All templates
Internal Registers & TrackersSection 8(6)
Data Breach Log Template
A running log to record, triage, and track every personal data breach incident from detection through closure.
Template
DATA BREACH LOG Organization: [Organization Name] Maintained By: [DPO / Incident Response Owner] Confidentiality: Internal - Restricted 1. PURPOSE This log records every suspected or confirmed personal data breach so that [Organization Name] can meet its obligation under Section 8(6) of the DPDP Act, 2023 to intimate the Data Protection Board of India and affected Data Principals without delay, and to maintain an auditable trail of the response. 2. INSTRUCTIONS Create an entry the moment a breach is suspected, not after confirmation. Update the status field as the incident progresses. Every closed entry must have a root cause and a corrective action recorded. 3. LOG Column headers: Incident ID | Date/Time Detected | Date/Time Reported Internally | Nature of Breach | Data Categories Affected | Approx. No. of Data Principals Affected | Root Cause (if known) | Board Intimated (Y/N, Date) | Data Principals Notified (Y/N, Date) | Containment Actions | Status | Closure Date | Owner Example Row 1: Incident ID: BR-2026-001 Date/Time Detected: [DD-MM-YYYY, HH:MM] Date/Time Reported Internally: [DD-MM-YYYY, HH:MM] Nature of Breach: Unauthorized access to customer support database via compromised credentials Data Categories Affected: Name, email, phone number, support ticket contents Approx. No. of Data Principals Affected: [1,240] Root Cause: Reused password on an admin account, no MFA enforced Board Intimated: Y - [DD-MM-YYYY], initial intimation filed without delay, detailed report to follow per Rules Data Principals Notified: Y - [DD-MM-YYYY], email notification per Section 8(6) Containment Actions: Credential reset, MFA enforced org-wide, session revoked Status: Under investigation Closure Date: [Pending] Owner: [Incident Response Lead] Example Row 2: Incident ID: BR-2026-002 Date/Time Detected: [DD-MM-YYYY, HH:MM] Date/Time Reported Internally: [DD-MM-YYYY, HH:MM] Nature of Breach: Misconfigured cloud storage bucket left briefly accessible without authentication Data Categories Affected: Uploaded KYC documents Approx. No. of Data Principals Affected: [37] Root Cause: Storage permission misconfiguration during a deployment Board Intimated: Y - [DD-MM-YYYY] Data Principals Notified: Y - [DD-MM-YYYY] Containment Actions: Bucket access revoked within [2] hours, access logs reviewed for exfiltration Status: Closed Closure Date: [DD-MM-YYYY] Owner: [Cloud Infrastructure Lead] 4. SEVERITY AND ESCALATION GUIDE Low: Limited data categories, no evidence of exfiltration, small number of Data Principals. Internal escalation to DPO within 24 hours. Medium: Sensitive categories involved or exfiltration suspected. Immediate DPO and leadership escalation, Board intimation assessment triggered. High: Large-scale exposure, financial or health data, or children's data involved. Immediate Board intimation and Data Principal notification process activated per Section 8(6). 5. POST-INCIDENT REVIEW Every closed incident requires a short post-incident note covering: what happened, why the safeguard failed, and what control was added or strengthened. File the note against the Incident ID above and cross-reference it in the Compliance Evidence Index.
This template is a starting point, not legal advice. Have it reviewed by qualified counsel before use, and adapt bracketed placeholders to your organization's facts.