📱Test our Android app — free beta!Join Beta GroupYou'll receive the install link by email after joining.

Differences

This shows you the differences between two versions of the page.


dpdp-data-breach-72-hours-notification-rule-7 [2026/07/10 22:02] (current) – created - external edit 127.0.0.1
Line 1: Line 1:
 +{{htmlmetatags>metatag-description=(DPDP Rules 2025 Rule 7: a company must tell you about a data breach without delay and report it to the Data Protection Board within 72 hours. Know your rights.)&metatag-keywords=(DPDP data breach notification 72 hours, DPDP Rules 2025 Rule 7, Data Protection Board breach report, personal data breach India)&metatag-robots=(index,follow)&metatag-og:title=(DPDP Rules 2025: Data Breach Must Be Reported In 72 Hours)&metatag-og:description=(DPDP Rules 2025 Rule 7: a company must tell you about a data breach without delay and report it to the Data Protection Board within 72 hours. Know your rights.)&metatag-og:type=(article)}}
  
 +====== DPDP Rules 2025: Data Breach Must Be Reported In 72 Hours ======
 +
 +If an app or company that holds your personal data is hacked or leaks your information, it must tell you without delay and report the breach to the Data Protection Board within 72 hours. This is Rule 7 of the Digital Personal Data Protection Rules 2025, notified by the Government on 13 November 2025 vide G.S.R. 846 E.
 +
 +**Short on time?** Jump to "Your rights as the affected user" below to see exactly what the company must tell you.
 +
 +===== A real scenario =====
 +
 +An app you use every day announces that hackers got in and user data leaked. Your name, email, phone number and maybe your Aadhaar or payment details may be out. You are worried. What is the company legally required to tell you, and when?
 +
 +Under the DPDP Rules 2025, the answer is now written into law. The company holding your data is called the "Data Fiduciary". You are the "Data Principal". The moment that company becomes aware of a personal data breach, two clocks start: one to inform you, and one to inform the regulator.
 +
 +A breach is not only a hacker attack. It includes any unauthorised access, loss, or sharing of your personal data that risks your privacy. So a misconfigured database, a leaked spreadsheet, or a lost laptop can all count.
 +
 +===== The 72-hour timeline: what the company must do =====
 +
 +Rule 7 is titled "Intimation of personal data breach". It sets a clear order of steps once the company learns of a breach.
 +
 +  - **Inform you without delay.** The Data Fiduciary must tell each affected user "in a concise, clear and plain manner and without delay". This goes through your registered account or contact channel.
 +  - **Inform the Board without delay.** At the same time, the company must give the Data Protection Board an initial description of the breach: its nature, extent, timing and likely impact.
 +  - **File a detailed report within 72 hours.** The rule says the company must, "within seventy-two hours of becoming aware of the breach, or within such longer period as the Board may allow on a request made in writing", give the Board the full picture.
 +
 +The detailed 72-hour report to the Board must include:
 +
 +  * Updated and detailed information about the breach.
 +  * The broad facts, circumstances and reasons that led to it.
 +  * Steps taken or proposed to reduce the harm.
 +  * Any findings about who caused the breach.
 +  * Remedial measures to stop it happening again.
 +  * A report on what was told to affected users.
 +
 +Note: the 72-hour deadline is for the detailed report to the Board. The duty to inform you, the affected user, is "without delay" and does not wait for the 72 hours to run.
 +
 +===== Your rights as the affected user =====
 +
 +When the company informs you under Rule 7, it must give you specific information, not a vague apology. You are entitled to:
 +
 +  * A description of the breach, including its nature, extent and when it happened.
 +  * The consequences that are likely to affect you personally.
 +  * The measures the company has taken or is taking to reduce the risk.
 +  * The safety steps you can take to protect yourself (for example, changing passwords or watching for fraud).
 +  * Business contact information so you can reach the company with questions.
 +
 +This is your legal floor. A notice that hides the cause or skips the consequences does not meet Rule 7.
 +
 +===== When does this rule start? =====
 +
 +Be aware of the timing. The DPDP Rules 2025 come into force in stages. Rule 7, the breach intimation rule, sits in the group of rules (Rules 3 and 5 to 16) that come into force 18 months after publication. Counting from 13 November 2025, that points to around mid-May 2027.
 +
 +So the binding 72-hour duty becomes fully operative on that date. Many responsible companies are expected to follow the standard early. But if a breach happens before the rule is live, your strongest tool is to escalate and complain rather than rely on a fixed legal deadline. Verify the current commencement status before acting on a live breach.
 +
 +For the wider picture, see our [[https://righttoinformation.wiki/dpdp-act-2023-complete-guide|complete guide to the DPDP Act 2023]] and your [[https://righttoinformation.wiki/dpdp-right-to-erasure-correction-personal-data-2025|right to erasure and correction of personal data]]. For RTI tactics to extract records from public bodies, keep [[https://righttoinformation.wiki/book|The RTI Playbook]] handy.
 +
 +===== What to do in the next 30 minutes =====
 +
 +  * Read the breach notice carefully and save a copy with the date and time.
 +  * Change the password for that app and any account where you reused it.
 +  * Turn on two-factor authentication wherever you can.
 +  * Watch your bank and UPI statements for any unknown activity.
 +  * Note the company's contact details from the notice and ask what data of yours leaked.
 +
 +==== FAQ ====
 +
 +==== What is the 72-hour rule in DPDP Rules 2025? ====
 +
 +Rule 7 of the DPDP Rules 2025 says a company that holds your personal data must report a data breach to the Data Protection Board with detailed information within 72 hours of becoming aware of it. The Board can allow a longer period only if the company asks in writing. The separate duty to inform you, the affected user, is "without delay", not 72 hours.
 +
 +==== Does the company have to tell me directly about a breach? ====
 +
 +Yes. Rule 7 requires the Data Fiduciary to intimate each affected user "without delay" through your registered account or contact channel. It cannot just inform the regulator and stay silent towards you. The notice must describe the breach, its likely consequences for you, the steps being taken, and what you can do to protect yourself.
 +
 +==== When does Rule 7 become legally binding? ====
 +
 +Rule 7 falls in the group of DPDP Rules (Rules 3 and 5 to 16) that come into force 18 months after the Rules were published on 13 November 2025. That points to around mid-2027. Before that date, the 72-hour duty is not yet a fixed legal deadline, so escalate and complain if a breach affects you in the meantime. Verify the live status before relying on it.
 +
 +==== What can I do if a company hides a data breach from me? ====
 +
 +Once the rule is operative, you can complain to the Data Protection Board of India, which can inquire and impose penalties on the Data Fiduciary. Keep evidence: screenshots, emails, transaction records and the date you noticed any misuse. If the data leak involves a public authority, you can also file an RTI application to ask what records were exposed and what action was taken.
 +
 +==== Is the 72-hour figure confirmed in the official gazette? ====
 +
 +Yes. The "seventy-two hours" figure and Rule 7 appear in the Digital Personal Data Protection Rules 2025, notified vide G.S.R. 846 E dated 13 November 2025 under Section 40 of the DPDP Act 2023. The rule requires the detailed report to the Board within seventy-two hours of the company becoming aware of the breach.
 +
 +==== Author ====
 +
 +Reviewed by Dr. Shrawan Kumar Pathak. This guide explains the law in plain terms and is not a substitute for legal advice on a specific breach.
 +
 +===== Sources =====
 +
 +  * Digital Personal Data Protection Rules 2025, Rule 7 (Intimation of personal data breach), notified vide G.S.R. 846 E dated 13 November 2025, under Section 40 of the DPDP Act 2023.
 +  * Digital Personal Data Protection Act 2023, Section 8(6) and Section 40.
 +===== DPDP Section 7 data breach notification: 72-hour rule and how to complain? =====
 +
 +Under the DPDP Act 2023, Section 7 requires personal data breach notification. Here is the complete guide:
 +
 +  - **Step 1: What is Section 7?** (a) Section 7 of the DPDP Act 2023 requires the Data Fiduciary to notify the Data Principal and the Data Protection Board of any personal data breach, (b) the notification must be given "as soon as possible" — the DPDP Rules 2025 specify the timeframe: (i) to the Board: within 72 hours of becoming aware of the breach, (ii) to the Data Principal: without undue delay (after the Board is notified), (c) the notification must include: (i) the nature of the breach (what data was compromised — names, PAN, Aadhaar, financial data, health data), (ii) the number of affected individuals, (iii) the remedial measures taken (and proposed).
 +  - **Step 2: Who must notify?** (a) the Data Fiduciary (the entity that determines the purpose and means of processing personal data — e.g., a company that collects customer data), (b) the Data Processor (the entity that processes data on behalf of the Data Fiduciary — e.g., a cloud service provider — must notify the Data Fiduciary, who then notifies the Board and the Data Principal), (c) Significant Data Fiduciaries (SDFs — large entities with high volume of data — have additional obligations: annual security audit, Data Protection Officer, independent audit).
 +  - **Step 3: What is a personal data breach?** (a) unauthorized access (a hacker accesses the database — and downloads customer data), (b) unauthorized disclosure (an employee shares customer data with a third party without authorisation), (c) unauthorized alteration (data is modified — e.g., wrong information is entered), (d) loss of data (data is lost — e.g., a laptop with customer data is stolen, a backup is lost), (e) any other compromise of confidentiality, integrity, or availability of personal data.
 +  - **Step 4: How to complain.** (a) if you are affected by a data breach: file a complaint with the Data Protection Board (the Board is established under the DPDP Act — the complaint is filed online at the Board's portal), (b) the complaint should include: (i) the Data Fiduciary's name (the company/entity that lost your data), (ii) the nature of the breach (what data was compromised), (iii) when you were notified (or when you discovered the breach — if the Data Fiduciary did not notify you), (iv) the impact (financial loss, identity theft, harassment), (c) the Board can: (i) order the Data Fiduciary to take remedial measures, (ii) impose a penalty (up to Rs 250 crore per violation — under Section 33), (iii) order compensation to the affected individuals.
 +  - **Step 5: File RTI.** File RTI with the Ministry of Electronics and Information Technology (MeitY) asking for: (a) the status of the Data Protection Board (is it constituted — if yes: provide the members and the contact details), (b) the number of data breach notifications received by the Board (since its constitution), (c) the action taken on each notification (including penalties imposed and compensation ordered), (d) the status of complaint number [number] filed on [date] (if you have filed a complaint with the Board), (e) the guidelines issued by the Board for data breach notification (the format and content requirements).
 +  - **Step 6: Other remedies.** (a) file a complaint with the cyber crime cell (at cybercrime.gov.in — if the breach involves criminal activity, e.g., hacking), (b) file a consumer complaint (the data breach is a deficiency of service — the consumer forum can order compensation), (c) file a civil suit for damages (under the DPDP Act, the Data Principal can claim compensation — the Board or the court can award it), (d) file a writ petition (if the Board does not act on the complaint — the High Court can direct the Board to act).
 +  - **Step 7: Preventive measures.** (a) use strong passwords and 2FA (two-factor authentication — for all online accounts), (b) minimize data sharing (share only the data that is necessary — do not share Aadhaar unless required by law), (c) check privacy settings (on social media and apps — limit the data that is shared), (d) monitor bank statements and credit reports (to detect identity theft early), (e) be cautious of phishing (scammers may use breached data to craft targeted phishing emails).
 +
 +See [[https://righttoinformation.wiki/dpdp-data-breach-72-hours-notification-rule-7|DPDP Section 7]] and [[https://righttoinformation.wiki/guide/find-pio-2026|Find PIO]].
 +
 +{{tag>dpdp act section 7 data breach 72 hours notification data protection board penalty complaint meity rti 2025 2026}}