All tools
Section 8(6)v1.3Live
Personal Data Breach Response Planner
A step-by-step planner for Board and Data Principal intimation timelines, containment actions, and post-incident review.
Overall progress0%
0 of 22 actions completed
1. Detect & Contain
Immediate0/4
2. Assess Scope & Impact
First hours0/4
3. Notify the Data Protection Board
Without delay0/3
4. Notify Affected Data Principals
Section 8(6)0/4
5. Detailed Report & Remediation
Follow-up window0/3
6. Post-Incident Review
Within 30 days0/4
Draft your Board intimation
Fill in what you know now — you can send the initial intimation before every detail is confirmed.
Details
Live preview
PERSONAL DATA BREACH INTIMATION To: Data Protection Board of India From: [Organization Name] DATE OF DISCOVERY: [discovery date] 1. NATURE OF THE BREACH [Organization Name] identified a personal data breach on [discovery date]. 2. DATA CATEGORIES AFFECTED [data categories] 3. ESTIMATED SCOPE Approximately [approximate number] Data Principals are believed to be affected. 4. KNOWN OR SUSPECTED CAUSE [known/suspected cause] 5. IMMEDIATE ACTIONS TAKEN [containment actions taken] 6. NEXT STEPS A detailed root-cause report, including full remedial and mitigating measures, will follow in accordance with the timeline prescribed under the DPDP Rules, 2025. Affected Data Principals are being separately notified in clear language, in accordance with Section 8(6) of the DPDP Act, 2023. 7. CONTACT FOR THIS INCIDENT [incident contact] --- Generated with the DPDP Navigator Breach Response Planner. Have this reviewed by legal/compliance counsel before submission.