Documentation
For a company that already has its notice and consent flows in place but no plan for the day something actually leaks. Section 8(6) and Rule 7 start two clocks the moment a breach happens: notify affected Data Principals without delay, and notify the Board without delay, then follow up with a detailed report inside 72 hours. We draft the playbook and both templates now, so nobody is writing them for the first time while the clock runs.
For a company that already has its notice and consent flows sorted but no plan for the day something actually leaks. Rule 7 starts two clocks the moment a breach happens. We draft the playbook and both intimation templates now, so nobody is writing them for the first time while the clock runs.
Section 8(6) requires intimation of a personal data breach to the Board and to every affected Data Principal. Rule 7 runs two tracks in parallel: one to each person affected, without delay, and one to the Board, without delay and then a full report within seventy-two hours of becoming aware. Neither track has a materiality threshold. As the Rules are drafted, every breach is notifiable. There's no carve-out for the ones that look minor in the moment.
Drafting a notification template during an actual incident is how deadlines get missed. This service builds the playbook and both templates before you need either.
Scope
The playbook walks through detect, contain, assess what happened, work out which notification duties apply, run both Rule 7 tracks at once, and log the incident properly.
The Board template covers Rule 7(2)'s two stages: an initial notice without delay, then a detailed report inside seventy-two hours covering what happened, why, what's been done about it, and what's changed to stop it recurring.
The Data Principal template covers Rule 7(1)'s five required items: the nature and timing of the breach, the likely consequences for that person, what's being done to mitigate it, what they can do to protect themselves, and a contact who can answer their questions.
The register logs every incident, whether or not it crossed the notification threshold, which sits alongside the minimum one-year log retention that Rule 6(1) already requires of your systems.
Specifics
| Who's notified | Timing | Rule |
|---|---|---|
| Each affected Data Principal | Without delay, through their user account or a registered mode of contact | Rule 7(1) |
| The Board, initial notice | Without delay: nature, extent, timing, location, likely impact | Rule 7(2)(a) |
| The Board, full report | Within 72 hours of becoming aware, or longer if the Board allows it on written request | Rule 7(2)(b) |
Neither the Act nor the Rules set a risk floor below which a breach doesn't need reporting. As drafted, every personal data breach is notifiable to the Board and to every affected person, which is stricter than the risk-based threshold GDPR uses for individual notification. A team quietly deciding a breach is too minor to report is taking on a risk the Rules don't actually give it the room to take.
We draft the plan and the templates. We don't run your incident response for you when something actually happens, and we don't implement the logging, monitoring, or backup systems that Rule 6(1) requires you to have in place before a breach occurs. Those are your team's systems to build and run; this plan tells them what to do once something goes wrong.
Process
Step 1 of 4
Tell us what's at risk
The systems and personal data a breach would most likely involve.
Common mistakes founders make
Clarifications
As the Act and Rules are currently drafted, yes. There's no materiality threshold in Rule 7, so a breach that looks minor still triggers both notification tracks.
The Rules don't define it as a fixed number of hours for the affected-person track or the Board's initial notice. It means what it says: notify as soon as you reasonably can. An internal review process that runs for days doesn't meet that bar.
CERT-In's cyber incident reporting runs on a separate six-hour clock under a different law, triggered by a broader category of cybersecurity event than a personal data breach. This service is scoped to the DPDP Rule 7 tracks. If you also need the CERT-In process built in, tell us at intake and we'll scope that alongside it.
The documentation pack includes this breach plan as one of its seven artifacts. This standalone version is for companies that already have their notice, consent, and vendor documents in place and specifically need the incident piece.
Related
Prefer to skip the paperwork?
BuildWright can take this off your plate — done properly, the first time.
Tell us about your partners and business and we'll take it from there.
Get a Quote
Skip the hassle — have us do it for you. We do it best.