Under the DPDP Act a Data Fiduciary that suffers a personal data breach must give intimation of it to the Data Protection Board of India and to each affected Data Principal, in the form and manner prescribed. The obligation is not conditional on the breach being judged severe, which is why organisations need a defined assessment and notification path rather than an ad hoc response.
Meeting a notification obligation is a systems problem before it is a legal one. You cannot tell affected individuals what happened to their data if you do not know which individuals' data was in the affected system — which is why the inventory and RoPA are prerequisites for breach response, not separate exercises.
Practically: detect, scope against the inventory, assess, notify, remediate, and keep an incident record showing when each step happened and who decided what.
General information about the DPDP Act, not legal advice. Obligations depend on your circumstances.
Dinkar Singh — Dinkar covers privacy engineering at ProtectComply — discovery, consent propagation and the evidence trail behind them.
Take the free readiness check and find out in 10 minutes.
Start free readiness check →