All templates
PoliciesSection 8
Data Breach Response Policy Template
An incident response policy detailing detection, assessment, containment, and intimation obligations for personal data breaches.
Template
PERSONAL DATA BREACH RESPONSE POLICY [Organization Name] Effective Date: [Effective Date] | Policy Owner: [DPO / CISO] 1. PURPOSE This Policy sets out how [Organization Name] detects, assesses, contains, and reports personal data breaches, in fulfilment of our obligation under Section 8(6) of the DPDP Act, 2023 to intimate the Data Protection Board of India and each affected Data Principal in the event of a breach, in the form and manner prescribed under the DPDP Rules, 2025. 2. DEFINITION OF A PERSONAL DATA BREACH Any unauthorised processing, accidental disclosure, loss, alteration, or destruction of personal data that compromises its confidentiality, integrity, or availability, whether caused by external attack, internal error, vendor failure, or system malfunction. 3. INCIDENT RESPONSE TEAM (IRT) - Incident Commander: [Role/Name] - Data Protection Officer: [Name] — coordinates regulatory intimation - IT Security Lead: [Role/Name] — leads technical containment - Legal Counsel: [Role/Name] — assesses notification obligations - Communications Lead: [Role/Name] — manages Data Principal and public communication 4. DETECTION AND REPORTING (INTERNAL) Any employee, contractor, or vendor who becomes aware of a suspected breach must report it immediately, and in any event within [X hours], to [breach-reporting@domain / hotline], using the Incident Report Form (Annexure A). No employee shall attempt to conceal or independently resolve a suspected breach. 5. ASSESSMENT (WITHIN [24-72] HOURS OF DETECTION) The IRT shall assess: a. Nature and scope of data involved (categories, number of Data Principals affected) b. Root cause (technical vulnerability, human error, third-party failure) c. Likely consequences for affected Data Principals (identity theft, financial loss, reputational harm) d. Whether the breach originated with a processor, triggering our contractual intimation rights against them. 6. CONTAINMENT AND REMEDIATION Immediate steps to contain the breach (e.g., revoke compromised credentials, patch vulnerability, isolate affected systems) shall be taken without waiting for the full assessment to conclude. A remediation plan with named owners and deadlines shall be documented. 7. INTIMATION TO THE DATA PROTECTION BOARD OF INDIA The Data Protection Officer shall prepare and submit intimation to the Data Protection Board of India in the form, manner, and within the timeline prescribed under the DPDP Rules, 2025, including known facts, likely impact, mitigation steps taken, and remedial measures offered to Data Principals. Where full facts are not yet available, an initial intimation shall be followed by supplementary updates as the investigation progresses. 8. INTIMATION TO AFFECTED DATA PRINCIPALS Affected Data Principals shall be notified via [email/SMS/in-app notice] describing: the nature of the breach, the categories of personal data likely affected, the likely consequences, the measures implemented to mitigate risk, and a contact point for queries (Grievance Officer). 9. VENDOR/PROCESSOR BREACHES Where a breach occurs at a processor engaged by us, the processor must notify us within [X hours] under the terms of the Data Processing Agreement, and we retain responsibility for onward intimation to the Board and Data Principals as the Data Fiduciary. 10. POST-INCIDENT REVIEW Within [X weeks] of resolution, the IRT shall conduct a post-mortem, update this Policy and relevant security controls, and record lessons learned in the Incident Register. 11. RECORD-KEEPING All incident reports, assessments, and intimations shall be logged in the Incident Register and retained for [X years] to demonstrate compliance and support any Board inquiry. 12. TRAINING All employees shall receive breach-recognition and reporting training at induction and annually thereafter. Approved by: [Name, Designation] Date: [Date] ANNEXURE A: Incident Report Form — [Reporter Name, Date/Time Detected, Description, Systems/Data Affected, Immediate Actions Taken]
This template is a starting point, not legal advice. Have it reviewed by qualified counsel before use, and adapt bracketed placeholders to your organization's facts.