How can a company legally handle a data breach, and what are the mandatory reporting timelines under the DPDP Act, 2023?

How can a company legally handle a data breach, and what are the mandatory reporting timelines under the DPDP Act, 2023? 

Author – Saachi Srivastava

Part I: Introduction and Abstract — The Constitutional Shift from Reactive Safeguards to Proactive Disclosure 

Abstract

In the context described above, the present paper seeks to critically analyse how the DPDP Act, 2023, transforms data breach management in India fundamentally. Corporate organisations were previously exploiting the loopholes in the previous Information Technology Act, 2000, in managing data breaches by using a strategy of internal fixes while maintaining a cloak of secrecy regarding such incidents. With the advent of the DPDP Act, such strategies will no longer be tenable. This paper analyses the statutory framework provided by Section 8(6) and Rule 7 of the DPDP Act, 2023, with reference to the constitutional privacy jurisprudence established in the seminal case of K.S. Puttaswamy v. Union of India (2017). Further, with examples from actual cases dealing with misconfigurations of cloud infrastructure and misuse of plug-ins from third-party vendors, the present paper attempts to identify the major operational challenges involved in implementing the mandatory dual-notification process prescribed by the law. In this regard, some notable challenges are those posed by the “Clash of the Clocks” created by the timeframes imposed under CERT-In’s guidelines and the DPDP Act as well as the legal pitfall present in the concept of awareness.

Introduction

In the case of India, corporations have always functioned in a period of self-paced data and structural compromise within corporations. Once a company’s defences give way and hackers manage to break through, the pressure inside the crisis room becomes overwhelming. Until relatively recently, the way that corporations handled a data breach in India was by fixing the problem internally, handling any potential public relations issues and revealing nothing more than absolutely necessary to avoid doing damage to their reputation and image. With the old, lax rules of the Information Technology Act, 2000, a data breach would be considered to be an internal problem on par with anything else in information technology would need to be addressed quietly while corporate management pondered whether it is better to remain silent or fess up and take responsibility. However, the introduction of the Digital Personal Data Protection Act (DPDPA), 2023, has done away with this secrecy forever, bringing data breach reporting firmly out of the realm of PR and making it a strictly legal obligation.

The following article provides a critical evaluation of the ways a corporation must handle a data breach in such a scenario.

To have a good understanding of how the new scheme will work in cases of emergency, it is necessary to get an exact definition of all the key terms used in the Act and take a closer look at the actual individuals and organisations affected by the data breach.

  • Data Principal (You and Me): Individual concerned by the data. In other words, it is an ordinary individual who can be identified through his phone number, home address, or even credit card number stored in the organisation’s database. It is the end-user of informational privacy laws. By this law, you are not a mere line in some table of numbers; rather, you become the sole owner of your own data.
  • Data Fiduciary (The Organisation Responsible): Person, business, or government organisation that, alone or jointly with others, determines the purpose and manner of processing the personal data. Because it controls the keys to the castle, the law burdens it with responsibility for ensuring security and reporting breaches.
  • Data Processor (Back-End Vendor): Any third-party vendor, cloud service, or contractor that uses your personal data for the purposes of a data fiduciary. Even though they provide the necessary technological means to store the data, they are not responsible by statute to notify the government; rather, their job is to report to the company in charge.
  • Personal Data Breach (Crisis): The law completely reframes what a crisis is. It is not about hackers wearing masks and gaining unauthorised access by cracking a password of the main server. As defined by the Act, a breach means any unauthorised access, collection, acquisition, use, disclosure, modification, disposal, or destruction of personal data that affects its integrity, confidentiality, or availability. Whether the employees publish a customer spreadsheet in a public forum by mistake, whether the server hard disc went missing, or whether some glitch locked all the customers out of their accounts – in such instances, there was a breach in your privacy, confidentiality, and availability of personal data.

Through the process of tying together three separate entities under one strict regime of transparency, DPDPA marks a new constitutional moment: the guarantee of informational security becomes a strictly regulated issue.

 

Part II: Background and Legal Framework — The Statutory Triad of Section 8(6), Rule 7, and Fundamental Privacy Jurisprudence 

To fully understand how data leak notifications are handled within India’s current laws, one must go beyond the red tape and look at the legal triad, which consists of Article 21 of the Constitution, DPDPA, and its procedures. It is this combination of law that eliminates the archaic idea of corporate discretion and replaces it with a mandatory baseline requirement for transparency.

Constitutional Grounding: Informational Autonomy under Article 21

The corporate requirement to notify on a data leak is no bureaucratic burden but flows from Article 21 of the Constitution. Indeed, in the K.S. Puttaswamy v. Union of India (2017) ruling delivered by the apex court’s nine-judge bench, it was unanimously determined that the right to privacy is an essential component of the rights to life and liberty contained within Article 21 of the Indian Constitution. What is critical in the case law is the recognition of informational privacy and informational autonomy as the fundamental constitutional rights. The logic behind this case law is absolutely flawless – we own our personal information, and corporations are merely custodians of such information. As soon as hackers breach the corporate database, such informational autonomy is compromised.

Thus, maintaining secrecy about the breach from the individual who has been affected becomes a continuous infringement on their right to privacy as guaranteed by the Constitution. Hence, the need to inform proactively: the person cannot take preventive action, like changing passwords, securing credit cards, and watching out for identity theft, without being notified about the breach of their online privacy.

Statutory Provisions: Deconstructing Section 8(6) and Rule 7

The legal obligation to practise transparency is provided in law through a clear-cut process as per Section 8(6) of the DPDP Act, 2023:

“In case of any breach of personal data, the data fiduciary shall inform the board and the concerned data principal about such breach in the form and manner as may be prescribed.”

Section 8(6) imposes an absolute notification obligation wherein companies have a responsibility to report to the regulatory authority, i.e., the Data Protection Board of India (DPBI), and every affected person.

Notably, the obligation does not come with any exception; it is fully non-delegable. Any kind of outsourcing would not affect this requirement. This means that even if the cloud service provider or analytics services company (the data processor) is attacked, the primary company responsible for performing the obligation of reporting the breach would remain the company which originally collected the information (i.e., the data fiduciary). Thus, you simply cannot delegate fundamental rights obligations.

Rule 7 provides a detailed procedure in terms of handling data breaches and reporting them. Under Rule 7, there are essentially two stages that need to be undertaken:

  1. Rule 7(1) – The Immediate Plain-Language Notification: On identifying any breach of personal information, the data fiduciary needs to provide an immediate notice to the data principals who have been adversely impacted by such a breach. Such a notice is required to be brief and easy to understand and has to clearly define the extent and nature of the data breach; the risks associated with the same for the individual (for instance, possible instances of financial fraud); measures undertaken to mitigate the impact of the data breach; and a contact point for questions. Along with sending a user notification, the first action also includes sending an alert to the DPBI.
  2. Rule 7(2) – The 72 Hours Report: While the user notification aims at immediate protection of the user data, the corporate legal team and forensic team need to shift focus towards addressing the regulatory authority. Within 72 hours of such an event, the Data Fiduciary shall submit a detailed technical report only to the DPBI.

In essence, the combination of the two becomes instrumental in bringing about a paradigm shift in the way the crisis room runs its operations. The process that was once shrouded in secrecy is now openly defended legally.

Legislative Intent: The Shift to “Transparency First”

The introduction of Section 8(6) and Rule 7 marks a definite change in the approach taken by legislators. According to the old guidelines provided under Section 43A of the IT Act, 2000 (together with the Privacy Rules of 2011), organisations could take care of their data in a passive manner that followed a “damage reduction” approach. Any breaches would be considered as security issues for the organisation itself. If there were any instances of leakage of user logs by an organisation, it could simply fix the problem privately without any external intervention.

However, this self-directed approach is consciously overridden by the DPDPA through a “Transparency First” approach. This means that, in line with this approach, any incident involving a personal data breach is perceived as a potential danger to the wellbeing of the individual concerned. The act makes sure that the obligation to disclose any incident is seen not as an alternative punishment for negligence, but as the basic fiduciary obligation. With its provisions for mandatory reporting without a reporting threshold regardless of the kind of data breach, the legislature ensures that corporate India cannot offset the costs of their reputation against the benefits of maintaining secrecy for their users. In essence, silence, concealment, and delay are all regarded as offences within themselves. Lack of diligence and inadequate security lead to an imposed fine of up to 250 crores on the entity, while not reporting the cyberattack results in yet another fine worth 200 crores.

Part III: Main Analysis and Case Studies — Dissecting Corporate Breach Lifecycles, Information Accountability, and Sectoral Incidents 

An analysis of how the Digital Personal Data Protection Act (DPDPA), 2023, operates requires insights into how a data breach happens in practice within the complex organization structure. It is through the examination of weaknesses of the former system as well as the legislation required currently that a benchmark in line with the legal requirements is set.

Historical Context: Regulatory Gaps and the Era of Corporate Denial

Prior to the introduction of the DPDPA, the data protection framework in India under the IT Act, 2000, was plagued by certain structural deficiencies which, in essence, allowed organisations to circumvent any claims of data breaches. As an exemplary case study where corporate defence strategies operated successfully, one would need to refer to the MobiKwik data breach incident that took place in the year 2021.

In this case, when independent cybersecurity experts pointed out the fact that there is a database of the KYC, user, and financial information of around 10 to 11 crore users which is being sold on the dark web, the organisation responded by denying the allegations. The company not only rejected the reports but also termed their claims as misleading and even made threats to take legal action against the concerned researchers. The forensic audit was initiated only after intervention by RBI.

In accordance with Section 43A of the IT Act, this sort of stonewalling tactic was legally justified by the lack of certain elements in our legal framework:

  • A centralized body responsible for the enforcement of privacy protection regulations;
  • Explicit and mandatory statutory deadlines at which users should be notified;
  • Significant punishments for any attempts at concealing breaches and delaying notification.

The newly established Data Protection Board of India (DPBI) puts an end to this strategy altogether. According to the DPDPA law, the concealment of information about the breach or delay of disclosure is considered a serious offence that can be separately prosecuted. Should the same breach have happened under the current legislation, the DPBI would have had enough power to examine the cause of the problem and impose penalties on the company up to 200 crore rupees for nondisclosure alone.

Real-World Compliance Matrix: Two Corporate Scenarios

In order to understand how the proposed statutory escalation process ladder operates under the DPDPA and its regulations, we will need to consider what happens during the crisis in reality. Below are examples of two corporate situations which are quite common for the work of corporate lawyers.

Scenario A: The E-Commerce Leak (Infrastructure Misconfiguration)

Let’s envision a popular e-commerce app with a vulnerability causing an exposure of data due to infrastructure misconfiguration such as an exposed AWS S3 storage bucket. All of a sudden, 100,000 users’ data, including full names, delivery addresses, and password hashes, become visible on the internet.

This is the way a statutory clock affects business decisions:

  • Hour 0 (Detection): Detection of a surge in data activity via automated cloud services.
  • Hour 2 (Validation): Verification of the last deployment script where the database’s authentication was removed from the DevSecOps team, leading to making the database public.
  • Hour 6 (Handshake between processor and fiduciary): Notification to the owner of the e-commerce service from the cloud provider, starting the statutory clock of 72 hours for the data fiduciary. 
  • Hour 6-Hour 24 (Containment): Steps taken by the team of the data fiduciary in order to minimise the exposure of the database and key rotation.
  • Hour 24-Hour 72 (Dual Escalation Life Cycle): The business needs to make a forensic disclosure to DPBI and also notify 100,000 data principals about the data breach.

Scenario B: The Third-Party Fintech API Breach (Complex Vendor Ecosystem)

The neo-banking platform, which uses a customised third-party Know-Your-Customer (KYC) application software company, experiences an API credential hack that results in the theft of the Aadhar numbers, PAN cards, and facial recognition data of the digital loan seekers.

In such circumstances, there is usually a legal battle over who “owns” the event and who should alert the government. The KYC company might claim that since the vulnerability was present within the structure of the custom integration of the neo-banking platform, they are not to blame.

THE LEGAL ALIGNMENT MATRIX

THE NEO-BANKING APP 

(Data Fiduciary)

THE PLUG-IN VENDOR

(Data Processor)

  • Retains core liability
  • Directs data processing
  • Obligated to notify DPBI & Data Principals
  •   Must alert Fiduciary immediately upon breach  
  • Confined to instructions
  • Indemnified by SLA

DPDPA removes any ambiguity about liability through explicit statutory categorisation:

  • The neo-banking app continues to be designated the data fiduciary, since it actively engages in the solicitation of the user’s relationship and sets the intended use of the data processing activity.
  • The plug-in company, meanwhile, becomes a data processor that processes the validation data only in line with the directions provided by the fiduciary.

As such, the public law liability is firmly established. In particular, while the vendor may be required to provide their technical logs and cooperate with forensic investigations, the unequivocal statutory obligation to inform the DPBI and the affected parties rests exclusively with the neobank. In the event that the neobank fails to do so for fear of commercial repercussions or an admission of fault from their vendor, they are still in breach of Section 8(6).

Part IV: Critical Analysis and Evaluation — The Clash of Regulatory Clocks, The Awareness Trap, and Tiered Policy Reforms 

Although the Digital Personal Data Protection Act (DPDPA), 2023, provides the basic statute necessary for information protection, upon critical analysis of its components, operational challenges arise as well as grey areas of the law that must be addressed. To a lawyer working for a corporation or CISO and compliance officer, a breach of live data while under such regulation can mean high risks in terms of compliance issues. The following discussion includes an academic analysis of the structural problems involved in the Indian cybersecurity system and some possible policy recommendations.

The Clash of the Clocks: CERT-In vs. DPDPA

The main compliance issue for a data fiduciary in the Indian scenario is the problem that arises due to overlapping reporting mechanisms: the CERT-In Cyber Security Directions and the DPDPA rules.

THE CLASH OF REGULATORY CLOCKS

CERT-In TIMELINE

    DPDPA TIMELINE

  • 6-Hour Reporting Window
  • Focus: System Security
  • Incident Vulnerability
  • Form: Technical Logs
  • 72-Hour Reporting Window
  • Focus: Data Principal
  • Breach Impact Assessment
  • Form: Plain Language

The CERT-In requirement mandates that the company has to make such reports concerning any security incidents or any breaches within six hours of identifying them. However, on the other hand, the DPDPA requires the very same entity to have up to 72 hours before the comprehensive forensic report concerning the breach can be filed.

The above combination, which happens to occur during the event of a cyberattack, causes a huge deal of anxiety for any corporation in the process of its management. The IT department has to stop the breach as quickly as possible, while the lawyer has only 360 minutes to comply with the CERT-In requirement, hence causing incomplete reports, which in turn leads to inconsistency between the two reports, hence increasing the chances of having a legal liability.

The Legal Trap of “Awareness”

The most significant gap or compliance issue that exists here involves the textual trigger for the DPDPA reporting clock. The 72-hour clock for reporting commences once the data fiduciary becomes “aware” of the security incident, and not when the extent of the incident becomes known following the forensic analysis.

In fact, this particular phrasing makes such action extremely precarious. In a sophisticated cloud environment, an IoC—a brute force or an abnormal batch download, for instance—could trigger a red flag on Day 1. Yet, a specialist company that provides external forensics services could take between four and five days merely investigating whether the IoC did indeed lead to the compromise of protected personal data.

By being conservative in their interpretation of what constitutes reasonable grounds to kick off the disclosure process, in-house legal teams would often end up exceeding the 72-hour window and making the organisation susceptible to heavy administrative penalties, which could go as high as ₹200 crores for late notice. At the same time, by taking any initial IoC too seriously, the corporate legal team would put themselves at risk of instigating a major panic among consumers and sending share prices crashing, opening the door to litigation.

Independent Suggestions and Regulatory Reforms

In order to address these legislative shortcomings, the Indian data protection authorities could take the following actionable steps:

  • Use of a Unified Reporting Portal: The Indian government should develop a unified reporting portal that simplifies this process. Data fiduciaries would have to make a single encrypted entry that meets the technical requirements of the CERT-In and the individual data preservation requirements of the DPBI. The portal could automatically send the pertinent technical fields to CERT-In within six hours but withhold individual notification metrics from the data principal until the end of the DPBI’s 72-hour amendment period to assess the true risk posed to the individual.
  • Development of a Tiered and Batched Individual Notification System: The DPBI must clearly delineate which individual notifications need to be tiered or batched based on severity since not all data leaks pose the same level of danger to an individual. For those that do not include sensitive information such as metadata about deliveries or loyalty points, the companies can use batch notifications or public notifications in a short span to avoid communication overload. Direct individual notification would only apply to high-severity breaches that involved financial accounts, biometric data, or government-issued identification numbers (e.g., PAN cards).

Part V: Conclusion — Compliance-by-Design and the New Paradigm of Indian Data Sovereignty 

Summary of Key Findings

The process of managing breaches according to the requirements of the DPDDP, 2023, will not be limited to simply rolling out a quick patch fix and doing some forensics in isolation or relying on spin doctors for PR purposes. This new framework ensures that cybersecurity becomes an absolute race against time, where the ticking of a statutory 72-hour clock is inevitable. In this new paradigm, the failure to deploy proper safeguards now comes at an astronomical cost of an administrative penalty worth up to ₹250 crores. What further complicates the picture for companies that fail to report the breaches is an additional penalty of up to ₹200 crores.

Forward-Looking Perspective

The design of a two-pronged punishment framework would necessitate an instant and radical change in corporate governance structures. The framework basically ensures the transition of the Indian organisations from reactionary firewall engineering to compliance-by-design. There will now be an inseparable association between data containment and legal transparency. Henceforth, only those companies will survive that embrace real-time data mapping, automated tracking of consents, deployment of data protection officers, and a pre-determined legal framework for dealing with the adversary before the attack takes place. In comparison, organisations that remain silent, unorganised, or inactive face tough monetary repercussions, disruption in operations, and total destruction of reputation under the strict supervision of the DPBI. In essence, the data breach framework within the DPDPA would forever alter the course of corporate responsibility by ensuring the security of data principals as an essential component of Indian data sovereignty.

References and Citations 

  • The Digital Personal Data Protection Act, No. 22 of 2023, Gazette of India, Extraordinary, pt. II sec. 1 (Aug. 11, 2023).
  • The Digital Personal Data Protection Rules, 2026.
  • The Information Technology Act, No. 21 of 2000, Gazette of India, Extraordinary, pt. II sec. 1 (June 9, 2000).
  • Justice K.S. Puttaswamy (Retd) and Anr. v. Union of India and Ors., (2017) 10 SCC1.
  • Ashutosh Kaushik v. Union of India & Ors., W.P.(C) 6218/2021 (Delhi HC).
  • Reserve Bank of India, Master Direction – Know Your Customer (KYC) Direction, 2016 (as updated)
  • Digital Personal Data Protection Act, 2023, Section 8(6).
  • Digital Personal Data Protection Rules, Rule 7.
  • MobiKwik Data Leak Case Study Analysis, Reserve Bank of India Directives (April 2021).
Saachi Srivastava
Author: Saachi Srivastava

Dedicated law student and legal researcher focused on robust research and its practical application. My primary areas of interest include Criminal Law, Alternative Dispute Resolution (ADR), and Family Law, though I remain highly versatile and open to exploring all new legal aspects. Grounded in a strong appreciation for foundational constitutional principles, I am committed to turning rigorous legal analysis into meaningful, real-world insights. Actively seeking fresh professional opportunities, internships, and research collaborations.