DPDP 72-Hour Breach Notification Checklist for India
Indian businesses face strict DPDP breach rules. Use this 72-hour checklist to detect, contain, assess, and notify authorities and Data Principals.
DPDP 72-Hour Breach Notification Checklist
The Digital Personal Data Protection Act (DPDP) mandates strict timelines for reporting personal data breaches. Indian businesses must notify the Data Protection Board of India (DPBI) and affected Data Principals promptly, often within 72 hours of becoming aware of a breach.
This checklist provides a structured approach to manage a personal data breach under DPDP, outlining actions, responsible roles, and estimated timeframes. Following these steps helps mitigate risk and ensures compliance.
Phase 1: Immediate Response (First 12-24 Hours)
- Identify and Contain the Breach:
- Action: Isolate affected systems, revoke access, and stop further data exfiltration. Document initial findings.
- Owner: CISO/Security Team, CTO
- Time Estimate: 2-6 hours
- External Help Cost (if needed): ₹50,000 – ₹1.5L (Incident Response Specialist)
- MBS Tier Relevance: Full DPDP Consulting (includes implementation support and DPO training)
- Preserve Evidence:
- Action: Secure logs, forensic images, and other relevant data without altering them.
- Owner: CISO/Security Team
- Time Estimate: 1-3 hours
- External Help Cost (if needed): ₹30,000 – ₹1L (Forensic Expert)
- Initial Assessment & Severity Analysis:
- Action: Determine the type of data compromised, the number of affected Data Principals, and potential impact.
- Owner: CISO/Security Team, DPO/Compliance Officer
- Time Estimate: 4-8 hours
- MBS Tier Relevance: DPDP Readiness Audit (helps identify breach impact areas)
- Assemble Incident Response Team:
- Action: Designate a core team including legal, IT/security, communications, and compliance. Define roles and communication channels.
- Owner: CXO/CEO
- Time Estimate: 1-2 hours
- Internal Communication:
- Action: Inform relevant internal stakeholders (legal, HR, management) about the breach and ongoing response.
- Owner: Management/DPO
- Time Estimate: 1 hour
Phase 2: Notification & Mitigation Planning (24-72 Hours)
- Prepare Initial Notification to DPBI:
- Action: Draft a preliminary breach notification including known details, impact, and mitigation steps. DPDP requires notification 'without undue delay'.
- Owner: DPO/Compliance Officer, Legal Counsel
- Time Estimate: 6-12 hours
- External Help Cost (if needed): ₹50,000 – ₹2L (Legal Counsel for DPDP)
- MBS Tier Relevance: DPDP Workshop (provides prioritized recommendations for such processes)
- Prepare Communication to Affected Data Principals (if required):
- Action: Assess if the breach poses significant harm requiring direct notification to individuals. Draft communication, outlining affected data, risks, and recommended actions for them.
- Owner: DPO/Compliance Officer, Communications Lead
- Time Estimate: 8-16 hours
- External Help Cost (if needed): ₹40,000 – ₹1.5L (PR/Communications Advisor)
- Review & Approve Notifications:
- Action: Legal and senior management review and approve all external communications.
- Owner: Legal Counsel, CXO
- Time Estimate: 2-4 hours
- Submit Notification to DPBI:
- Action: Formally submit the breach notification to the Data Protection Board of India.
- Owner: DPO/Compliance Officer
- Time Estimate: 1 hour
- Implement Immediate Mitigation & Recovery Steps:
- Action: Restore systems from backups, patch vulnerabilities, reset passwords, and enhance security controls based on initial findings.
- Owner: CISO/Security Team
- Time Estimate: Ongoing, 12-48 hours within this phase
- MBS Tier Relevance: Full DPDP Consulting (implementation support)
Phase 3: Post-Notification & Remediation (Beyond 72 Hours)
- Communicate with Affected Data Principals:
- Action: Distribute the approved notification to individuals, offering support or resources as needed (e.g., credit monitoring).
- Owner: Communications Lead, DPO
- Time Estimate: 2-8 hours (distribution), ongoing (support)
- Conduct Root Cause Analysis:
- Action: Investigate how the breach occurred to prevent future incidents. Document findings.
- Owner: CISO/Security Team, Internal Audit
- Time Estimate: 1-3 weeks
- MBS Tier Relevance: DPDP Readiness Audit (identifies potential gaps)
- Enhance Security Controls & Policies:
- Action: Implement new security measures, update policies, and conduct staff training based on the root cause analysis.
- Owner: CISO/Security Team, HR, DPO
- Time Estimate: Ongoing, 2-4 weeks
- MBS Tier Relevance: Full DPDP Consulting (implementation, DPO training)
- Document & Review Incident:
- Action: Create a comprehensive post-incident report, including lessons learned and action items for continuous improvement.
- Owner: DPO/Compliance Officer
- Time Estimate: 1-2 weeks
What This Costs: DIY vs. Meridian Bridge Strategy Services
Managing a data breach effectively requires specialized expertise in cybersecurity, legal interpretation, and communication. While some initial steps can be managed internally, complex breaches often necessitate external support.
| Aspect | DIY Approach (Internal Resources) | MBS DPDP Service Tier Support | Estimated Cost (External if needed) |
|---|---|---|---|
| Initial Containment & Forensics | Requires skilled internal IT/Security team. | Supported by Full DPDP Consulting (training, readiness planning). | ₹80,000 – ₹2.5L (external specialists) |
| Breach Assessment & Impact Analysis | Relies on internal DPO/Compliance Officer understanding of data flows and DPDP. | Directly addressed by Data Mapping (₹1.5L – ₹3L) and DPDP Readiness Audit (₹2L – ₹6L). | Part of MBS tiers, or ₹50,000 – ₹1.5L (external legal/consultant) |
| Notification Drafting & Legal Review | Requires internal legal counsel with DPDP expertise. | Benefits from insights in DPDP Workshop (₹5L – ₹10L) and Full DPDP Consulting (₹7L – ₹12L) which includes DPO training. | ₹70,000 – ₹2.5L (external legal counsel) |
| Implementation of Remediation | Requires internal IT and project management. | Supported by Full DPDP Consulting (₹7L – ₹12L). | Varies widely based on technical changes, could be significant. |
Sushant Pasamarty, founder of Meridian Bridge Strategy, emphasizes, "Preparing for a breach before it happens is not optional under DPDP. Our services build the framework and train your teams, reducing the chaos and cost during an actual incident."
Next Step: Bolster Your Breach Readiness
Don't wait for a breach to realize your organization's gaps. Understanding your data flows and current readiness is the first step towards a robust incident response plan.
Use the free calculator on dpdpworkshop.com to determine which MBS service tier is right for your business. From fundamental data mapping to comprehensive implementation support, MBS helps you build resilience.
Frequently Asked Questions
What is the '72-hour' rule under DPDP for breach notification?
DPDP requires Data Fiduciaries to notify the Data Protection Board of India (DPBI) 'without undue delay' and, where appropriate, the affected Data Principals 'in the prescribed manner'. While DPDP doesn't explicitly state 72 hours, this is a common international benchmark for 'undue delay' and best practice for timely notification.
When do I need to notify Data Principals directly about a breach?
Notification to Data Principals is required if the breach is likely to result in significant harm to the individual. This assessment considers the type of data, the sensitivity, the potential for identity theft, financial loss, or reputational damage. Your DPO or legal counsel should make this determination.
How can MBS help my company prepare for DPDP breach notification?
Meridian Bridge Strategy offers services that directly build breach readiness. Our <strong>DPDP Readiness Audit</strong> identifies gaps in your incident response plan, and the <strong>DPDP Workshop</strong> provides prioritized recommendations. For comprehensive support, <strong>Full DPDP Consulting</strong> includes implementation support, DPO training, and helps build robust processes to handle breaches efficiently.
Related Guides
Checklist for Startups: 2026 Plan: DPDP Checklist
See the likely DPDP cost for compliance Checklist for Indian Startups: 2026 Plan. Get the quick range, cost drivers, and next step. Use the free calculator t...
Checklist for Enterprises & CXOs: DPDP Checklist
See the likely DPDP cost for compliance Checklist for Indian Enterprises & CXOs. Get the quick range, cost drivers, and next step. Use the free calculator to...
in 90 Days: Roadmap for Businesses: DPDP Checklist
See the likely DPDP cost for compliance in 90 Days: Roadmap for Indian Businesses. Get the quick range, cost drivers, and next step. Use the free calculator...
Check Your DPDP Cost
Use the free calculator to estimate your compliance cost. Then book a call with Sushant to scope the right engagement.
Estimate My DPDP Cost →