Share 💬 💼
DPDP

Data Breach — How to Respond in 72 Hours: Step-by-Step Plan + Templates

📅 Apr 02, 2026
👤 Adv. Deepak Kumar
⏱️ 20 min read
📂 DPDP
Data Breach — How to Respond in 72 Hours: Step-by-Step Plan + Templates
Your legal clock starts the moment a breach is discovered. DPDPA Rule 6 requires notification to the Data Protection Board and all affected individuals — with ₹200 crore penalty for silence and ₹250 crore for the underlying breach. This operational playbook covers every action from Hour 0 containment to Board notification to individual user notices — with fill-in-the-blank templates for every document you need to complete.
🚨 BREACH DISCOVERED? START HERE
Your legal clock started the moment you discovered the breach.
Under DPDPA + Rule 6, you must notify the Data Protection Board. Penalty for silence: ₹200 crore. This guide is your operational plan — work through it in order, right now.
⏰ Hour 0–6
Contain & assess
🔔 Hour 6–24
Escalate & notify Board
📢 Hour 24–72
Notify affected users
📋 Post-72hrs
Document & remediate
DPDPA Rule 6 — Mandatory Breach Response + Notification

A data breach is discovered at 11 pm. Your DBA calls — the customer database has been exfiltrated. Or your CEO's laptop is stolen at an airport. Or a phishing attack has given an attacker access to your HR system for six days before anyone noticed. In every one of these scenarios, the DPDP Act, 2023 and Rule 6 of the DPDP Rules 2025 impose mandatory notification obligations — to the Data Protection Board and to every affected individual — within defined timelines. The penalty for failing to notify: up to ₹200 crore. The penalty for the underlying breach: up to ₹250 crore. This guide is not an article to read when you have time. It is an operational playbook to execute the moment a breach is discovered. Every section has a fill-in-the-blank template. Print it. Save it. And share the link with your CISO and legal team today — before you need it.

₹250 Cr
For breach of data security safeguards — the underlying security failure
₹200 Cr
For failure to notify the Data Protection Board — the concealment penalty
₹50 Cr
Per failure to notify affected individuals — multiplied by number of individuals
Rule 6
DPDP Rules 2025 — the operative notification rule. Format prescribed. No discretion on whether to notify.

Before You Start: Is This a Notifiable Breach?

Not every security incident is a notifiable breach. Before triggering the 72-hour plan, make this determination — quickly. DPDPA Section 8(6) and Rule 6 apply to any "personal data breach" — defined as any breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.

Incident Type Notifiable? Why
Hacker exfiltrates customer database YES Unauthorised access to and disclosure of personal data. Both Board and individuals must be notified.
Ransomware encrypts servers (data not confirmed exfiltrated) YES Unauthorised access occurred when the attacker entered the system. The breach is the access — not the confirmed exfiltration. Cannot assume no data was taken.
Employee laptop stolen — contained personal data YES Loss of device containing personal data = unauthorised potential disclosure. Notifiable even if the thief was after the hardware, not the data.
Employee accidentally emails customer list to wrong recipient YES Accidental unauthorised disclosure of personal data. The Act does not require malicious intent — accidental breaches are equally notifiable.
Third-party vendor suffers breach affecting your customer data YES You are the Data Fiduciary. Your vendor is your Data Processor. Their breach of your data is your breach obligation to notify. The vendor must notify you — you then notify the Board.
Misconfigured database publicly exposed — no evidence of access LIKELY YES Even without confirmed access, an open database is an unauthorised potential disclosure. Err on the side of notification — the penalty for silence is far greater than the cost of over-notification.
DDoS attack — no data accessed or exfiltrated LIKELY NO If the DDoS caused only downtime with no access to or loss of personal data, this is a security incident but not a personal data breach. Document the determination.
Properly encrypted laptop stolen — encryption key not compromised LIKELY NO If data was encrypted at rest and the encryption key is intact and uncompromised, the stolen device does not expose readable personal data. Document and monitor.

The golden rule: When in doubt, treat it as notifiable. The penalty for failing to notify a breach (₹200 crore) vastly exceeds any reputational cost from a transparent notification. The Data Protection Board will consider your good-faith notification effort when assessing penalties for the underlying breach. Concealment eliminates all mitigating factors and adds the full ₹200 crore notification penalty on top.

Step 0 (Do This First): Appoint Your Incident Commander

Before any technical or legal action begins, one person must take command. The Incident Commander has decision-making authority for the duration of the response. Everyone else reports to them. No decisions by committee during an active breach.

📋
FILL IN NOW — Incident Command Record
Complete within 30 minutes of breach discovery
Breach Discovery Date & Time
[ Date ] at [ Time ] IST
Who Discovered It
[ Name ] — [ Role ]
Incident Commander (IC) — Name
[ Full Name ]
IC Contact (Available 24/7 During Response)
[ Mobile ] — [ Email ]
Technical Lead
[ CISO / Head of IT ] — [ Contact ]
Legal Lead (Internal or External Counsel)
[ Advocate / GC ] — [ Contact ]
Communications Lead (Internal + External)
[ PR / Corp Comms ] — [ Contact ]
Grievance Officer (DPDPA Contact Point)
[ Name ] — [ Email ]
Critical rule: All breach communications between team members must be kept on a separate, secure channel (encrypted messaging, not company email which may be compromised). All communications are potentially discoverable in litigation — keep them factual, not speculative. No "this is going to be catastrophic" emails. Facts only.
Hour 0 to Hour 6
Contain the breach · Assess scope · Preserve evidence · Notify leadership
Clock starts
at discovery

Action 1: Immediate Technical Containment

The first technical priority is to stop the bleeding — prevent further data from being accessed, exfiltrated, or destroyed. This must happen simultaneously with, not before, evidence preservation.

☑ Containment Checklist — Complete within 2 hours

Action 2: Rapid Breach Assessment — Fill In This Form Now

📋 BREACH ASSESSMENT RECORD — Complete within 3 hours
This document forms the basis of your Board notification. Every field must be completed as accurately as possible — "unknown" is acceptable; blank is not.
Nature of the breach (tick all that apply)
Estimated date/time breach first occurred
[ Date ] at [ Time ] (or "Unknown — investigating")
Date/time breach was discovered
[ Date ] at [ Time ] IST
Systems / databases / files affected
[ e.g. Customer MySQL database on AWS RDS instance, customer_db — production environment ]
Categories of personal data potentially affected (tick all)
Estimated number of individuals affected
[ Number ] or "Under investigation — estimated [range]"
Who are the affected individuals?
[ e.g. Registered customers / employees / users of [product] ]
Likely consequences for affected individuals
Immediate containment measures already taken
[ Describe what has been done to stop further data exposure ]

Action 3: Notify Leadership and Legal Counsel — Within 2 Hours

Who must be notified within the first 2 hours
🔔
Hour 6 to Hour 24
Prepare Board notification · Engage forensics · Internal escalation complete
₹200 Cr
if you stay silent

Action 4: Prepare the Board Notification — The Rule 6 Report

Rule 6 of the DPDP Rules 2025 prescribes the format and content of the notification to the Data Protection Board. This must be filed as soon as practically possible — the longer you delay after discovery without a legitimate reason, the more the Board will view it as concealment rather than investigation. "We needed more time to understand the breach" is accepted for the first 24 hours. It becomes increasingly difficult to justify beyond 48 hours without demonstrated active investigation effort.

📋 RULE 6 BOARD NOTIFICATION — Fill-in-the-Blank Template
File this with the Data Protection Board through the Board's official portal (once operational) or by written notice to the Board's registered address.

TO: The Chairperson, Data Protection Board of India

[ Board's official address / portal ]

From (Data Fiduciary):

Company Name: [ Full Registered Name of Company ]

CIN / Registration Number: [ CIN ]

Registered Address: [ Full Address ]

Nature of Business: [ Brief description — e.g. e-commerce platform / healthcare provider / financial services ]

Contact for this notification: [ Grievance Officer Name ] — [ Email ] — [ Phone ]

1. Nature and Description of the Breach

On [ Date ] at approximately [ Time ] IST, [ Company Name ] became aware of a [ nature of breach — e.g. unauthorised access to / exfiltration of / accidental disclosure of ] personal data. The breach [ was discovered by / was reported to us by ] [ who — e.g. our security monitoring system / a third-party researcher / our vendor ] when [ describe how it was discovered ]. We believe the breach [ occurred on / began on / has been ongoing since ] approximately [ date or "unknown — under investigation" ].

2. Categories of Personal Data Affected

The personal data potentially affected includes: [ list — e.g. names, email addresses, phone numbers, encrypted passwords, and/or Aadhaar numbers / financial data / health data — delete as applicable ]. The data was [ stored in / processed by ] [ system name ] [ located at / hosted on ] [ location / cloud provider and region ].

3. Approximate Number of Data Principals Affected

We estimate that approximately [ number ] Data Principals [ have been / may have been ] affected. This estimate is [ based on our initial assessment of the affected database / preliminary and subject to revision as our investigation continues ]. [ If unknown: "The precise number is not yet known — our investigation is ongoing and we will update this notification as information becomes available." ]

4. Likely Consequences of the Breach

Based on our current assessment, the likely consequences for affected Data Principals include: [ describe — e.g. risk of phishing attacks using their email address and name / risk of identity fraud if Aadhaar data is misused / financial fraud risk from exposed bank data ]. [ Where no harm is currently assessed: "Based on our current assessment, the risk to Data Principals is [ low / unknown — under investigation ] because [ reason — e.g. the exposed data did not include financial or identity information ]." ]

5. Measures Taken and Proposed

We have taken the following immediate measures to address the breach: [ list — e.g. (a) isolated the affected system from our network at [ time ]; (b) revoked all active sessions on the affected platform; (c) engaged a forensic investigation firm [ name ] to conduct a full investigation; (d) forced password resets for all affected users; (e) notified our cyber insurer and filed a First Information Report (FIR) with [ police station ] on [ date ] ].

We propose the following additional measures: [ list — e.g. (a) complete forensic audit by [ estimated date ]; (b) notification to affected Data Principals by [ planned date ]; (c) implementation of additional security controls including [ list ] by [ date ] ].

6. Contact for Further Information

We are committed to full cooperation with the Data Protection Board and will provide any additional information or documentation requested. Our designated contact for this matter is:
[ Grievance Officer / Data Protection Lead Name ] | [ Title ] | [ Email ] | [ Phone ] | Available [ hours ]

Signed: [ Authorised Signatory Name ]

Designation: [ CEO / MD / GC / DPO ]

Date: [ Date of Notification ]

Action 5: Engage a Forensic Investigator — Within 12 Hours

A qualified digital forensic investigator must be engaged to: (a) determine the exact entry point and method, (b) establish the timeline of the attack, (c) confirm what data was accessed or exfiltrated, (d) collect evidence in a forensically sound manner that will hold up if litigation follows, and (e) produce a forensic report that can be submitted to the Board if required. Do not attempt to investigate internally if you do not have qualified forensic capability — contaminated evidence is worse than no evidence. Engage an external forensic firm. Contact your legal counsel for referrals.
Forensic Firm Engaged
[ Firm Name ] — [ Contact ]
Expected Preliminary Report By
[ Date ] at [ Time ]
📢
Hour 24 to Hour 72
Notify affected Data Principals · Police FIR · Ongoing investigation
₹50 Cr per person
if you stay silent

Action 6: Notify Affected Data Principals

Under DPDPA Section 8(6), every individual whose data was involved in the breach must be notified. The notification must be clear, in plain language, and must tell them what happened, what data was affected, what the likely consequences are, and what they should do. Use the template below — adapt for your specific breach facts.

📧 DATA PRINCIPAL NOTIFICATION — Template (Email / SMS / In-App / WhatsApp)
Send to all confirmed affected individuals. Use the fastest available channel — email for most users, SMS for those without email. WhatsApp broadcast only if you have prior consent for WhatsApp communication.

Subject: Important notice regarding the security of your personal data — [ Company Name ]


Dear [ Name / Valued Customer ],

We are writing to inform you of a security incident involving [ Company Name ] that may have affected some of your personal data. We want to be fully transparent with you about what happened, what data was involved, and what we are doing about it.

What happened:

On [ date ], we discovered that [ brief description of breach in plain language — e.g. an unauthorised third party gained access to a portion of our customer database / a laptop containing customer records was stolen / a system misconfiguration made some customer data accessible to the internet for approximately X hours ]. We immediately took steps to secure our systems and are conducting a thorough investigation with the assistance of cybersecurity experts.

What information was involved:

The personal information that may have been accessed or exposed includes: [ specific list — e.g. your name and email address / your name, email address, and phone number / your name, email, and encrypted password (note: your password was encrypted and cannot be directly read) ]. [ Be specific — avoid "some information" — if you genuinely do not know, say so: "We are still investigating the precise extent of the data involved and will update you as our investigation progresses." ]

What information was NOT involved:

[ Your payment card details / bank account information / Aadhaar / government ID numbers ] were NOT part of the affected data. [ This is important to state if true — it limits panic and demonstrates transparency. ]

What we are doing:

We have:

  • Secured the affected systems immediately upon discovery
  • Engaged independent cybersecurity forensic experts to investigate fully
  • Notified the Data Protection Board of India as required by law
  • [ Any other specific steps taken ]

What you should do:

  • [ If passwords were exposed: ] Change your password on our platform immediately, and change it on any other site where you used the same password.
  • Be alert to phishing emails or messages claiming to be from [ Company Name ] or other organisations. We will never ask for your password, OTP, or bank details by email or SMS.
  • [ If financial data was exposed: ] Monitor your bank statements and immediately report any suspicious transactions to your bank.
  • If you notice any suspicious activity related to your account or identity, contact us immediately at [ contact ].

How to reach us:

If you have questions or concerns about this incident, please contact our Grievance Officer at:
[ Grievance Officer Name ] | [ Email address ] | [ Phone ] | Available [ hours ]
We are committed to responding to all enquiries within 48 hours.

We sincerely apologise for this incident and for any concern it may cause. The security and privacy of your personal data is our responsibility and we take this matter extremely seriously.

Sincerely,
[ CEO Name ]
[ Company Name ]
[ Date ]

Action 7: File FIR with Police — Recommended Within 24 Hours

Filing an FIR with the local cybercrime police station serves multiple purposes: it demonstrates good faith to the Data Protection Board, creates a contemporaneous record of the breach discovery timeline, may trigger law enforcement assistance in identifying attackers, and can be relevant in insurance claims. File the FIR at the cybercrime police station with jurisdiction over your registered office or the affected systems' location.

Police Station
[ Cybercrime PS Name + Address ]
FIR Number (once filed)
[ FIR No. ] dated [ Date ]
CERT-In Notification
CERT-In requires notification within 6 hours of discovery for most cyber incidents. File at incident@cert-in.org.in
📋
Post-72 Hours — Sustained Response
Investigation · Board follow-up · Remediation · Documentation

Action 8: Ongoing Documentation — Your Breach Register Entry

📓 BREACH REGISTER ENTRY — Maintain Throughout the Incident
This is your legal record. The Data Protection Board can request this at any time. Keep it updated. Keep it factual.
Breach reference number
BREACH-[ YYYY ]-[ NNN ]
Date/time breach occurred (actual)
[ Date / Time / "Under investigation" ]
Date/time breach discovered
[ Date / Time ]
Board notification filed
[ Date / Time / Reference number ]
Individual notifications sent
[ Date / Number of individuals / Method ]
FIR filed (number)
[ FIR number / Police station ]
Root cause (from forensic investigation)
[ To be completed once forensic investigation is concluded ]
Remediation measures implemented
[ List all security improvements made in response to this breach ]
Date incident closed / systems restored
[ Date ]
Post-incident review completed
[ Date / findings / actions taken ]

Action 9: The Post-72 Hour Sustained Response Checklist

Complete over Days 4–30
Legal and Regulatory
Technical and Operational

Special Scenarios — Adapting the 72-Hour Plan

🦠 Scenario: Ransomware Attack — Do You Pay?
The ransom payment question is one of the most fraught decisions in cybersecurity. Under DPDPA, it is also a legal compliance decision. Paying a ransom does not reduce your notification obligation — the breach occurred when the attacker entered your system, not when they published data. You must still notify the Board and affected individuals. Additionally, paying ransom may potentially expose you to financial sanctions if the ransomware group is on an international sanctions list. Before any payment decision: engage legal counsel, engage your cyber insurer, contact law enforcement. The 72-hour clock continues regardless of the ransom negotiation timeline.
🏭 Scenario: Breach at Your Vendor / Data Processor
Your payment gateway, cloud provider, or HR software vendor calls to say they have been breached and your data may be affected. Under DPDPA, you are the Data Fiduciary — you bear the notification obligation. The vendor's breach is your breach obligation to notify. Immediately: (1) obtain a written incident report from the vendor, (2) determine what data of yours was held on their systems and whether it was affected, (3) file your Board notification as soon as the assessment is complete — you cannot wait for the vendor's full investigation to conclude. Check your DPA with the vendor — it should specify the timeline within which they must notify you of a breach. If no DPA exists, that is a separate compliance failure.
🌐 Scenario: Breach Affecting Both Indian and EU/International Users
If the breach affects both Indian and EU users, you face simultaneous notification obligations under DPDPA (notify India's Data Protection Board) and GDPR (notify the relevant EU supervisory authority within 72 hours of discovery — a strict hard deadline). The GDPR 72-hour clock is firm — there is no "as soon as practicable" discretion for the supervisory authority notification. Build your response plan to meet the GDPR 72-hour deadline and the DPDPA notification will be satisfied simultaneously. Engage your EU-based Data Protection Officer (if designated) and EU legal counsel immediately alongside India response.
👶 Scenario: Children's Data Breached
A breach involving children's data (users under 18) is treated with maximum severity by the Board. If you know or suspect children's data was involved: (1) identify it as a priority category in your Board notification, (2) ensure parent/guardian notification goes out — not just to the child's registered email, (3) consider whether a public statement is warranted given the heightened sensitivity, (4) assess whether POCSO or other child protection legislation creates additional reporting obligations depending on the nature of the data. Schools, ed-tech platforms, gaming companies, and consumer apps must be particularly prepared for this scenario.

Prepare Before a Breach: The Pre-Incident Readiness Checklist

The companies that respond well to data breaches are the ones that prepared before it happened. The 72-hour plan above is far easier to execute if you have already done the following:

📋 Documentation Ready Before a Breach
  • This 72-hour response plan — saved, accessible offline
  • Incident command team with 24/7 contact details
  • Data inventory — what data you hold, where, and whose
  • Vendor DPAs with breach notification clauses — filed and accessible
  • Pre-drafted Board notification template (this guide)
  • Pre-drafted individual notification template (this guide)
  • Forensic firm on retainer or pre-vetted contact
  • Legal counsel contact for emergency engagement
  • Cyber insurance policy details and insurer's 24-hour line
  • CERT-In notification email and procedure printed
  • Local cybercrime police station contact
🔒 Technical Readiness — Before a Breach
  • Encryption at rest for all personal data databases
  • Centralised log management with at least 90-day retention
  • Security monitoring / SIEM with alerting configured
  • MFA enforced on all admin and privileged accounts
  • Tested incident isolation procedure — can you disconnect a system without losing evidence?
  • Regular backups tested and confirmed restorable
  • Endpoint detection and response (EDR) on all critical systems
  • Documented asset inventory — what systems process personal data
  • Annual penetration testing completed
  • Staff phishing simulation training completed
📊 72-Hour Breach Response — At a Glance
Hour 0
Appoint IC, contain breach, preserve evidence, notify leadership
Hour 6
Breach assessment complete, Board notification prepared, forensics engaged
Hour 24
Board notification filed, individual notifications sent, FIR filed
Hour 72
All notifications complete. Sustained investigation and remediation begins.
₹450 Cr
Combined maximum penalty (₹250Cr + ₹200Cr) for breach + concealment

If You Are Dealing With a Breach Right Now — Contact Us Immediately

A data breach is a legal emergency. The notifications required under DPDPA — to the Data Protection Board and to affected individuals — must be legally accurate, factually complete, and written in a way that does not inadvertently create additional liability. Getting the notification wrong is as damaging as getting the response wrong. Our team can support you through a live breach — from the first assessment call to Board notification drafting to individual user communications — available on priority basis.

If you are not in a breach right now, the best time to prepare is today. We offer a Breach Readiness Review — a structured assessment of your organisation's breach detection, notification, and response capabilities against DPDPA Rule 6 requirements, delivered with a gap report and a customised, pre-filled version of this 72-hour response plan for your specific business, data flows, and vendor ecosystem.

Our breach advisory team works with companies across sectors — fintech, healthcare, e-commerce, manufacturing, and MNC India subsidiaries. Every engagement is confidential. Every breach response engagement is available on a priority-access basis.

AD
Adv. Deepak Kumar
IP & Legal Expert · Vakil Help Desk
Our editorial team comprises experienced IP advocates, DPDPA compliance specialists, and legal professionals dedicated to making India's legal landscape accessible to every business. We cover trademark law, patent filing, copyright protection, and DPDP Act 2023 compliance.
Found this helpful? Share it →
💼 LinkedIn

Need Expert Help with DPDP?

Our team of advocates and compliance specialists are ready to help. Free consultation — response within 2 hours.

⚡ Get Free Consultation →
📋 Table of Contents
    Free Consultation
    Get expert advice on DPDP matters. We respond within 2 hours.
    Book Free Call → 💬 WhatsApp Us
    DPDPA Deadline
    Days to May 2027 enforcement
    Get Compliant Now →
    Get Free Consultation
    Call Now WhatsApp