DPDP NavigatorAct 2023 · Rules 2025
Rule 7Security Safeguards & Breach Intimation

Intimation of personal data breach

What the Rule sets out

Requires intimation to the Board without undue delay once the Data Fiduciary becomes aware of a breach, describing its nature, extent and likely impact, followed by a more detailed report — including root cause, mitigating actions taken, and remedial steps — within a further prescribed window. Affected Data Principals must separately be told in clear language what happened and what they can do about it.

What this means in practice
  • Treat this as two separate deliverables: a fast initial notification, then a fuller root-cause report — don't wait to have every detail before sending the first one.
  • Your incident response runbook should map directly onto these two deliverables plus the individual-facing notice.

Summarised for practical use from the publicly notified DPDP Rules, 2025. Confirm exact clause text against the official Gazette notification before relying on it for compliance decisions.