The first ninety minutes were the best part

They were good. Sandhya had the link killed in eleven minutes by the wall clock. The folder went private, the platform tokens were rotated, the access log was exported before anyone touched settings, a ticket was raised with a real severity on it, and the COO knew inside twenty minutes.

This is the part Indian IT teams are genuinely good at, and I want to say so before I say the rest. Everybody has practised turning something off. Nobody practises writing.

By 11:35 the whiteboard had a clean containment timeline on it. Someone brought chai. It had gone thanda by the time anybody drank it, because that was the moment Ramesh, who runs operations, asked his question.

Then Ramesh asked whose data it was

How many patients, he said. And which ones.

The room went quiet in a way I have heard before. Sandhya pulled the platform log back up. It showed one external session, the duration, and a count of files opened in it. It did not show which files. The folder itself had been accumulating since a migration two years earlier, and no one in the building could say how many reports were inside it, or which patients, or which fields travelled with each report. Name, phone number, referring doctor, test result. Health data, in other words, which is the category you least want to be vague about.

Somebody said we will have to check. That sentence is completely reasonable on a Thursday morning. It is fatal on a filing. Rule 7 also asks you to intimate each affected data principal, without delay, in clear language, describing the nature and extent and timing of the breach and what it is likely to mean for that person. You cannot write to people you cannot name.

The real bottleneck
Containment is a security capability. Scope is an inventory capability. The seventy-two hours gets consumed almost entirely by scope, and scope cannot be bought during an incident. It is built on a quiet Tuesday, months earlier, by someone with a spreadsheet and no urgency.

The clock had started on Tuesday

Halfway down the scenario page, in a line most rooms skim, sat the detail that decided the drill. A monitoring alert had flagged unusual external access on the folder on Tuesday evening. The night shift had reviewed it and closed it as a false positive.

So when I asked the room when they became aware, Thursday stopped being defensible. The answer was arguably Tuesday, at 9:40 in the evening, when a named person looked at an alert about personal data being reached by someone outside the company. Theek hai, said Sandhya, after a pause I will not forget. Then we are already a day and a half in.

I want to be honest about a mistake, because the mistake is the lesson. I wrote that scenario. I also wrote the trigger clause in this client’s incident response plan a year earlier, and my clause said the notification timeline begins on a confirmed breach. Confirmed by whom, and inside how long. I had left the most expensive word in the document undefined and signed it off, and no auditor had pulled me up on it, because auditors read for presence and not for teeth.

Awareness is a decision somebody has to be authorised to make. Leave nobody authorised and a regulator makes it for you later, working backwards through your own logs.

What the 72-hour report actually asks you to hand over

Pin this above a desk. There are four obligations running on three different timers, and they go to three different places.

ObligationWhenGoes toWhat it must contain
CERT-In cyber incident reportWithin six hours of noticing, or of being toldCERT-InIncident type, affected systems, a brief description, contact details
Intimation to affected peopleWithout delay, on becoming awareEach affected data principalNature, extent, timing and location of the breach, likely consequences for them, what you are doing about it, what they should do, and who to contact
First intimation to the BoardWithout delay, on becoming awareData Protection Board of IndiaNature, extent, timing and location of the breach, and its likely impact
Detailed report to the BoardWithin 72 hours (Rule 7), or longer if the Board allows it on a written requestData Protection Board of IndiaBroad facts and causes, mitigation done and planned, findings on who or what was responsible, remedial steps against recurrence, and a summary of the intimations you sent

Timings above follow the Digital Personal Data Protection Rules, 2025 and the CERT-In directions of 28 April 2022.

The last row is the expensive one. Findings on who or what was responsible. Inside seventy-two hours you are expected to have done enough root cause work to hold a finding rather than a theory. That is an investigation with a deadline stapled to it. It runs at the same time as the letters going out to patients.

What a miss is priced at
Section 8(6) of the Digital Personal Data Protection Act, 2023 carries the intimation duty, and the Schedule prices a failure to give that intimation at up to ₹200 crore. The Rules were notified on 13 November 2025 in phases, and Rule 7 lands on 13 May 2027. Today this is a drill. In roughly nine months it is a filing.

The wider compliance calendar behind that date, the consent manager work and the retention side, we set out in a Mumbai bank’s notification-day plan. If you sit in a regulated sector, the sequencing question of which circular wins is covered in what IRDAI and RBI expect on DPDP.

Running this drill yourself

Five steps. The order matters more than the tooling, and the first two cost nothing but attention.

Define awareness in one sentence, with a named role attached. Something a night-shift technician can apply at two in the morning. Awareness begins when any person on this list has reason to believe personal data has been accessed by someone not entitled to it. Not confirmed. Reason to believe.

Build the scope answer before you need it. Which systems hold personal data, which fields, whose, and how you would produce a per-person list. This is the same exercise as a data mapping day at an NBFC, and it is the step most firms skip because it produces no dashboard.

Put both clocks in one runbook. The six-hour CERT-In report does not wait politely while you assemble your DPDP paperwork, and the two get written by the same two people at the same desk.

Pre-write the intimation letter. It has a fixed shape and a fixed set of contents. Draft it on a calm day, get it read by whoever handles your customer communication, and keep it where the on-call person can find it at midnight.

Then rehearse the report and not the containment. Timebox the drill so the room gets fifteen minutes on stopping the bleed and spends the rest on the document. That is where the gaps are, and it is why we run these as a paperwork exercise rather than a red team.

Then the objection, usually from the CFO rather than the compliance head. Enforcement is not live yet, we will deal with it later. Enforcement timing is a gamble, and even before a single fine, your clients’ RFPs are already starting to ask about it. Later is more expensive and more panicked, which is the only reliable thing about later.

And the quieter one, from the founder. We have not had a breach, so why spend on this at all. Most companies have not had a breach they know about, which is a different sentence from not having had one. The Tuesday alert in that scenario was not invented for effect. It is the most common shape I see in real access logs, and it is usually closed by someone with four minutes and nowhere to escalate.

The tooling question comes last. Discovery and data-movement monitoring, the part that answers whose data and which fields, sits in Secure Data Guard. The device side matters more than people expect here, because a returned laptop that left the building unwiped is a breach nobody has an alert for. That belongs with device lifecycle management, and if you are buying 50 or more machines this year, ask us about DaaS while you are at it.

Where our pitch loses, and I would rather say it here than in a proposal. If you already run a staffed SOC with a written incident classification policy and a live data inventory, you do not need Sirius Star for the runbook. Ask us for the endpoint and data-movement layer instead, or do not ask us at all.

What to take away

  1. The seventy-two hours is for the report, not the repair. By the deadline you owe the Board causes, mitigation, a finding on responsibility, remedial steps, and a summary of what you told affected people.
  2. Define awareness or a regulator will define it for you. Name the roles who can declare it, use reason to believe rather than confirmed, and put a maximum review time on every alert that touches personal data.
  3. Scope eats the window. Containment took eleven minutes. Whose data and how many people had no answer at all, and that is an inventory built months earlier, not a tool bought during the incident.
  4. Two regulators, two clocks. CERT-In at six hours runs before anything DPDP asks for. One runbook, both timers, same two people.
  5. Pre-write the letter to the data principal. Its contents are fixed by the Rules. Drafting it under pressure is how firms end up promising things they have not verified.

Two words in this piece, in plain English

DPDP Act 2023
India’s national data protection law. If your business holds personal information about people in India, names, phone numbers, ID numbers, medical results, the Act sets out what you may do with it and what you owe those people. The Rules under it, notified in November 2025, add the operating detail, including the breach intimation timings in this article.
DaaS, or Device-as-a-Service
Renting your laptops instead of buying them. One monthly cost per device covers supply, support, replacement and a certified wipe when the machine comes back. It matters to this topic because an unwiped laptop leaving the building is a data breach with nobody watching for it.

Questions Sandhya wishes she had asked on Tuesday

When does the DPDP 72-hour clock actually start?

On becoming aware of the personal data breach, not on confirming it and not on finishing your investigation. That is why the definition of awareness matters more than any tool you buy. Write down which roles can declare awareness, define it as having reason to believe personal data was accessed by someone not entitled to it, and cap how long an alert about personal data can sit in review. Leave it undefined and the date gets reconstructed later from your own logs, and it will be earlier than you would like.

Do we report to CERT-In and the Data Protection Board separately?

Yes. They are separate obligations under separate laws with different timings. The CERT-In directions under the IT Act require reporting of listed cyber incidents within six hours of noticing them or being told about them. The DPDP Rules require intimation to the Data Protection Board without delay, then a detailed report within 72 hours (Rule 7). A folder exposure that leaks patient records can trigger both. Build one runbook that fires both, because the same two people will be writing both under the same pressure.

What if we cannot identify which people were affected inside seventy-two hours?

You still file, and you file what you know along with the mitigation and the responsibility finding. The problem is that the duty to intimate each affected data principal does not go away because your inventory is weak. It moves the failure from a missed deadline to an incomplete notification, which is the harder one to explain. The Board can allow a longer period for the detailed report on a written request with reasons, but treat that as an exception you may not get rather than a plan.

Is DPDP breach notification already enforceable in India?

Not yet, and the date is close enough to matter. The Rules were notified on 13 November 2025 with a phased commencement. Data Protection Board provisions took effect immediately, consent manager provisions from November 2026, and the substantive obligations including breach intimation from 13 May 2027. What is already live is commercial pressure. Enterprise and BFSI clients are putting breach notification questions into vendor RFPs now, well ahead of the statutory date.

P.S. Priya here.
In the debrief somebody made a joke about the night-shift technician who closed the Tuesday alert. Sandhya stopped it flat. She said the queue gives him about four minutes an alert, and no way to escalate at two in the morning without waking a director who does not want to be woken. Bas. He did not misread the alert. The process gave him nowhere to put it. Fix the queue before you fix the person, and your awareness clause will hold on the night it is tested.
Free readiness check
Get a free DPDP breach-notification readiness check

We run the paperwork drill against your estate, pressure-test your awareness definition, and hand you a one-page runbook that fires the CERT-In and DPDP clocks together with the intimation letter already drafted.

Get my free breach-notification readiness check

Free. A short form, then we get back to you within 24 working hours. 200+ Indian businesses work with us, from Vashi, Navi Mumbai.

Timings and contents above are drawn from the Digital Personal Data Protection Rules, 2025 and the CERT-In directions of 28 April 2022 as they stood at the time of writing, and the commencement dates follow the phased notification of 13 November 2025. Confirm the current text and any amendment before relying on a date. The Hyderabad engagement is one anonymised client drill, not a published benchmark. This is a practitioner note on operating practice, not legal advice.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *