DPDP NavigatorAct 2023 · Rules 2025
All tools
Section 8(6)v1.3Live

Personal Data Breach Response Planner

A step-by-step planner for Board and Data Principal intimation timelines, containment actions, and post-incident review.

Overall progress0%
0 of 22 actions completed

1. Detect & Contain

Immediate0/4

2. Assess Scope & Impact

First hours0/4

3. Notify the Data Protection Board

Without delay0/3

4. Notify Affected Data Principals

Section 8(6)0/4

5. Detailed Report & Remediation

Follow-up window0/3

6. Post-Incident Review

Within 30 days0/4

Draft your Board intimation

Fill in what you know now — you can send the initial intimation before every detail is confirmed.

Details

Live preview
PERSONAL DATA BREACH INTIMATION
To: Data Protection Board of India
From: [Organization Name]

DATE OF DISCOVERY: [discovery date]

1. NATURE OF THE BREACH
   [Organization Name] identified a personal data breach on [discovery date].

2. DATA CATEGORIES AFFECTED
   [data categories]

3. ESTIMATED SCOPE
   Approximately [approximate number] Data Principals are believed to be affected.

4. KNOWN OR SUSPECTED CAUSE
   [known/suspected cause]

5. IMMEDIATE ACTIONS TAKEN
   [containment actions taken]

6. NEXT STEPS
   A detailed root-cause report, including full remedial and mitigating
   measures, will follow in accordance with the timeline prescribed under
   the DPDP Rules, 2025. Affected Data Principals are being separately
   notified in clear language, in accordance with Section 8(6) of the
   DPDP Act, 2023.

7. CONTACT FOR THIS INCIDENT
   [incident contact]

---
Generated with the DPDP Navigator Breach Response Planner.
Have this reviewed by legal/compliance counsel before submission.