Before a breach — are the foundations in place?
- We maintain an up-to-date record of the personal data we hold and where it flows (a RoPA). You cannot report what you cannot see.
- We have a written incident response plan, and the people named in it know their roles.
- We have a designated response team with clear ownership across technical, legal, and communications.
- We have breach-notification templates drafted and ready to adapt — for the Data Protection Board and for affected individuals.
- Our contracts with vendors and processors require them to alert us promptly if they suffer a breach.
- We have logging and detection in place, so we would actually know a breach had occurred.
In the first hours — can you detect and contain?
- There is a clear route for a suspected breach to be reported internally, and staff know to use it.
- We can quickly assess the scope: what data was involved, and whose.
- We can contain the incident and preserve evidence for the investigation.
- We know who decides that a reportable breach has occurred — and when the clock starts.
The notification window — can you meet the timeline?
- We can send an initial intimation to the Data Protection Board without delay on becoming aware.
- We can, without delay, notify affected data principals in plain language — what happened, what data was involved, what they can do to protect themselves, and how to reach us.
- We can give the Board a detailed report within 72 hours — the nature and circumstances of the breach, the mitigation steps taken, and our findings on cause.
- We know an extension can be requested from the Board, in writing, if the detailed report needs more time.
After the breach — do you close the loop?
- We remediate the underlying weakness, not just the immediate symptom.
- We document the incident and our response in full.
- We update the incident response plan with what we learned.
How did you do?
Every unticked box is a gap that will cost you time you will not have during a live incident — and, under the DPDP Act, a failure to report a breach can attract penalties of up to ₹200 crore. The organisations that handle breaches well are not the ones that never suffer them; they are the ones that decided, in advance, exactly what they would do. The best time to build that readiness is before you need it.
This article is for general information and does not constitute legal advice. For help building or testing a breach response plan that meets the DPDP Rules, speak with a data protection lawyer.

