BuildWrightFor Builders
ServicesPricingResourcesPartners

BuildWright Consultants

Your virtual compliance team for early-stage businesses across India: incorporation, licenses, documentation, and dispute resolution.

Services

  • Incorporation
  • Licenses & registrations
  • Documentation
  • Dispute resolution
  • Monthly plans

Company

  • Blog
  • Resources
  • Tools
  • Partners
  • For Advisers
  • For Freelancers
  • Privacy Policy
  • Terms of Use

Get in touch

  • Free consultation
  • WhatsApp
  • Client login

BuildWright Consultants is a virtual compliance team. We do not provide advocacy or litigation representation.

Your data is encrypted in transit and at rest on Google Cloud infrastructure. We never sell it. See our privacy policy.

© 2026 BuildWright Consultants. All rights reserved.

HomeDocumentationDPDP Breach Response Plan

Documentation

DPDP Breach Response Plan

For a company that already has its notice and consent flows in place but no plan for the day something actually leaks. Section 8(6) and Rule 7 start two clocks the moment a breach happens: notify affected Data Principals without delay, and notify the Board without delay, then follow up with a detailed report inside 72 hours. We draft the playbook and both templates now, so nobody is writing them for the first time while the clock runs.

For a company that already has its notice and consent flows sorted but no plan for the day something actually leaks. Rule 7 starts two clocks the moment a breach happens. We draft the playbook and both intimation templates now, so nobody is writing them for the first time while the clock runs.

Section 8(6) requires intimation of a personal data breach to the Board and to every affected Data Principal. Rule 7 runs two tracks in parallel: one to each person affected, without delay, and one to the Board, without delay and then a full report within seventy-two hours of becoming aware. Neither track has a materiality threshold. As the Rules are drafted, every breach is notifiable. There's no carve-out for the ones that look minor in the moment.

Drafting a notification template during an actual incident is how deadlines get missed. This service builds the playbook and both templates before you need either.

Scope

What's included

  • The playbook walks through detect, contain, assess what happened, work out which notification duties apply, run both Rule 7 tracks at once, and log the incident properly.

  • The Board template covers Rule 7(2)'s two stages: an initial notice without delay, then a detailed report inside seventy-two hours covering what happened, why, what's been done about it, and what's changed to stop it recurring.

  • The Data Principal template covers Rule 7(1)'s five required items: the nature and timing of the breach, the likely consequences for that person, what's being done to mitigate it, what they can do to protect themselves, and a contact who can answer their questions.

  • The register logs every incident, whether or not it crossed the notification threshold, which sits alongside the minimum one-year log retention that Rule 6(1) already requires of your systems.

Specifics

The details

The two clocks Rule 7 starts

Who's notifiedTimingRule
Each affected Data PrincipalWithout delay, through their user account or a registered mode of contactRule 7(1)
The Board, initial noticeWithout delay: nature, extent, timing, location, likely impactRule 7(2)(a)
The Board, full reportWithin 72 hours of becoming aware, or longer if the Board allows it on written requestRule 7(2)(b)

Neither the Act nor the Rules set a risk floor below which a breach doesn't need reporting. As drafted, every personal data breach is notifiable to the Board and to every affected person, which is stricter than the risk-based threshold GDPR uses for individual notification. A team quietly deciding a breach is too minor to report is taking on a risk the Rules don't actually give it the room to take.

What this service doesn't cover

We draft the plan and the templates. We don't run your incident response for you when something actually happens, and we don't implement the logging, monitoring, or backup systems that Rule 6(1) requires you to have in place before a breach occurs. Those are your team's systems to build and run; this plan tells them what to do once something goes wrong.

Process

How it works

Step 1 of 4

Tell us what's at risk

The systems and personal data a breach would most likely involve.

Tell us what's at risk

The systems and personal data a breach would most likely involve.

Common mistakes founders make

  • Deciding internally that a breach is too small to report, when Rule 7 sets no materiality threshold at all.
  • Drafting the Board and Data Principal notices for the first time during an actual incident instead of having them ready beforehand.
  • Treating the seventy-two-hour window as the deadline to notify the Board at all, when the initial notice is due without delay and the seventy-two hours is for the full follow-up report.
  • Assuming a breach plan satisfies the separate CERT-In cyber incident reporting duty, which runs on its own six-hour clock under a different law.

Clarifications

Frequently asked questions

As the Act and Rules are currently drafted, yes. There's no materiality threshold in Rule 7, so a breach that looks minor still triggers both notification tracks.

The Rules don't define it as a fixed number of hours for the affected-person track or the Board's initial notice. It means what it says: notify as soon as you reasonably can. An internal review process that runs for days doesn't meet that bar.

CERT-In's cyber incident reporting runs on a separate six-hour clock under a different law, triggered by a broader category of cybersecurity event than a personal data breach. This service is scoped to the DPDP Rule 7 tracks. If you also need the CERT-In process built in, tell us at intake and we'll scope that alongside it.

The documentation pack includes this breach plan as one of its seven artifacts. This standalone version is for companies that already have their notice, consent, and vendor documents in place and specifically need the incident piece.

Related

Learn more

Prefer to skip the paperwork?

BuildWright can take this off your plate — done properly, the first time.

Ready to get started?

Tell us about your partners and business and we'll take it from there.

Get a Quote

Skip the hassle — have us do it for you. We do it best.

  • The journey
  • What's included
  • The details
  • How it works
  • FAQ
  • Learn more
  • Pricing

Key terms

Personal data breach
Under section 8(6) and Rule 7, an incident triggering a duty to notify both the Data Protection Board and every affected Data Principal, with no materiality floor as currently drafted.
Intimation
The Rules' own term for the notification sent to the Board or to a Data Principal after a breach, distinct from a general public disclosure.
CERT-In
India's Computer Emergency Response Team. Its own six-hour cyber incident reporting duty runs alongside DPDP's breach notification rules, triggered by a broader set of events.