Checklist4 min read

DPDP 72-Hour Breach Notification Checklist for India

Indian businesses face strict DPDP breach rules. Use this 72-hour checklist to detect, contain, assess, and notify authorities and Data Principals.

SP
Sushant Pasumarty

DPDP 72-Hour Breach Notification Checklist

The Digital Personal Data Protection Act (DPDP) mandates strict timelines for reporting personal data breaches. Indian businesses must notify the Data Protection Board of India (DPBI) and affected Data Principals promptly, often within 72 hours of becoming aware of a breach.

This checklist provides a structured approach to manage a personal data breach under DPDP, outlining actions, responsible roles, and estimated timeframes. Following these steps helps mitigate risk and ensures compliance.

Phase 1: Immediate Response (First 12-24 Hours)

  1. Identify and Contain the Breach:
    • Action: Isolate affected systems, revoke access, and stop further data exfiltration. Document initial findings.
    • Owner: CISO/Security Team, CTO
    • Time Estimate: 2-6 hours
    • External Help Cost (if needed): ₹50,000 – ₹1.5L (Incident Response Specialist)
    • MBS Tier Relevance: Full DPDP Consulting (includes implementation support and DPO training)
  2. Preserve Evidence:
    • Action: Secure logs, forensic images, and other relevant data without altering them.
    • Owner: CISO/Security Team
    • Time Estimate: 1-3 hours
    • External Help Cost (if needed): ₹30,000 – ₹1L (Forensic Expert)
  3. Initial Assessment & Severity Analysis:
    • Action: Determine the type of data compromised, the number of affected Data Principals, and potential impact.
    • Owner: CISO/Security Team, DPO/Compliance Officer
    • Time Estimate: 4-8 hours
    • MBS Tier Relevance: DPDP Readiness Audit (helps identify breach impact areas)
  4. Assemble Incident Response Team:
    • Action: Designate a core team including legal, IT/security, communications, and compliance. Define roles and communication channels.
    • Owner: CXO/CEO
    • Time Estimate: 1-2 hours
  5. Internal Communication:
    • Action: Inform relevant internal stakeholders (legal, HR, management) about the breach and ongoing response.
    • Owner: Management/DPO
    • Time Estimate: 1 hour

Phase 2: Notification & Mitigation Planning (24-72 Hours)

  1. Prepare Initial Notification to DPBI:
    • Action: Draft a preliminary breach notification including known details, impact, and mitigation steps. DPDP requires notification 'without undue delay'.
    • Owner: DPO/Compliance Officer, Legal Counsel
    • Time Estimate: 6-12 hours
    • External Help Cost (if needed): ₹50,000 – ₹2L (Legal Counsel for DPDP)
    • MBS Tier Relevance: DPDP Workshop (provides prioritized recommendations for such processes)
  2. Prepare Communication to Affected Data Principals (if required):
    • Action: Assess if the breach poses significant harm requiring direct notification to individuals. Draft communication, outlining affected data, risks, and recommended actions for them.
    • Owner: DPO/Compliance Officer, Communications Lead
    • Time Estimate: 8-16 hours
    • External Help Cost (if needed): ₹40,000 – ₹1.5L (PR/Communications Advisor)
  3. Review & Approve Notifications:
    • Action: Legal and senior management review and approve all external communications.
    • Owner: Legal Counsel, CXO
    • Time Estimate: 2-4 hours
  4. Submit Notification to DPBI:
    • Action: Formally submit the breach notification to the Data Protection Board of India.
    • Owner: DPO/Compliance Officer
    • Time Estimate: 1 hour
  5. Implement Immediate Mitigation & Recovery Steps:
    • Action: Restore systems from backups, patch vulnerabilities, reset passwords, and enhance security controls based on initial findings.
    • Owner: CISO/Security Team
    • Time Estimate: Ongoing, 12-48 hours within this phase
    • MBS Tier Relevance: Full DPDP Consulting (implementation support)

Phase 3: Post-Notification & Remediation (Beyond 72 Hours)

  1. Communicate with Affected Data Principals:
    • Action: Distribute the approved notification to individuals, offering support or resources as needed (e.g., credit monitoring).
    • Owner: Communications Lead, DPO
    • Time Estimate: 2-8 hours (distribution), ongoing (support)
  2. Conduct Root Cause Analysis:
    • Action: Investigate how the breach occurred to prevent future incidents. Document findings.
    • Owner: CISO/Security Team, Internal Audit
    • Time Estimate: 1-3 weeks
    • MBS Tier Relevance: DPDP Readiness Audit (identifies potential gaps)
  3. Enhance Security Controls & Policies:
    • Action: Implement new security measures, update policies, and conduct staff training based on the root cause analysis.
    • Owner: CISO/Security Team, HR, DPO
    • Time Estimate: Ongoing, 2-4 weeks
    • MBS Tier Relevance: Full DPDP Consulting (implementation, DPO training)
  4. Document & Review Incident:
    • Action: Create a comprehensive post-incident report, including lessons learned and action items for continuous improvement.
    • Owner: DPO/Compliance Officer
    • Time Estimate: 1-2 weeks
💡 Key Insight: Timely and accurate breach notification is a cornerstone of DPDP compliance. A well-defined incident response plan, built during your readiness phase, is critical to meet the 72-hour deadline.

What This Costs: DIY vs. Meridian Bridge Strategy Services

Managing a data breach effectively requires specialized expertise in cybersecurity, legal interpretation, and communication. While some initial steps can be managed internally, complex breaches often necessitate external support.

AspectDIY Approach (Internal Resources)MBS DPDP Service Tier SupportEstimated Cost (External if needed)
Initial Containment & ForensicsRequires skilled internal IT/Security team.Supported by Full DPDP Consulting (training, readiness planning).₹80,000 – ₹2.5L (external specialists)
Breach Assessment & Impact AnalysisRelies on internal DPO/Compliance Officer understanding of data flows and DPDP.Directly addressed by Data Mapping (₹1.5L – ₹3L) and DPDP Readiness Audit (₹2L – ₹6L).Part of MBS tiers, or ₹50,000 – ₹1.5L (external legal/consultant)
Notification Drafting & Legal ReviewRequires internal legal counsel with DPDP expertise.Benefits from insights in DPDP Workshop (₹5L – ₹10L) and Full DPDP Consulting (₹7L – ₹12L) which includes DPO training.₹70,000 – ₹2.5L (external legal counsel)
Implementation of RemediationRequires internal IT and project management.Supported by Full DPDP Consulting (₹7L – ₹12L).Varies widely based on technical changes, could be significant.

Sushant Pasamarty, founder of Meridian Bridge Strategy, emphasizes, "Preparing for a breach before it happens is not optional under DPDP. Our services build the framework and train your teams, reducing the chaos and cost during an actual incident."

✅ Pro Tip: Regular mock breach exercises and updating your DPDP implementation timeline with incident response drills can significantly improve your team's reaction time and compliance posture.

Next Step: Bolster Your Breach Readiness

Don't wait for a breach to realize your organization's gaps. Understanding your data flows and current readiness is the first step towards a robust incident response plan.

Use the free calculator on dpdpworkshop.com to determine which MBS service tier is right for your business. From fundamental data mapping to comprehensive implementation support, MBS helps you build resilience.

Frequently Asked Questions

What is the '72-hour' rule under DPDP for breach notification?

DPDP requires Data Fiduciaries to notify the Data Protection Board of India (DPBI) 'without undue delay' and, where appropriate, the affected Data Principals 'in the prescribed manner'. While DPDP doesn't explicitly state 72 hours, this is a common international benchmark for 'undue delay' and best practice for timely notification.

When do I need to notify Data Principals directly about a breach?

Notification to Data Principals is required if the breach is likely to result in significant harm to the individual. This assessment considers the type of data, the sensitivity, the potential for identity theft, financial loss, or reputational damage. Your DPO or legal counsel should make this determination.

How can MBS help my company prepare for DPDP breach notification?

Meridian Bridge Strategy offers services that directly build breach readiness. Our <strong>DPDP Readiness Audit</strong> identifies gaps in your incident response plan, and the <strong>DPDP Workshop</strong> provides prioritized recommendations. For comprehensive support, <strong>Full DPDP Consulting</strong> includes implementation support, DPO training, and helps build robust processes to handle breaches efficiently.

Related Guides

Check Your DPDP Cost

Use the free calculator to estimate your compliance cost. Then book a call with Sushant to scope the right engagement.

Estimate My DPDP Cost →

Recently Updated Guides

Readiness Audit Cost In India: A Price GuideDPDP Workshop for BFSI companies in MumbaiData Breach Cost India: Response & Prevention Guidevs. GDPR: Comparative Compliance Costs: DPDP CostIn-House vs. Consultant: DPDP Cost Comparison for Busines...DPDP Cost for MediaDPDP Cost for NgoDPDP Workshop in MumbaiDPDP Workshop in PuneSignificant Data Fiduciary: DPDP Act Criteria for India:...Checklist for Startups: 2026 Plan: DPDP Checklistin 90 Days: Roadmap for Businesses: DPDP ChecklistDPDP for 10 Employee CompanyDPDP Implementation Timeline: Realistic Phases & CostsDPDP for Franchise Businesses in India: Costs & StepsDPDP Cost for LegalDPDP Workshop in AhmedabadDPDP for Family BusinessDPDP Workshop for Healthcare companies in DelhiDPDP Workshop for Ecommerce companies in BangaloreDPDP Workshop for Ecommerce companies in PuneDPDP Workshop for SaaS companies in MumbaiDPDP Workshop for Manufacturing companies in ChennaiDPDP Workshop for Retail companies in DelhiDPDP Workshop for Hospitality companies in JaipurDPDP Workshop for BFSI companies in KolkataDPDP Compliance: Mandatory for Indian Startups?DPDP vs IT Act 2000: Key Differences for Indian BusinessesCompliant Privacy Policy Cost In India Mbs GuideCompliance Cost: Unlocking Roi For Indian Businessesvs ISO 27001: Costs for Indian Businesses: DPDP CostOneTrust vs CookieBot vs CookieYes: Best CMP for DPDP: DP...In-House vs. Outsourced DPO: Cost & Effectiveness for Ind...Online DPDP Training vs. In-Person Workshop: Which Suits?...DPDP Cost for FintechBig 4 vs. Boutique Consultants for DPDP: Which is Right?:...DPDP Cost for SaaSDPDP Cost for HospitalityDPDP Cost for Real EstateDPDP Cost for GamingDPDP Cost for TelecomDPDP Cost for LogisticsDPDP Cost for RecruitmentDPDP Cost for RetailDPDP Cost for EvDPDP Cost for CryptoDPDP Cost for PharmacyDPDP Cost for CA FirmDPDP Workshop in DelhiDPDP Workshop in HyderabadDPDP Workshop in ChennaiDPDP Workshop in GurgaonDPDP Workshop in NoidaDPDP Workshop in KolkataDPDP Workshop in JaipurDPDP Workshop in KochiDPDP Workshop in LucknowDPDP Workshop in ChandigarhDPDP Workshop in GoaData Fiduciary Under DPDP Act: Compliance Guide: DPDP GuideData Breach: 72-Hour India Notification Guide: DPDP GuideChecklist for Enterprises & CXOs: DPDP ChecklistVendor Evaluation Checklist for Businesses: DPDP ChecklistEmployee Onboarding Checklist: Data Privacy in India: DPD...DPDP Workshop for Edtech companies in HyderabadDPDP Workshop for Real Estate companies in MumbaiDPDP Workshop: Real Estate Delhi-NCR ComplianceDPDP Compliance for Hyderabad Gaming InnovatorsDPDP 30-Day Action Plan for Indian CompaniesDPDP: Handling Consent Withdrawal in IndiaDPDP Data Mapping for Indian Companies: Step-by-Step GuideDPDP Cost for D2C Brands in Bangalore (2024 Guide)DPDP Workshop for Distributed Teams: Includes & CostsDPDP Workshop for Fintech companies in DelhiDPDP Workshop for Healthcare companies in BangaloreDPDP Workshop for Edtech companies in BangaloreDPDP Workshop for BFSI companies in DelhiDPDP Workshop for Real Estate companies in BangaloreDPDP Briefing for Board Members: Governance & LiabilityDPDP Workshop for Customer Support Teams in IndiaDPDP for Temples & Religious Orgs: Does it Apply?