Breach Notifications

Breach Notification, Report to DPA Within 72 Hours. Automatically.

Section 8(6) of the DPDP Act mandates notification to the Data Protection Authority within 72 hours of discovering a breach. Miss that window and face penalties up to ₹250 Crore. dcomply automates the entire response, countdown timer, evidence collection, DPA notification report generation, and data principal communication, so your team responds correctly under pressure.

Try the live product
72-hour countdown auto-tracked Rule 7 DPA report generated Complete evidence audit trail
ACTIVE BREACH INCIDENT Critical
BRN-2026-0007
DPA Notification Deadline 31:14:08
hrs : min : sec remaining
Breach TypeUnauthorized Access. DB
Individuals Affected~14,200
DPA ReportGenerated ✓
Principal NoticePending Review
Section 8(6) DPDP + Rule 7 compliant response workflow
Regulatory Context

Section 8(6), Rule 7, and ₹250 Crore. The Regulatory Stakes

A data breach is already a crisis. A missed 72-hour notification window turns a security incident into a compliance catastrophe.

Section 8(6). 72-Hour Notification Obligation

Section 8(6) of the DPDP Act requires every Data Fiduciary to notify the DPA of a personal data breach "as soon as practicable" after becoming aware. Rule 7 sets this at 72 hours from discovery. The notification must be submitted in the DPA's prescribed format, not an ad-hoc email. Organizations that wait for full forensic investigation before notifying are already in violation. The clock starts at discovery, not at confirmation.

Rule 7. DPA Notification Format Requirements

Rule 7 of the DPDP Rules 2025 prescribes the mandatory content of a DPA breach notification: breach nature, categories and number of individuals affected, categories and number of data records affected, DPO/grievance officer contact details, likely consequences, and measures taken or proposed. A notification that omits any of these elements is non-compliant, even if it was submitted within 72 hours. dcomply's DPA report template is pre-structured to Rule 7 requirements, filling in what you've documented during incident response.

DPDP Schedule. ₹250 Crore Penalty

Failure to notify the DPA of a breach within the prescribed timeline carries penalties up to ₹250 Crore, the highest tier in the DPDP Schedule, equivalent to the penalty for failing to implement security safeguards entirely. This is not a fine for the breach itself, it is a separate and additional penalty for the failure to notify. An organization that experiences a breach and then misses the notification deadline faces double jeopardy: the breach penalty and the notification failure penalty.

Core Capabilities

Everything Your Team Needs to Respond Correctly Under Pressure

72-Hour Countdown with Visual Alerts

The moment you log an incident, the countdown timer starts from your documented discovery timestamp. The dashboard shows hours:minutes:seconds remaining. At 48 hours remaining, a yellow alert is triggered. At 24 hours, red critical alert. At 12 hours, email and SMS escalation to the DPO and CISO. The countdown is immutable, it records the moment you created the incident record, providing an audit trail for when your organization "became aware."

Rule 7 DPA Notification Report Generator

One click generates a complete DPA notification report pre-filled with your documented incident details, breach nature, affected individuals count, data categories, your DPO contact, consequences assessed, and remediation steps taken. The report format matches Rule 7 requirements exactly. You review it, sign it, and submit. The generation timestamp and your approval are recorded as part of the compliance evidence trail.

Data Principal Notification Templates

For breaches affecting sensitive personal data (health, financial, Aadhaar, biometric), data principals must also be notified under Section 8(6). dcomply generates a data principal notification letter, in plain language as required, specifying what data was affected, what the risk is, and what actions they should take. You can customize the letter before sending, and the system tracks how many individuals were notified and when, critical evidence for demonstrating complete DPDP compliance.

Structured Incident Response Workflow

A five-stage workflow guides your team through the complete response: Suspected (investigation ongoing) → Investigating → Contained → Notifying → Closed. Every status transition is timestamped and attributed to a named user. The workflow ensures no stage is skipped and each stage has mandatory fields, you cannot close an incident without documenting the DPA notification status and the remediation measures taken.

Complete Incident Timeline and Audit Trail

Every action taken during incident response is automatically recorded in an immutable timeline: who logged the breach and when; each status change; notes added; templates generated; notifications sent; DPA reference number recorded. This timeline is the primary evidence in any DPA investigation, it shows that your organization responded systematically, promptly, and in good faith. The timeline is available as a formatted PDF or JSON export.

Personal Data Impact Assessment

Structured data impact form captures: breach type (unauthorized access, accidental disclosure, ransomware, insider threat, physical theft, vendor breach), data categories affected (Aadhaar, PAN, financial account data, health records, biometric data, contact details), estimated number of records, systems impacted, and geographical scope. This impact assessment drives both the notification report content and the remediation priority matrix.

How It Works

Structured Response From Discovery to DPA Notification. Before the Clock Runs Out

A breach is the worst time to figure out your response plan. Set it up before you need it. Use it confidently when you do.

Step 1. Log the incident immediately upon discovery

The moment your IT team, security monitoring system, or a staff member identifies a potential breach, log it in dcomply. Enter the discovery timestamp (when awareness began, not when you're sure), a brief description, and initial severity assessment. The 72-hour countdown clock starts immediately and is recorded against this timestamp. Even logging a "suspected breach" is sufficient and legally protective, it documents that you responded promptly.

Step 2. Complete the personal data impact assessment

Fill in the structured impact form: breach type, what systems were affected, what personal data categories were involved, estimated number of individuals affected, and whether sensitive data categories (Aadhaar, health records, financial data) are implicated. This form can be updated as the investigation progresses, the system retains all versions with timestamps, showing the evolution of your understanding of the incident.

Step 3. Document containment and remediation actions

Record every containment step taken: systems isolated, credentials rotated, vendor access revoked, patches applied, backup restoration initiated. Document the timeline of each action. These actions are critical for two reasons: they demonstrate your organization took immediate steps to limit the breach, and they pre-populate the "measures taken" section of the DPA notification, which is a Rule 7 mandatory field.

Step 4. Generate and send DPA notification report

With the impact assessment and containment documentation complete, generate the Rule 7 DPA notification report. Review the pre-filled report for accuracy, add any supplementary details, and submit. Record the DPA reference number when you receive it. If submitting an initial notification within 72 hours with supplementary information to follow, the system tracks both submissions and their timing for the compliance record.

Step 5. Notify affected data principals and close with full evidence package

Generate data principal notifications for affected individuals, plain language, specifying what happened and what they should do. Track notification count and dispatch date. Once all notifications are sent and remediation is complete, close the incident. The system generates a complete evidence package: the incident timeline, impact assessment, containment log, DPA notification with reference number, data principal notifications, and a final incident report, formatted for DPA submission, board reporting, or ISO 27001 audit evidence.

Use Cases by Industry

Breach Response Challenges Vary by Sector

IT Teams. After-Hours Incident Discovery

Security incidents don't follow business hours. When a breach is detected at 2 AM by an automated alert, the on-call engineer needs a structured, guided response, not a blank page.

  • Mobile-accessible breach logging with guided intake form
  • Automatic escalation to DPO and CISO when incident is logged
  • 72-hour clock visible immediately, no ambiguity about deadline
  • Structured response checklist prevents missed steps under pressure
Healthcare. Patient Data Breach Response

Patient health data is among the most sensitive personal data under DPDP. Healthcare organizations face both DPDP obligations and sector-specific health data protection requirements.

  • Pre-configured health data impact assessment categories (EMR, diagnostics, biometric)
  • Patient notification templates in plain language
  • Simultaneous DPDP + CERT-In notification tracking
  • NHSP incident reporting documentation support
FinTechs. Payment Data Incident Response

Payment data breaches affect financial account details, UPI credentials, and card data, triggering DPDP notification obligations alongside RBI incident reporting requirements.

  • Financial data breach categories: UPI, banking credentials, card data, account numbers
  • Parallel tracking for DPDP (DPA) and RBI (CISO office) notifications
  • CERT-In 6-hour reporting coordination alongside DPDP 72-hour window
  • Customer fraud risk alert communication templates
What's Included

Complete Breach Notification Feature List

72-hour countdown timer from discovery timestamp
Rule 7 DPA notification report generator (pre-filled from incident data)
Data principal notification letter generator (plain language)
Structured personal data impact assessment (data categories + affected count)
Five-stage incident workflow (Suspected → Investigating → Contained → Notifying → Closed)
Immutable incident timeline with timestamps and user attribution
Multi-regulator notification tracking (DPDP, CERT-In, RBI, IRDAI)
DPA reference number recording and confirmation tracking
Data principal notification count and dispatch date tracking
Containment actions documentation with timestamps
Complete evidence package PDF export on incident close
Email and SMS escalation at 48h, 24h, and 12h remaining
Suspected breach status (clock starts, investigation can continue)
Management briefing and internal incident report templates
Integration & Technical Details

Breach Response That Connects Your Security and Compliance Teams

Connected to dcomply Security Modules

When the Risk Register or Vendor Risk module identifies a critical security incident involving personal data, it can automatically create a breach record in the notification module, starting the 72-hour clock immediately. The Phishing Tracker module flags credential compromise incidents for potential breach assessment. This integration means the 72-hour window starts at the right moment, not when someone manually creates a record hours later.

Webhook Alerts and SIEM Integration

REST API for creating breach incidents from external systems. SIEM platforms, security monitoring tools, and vulnerability scanners can auto-create breach records when their thresholds are breached. Webhook support sends real-time notifications to Slack, Microsoft Teams, and PagerDuty when a breach is created or moves into critical countdown territory. API documentation available in the developer portal on Enterprise plans.

Incident Data Security and Retention

Breach incident records, including impact assessments and notification letters, are encrypted at rest (AES-256) and in transit (TLS 1.3). Access to breach records is role-controlled, security engineers can log incidents, but only DPO and Compliance Manager roles can approve and send DPA notifications. Breach records are retained for 7 years, exceeding the DPDP's standard retention expectation, to support long-tail regulatory inquiries.

FAQ

Frequently Asked Questions About DPDP Breach Notification

Under Section 8(6) of the DPDP Act, a personal data breach is any unauthorized processing of personal data, or accidental disclosure, acquisition, sharing, use, alteration, destruction, or loss of access to personal data. This covers: ransomware attacks, unauthorized employee access to customer records, accidental emails to the wrong recipient containing personal data, third-party vendors exposing your data through their misconfiguration, and physical theft of devices containing personal data. Even suspected breaches where you are not yet certain whether data was accessed should be treated as potential breaches for the purpose of starting your 72-hour clock.

The 72-hour clock starts from the moment your organization 'becomes aware' of a breach. 'Becoming aware' means when a responsible person in your organization has reasonable grounds to believe a breach has occurred, not when it is fully investigated or confirmed. If your IT security team informs your CISO at 3 PM Tuesday that there has been a possible unauthorized access, the clock starts at 3 PM Tuesday. dcomply records the 'discovery timestamp' when you log the incident, creating an immutable record of when awareness began, protecting you if the discovery time is questioned later.

Rule 7 of the DPDP Rules 2025 prescribes the mandatory notification content: (a) nature of the breach; (b) categories and approximate number of individuals affected; (c) categories and approximate number of personal data records affected; (d) contact details of the DPO or grievance officer; (e) likely consequences of the breach; (f) measures taken or proposed to address the breach. If all information is not available within 72 hours, you may submit an initial notification with available information and supplement it subsequently, but the initial notification must be made within the 72-hour window. dcomply's template is pre-structured to Rule 7 requirements.

Yes, under certain conditions. Section 8(6) of the DPDP Act also requires notifying affected data principals when a breach is 'likely to affect' their rights and interests. The threshold for individual notification is separate from DPA notification, you may need to notify individuals even for relatively minor breaches affecting sensitive personal data (health records, financial data, Aadhaar details). dcomply generates both a DPA notification letter and a data principal communication template simultaneously, with separate tracking for how many individuals were notified and when.

Uncertainty is the most common state in the first hours of a security incident. The DPDP Act does not require certainty before the 72-hour clock starts, it requires action once you 'become aware' of a possible breach. dcomply's system handles this with a 'suspected breach' status that starts the 72-hour clock while investigation is ongoing. If investigation confirms no breach occurred, you close the record as a false positive with investigation documentation. It is significantly safer to log a suspected breach and close it as a false positive than to delay logging and later discover the clock started earlier than you thought.

Failure to notify the DPA of a personal data breach within the prescribed timeline carries penalties up to ₹250 Crore under the DPDP Schedule, the highest tier in the Act. This is a separate and additional penalty to any penalty for the breach itself. A delayed or inadequate notification is evidence of poor breach response governance, which typically increases the penalty quantum when the DPA exercises its discretion. Organizations that notify promptly, comprehensively, and with documented evidence of their response historically receive significantly lower penalties than those that delay notification while hoping the breach goes undetected.

Be Ready to Respond. Before a Breach Happens

The 72-hour window starts the moment you discover a breach. Set up your response workflow now, when there's no pressure. Use it with confidence when there is.

Try the live product