Breach Notification, Report to DPA Within 72 Hours. Automatically.
Section 8(6) of the DPDP Act mandates notification to the Data Protection Authority within 72 hours of discovering a breach. Miss that window and face penalties up to ₹250 Crore. dcomply automates the entire response, countdown timer, evidence collection, DPA notification report generation, and data principal communication, so your team responds correctly under pressure.
Section 8(6), Rule 7, and ₹250 Crore. The Regulatory Stakes
A data breach is already a crisis. A missed 72-hour notification window turns a security incident into a compliance catastrophe.
Section 8(6). 72-Hour Notification Obligation
Section 8(6) of the DPDP Act requires every Data Fiduciary to notify the DPA of a personal data breach "as soon as practicable" after becoming aware. Rule 7 sets this at 72 hours from discovery. The notification must be submitted in the DPA's prescribed format, not an ad-hoc email. Organizations that wait for full forensic investigation before notifying are already in violation. The clock starts at discovery, not at confirmation.
Rule 7. DPA Notification Format Requirements
Rule 7 of the DPDP Rules 2025 prescribes the mandatory content of a DPA breach notification: breach nature, categories and number of individuals affected, categories and number of data records affected, DPO/grievance officer contact details, likely consequences, and measures taken or proposed. A notification that omits any of these elements is non-compliant, even if it was submitted within 72 hours. dcomply's DPA report template is pre-structured to Rule 7 requirements, filling in what you've documented during incident response.
DPDP Schedule. ₹250 Crore Penalty
Failure to notify the DPA of a breach within the prescribed timeline carries penalties up to ₹250 Crore, the highest tier in the DPDP Schedule, equivalent to the penalty for failing to implement security safeguards entirely. This is not a fine for the breach itself, it is a separate and additional penalty for the failure to notify. An organization that experiences a breach and then misses the notification deadline faces double jeopardy: the breach penalty and the notification failure penalty.
Everything Your Team Needs to Respond Correctly Under Pressure
72-Hour Countdown with Visual Alerts
The moment you log an incident, the countdown timer starts from your documented discovery timestamp. The dashboard shows hours:minutes:seconds remaining. At 48 hours remaining, a yellow alert is triggered. At 24 hours, red critical alert. At 12 hours, email and SMS escalation to the DPO and CISO. The countdown is immutable, it records the moment you created the incident record, providing an audit trail for when your organization "became aware."
Rule 7 DPA Notification Report Generator
One click generates a complete DPA notification report pre-filled with your documented incident details, breach nature, affected individuals count, data categories, your DPO contact, consequences assessed, and remediation steps taken. The report format matches Rule 7 requirements exactly. You review it, sign it, and submit. The generation timestamp and your approval are recorded as part of the compliance evidence trail.
Data Principal Notification Templates
For breaches affecting sensitive personal data (health, financial, Aadhaar, biometric), data principals must also be notified under Section 8(6). dcomply generates a data principal notification letter, in plain language as required, specifying what data was affected, what the risk is, and what actions they should take. You can customize the letter before sending, and the system tracks how many individuals were notified and when, critical evidence for demonstrating complete DPDP compliance.
Structured Incident Response Workflow
A five-stage workflow guides your team through the complete response: Suspected (investigation ongoing) → Investigating → Contained → Notifying → Closed. Every status transition is timestamped and attributed to a named user. The workflow ensures no stage is skipped and each stage has mandatory fields, you cannot close an incident without documenting the DPA notification status and the remediation measures taken.
Complete Incident Timeline and Audit Trail
Every action taken during incident response is automatically recorded in an immutable timeline: who logged the breach and when; each status change; notes added; templates generated; notifications sent; DPA reference number recorded. This timeline is the primary evidence in any DPA investigation, it shows that your organization responded systematically, promptly, and in good faith. The timeline is available as a formatted PDF or JSON export.
Personal Data Impact Assessment
Structured data impact form captures: breach type (unauthorized access, accidental disclosure, ransomware, insider threat, physical theft, vendor breach), data categories affected (Aadhaar, PAN, financial account data, health records, biometric data, contact details), estimated number of records, systems impacted, and geographical scope. This impact assessment drives both the notification report content and the remediation priority matrix.
Structured Response From Discovery to DPA Notification. Before the Clock Runs Out
A breach is the worst time to figure out your response plan. Set it up before you need it. Use it confidently when you do.
Step 1. Log the incident immediately upon discovery
The moment your IT team, security monitoring system, or a staff member identifies a potential breach, log it in dcomply. Enter the discovery timestamp (when awareness began, not when you're sure), a brief description, and initial severity assessment. The 72-hour countdown clock starts immediately and is recorded against this timestamp. Even logging a "suspected breach" is sufficient and legally protective, it documents that you responded promptly.
Step 2. Complete the personal data impact assessment
Fill in the structured impact form: breach type, what systems were affected, what personal data categories were involved, estimated number of individuals affected, and whether sensitive data categories (Aadhaar, health records, financial data) are implicated. This form can be updated as the investigation progresses, the system retains all versions with timestamps, showing the evolution of your understanding of the incident.
Step 3. Document containment and remediation actions
Record every containment step taken: systems isolated, credentials rotated, vendor access revoked, patches applied, backup restoration initiated. Document the timeline of each action. These actions are critical for two reasons: they demonstrate your organization took immediate steps to limit the breach, and they pre-populate the "measures taken" section of the DPA notification, which is a Rule 7 mandatory field.
Step 4. Generate and send DPA notification report
With the impact assessment and containment documentation complete, generate the Rule 7 DPA notification report. Review the pre-filled report for accuracy, add any supplementary details, and submit. Record the DPA reference number when you receive it. If submitting an initial notification within 72 hours with supplementary information to follow, the system tracks both submissions and their timing for the compliance record.
Step 5. Notify affected data principals and close with full evidence package
Generate data principal notifications for affected individuals, plain language, specifying what happened and what they should do. Track notification count and dispatch date. Once all notifications are sent and remediation is complete, close the incident. The system generates a complete evidence package: the incident timeline, impact assessment, containment log, DPA notification with reference number, data principal notifications, and a final incident report, formatted for DPA submission, board reporting, or ISO 27001 audit evidence.
Breach Response Challenges Vary by Sector
IT Teams. After-Hours Incident Discovery
Security incidents don't follow business hours. When a breach is detected at 2 AM by an automated alert, the on-call engineer needs a structured, guided response, not a blank page.
- Mobile-accessible breach logging with guided intake form
- Automatic escalation to DPO and CISO when incident is logged
- 72-hour clock visible immediately, no ambiguity about deadline
- Structured response checklist prevents missed steps under pressure
Healthcare. Patient Data Breach Response
Patient health data is among the most sensitive personal data under DPDP. Healthcare organizations face both DPDP obligations and sector-specific health data protection requirements.
- Pre-configured health data impact assessment categories (EMR, diagnostics, biometric)
- Patient notification templates in plain language
- Simultaneous DPDP + CERT-In notification tracking
- NHSP incident reporting documentation support
FinTechs. Payment Data Incident Response
Payment data breaches affect financial account details, UPI credentials, and card data, triggering DPDP notification obligations alongside RBI incident reporting requirements.
- Financial data breach categories: UPI, banking credentials, card data, account numbers
- Parallel tracking for DPDP (DPA) and RBI (CISO office) notifications
- CERT-In 6-hour reporting coordination alongside DPDP 72-hour window
- Customer fraud risk alert communication templates
Complete Breach Notification Feature List
Breach Response That Connects Your Security and Compliance Teams
Connected to dcomply Security Modules
When the Risk Register or Vendor Risk module identifies a critical security incident involving personal data, it can automatically create a breach record in the notification module, starting the 72-hour clock immediately. The Phishing Tracker module flags credential compromise incidents for potential breach assessment. This integration means the 72-hour window starts at the right moment, not when someone manually creates a record hours later.
Webhook Alerts and SIEM Integration
REST API for creating breach incidents from external systems. SIEM platforms, security monitoring tools, and vulnerability scanners can auto-create breach records when their thresholds are breached. Webhook support sends real-time notifications to Slack, Microsoft Teams, and PagerDuty when a breach is created or moves into critical countdown territory. API documentation available in the developer portal on Enterprise plans.
Incident Data Security and Retention
Breach incident records, including impact assessments and notification letters, are encrypted at rest (AES-256) and in transit (TLS 1.3). Access to breach records is role-controlled, security engineers can log incidents, but only DPO and Compliance Manager roles can approve and send DPA notifications. Breach records are retained for 7 years, exceeding the DPDP's standard retention expectation, to support long-tail regulatory inquiries.
Frequently Asked Questions About DPDP Breach Notification
Breach Response Is the Last Line. Build the Others First
Be Ready to Respond. Before a Breach Happens
The 72-hour window starts the moment you discover a breach. Set up your response workflow now, when there's no pressure. Use it with confidence when there is.