Decode Ballistic Reports Like a Pro. Register Now!
LCI Learning

Share on Facebook

Share on Twitter

Share on LinkedIn

Share on Email

Share More


Quick Summary
India's Digital Personal Data Protection Act (DPDP) of 2023, along with its 2025 Rules, has transformed how data breaches are handled legally. Previously a reputational risk, breaches are now regulatory events with strict notification duties and significant penalties. The law mandates reporting all breaches, regardless of materiality, to both CERT-In within six hours and the Data Protection Board within 72 hours, alongside notifying affected individuals.

Introduction

A cyber lawyer's recent commentary on LinkedIn, discussing data privacy, cybersecurity, and data breaches, has reignited a conversation that the Indian legal fraternity can no longer afford to side-line: what actually happens, legally, the moment personal data leaks out of an organisation's systems? For years, that question sat mostly with IT teams and CISOs. In 2026, it sits squarely on a lawyer's desk too, because India's data protection regime has matured from a set of contractual promises into a statute with teeth.
The Digital Personal Data Protection Act, 2023 ("DPDP Act"), read with the Digital Personal Data Protection Rules, 2025 ("DPDP Rules") notified by the Ministry of Electronics and Information Technology (MeitY) in November 2025, has fundamentally changed how a "data breach" is treated in Indian law. What was once primarily a reputational and commercial risk is now a regulatory event with hard deadlines, dual notification duties, and penalties that can run into hundreds of crores of rupees. This article walks through the legal architecture governing data breaches in India, the practical obligations it places on organisations and their counsel, and where the framework still leaves victims under-protected.

What the Law Means by a "Personal Data Breach"

Under Section 2(u) of the DPDP Act, a personal data breach is any unauthorised processing of personal data, or any accidental disclosure, acquisition, sharing, use, alteration, destruction, or loss of access to personal data that compromises its confidentiality, integrity, or availability. The definition is deliberately wide. It is not limited to a hacker breaking through a firewall; a misconfigured database left open to the public internet, an employee emailing a spreadsheet of customer records to the wrong address, or a vendor losing an unencrypted laptop can each qualify as a breach that triggers legal obligations.

Crucially, the DPDP Act does not import a materiality or "likely to cause harm" threshold of the kind found in the European Union's General Data Protection Regulation (GDPR). Under GDPR, an organisation may skip notifying individuals if the breach is unlikely to result in high risk to their rights. India's law contains no such carve-out. Every breach, regardless of the number of individuals affected or the sensitivity of the data involved, must be reported. This is one of the most consequential and, for compliance teams, one of the most demanding features of the Indian framework.

The Dual-Clock Problem: CERT-In and the DPDP Act

Organisations operating in India must reckon with two overlapping breach reporting regimes, not one.

1. The CERT-In Six-Hour Window
Under the Information Technology Act, 2000 and the CERT-In Directions of April 2022, entities must report specified categories of cyber incidents including data breaches, ransomware attacks, unauthorised access, and website defacement to the Indian Computer Emergency Response Team (CERT-In) within six hours of noticing or being made aware of the incident. This obligation is already in force and is enforced independently of the DPDP framework. Missing this deadline is a live compliance risk today, irrespective of whether the DPDP Rules' timelines have fully crystallised for a given organisation.

2. The DPDP Rules' Two-Stage, 72 Hour Process
Section 8(6) of the DPDP Act requires a Data Fiduciary to give the Data Protection Board of India ("the Board") and each affected Data Principal intimation of a personal data breach, in the manner prescribed by the Rules. Rule 7 of the DPDP Rules, 2025 operationalises this into a two-stage process: an immediate, "without delay" preliminary alert to the Board once the Fiduciary becomes aware of the breach, followed by a detailed report within seventy-two hours (or such further time as the Board may allow) containing the facts of the breach, the categories and approximate number of Data Principals and personal data affected, the likely impact, remedial measures taken or proposed, and the identity of the person who caused the breach, if known.

The obligation to notify affected Data Principals runs on a parallel track. That notification must be in plain, understandable language describing the nature of the breach, the personal data affected, the likely consequences, the measures being taken to mitigate risk, safety steps the individual can take, and contact details of a person who can answer queries. Sound legal drafting practice increasingly treats this notice as a distinct deliverable that counsel should draft and review, since a poorly worded notice can itself invite regulatory scrutiny or fuel follow-on litigation.

Who Bears the Liability: Fiduciaries, Processors, and Significant Data Fiduciaries

The DPDP Act draws a clear line between a Data Fiduciary, the entity that determines the purpose and means of processing personal data and a Data Processor, which processes data on the Fiduciary's behalf, typically under an outsourcing or service arrangement. This distinction matters enormously in breach scenarios. Even where the actual point of failure lies with a cloud host, payment gateway, CRM vendor, or marketing agency acting as a processor, liability for the breach and the notification obligations remains with the Data Fiduciary. Processors do not owe the Board or Data Principals a direct statutory duty; the Fiduciary is expected to have flowed down equivalent obligations through its data processing agreements.

This has two practical consequences that lawyers advising businesses should flag early. First, standard vendor contracts drafted before 2023 rarely contain adequate breach-notification timelines, audit rights, or indemnity language calibrated to the DPDP Rules' compressed clock, and should be revisited. Second, entities notified by the Board as "Significant Data Fiduciaries" under Section 10, typically large-scale processors of sensitive or high-volume personal data face additional obligations, including appointing a Data Protection Officer based in India, undertaking periodic Data Protection Impact Assessments, and independent data audits, all of which materially shape how quickly and credibly they can respond to a breach when it occurs.

Penalties: The Numbers That Changed the Boardroom Conversation

The Schedule to the DPDP Act sets out some of the steepest data-protection penalties in the world for a jurisdiction of India's size. Failure to take reasonable security safeguards to prevent a personal data breach, under Section 8(5), attracts a penalty of up to ₹250 crore, the highest slab under the Act. Failure to notify the Board or affected Data Principals of a breach, under Section 8(6), attracts a penalty of up to ₹200 crore. Non-compliance with the special obligations relating to children's data under Section 9, and failure by a Significant Data Fiduciary to discharge its additional obligations under Section 10, are each capped at ₹200 crore and ₹150 crore respectively. Even a Data Principal's own breach of duties under Section 15 can attract a modest penalty of up to ₹10,000, though the enforcement focus is overwhelmingly on organisations.

These are not theoretical numbers. The Data Protection Board of India, once fully operational, is empowered to inquire into breaches either on a reference from the government or on receiving a Fiduciary's own intimation, and to impose penalties after hearing the affected entity. Factors the Board may weigh include the nature and gravity of the breach, the number of Data Principals affected, whether the Fiduciary took timely remedial action, and whether the non-compliance was repetitive.

The Compensation Gap: A Point of Real Concern for Practitioners

One aspect of the transition from the old regime to the new one deserves particular attention from litigators and consumer-rights advocates. Section 43A of the erstwhile Information Technology Act, 2000 allowed an individual whose sensitive personal data was compromised due to a body corporate's negligence in maintaining reasonable security practices to claim compensation directly through civil proceedings. The DPDP Act, by contrast, is architected around penalties payable to the exchequer via the Board, not compensation payable to the individuals whose data was actually exposed.

This means that while the DPDP Act substantially raises the cost of non-compliance for organisations, it does not, on its own, give a breached individual a straightforward statutory route to monetary compensation for the anxiety, fraud exposure, or reputational harm a leak may cause them. Practitioners advising affected individuals will often need to fall back on tort principles, contract law, or, where the facts fit, the residual provisions of the IT Act, rather than the DPDP Act itself, to pursue a compensation claim. This gap is likely to remain a live area of debate, and possibly future amendment, as the Board's enforcement record develops.
 

How a Breach Actually Unfolds: An Illustrative Scenario

Consider a mid-sized fintech NBFC that discovers, on a Friday evening, that a third-party analytics vendor left a cloud storage bucket containing loan-applicant KYC documents publicly accessible for several weeks. The moment an employee flags this to the compliance team, two clocks start running simultaneously, not one after the other. The CERT-In six-hour window begins immediately: the incident falls squarely within the categories the CERT-In Directions require to be reported, and by law the organisation should already have a designated point of contact ready to file that report within hours, even before the full scope of the exposure is known.

In parallel, the DPDP Rules' two-stage process kicks in. The NBFC, as the Data Fiduciary, must send the Board an initial, "without delay" intimation, followed within seventy-two hours by a fuller report covering how many applicants were affected, what KYC data was exposed, and what containment steps have been taken. Because the vendor, not the NBFC, caused the misconfiguration, legal teams must also move quickly to establish from the data processing agreement whether the vendor is bound to cooperate with the investigation and share the cost of remediation, something that cannot be negotiated for the first time while the clock is already running.

At the same time, every affected loan applicant is legally owed a plain-language notice explaining what happened, what risks it exposes them to, and what steps they can take to protect themselves. A rushed or overly legalistic notice risks looking evasive, and can itself become an exhibit in a later Board inquiry into whether the response was adequate. This is precisely where the line between "IT incident" and "legal matter requiring counsel's direct involvement" disappears within the first hour, illustrating why so much of DPDP compliance is really about preparation done long before any breach occurs.

Practitioner's Perspective

The growing regulatory framework around data breaches in India reflects a positive shift towards greater accountability, but it also creates a significant compliance challenge for organisations. The difficulty is no longer limited to determining whether a breach has occurred; organisations must also identify which legal framework has been triggered, which regulator has jurisdiction, and which reporting deadline applies.

A single incident may have implications under the CERT-In Directions, the DPDP framework, and sector-specific regulations issued by authorities such as RBI or SEBI. For businesses operating across regulated sectors, this overlap can make breach response particularly complex. Compliance with one reporting obligation cannot automatically be assumed to satisfy another.

From a legal perspective, organisations should therefore move away from a generic data-breach checklist towards a sector-specific Regulatory Incident Reporting Matrix. Such a framework should clearly identify the applicable regulator, reporting trigger, timeline, information required, internal decision-maker, and subsequent reporting obligations. It should also be reviewed periodically as regulatory requirements and reporting mechanisms evolve.

The role of lawyers is equally important. Legal counsel should not be brought in only after the technical investigation is complete. Early legal involvement allows the organisation to assess reporting obligations while forensic teams investigate the incident, ensuring that the need for additional information does not result in missed statutory or regulatory deadlines.

Ultimately, effective data-breach management requires a coordinated response between legal, cybersecurity, compliance, and management teams. The objective should be to ensure that when a breach occurs, the organisation is not merely capable of identifying what went wrong, but is also prepared to determine what the law requires it to do next and how quickly it must do it.

Conclusion

The message for Indian businesses, and for the lawyers who advise them, is straightforward: a data breach is no longer purely a technical failure to be quietly patched, logged, and forgotten. It is a legal event with a clock that starts ticking the moment anyone in the organisation becomes aware of it, and the DPDP Act has made that clock a matter of statutory obligation rather than good corporate citizenship. Getting ahead of it 
through mapped data flows, tightened vendor contracts, rehearsed notification templates, and counsel who understand both the six-hour CERT-In window and the DPDP Rules' seventy-two-hour reporting cycle is now as much a part of corporate legal hygiene as drafting a sound commercial contract or filing statutory returns on time.

For the legal profession specifically, this shift carries real professional opportunity alongside the obvious responsibility. Data protection compliance work is no longer the preserve of a handful of specialist technology lawyers; it increasingly touches corporate, banking, employment, healthcare, and even matrimonial and family law practices, wherever personal data is collected, stored, or shared. Litigators should expect a rising volume of disputes at the intersection of privacy, consumer protection, and tort law as the compensation gap under the DPDP Act pushes aggrieved individuals toward creative pleadings. Transactional lawyers will find that due diligence checklists for mergers, acquisitions, and vendor onboarding now routinely need a dedicated data protection workstream, assessing not just whether a target or counterparty is DPDP-compliant on paper, but whether it has actually rehearsed what happens in the first six hours after a breach. And regulatory and compliance counsel will increasingly be judged not on how well they can explain the law after an incident, but on how thoroughly they prepared their clients before one ever occurred.

As enforcement under the DPDP Act gathers pace through 2026 and 2027, and as the Data Protection Board of India builds its first body of orders and precedent, the organisations and the lawyers advising them who treated this as a standing compliance discipline early will be far better placed than those who treat it as a crisis to be managed only once the breach has already happened. In that sense, the DPDP Act has done for data protection what the Companies Act once did for corporate governance: it has converted what used to be good practice into a legal floor beneath which no organisation, and no counsel advising one, can safely operate.


"Loved reading this piece by Himanshi Gupta?
Join LAWyersClubIndia's network for daily News Updates, Judgment Summaries, Articles, Forum Threads, Online Law Courses, and MUCH MORE!!"







Category Others, Other Articles by - Himanshi Gupta 



Comments