{"id":10072,"date":"2026-08-25T07:32:16","date_gmt":"2026-08-25T07:32:16","guid":{"rendered":"https:\/\/protectcomply.com\/blog\/?p=10072"},"modified":"2026-09-01T08:33:46","modified_gmt":"2026-09-01T08:33:46","slug":"dpdp-breach-notification-72-hours","status":"publish","type":"post","link":"https:\/\/protectcomply.com\/blog\/dpdp-breach-notification-72-hours\/","title":{"rendered":"DPDP Breach Notification: The 72-Hour Rule Explained"},"content":{"rendered":"<p>Almost every article on <strong>DPDP breach notification<\/strong> in India leads with &#8220;you have 72 hours.&#8221; That framing is wrong, and it is the kind of wrong that costs money.<\/p>\r\n\r\n\r\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/protectcomply.com\/blog\/wp-content\/uploads\/2026\/08\/dpdp-breach-notification-72-hour-sequence.png\" alt=\"DPDP breach notification sequence: intimate the Data Protection Board and affected data principals without delay, then file the detailed report with the Board within 72 hours\" class=\"wp-image-10148\" width=\"1200\" height=\"675\"\/><figcaption class=\"wp-element-caption\">Intimation is immediate. The 72 hours applies to the detailed report to the Board, not to telling anyone.<\/figcaption><\/figure>\r\n\r\n\r\n\r\n\r\n<p>Rule 7 of the DPDP Rules 2025 sets two clocks running from the same moment, and the shorter one has no number attached to it at all. Understanding which obligation carries which deadline is the difference between a defensible response and a second penalty stacked on top of the first.<\/p>\r\n\r\n<h2>DPDP breach notification: two clocks, not one<\/h2>\r\n\r\n<table>\r\n<thead>\r\n<tr><th>Obligation<\/th><th>Who receives it<\/th><th>Deadline<\/th><\/tr>\r\n<\/thead>\r\n<tbody>\r\n<tr><td>Intimation of the breach<\/td><td>Every affected Data Principal<\/td><td><strong>Without delay<\/strong><\/td><\/tr>\r\n<tr><td>Initial intimation<\/td><td>Data Protection Board<\/td><td><strong>Without delay<\/strong><\/td><\/tr>\r\n<tr><td>Detailed report<\/td><td>Data Protection Board<\/td><td><strong>Within 72 hours<\/strong>, or longer if the Board permits<\/td><\/tr>\r\n<\/tbody>\r\n<\/table>\r\n\r\n<p>&#8220;Without delay&#8221; is not 72 hours. It is not &#8220;as soon as reasonably practicable&#8221; either. It is the strictest standard in the Rule, and it applies both to telling affected individuals and to the first alert to the Board. The 72 hours applies only to the comprehensive report that follows.<\/p>\r\n\r\n<p>The clock starts when you become <em>aware<\/em> that a personal data breach has occurred \u2014 not when the incident happened, not when forensics concludes, and not when legal signs off.<\/p>\r\n\r\n<h2>What counts as a personal data breach<\/h2>\r\n\r\n<p>The Act defines it broadly: any unauthorised processing of personal data, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access, that compromises the confidentiality, integrity or availability of personal data.<\/p>\r\n\r\n<p>Three consequences follow, and each surprises someone:<\/p>\r\n\r\n<ul>\r\n<li><strong>Availability counts.<\/strong> A ransomware event that encrypts personal data without exfiltrating it is still a breach.<\/li>\r\n<li><strong>Internal misuse counts.<\/strong> An employee accessing customer records outside their authorisation is unauthorised processing.<\/li>\r\n<li><strong>There is no materiality threshold.<\/strong> Unlike the GDPR, which allows you to skip notifying the supervisory authority where a breach is unlikely to result in risk, Rule 7 contains no risk-based carve-out. A misdirected email containing one person&#8217;s data is, on the text, notifiable.<\/li>\r\n<\/ul>\r\n\r\n<p>That last point is the single biggest divergence from a GDPR-shaped playbook, and it is why importing a European runbook wholesale is a mistake. We cover the wider divergence in <a href=\"https:\/\/protectcomply.com\/blog\/gdpr-vs-dpdp-act\/\">GDPR vs the DPDP Act<\/a>.<\/p>\r\n\r\n<h2>What you must tell affected Data Principals<\/h2>\r\n\r\n<p>Rule 7 requires intimation to each affected individual, through their registered contact method or user account, in clear and plain language. It must include:<\/p>\r\n\r\n<ol>\r\n<li>a description of the breach \u2014 its <strong>nature, extent and timing<\/strong>;<\/li>\r\n<li>the <strong>likely consequences<\/strong> relevant to that individual;<\/li>\r\n<li>the <strong>measures implemented and being implemented<\/strong> by you to mitigate risk;<\/li>\r\n<li><strong>safety measures the individual can take<\/strong> to protect themselves;<\/li>\r\n<li><strong>business contact information<\/strong> of a person able to respond to their questions.<\/li>\r\n<\/ol>\r\n\r\n<p>Point five ties back to <a href=\"https:\/\/protectcomply.com\/blog\/data-protection-officer-dpdp-act\/\">Rule 9 and the DPO contact requirement<\/a>, which already requires you to publish that contact. If you have not named one, you will be inventing it during an incident \u2014 which is exactly when you cannot afford to.<\/p>\r\n\r\n<p>Note &#8220;relevant to that individual.&#8221; A generic bulletin sent to your whole user base does not satisfy a requirement framed around consequences for the affected person.<\/p>\r\n\r\n<h2>What you must tell the Board<\/h2>\r\n\r\n<p><strong>Immediately, without delay:<\/strong> the nature, extent, timing and location of the occurrence, and the likely impact.<\/p>\r\n\r\n<p><strong>Within 72 hours<\/strong> \u2014 or a longer period the Board permits on a reasoned written request:<\/p>\r\n\r\n<ul>\r\n<li>the broad facts, circumstances and reasons leading to the breach;<\/li>\r\n<li>risk mitigation measures implemented and proposed;<\/li>\r\n<li>findings regarding the person who caused the breach;<\/li>\r\n<li>remedial measures taken to prevent recurrence;<\/li>\r\n<li>a copy or summary of the intimations given to affected Data Principals.<\/li>\r\n<\/ul>\r\n\r\n<p>Two things worth flagging. First, &#8220;findings regarding the person who caused the breach&#8221; has no GDPR equivalent \u2014 it presumes an attribution exercise inside 72 hours, which drives your forensic readiness requirements. Second, the extension is available but must be requested with reasons, in writing. It is not automatic and it is not retroactive.<\/p>\r\n\r\n<h2>The penalty exposure<\/h2>\r\n\r\n<table>\r\n<thead>\r\n<tr><th>Default<\/th><th>Maximum penalty<\/th><\/tr>\r\n<\/thead>\r\n<tbody>\r\n<tr><td>Failure to take reasonable security safeguards<\/td><td>\u20b9250 crore<\/td><\/tr>\r\n<tr><td>Failure to notify the Board or affected Data Principals<\/td><td>\u20b9200 crore<\/td><\/tr>\r\n<tr><td>Breach of Significant Data Fiduciary obligations<\/td><td>\u20b9150 crore<\/td><\/tr>\r\n<tr><td>Non-compliance with Board directions<\/td><td>\u20b950 crore<\/td><\/tr>\r\n<\/tbody>\r\n<\/table>\r\n\r\n<p>These are separate defaults. One incident can produce a safeguards failure, a notification failure and a direction failure \u2014 each of which the Data Protection Board can penalise. Appeals go to TDSAT within 60 days, and to the Supreme Court on questions of law. Full detail in <a href=\"https:\/\/protectcomply.com\/blog\/dpdp-act-penalties-explained\/\">DPDP Act penalties explained<\/a>.<\/p>\r\n\r\n<h2>A 72-hour DPDP breach notification playbook<\/h2>\r\n\r\n<h3>Hour 0 to 1 \u2014 Establish awareness<\/h3>\r\n<p>Record the timestamp at which a responsible person became aware that personal data was involved. That timestamp is the anchor for every subsequent deadline, and you will be asked to evidence it. Convene the incident team and appoint a single owner for regulatory communications.<\/p>\r\n\r\n<h3>Hour 1 to 6 \u2014 Scope and send the first Board intimation<\/h3>\r\n<p>You do not need the full picture. You need nature, extent, timing, location and likely impact \u2014 as currently understood. Send it. A short, accurate, clearly provisional intimation filed early is far better than a complete one filed late. State explicitly that details may be revised.<\/p>\r\n\r\n<h3>Hour 6 to 24 \u2014 Identify and notify affected individuals<\/h3>\r\n<p>This is where most organisations fail, because &#8220;without delay&#8221; collides with not knowing exactly who was affected. Work from your data map. If you cannot identify affected individuals from your own <a href=\"https:\/\/protectcomply.com\/blog\/records-of-processing-activities-ropa\/\">RoPA and data inventory<\/a> within a day, that is the gap to fix before an incident, not during one.<\/p>\r\n\r\n<h3>Hour 24 to 60 \u2014 Contain, attribute, remediate<\/h3>\r\n<p>Containment evidence and attribution findings both feed the 72-hour report. Preserve logs. Document every decision with a timestamp \u2014 the report asks for circumstances and reasons, and reconstructed narratives read as reconstructed narratives.<\/p>\r\n\r\n<h3>Hour 60 to 72 \u2014 File the detailed report<\/h3>\r\n<p>Cover all five required elements. Attach the individual intimation template you actually used. If you genuinely cannot complete it, request an extension in writing with reasons <em>before<\/em> the deadline passes.<\/p>\r\n\r\n<h3>After \u2014 Prevent recurrence<\/h3>\r\n<p>The report commits you to remedial measures. The Board can ask what you did about them. Track them like audit findings, not like good intentions.<\/p>\r\n\r\n<h2>What to prepare before you need it<\/h2>\r\n\r\n<ul>\r\n<li><strong>A named regulatory-communications owner<\/strong> and a deputy, with authority to file without waiting for a committee.<\/li>\r\n<li><strong>Pre-drafted templates<\/strong> for the Board intimation, the 72-hour report, and the Data Principal notice \u2014 reviewed by counsel in calm conditions.<\/li>\r\n<li><strong>A current data map.<\/strong> Without one, &#8220;who was affected&#8221; takes days you do not have.<\/li>\r\n<li><strong>Log retention<\/strong> sufficient to support attribution.<\/li>\r\n<li><strong>Processor clauses<\/strong> requiring your vendors to notify you fast enough that you can still meet your own clock. A processor who tells you at hour 70 has consumed your entire window. See <a href=\"https:\/\/protectcomply.com\/blog\/vendor-risk-management-dpdp\/\">vendor risk management under DPDP<\/a>.<\/li>\r\n<li><strong>A tabletop exercise<\/strong> against a 72-hour clock, at least annually. Fold the findings into your wider <a href=\"https:\/\/protectcomply.com\/blog\/dpdp-compliance-checklist\/\">DPDP compliance checklist<\/a>.<\/li>\r\n<\/ul>\r\n\r\n<h2>How this interacts with CERT-In<\/h2>\r\n\r\n<p>DPDP breach notification does not replace your existing obligations. CERT-In directions impose their own reporting duty on a much shorter timeline for specified cyber incidents, and sectoral regulators \u2014 RBI, SEBI, IRDAI \u2014 impose their own. An incident involving personal data at a regulated entity can therefore trigger three or four separate reporting obligations with different deadlines, recipients and formats. Map them once, in advance, into a single trigger matrix. Sector-specific context in our guides for <a href=\"https:\/\/protectcomply.com\/blog\/dpdp-compliance-for-bfsi\/\">BFSI<\/a>, <a href=\"https:\/\/protectcomply.com\/blog\/dpdp-compliance-for-hospitals\/\">hospitals<\/a> and <a href=\"https:\/\/protectcomply.com\/blog\/dpdp-compliance-for-saas\/\">SaaS<\/a>.<\/p>\r\n\r\n<h2>When does DPDP breach notification become enforceable?<\/h2>\r\n\r\n<p>Rule 7 sits in the tranche of obligations that take effect 13 May 2027, 18 months after the Rules were notified in November 2025. That is preparation time, not dormancy: an organisation that has not run a tabletop exercise before then will discover its gaps during a real incident. Full sequencing in our <a href=\"https:\/\/protectcomply.com\/blog\/dpdp-rules-2025-timeline\/\">DPDP Rules 2025 timeline<\/a>.<\/p>\r\n\r\n<h2>A worked example<\/h2>\r\n\r\n<p>A mid-sized Indian lender discovers at 9:40 pm on a Friday that a misconfigured storage bucket exposed loan application files. Here is where the clocks land.<\/p>\r\n\r\n<p><strong>Friday 21:40 \u2014 awareness.<\/strong> A security engineer confirms personal data is in the exposed bucket. That is the anchor timestamp. Not Monday morning when the CISO is briefed.<\/p>\r\n\r\n<p><strong>Friday 22:30 \u2014 first Board intimation.<\/strong> Nature: unauthorised access to a cloud storage bucket. Extent: approximately 40,000 loan applications, under investigation. Timing: exposure window under review, discovered 21:40 IST. Location: cloud storage in the Mumbai region. Likely impact: exposure of identity documents and financial details. Filed as provisional.<\/p>\r\n\r\n<p><strong>Saturday 08:00 to 16:00 \u2014 identification.<\/strong> The lender queries its data inventory to map application IDs to registered contact details. Because the RoPA was current, this takes eight hours. Without it, the same exercise routinely takes four to five days \u2014 which would have breached the &#8220;without delay&#8221; obligation for the individual intimations by a wide margin.<\/p>\r\n\r\n<p><strong>Saturday 18:00 \u2014 Data Principal intimation.<\/strong> Sent by SMS and email to registered contacts, in the language each applicant used at onboarding, describing the exposure, the specific documents involved, the credit-monitoring step the lender is funding, advice on watching for identity fraud, and a named contact.<\/p>\r\n\r\n<p><strong>Sunday to Monday \u2014 attribution and containment.<\/strong> Logs establish the misconfiguration date, the access pattern, and that a third-party integrator changed the bucket policy during a migration. That finding goes into the report.<\/p>\r\n\r\n<p><strong>Monday 20:00, hour 70 \u2014 detailed report filed.<\/strong> Circumstances, cause, the integrator&#8217;s role, containment, remediation including a policy-as-code control to prevent recurrence, and a copy of the individual intimation used.<\/p>\r\n\r\n<p>The lender&#8217;s exposure is still real \u2014 a safeguards failure occurred. But it has not added a notification default on top, and it can evidence every decision with a timestamp. That is the achievable outcome.<\/p>\r\n\r\n<h2>Where DPDP breach notification actually fails<\/h2>\r\n\r\n<ul>\r\n<li><strong>Delayed awareness.<\/strong> The clock starts at awareness, so weak detection does not buy time \u2014 it just means the breach ran longer before the clock started, which the Board will read as a safeguards failure.<\/li>\r\n<li><strong>Waiting for certainty.<\/strong> Teams sit on the first Board intimation until forensics is complete. &#8220;Without delay&#8221; does not admit that. File provisionally and revise.<\/li>\r\n<li><strong>No way to identify affected individuals.<\/strong> The most common blocker. If your data map cannot answer &#8220;whose data was in this system&#8221; in hours, fix that first.<\/li>\r\n<li><strong>Escalation that stalls out of hours.<\/strong> Most incidents are discovered outside business hours. If filing requires a committee that meets on Tuesdays, you have already missed.<\/li>\r\n<li><strong>Processor silence.<\/strong> Vendor contracts that say &#8220;notify promptly&#8221; instead of &#8220;notify within 12 hours of awareness&#8221; hand your window to someone else.<\/li>\r\n<li><strong>Generic notices.<\/strong> One bulletin to the whole user base does not describe consequences relevant to the individual.<\/li>\r\n<li><strong>Remediation that never happens.<\/strong> The report is a commitment. Track it.<\/li>\r\n<\/ul>\r\n\r\n<h2>Template outlines<\/h2>\r\n\r\n<p>Have these drafted and legally reviewed before you need them. Fill-in-the-blank beats blank-page drafting at 2am.<\/p>\r\n\r\n<p><strong>Initial Board intimation<\/strong> \u2014 organisation and Data Fiduciary details; named contact; nature of the breach; extent, with numbers marked as provisional; timing of occurrence and of awareness; location; categories of personal data involved; likely impact; immediate containment; a statement that details may be revised.<\/p>\r\n\r\n<p><strong>72-hour detailed report<\/strong> \u2014 everything above, confirmed; broad facts and circumstances; root cause; findings on who caused the breach; risk mitigation implemented and proposed; remedial measures to prevent recurrence with owners and dates; the number of Data Principals intimated, when, and by what channel; a copy of the intimation text.<\/p>\r\n\r\n<p><strong>Data Principal intimation<\/strong> \u2014 plain language, no legal hedging; what happened and when; exactly which of their data was involved; likely consequences for them; what you have done; what they should do, with specific steps; the named contact and how to reach them; where to find updates.<\/p>\r\n\r\n<p>Keep the individual notice under 400 words. Long notices do not get read, and an unread notice does not reduce harm.<\/p>\r\n\r\n<h2>Frequently asked questions<\/h2>\r\n\r\n<h3>Is the DPDP breach notification deadline 72 hours?<\/h3>\r\n<p>Partly. Intimation to affected Data Principals and the initial intimation to the Board are both due &#8220;without delay.&#8221; The 72-hour deadline applies only to the detailed report to the Board.<\/p>\r\n\r\n<h3>When does the clock start?<\/h3>\r\n<p>On becoming aware that a personal data breach has occurred \u2014 not when the incident began, and not when investigation concludes.<\/p>\r\n\r\n<h3>Do we have to notify small breaches?<\/h3>\r\n<p>Rule 7 contains no materiality threshold and no risk-based exemption. On the text, every personal data breach is notifiable to the Board and to affected individuals.<\/p>\r\n\r\n<h3>Can we get an extension?<\/h3>\r\n<p>The Board may permit a longer period for the detailed report. Request it in writing with reasons, before the 72 hours expire. There is no extension for the &#8220;without delay&#8221; obligations.<\/p>\r\n\r\n<h3>What if our vendor caused the breach?<\/h3>\r\n<p>You remain the accountable Data Fiduciary. The obligation to notify is yours, and the report must include findings on who caused it. Build the notification timeline into your processor contracts.<\/p>\r\n\r\n<h3>Does DPDP notification replace CERT-In reporting?<\/h3>\r\n<p>No. They are parallel obligations with different timelines and recipients, and sectoral regulators may add more.<\/p>\r\n\r\n<hr>\r\n\r\n<p><strong>Can your team evidence hour zero?<\/strong> DPDP breach notification is won or lost on preparation. ProtectComply&#8217;s breach module runs Board notification and the 72-hour report against SLA timers, with the audit trail attached. <a href=\"https:\/\/protectcomply.com\/contact\">Book a walkthrough<\/a>, or see how breach readiness sits inside a full programme in our comparison of the <a href=\"https:\/\/protectcomply.com\/blog\/best-dpdp-platform-in-india\/\">best DPDP platform in India<\/a>.<\/p>","protected":false},"excerpt":{"rendered":"<p>Almost every article on DPDP breach notification in India leads with &#8220;you have 72 hours.&#8221; That framing is wrong, and it is the kind of wrong that costs money. Rule\u2026<\/p>\n","protected":false},"author":2,"featured_media":10148,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-10072","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-whitepapers"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.2 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>DPDP Breach Notification: The 72-Hour Rule Explained<\/title>\n<meta name=\"description\" content=\"DPDP breach notification runs two clocks: without delay to data principals and 72 hours to the Board. Rule 7 duties, a playbook, templates and penalties.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/protectcomply.com\/blog\/dpdp-breach-notification-72-hours\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"DPDP Breach Notification: The 72-Hour Rule Explained\" \/>\n<meta property=\"og:description\" content=\"DPDP breach notification runs two clocks: without delay to data principals and 72 hours to the Board. Rule 7 duties, a playbook, templates and penalties.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/protectcomply.com\/blog\/dpdp-breach-notification-72-hours\/\" \/>\n<meta property=\"og:site_name\" content=\"ProtectComply Blog\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-25T07:32:16+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-01T08:33:46+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/protectcomply.com\/blog\/wp-content\/uploads\/2026\/09\/dpdp-breach-notification-72-hour-sequence.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"675\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Yatin Chaudhary\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Yatin Chaudhary\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"10 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/protectcomply.com\\\/blog\\\/dpdp-breach-notification-72-hours\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/protectcomply.com\\\/blog\\\/dpdp-breach-notification-72-hours\\\/\"},\"author\":{\"name\":\"Yatin Chaudhary\",\"@id\":\"https:\\\/\\\/protectcomply.com\\\/blog\\\/#\\\/schema\\\/person\\\/c160372f03b02285711e68f42c5dc9d5\"},\"headline\":\"DPDP Breach Notification: The 72-Hour Rule Explained\",\"datePublished\":\"2026-08-25T07:32:16+00:00\",\"dateModified\":\"2026-09-01T08:33:46+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/protectcomply.com\\\/blog\\\/dpdp-breach-notification-72-hours\\\/\"},\"wordCount\":2141,\"image\":{\"@id\":\"https:\\\/\\\/protectcomply.com\\\/blog\\\/dpdp-breach-notification-72-hours\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/protectcomply.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/dpdp-breach-notification-72-hour-sequence.png\",\"articleSection\":[\"Whitepapers\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/protectcomply.com\\\/blog\\\/dpdp-breach-notification-72-hours\\\/\",\"url\":\"https:\\\/\\\/protectcomply.com\\\/blog\\\/dpdp-breach-notification-72-hours\\\/\",\"name\":\"DPDP Breach Notification: The 72-Hour Rule Explained\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/protectcomply.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/protectcomply.com\\\/blog\\\/dpdp-breach-notification-72-hours\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/protectcomply.com\\\/blog\\\/dpdp-breach-notification-72-hours\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/protectcomply.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/dpdp-breach-notification-72-hour-sequence.png\",\"datePublished\":\"2026-08-25T07:32:16+00:00\",\"dateModified\":\"2026-09-01T08:33:46+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/protectcomply.com\\\/blog\\\/#\\\/schema\\\/person\\\/c160372f03b02285711e68f42c5dc9d5\"},\"description\":\"DPDP breach notification runs two clocks: without delay to data principals and 72 hours to the Board. Rule 7 duties, a playbook, templates and penalties.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/protectcomply.com\\\/blog\\\/dpdp-breach-notification-72-hours\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/protectcomply.com\\\/blog\\\/dpdp-breach-notification-72-hours\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/protectcomply.com\\\/blog\\\/dpdp-breach-notification-72-hours\\\/#primaryimage\",\"url\":\"https:\\\/\\\/protectcomply.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/dpdp-breach-notification-72-hour-sequence.png\",\"contentUrl\":\"https:\\\/\\\/protectcomply.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/dpdp-breach-notification-72-hour-sequence.png\",\"width\":1200,\"height\":675,\"caption\":\"Intimation is immediate. The 72 hours applies to the detailed report to the Board, not to telling anyone.\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/protectcomply.com\\\/blog\\\/dpdp-breach-notification-72-hours\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/protectcomply.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"DPDP Breach Notification: The 72-Hour Rule Explained\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/protectcomply.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/protectcomply.com\\\/blog\\\/\",\"name\":\"ProtectComply Blog\",\"description\":\"Compliance, decoded.\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/protectcomply.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/protectcomply.com\\\/blog\\\/#\\\/schema\\\/person\\\/c160372f03b02285711e68f42c5dc9d5\",\"name\":\"Yatin Chaudhary\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/b3118fd8d92f29a765fb664cac1dfe2f89c06e1cb94e0e44c895a237e84a15d1?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/b3118fd8d92f29a765fb664cac1dfe2f89c06e1cb94e0e44c895a237e84a15d1?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/b3118fd8d92f29a765fb664cac1dfe2f89c06e1cb94e0e44c895a237e84a15d1?s=96&d=mm&r=g\",\"caption\":\"Yatin Chaudhary\"},\"url\":\"https:\\\/\\\/protectcomply.com\\\/blog\\\/author\\\/yatin-chaudhary\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"DPDP Breach Notification: The 72-Hour Rule Explained","description":"DPDP breach notification runs two clocks: without delay to data principals and 72 hours to the Board. Rule 7 duties, a playbook, templates and penalties.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/protectcomply.com\/blog\/dpdp-breach-notification-72-hours\/","og_locale":"en_US","og_type":"article","og_title":"DPDP Breach Notification: The 72-Hour Rule Explained","og_description":"DPDP breach notification runs two clocks: without delay to data principals and 72 hours to the Board. Rule 7 duties, a playbook, templates and penalties.","og_url":"https:\/\/protectcomply.com\/blog\/dpdp-breach-notification-72-hours\/","og_site_name":"ProtectComply Blog","article_published_time":"2026-08-25T07:32:16+00:00","article_modified_time":"2026-09-01T08:33:46+00:00","og_image":[{"width":1200,"height":675,"url":"https:\/\/protectcomply.com\/blog\/wp-content\/uploads\/2026\/09\/dpdp-breach-notification-72-hour-sequence.png","type":"image\/png"}],"author":"Yatin Chaudhary","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Yatin Chaudhary","Est. reading time":"10 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/protectcomply.com\/blog\/dpdp-breach-notification-72-hours\/#article","isPartOf":{"@id":"https:\/\/protectcomply.com\/blog\/dpdp-breach-notification-72-hours\/"},"author":{"name":"Yatin Chaudhary","@id":"https:\/\/protectcomply.com\/blog\/#\/schema\/person\/c160372f03b02285711e68f42c5dc9d5"},"headline":"DPDP Breach Notification: The 72-Hour Rule Explained","datePublished":"2026-08-25T07:32:16+00:00","dateModified":"2026-09-01T08:33:46+00:00","mainEntityOfPage":{"@id":"https:\/\/protectcomply.com\/blog\/dpdp-breach-notification-72-hours\/"},"wordCount":2141,"image":{"@id":"https:\/\/protectcomply.com\/blog\/dpdp-breach-notification-72-hours\/#primaryimage"},"thumbnailUrl":"https:\/\/protectcomply.com\/blog\/wp-content\/uploads\/2026\/09\/dpdp-breach-notification-72-hour-sequence.png","articleSection":["Whitepapers"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/protectcomply.com\/blog\/dpdp-breach-notification-72-hours\/","url":"https:\/\/protectcomply.com\/blog\/dpdp-breach-notification-72-hours\/","name":"DPDP Breach Notification: The 72-Hour Rule Explained","isPartOf":{"@id":"https:\/\/protectcomply.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/protectcomply.com\/blog\/dpdp-breach-notification-72-hours\/#primaryimage"},"image":{"@id":"https:\/\/protectcomply.com\/blog\/dpdp-breach-notification-72-hours\/#primaryimage"},"thumbnailUrl":"https:\/\/protectcomply.com\/blog\/wp-content\/uploads\/2026\/09\/dpdp-breach-notification-72-hour-sequence.png","datePublished":"2026-08-25T07:32:16+00:00","dateModified":"2026-09-01T08:33:46+00:00","author":{"@id":"https:\/\/protectcomply.com\/blog\/#\/schema\/person\/c160372f03b02285711e68f42c5dc9d5"},"description":"DPDP breach notification runs two clocks: without delay to data principals and 72 hours to the Board. Rule 7 duties, a playbook, templates and penalties.","breadcrumb":{"@id":"https:\/\/protectcomply.com\/blog\/dpdp-breach-notification-72-hours\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/protectcomply.com\/blog\/dpdp-breach-notification-72-hours\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/protectcomply.com\/blog\/dpdp-breach-notification-72-hours\/#primaryimage","url":"https:\/\/protectcomply.com\/blog\/wp-content\/uploads\/2026\/09\/dpdp-breach-notification-72-hour-sequence.png","contentUrl":"https:\/\/protectcomply.com\/blog\/wp-content\/uploads\/2026\/09\/dpdp-breach-notification-72-hour-sequence.png","width":1200,"height":675,"caption":"Intimation is immediate. The 72 hours applies to the detailed report to the Board, not to telling anyone."},{"@type":"BreadcrumbList","@id":"https:\/\/protectcomply.com\/blog\/dpdp-breach-notification-72-hours\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/protectcomply.com\/blog\/"},{"@type":"ListItem","position":2,"name":"DPDP Breach Notification: The 72-Hour Rule Explained"}]},{"@type":"WebSite","@id":"https:\/\/protectcomply.com\/blog\/#website","url":"https:\/\/protectcomply.com\/blog\/","name":"ProtectComply Blog","description":"Compliance, decoded.","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/protectcomply.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/protectcomply.com\/blog\/#\/schema\/person\/c160372f03b02285711e68f42c5dc9d5","name":"Yatin Chaudhary","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/b3118fd8d92f29a765fb664cac1dfe2f89c06e1cb94e0e44c895a237e84a15d1?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/b3118fd8d92f29a765fb664cac1dfe2f89c06e1cb94e0e44c895a237e84a15d1?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/b3118fd8d92f29a765fb664cac1dfe2f89c06e1cb94e0e44c895a237e84a15d1?s=96&d=mm&r=g","caption":"Yatin Chaudhary"},"url":"https:\/\/protectcomply.com\/blog\/author\/yatin-chaudhary\/"}]}},"_links":{"self":[{"href":"https:\/\/protectcomply.com\/blog\/wp-json\/wp\/v2\/posts\/10072","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/protectcomply.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/protectcomply.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/protectcomply.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/protectcomply.com\/blog\/wp-json\/wp\/v2\/comments?post=10072"}],"version-history":[{"count":3,"href":"https:\/\/protectcomply.com\/blog\/wp-json\/wp\/v2\/posts\/10072\/revisions"}],"predecessor-version":[{"id":10163,"href":"https:\/\/protectcomply.com\/blog\/wp-json\/wp\/v2\/posts\/10072\/revisions\/10163"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/protectcomply.com\/blog\/wp-json\/wp\/v2\/media\/10148"}],"wp:attachment":[{"href":"https:\/\/protectcomply.com\/blog\/wp-json\/wp\/v2\/media?parent=10072"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/protectcomply.com\/blog\/wp-json\/wp\/v2\/categories?post=10072"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/protectcomply.com\/blog\/wp-json\/wp\/v2\/tags?post=10072"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}