Data breach notification under DPDP: the 72-hour rule
Updated 19 Sep 2026 · 5min read · Reviewed by ConsentLo's DPDP audit team
Under the DPDP Act every personal data breach must be reported, both to the Data Protection Board of India and to each affected person. There is no "low risk" exemption. Here is how the process works.
What counts as a personal data breach
Any unauthorised processing, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data that compromises its confidentiality, integrity or availability. A misdirected email with customer details counts, as does ransomware.
Who to tell, and when
Two clocks start when you become aware of the breach:
- Affected Data Principals: without delay, in clear language, covering what happened, likely consequences, what you are doing and what they can do.
- The Data Protection Board: an initial intimation without delay, then a detailed report within 72 hours covering facts, cause, mitigation, and the people affected.
Preparing before it happens
Decide in advance who can declare an incident, who approves the notices, and how you will reach every affected person. Keep draft templates ready, and log every containment step with timestamps: the Board will ask.
How ConsentLo helps
ConsentLo starts both clocks the moment a breach is logged, drafts the Board report and the principal notice from the facts you record, requires human approval before anything is sent, sends notices in batches, and keeps the whole trail as evidence.
Frequently asked questions
Is there a threshold below which a breach need not be reported?
No. The DPDP Act requires every personal data breach to be reported to the Board and to affected Data Principals, with no materiality threshold.
What is the penalty for not reporting a breach?
Failing to notify the Board or affected Data Principals can attract a penalty of up to ₹200 crore.
Does CERT-In reporting replace DPDP breach reporting?
No. CERT-In's cyber incident reporting obligations continue separately. A breach may need to be reported to both.