Differences
This shows you the differences between two versions of the page.
| — | dpdp-data-breach-72-hours-notification-rule-7 [2026/07/10 22:02] (current) – created - external edit 127.0.0.1 | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| + | {{htmlmetatags> | ||
| + | ====== DPDP Rules 2025: Data Breach Must Be Reported In 72 Hours ====== | ||
| + | |||
| + | If an app or company that holds your personal data is hacked or leaks your information, | ||
| + | |||
| + | **Short on time?** Jump to "Your rights as the affected user" below to see exactly what the company must tell you. | ||
| + | |||
| + | ===== A real scenario ===== | ||
| + | |||
| + | An app you use every day announces that hackers got in and user data leaked. Your name, email, phone number and maybe your Aadhaar or payment details may be out. You are worried. What is the company legally required to tell you, and when? | ||
| + | |||
| + | Under the DPDP Rules 2025, the answer is now written into law. The company holding your data is called the "Data Fiduciary" | ||
| + | |||
| + | A breach is not only a hacker attack. It includes any unauthorised access, loss, or sharing of your personal data that risks your privacy. So a misconfigured database, a leaked spreadsheet, | ||
| + | |||
| + | ===== The 72-hour timeline: what the company must do ===== | ||
| + | |||
| + | Rule 7 is titled " | ||
| + | |||
| + | - **Inform you without delay.** The Data Fiduciary must tell each affected user "in a concise, clear and plain manner and without delay" | ||
| + | - **Inform the Board without delay.** At the same time, the company must give the Data Protection Board an initial description of the breach: its nature, extent, timing and likely impact. | ||
| + | - **File a detailed report within 72 hours.** The rule says the company must, " | ||
| + | |||
| + | The detailed 72-hour report to the Board must include: | ||
| + | |||
| + | * Updated and detailed information about the breach. | ||
| + | * The broad facts, circumstances and reasons that led to it. | ||
| + | * Steps taken or proposed to reduce the harm. | ||
| + | * Any findings about who caused the breach. | ||
| + | * Remedial measures to stop it happening again. | ||
| + | * A report on what was told to affected users. | ||
| + | |||
| + | Note: the 72-hour deadline is for the detailed report to the Board. The duty to inform you, the affected user, is " | ||
| + | |||
| + | ===== Your rights as the affected user ===== | ||
| + | |||
| + | When the company informs you under Rule 7, it must give you specific information, | ||
| + | |||
| + | * A description of the breach, including its nature, extent and when it happened. | ||
| + | * The consequences that are likely to affect you personally. | ||
| + | * The measures the company has taken or is taking to reduce the risk. | ||
| + | * The safety steps you can take to protect yourself (for example, changing passwords or watching for fraud). | ||
| + | * Business contact information so you can reach the company with questions. | ||
| + | |||
| + | This is your legal floor. A notice that hides the cause or skips the consequences does not meet Rule 7. | ||
| + | |||
| + | ===== When does this rule start? ===== | ||
| + | |||
| + | Be aware of the timing. The DPDP Rules 2025 come into force in stages. Rule 7, the breach intimation rule, sits in the group of rules (Rules 3 and 5 to 16) that come into force 18 months after publication. Counting from 13 November 2025, that points to around mid-May 2027. | ||
| + | |||
| + | So the binding 72-hour duty becomes fully operative on that date. Many responsible companies are expected to follow the standard early. But if a breach happens before the rule is live, your strongest tool is to escalate and complain rather than rely on a fixed legal deadline. Verify the current commencement status before acting on a live breach. | ||
| + | |||
| + | For the wider picture, see our [[https:// | ||
| + | |||
| + | ===== What to do in the next 30 minutes ===== | ||
| + | |||
| + | * Read the breach notice carefully and save a copy with the date and time. | ||
| + | * Change the password for that app and any account where you reused it. | ||
| + | * Turn on two-factor authentication wherever you can. | ||
| + | * Watch your bank and UPI statements for any unknown activity. | ||
| + | * Note the company' | ||
| + | |||
| + | ==== FAQ ==== | ||
| + | |||
| + | ==== What is the 72-hour rule in DPDP Rules 2025? ==== | ||
| + | |||
| + | Rule 7 of the DPDP Rules 2025 says a company that holds your personal data must report a data breach to the Data Protection Board with detailed information within 72 hours of becoming aware of it. The Board can allow a longer period only if the company asks in writing. The separate duty to inform you, the affected user, is " | ||
| + | |||
| + | ==== Does the company have to tell me directly about a breach? ==== | ||
| + | |||
| + | Yes. Rule 7 requires the Data Fiduciary to intimate each affected user " | ||
| + | |||
| + | ==== When does Rule 7 become legally binding? ==== | ||
| + | |||
| + | Rule 7 falls in the group of DPDP Rules (Rules 3 and 5 to 16) that come into force 18 months after the Rules were published on 13 November 2025. That points to around mid-2027. Before that date, the 72-hour duty is not yet a fixed legal deadline, so escalate and complain if a breach affects you in the meantime. Verify the live status before relying on it. | ||
| + | |||
| + | ==== What can I do if a company hides a data breach from me? ==== | ||
| + | |||
| + | Once the rule is operative, you can complain to the Data Protection Board of India, which can inquire and impose penalties on the Data Fiduciary. Keep evidence: screenshots, | ||
| + | |||
| + | ==== Is the 72-hour figure confirmed in the official gazette? ==== | ||
| + | |||
| + | Yes. The " | ||
| + | |||
| + | ==== Author ==== | ||
| + | |||
| + | Reviewed by Dr. Shrawan Kumar Pathak. This guide explains the law in plain terms and is not a substitute for legal advice on a specific breach. | ||
| + | |||
| + | ===== Sources ===== | ||
| + | |||
| + | * Digital Personal Data Protection Rules 2025, Rule 7 (Intimation of personal data breach), notified vide G.S.R. 846 E dated 13 November 2025, under Section 40 of the DPDP Act 2023. | ||
| + | * Digital Personal Data Protection Act 2023, Section 8(6) and Section 40. | ||
| + | ===== DPDP Section 7 data breach notification: | ||
| + | |||
| + | Under the DPDP Act 2023, Section 7 requires personal data breach notification. Here is the complete guide: | ||
| + | |||
| + | - **Step 1: What is Section 7?** (a) Section 7 of the DPDP Act 2023 requires the Data Fiduciary to notify the Data Principal and the Data Protection Board of any personal data breach, (b) the notification must be given "as soon as possible" | ||
| + | - **Step 2: Who must notify?** (a) the Data Fiduciary (the entity that determines the purpose and means of processing personal data — e.g., a company that collects customer data), (b) the Data Processor (the entity that processes data on behalf of the Data Fiduciary — e.g., a cloud service provider — must notify the Data Fiduciary, who then notifies the Board and the Data Principal), (c) Significant Data Fiduciaries (SDFs — large entities with high volume of data — have additional obligations: | ||
| + | - **Step 3: What is a personal data breach?** (a) unauthorized access (a hacker accesses the database — and downloads customer data), (b) unauthorized disclosure (an employee shares customer data with a third party without authorisation), | ||
| + | - **Step 4: How to complain.** (a) if you are affected by a data breach: file a complaint with the Data Protection Board (the Board is established under the DPDP Act — the complaint is filed online at the Board' | ||
| + | - **Step 5: File RTI.** File RTI with the Ministry of Electronics and Information Technology (MeitY) asking for: (a) the status of the Data Protection Board (is it constituted — if yes: provide the members and the contact details), (b) the number of data breach notifications received by the Board (since its constitution), | ||
| + | - **Step 6: Other remedies.** (a) file a complaint with the cyber crime cell (at cybercrime.gov.in — if the breach involves criminal activity, e.g., hacking), (b) file a consumer complaint (the data breach is a deficiency of service — the consumer forum can order compensation), | ||
| + | - **Step 7: Preventive measures.** (a) use strong passwords and 2FA (two-factor authentication — for all online accounts), (b) minimize data sharing (share only the data that is necessary — do not share Aadhaar unless required by law), (c) check privacy settings (on social media and apps — limit the data that is shared), (d) monitor bank statements and credit reports (to detect identity theft early), (e) be cautious of phishing (scammers may use breached data to craft targeted phishing emails). | ||
| + | |||
| + | See [[https:// | ||
| + | |||
| + | {{tag> | ||