legalanswers.in logolegalanswers.in
Technology & Future Law

What are the data breach notification obligations under India's Digital Personal Data Protection Act 2023?

Updated · 25 July 2026

Under the Digital Personal Data Protection Act, 2023 (DPDPA), a data fiduciary — any organisation that collects and processes personal data — must notify the Data Protection Board and every affected individual of a personal data breach. The notification must be given in the "prescribed manner" (rules to be notified by the government). Failure to notify is a civil default attracting a penalty of up to ₹200 crore per instance under Schedule 1 of the Act.

What counts as a personal data breach under DPDPA?

The DPDPA 2023 defines a 'personal data breach' as any unauthorised processing of personal data, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises the confidentiality, integrity or availability of personal data (Section 2(t)).

Practically, this covers: a ransomware attack that encrypts customer databases; a misconfigured S3 bucket exposing user records; an employee emailing a list of customer PAN numbers to the wrong recipient; a SaaS vendor's server being compromised; loss of an unencrypted laptop containing personal data; an insider leaking employee salary data.

The definition is intentionally broad. 'Accidental' disclosures — not just malicious attacks — are squarely within scope. Unlike GDPR, the DPDPA does not require the breach to pose a 'risk to the rights and freedoms' of individuals as a threshold; the statutory obligation is triggered by the breach itself, subject to the prescribed manner of reporting (which the rules will flesh out).

Notably, DPDPA covers digital personal data only — data that is either collected digitally or later digitised. Paper records that are never digitised fall outside the Act. However, this distinction is less meaningful in practice for most modern businesses whose records are routinely stored electronically.

Who must notify, and to whom?

The notification obligation rests on the data fiduciary — the entity that determines the purpose and means of processing. If you are a SaaS company that processes data on behalf of another business, you are a data processor and the obligation runs from the data fiduciary to its data processor via contractual terms (Section 8(1)). The data processor must inform the fiduciary of a breach; the fiduciary then notifies the Board and affected individuals.

Two notifications are required:
(1) To the Data Protection Board — the regulatory authority established under Section 18. The Board will be the adjudicating authority for DPDPA penalties. Notification to the Board allows the regulator to assess severity, order further action, and determine whether a penalty is warranted.
(2) To each affected data principal — the individual whose personal data has been breached. This ensures the person can take protective steps: change passwords, monitor credit, flag their bank etc.

Significant data fiduciaries (SDFs) — entities the Central Government designates as handling large volumes of sensitive data, such as major social media platforms, large e-commerce companies, and healthcare providers — will likely face stricter rules under subordinate legislation, including a Data Protection Officer requirement and mandatory Data Protection Impact Assessments. The SDF designation list has not yet been published as of mid-2025.

What must a breach notification contain and what is the timeline?

The content and timeline of breach notifications are to be prescribed by government rules under the DPDPA — the Act sets the obligation but delegates the mechanics. The Digital Personal Data Protection Rules are expected to specify: a reporting window (likely 72 hours to the Board, similar to GDPR); the minimum information required (nature of breach, data categories affected, estimated number of data principals, contact details of the DPO or nodal officer); and the format for individual notifications.

Until the rules are notified, the practical approach for compliance is to follow the Act's plain requirement — notify promptly on becoming aware — and benchmark against GDPR's 72-hour rule as the dominant global standard.

What a notification should contain (based on international practice and likely Indian rules): (a) nature and scope of the breach; (b) personal data categories and approximate volume affected; (c) likely consequences of the breach; (d) measures taken or proposed to address the breach; (e) contact point for affected individuals to seek further information. Individual notifications should be sent directly — not buried in a privacy policy update or a generic press release.

What are the penalties for failing to notify a data breach?

Schedule 1 of the DPDPA 2023 sets out a penalty of up to ₹200 crore for failure to notify the Data Protection Board or affected data principals of a personal data breach (Item 2 of Schedule 1).

For context, other DPDPA penalties include: failure to implement reasonable security safeguards — up to ₹250 crore (Item 1); non-fulfilment of additional obligations for significant data fiduciaries — up to ₹150 crore (Item 3); breach of children's data obligations — up to ₹200 crore (Item 4).

The Data Protection Board can initiate proceedings suo motu or on a complaint. It must give the data fiduciary an opportunity to be heard, and any penalty order can be appealed to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) and then to the High Court. The Board cannot impose criminal penalties — DPDPA is a civil enforcement statute (unlike the old IT Act Section 43A regime it partially supersedes).

Critically, the ₹200 crore figure is a per-instance cap, not a total annual cap. Organisations with repeated breaches or systematic failures face cumulative liability. The DPDPA does not have a 4% global turnover cap like GDPR — the rupee amounts are fixed, which can be disproportionately low for large multinationals but significant for Indian startups and mid-size companies.

How does India's DPDPA compare to GDPR on breach notification?

For companies that already comply with GDPR (European data protection law), DPDPA adds an Indian layer rather than replacing their existing program. Key differences on breach notification:

Threshold: GDPR requires notification only when a breach is 'likely to result in a risk to the rights and freedoms of natural persons' — low-risk breaches can be documented internally without reporting. DPDPA has no such risk threshold on the face of the Act; all personal data breaches must be notified (subject to prescribed manner in rules, which may introduce a threshold).

Timeline: GDPR's 72-hour clock for supervisory authority notification is explicit in the regulation. DPDPA's timeline is delegated to rules — not yet published as of mid-2025. Assume 72 hours as a working standard.

Individual notification threshold: GDPR requires notifying individuals only when the breach is 'likely to result in a high risk.' DPDPA as drafted requires notifying every affected data principal — a stricter standard.

Regulator: GDPR is enforced by national Data Protection Authorities (DPAs) in each EU state. DPDPA is enforced by the central Data Protection Board of India — a single national authority.

Penalty structure: GDPR penalties are percentage-based (up to 4% of global annual turnover or €20 million, whichever is higher). DPDPA penalties are fixed rupee amounts — potentially lower for large MNCs but significant for smaller Indian entities.

Practical takeaway for businesses: DPDPA compliance is not a GDPR add-on — it has its own obligations, its own regulator, and will have its own enforcement cadence once the Board is constituted and the rules are finalised.
Reference Citation: Digital Personal Data Protection Act, 2023 (Sections 2(t), 8(6), 18, Schedule 1); Information Technology Act, 2000 (Section 43A, superseded in part); MEITY DPDPA full text

Disclaimer: Content provided here is for general legal knowledge only and does not constitute formal legal advice. If you have an urgent or specific matter, please consult a registered advocate.