Breach reporting in India

CERT-In vs DPDP breach reporting:
two clocks, one incident.

A breach in India can start two separate clocks: CERT-In's six hours and the DPDP Act's 72 hours. They run to different bodies, ask for different content and carry very different penalties. Here is each duty side by side, with the sector regulators and a worked timeline.

Last updated Published by TryTrustableNot legal advice

01

Do I owe CERT-In and the Data Protection Board separate reports?

Yes, for most personal data breaches. The CERT-In Directions require a report to CERT-In within six hours of noticing any of 20 listed incident types, including data breach and data leak. From 13 May 2027 the DPDP Act separately requires the Data Fiduciary to tell the Data Protection Board and every affected person, with a detailed report to the Board within 72 hours.

The two duties come from different statutes. CERT-In's comes from the Directions of 28 April 2022, issued under section 70B(6) of the Information Technology Act, 2000. It is a cyber security duty: it covers incidents with no personal data in them at all, such as a DDoS attack or a defaced website, and it applies to any service provider, intermediary, data centre, body corporate or government organisation. The DPDP duty comes from section 8(6) of the Digital Personal Data Protection Act, 2023 and Rule 7 of the DPDP Rules 2025. It is a privacy duty: it only arises for personal data, it falls on the Data Fiduciary, and it adds a duty CERT-In never had, which is telling the people affected.

Neither report discharges the other. CERT-In does not forward your report to the Board, and the Board's intimation is not a CERT-In report. Plan for both, from the same facts, written by people who know the difference. The guide to the CERT-In Directions covers the six-hour rule and the logging duties in more depth.

02

CERT-In, DPDP and GDPR side by side

Each cell is taken from the primary text: the CERT-In Directions and CERT-In's FAQs of May 2022, Rule 7 as notified, and the GDPR on EUR-Lex.

CERT-In Directions (2022)DPDP Act s.8(6) + Rule 7GDPR Art. 33 and 34
TriggerAny of the 20 incident types in Annexure I, from targeted scanning and ransomware to data breach and data leak. Not limited to personal data.Any personal data breach: unauthorised processing or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access that compromises confidentiality, integrity or availability (s.2(u)). No threshold.A personal data breach, unless unlikely to result in a risk to people's rights and freedoms. Individuals only where the risk is high.
Who must reportService providers, intermediaries, data centres, body corporate and government organisations. The duty is not transferable.The Data Fiduciary. A Data Processor's duty to tell the Fiduciary comes from your contract, not Rule 7.The controller. A processor tells the controller without undue delay (Art. 33(2)).
Who is toldCERT-In.The Data Protection Board and each affected Data Principal.The supervisory authority; the data subjects if high risk.
Deadline6 hours from noticing or being told. Partial information is acceptable; the rest follows.Data Principals and the Board: without delay. Detailed report to the Board: 72 hours from becoming aware, or longer if the Board allows on a written request.Authority: without undue delay and where feasible 72 hours; late notices must give reasons. Individuals: without undue delay.
ContentThe incident reporting form fields: reporter, affected entity, incident type, affected systems (domain, IP, OS, cloud, location, ISP), description, occurrence and detection time. Logs on request or with the report.Board: nature, extent, timing, location, likely impact; then events and reasons, mitigation, findings on the person responsible, remedial steps, report on intimations. Principals: description, consequences, mitigation, safety steps, a contact.Nature, categories and approximate numbers of people and records; DPO or contact; likely consequences; measures taken or proposed. Information may be given in phases.
ChannelEmail incident@cert-in.org.in, phone 1800-11-4949 or fax 1800-11-6969. The form is optional.To the Board as it specifies (it works as a digital office). To people through their user account or a registered contact route.The authority's own form or portal.
PenaltyUp to one year's imprisonment, a fine of up to ₹1 lakh, or both (IT Act s.70B(7)).Up to ₹200 crore per instance for failing to notify. See the DPDP penalty schedule.Up to €10 million or 2% of worldwide annual turnover, whichever is higher (Art. 83(4)).
In forceSince end of June 2022; 25 September 2022 for MSMEs.13 May 2027.Since 25 May 2018.

Summary for orientation. Section, rule and article numbers are given so you can check each one against the text.

Three differences cause most of the trouble. Scope: CERT-In is wider on incidents and narrower on people; it never asks you to tell a customer anything. Threshold: the GDPR lets a controller decide a breach is unlikely to cause risk and skip the authority; the DPDP Act has no such exit. Penalty: a CERT-In failure is capped at ₹1 lakh but can carry imprisonment, while the DPDP cap is ₹200 crore with no imprisonment at all. The gap in size is deliberate policy, not a drafting accident.

03

What does 'without delay' mean under Rule 7?

Rule 7 gives no hour count for telling Data Principals or for the Board's first intimation. 'Without delay' means as soon as you can describe the breach usefully, not after the investigation ends. The only fixed DPDP deadline is the detailed report to the Board, due 72 hours after becoming aware unless the Board extends it on a written request.

Read the structure of Rule 7(2) and the intent is plain. The first intimation needs only a description: nature, extent, timing, location and likely impact. The 72-hour report then asks for the broad facts behind the breach, mitigation, any findings about the person who caused it, remedial measures, and a report on the intimations already given to Data Principals. That last item makes the order of work explicit: people should have been told before the 72 hours are up, because the report has to describe how.

Our planning assumption, not a rule: send the first Board intimation and the notices to people the same day, once the Rule 7(2)(a) facts are known. If you need longer for the detailed report, ask the Board in writing before the 72 hours expire.

04

A dual-clock scenario, hour by hour

A Bengaluru subscription app with Indian users and a few thousand in Germany. The facts are invented; the clocks are real. The DPDP duties are shown as they will apply from 13 May 2027.

When (IST)What happensClock status
Thu 3 Jun 2027, 23:50An attacker uses an access key leaked in a public repository to read a production database replica. Nobody knows yet.No clock running. Occurrence is not awareness.
Fri 4 Jun, 21:30An alert fires on an unusual bulk export from the replica. The on-call engineer acknowledges it.T0. The CERT-In six hours start on noticing. Treat this as the moment you became aware for DPDP and GDPR too, unless counsel advises a later point.
Fri 4 Jun, 22:15The engineer confirms that customer records left the network: names, emails, phone numbers, hashed passwords. About 180,000 Indian users and 6,000 in Germany.Confirmation does not restart any clock.
Fri 4 Jun, 23:00Key revoked, replica isolated. Incident lead appointed; the CERT-In point of contact and counsel are paged.4.5 hours left on CERT-In.
Sat 5 Jun, 02:10Report emailed to incident@cert-in.org.in using the incident reporting form fields, with the relevant logs, marked as an initial report.CERT-In deadline 03:30: met with 80 minutes to spare.
Sat 5 Jun, 10:00Initial intimation to the Data Protection Board: description, nature, extent, timing, location and likely impact (Rule 7(2)(a)).'Without delay'. No hour count is given.
Sat 5 Jun, 14:00Notice to each affected user in the app and to their registered email, with the Rule 7(1) contents: what happened, what it means for them, what we did, what they should do, whom to ask.'Without delay'. The 72-hour report must describe these intimations.
Mon 7 Jun, 12:00Article 33 notification to the competent EU supervisory authority, in phases if the facts are still coming in.GDPR deadline 21:30 IST (18:00 CEST).
Mon 7 Jun, 17:00Detailed report to the Board: updated description, the events and reasons, mitigation, findings about who caused it, steps against recurrence, and the report on user intimations (Rule 7(2)(b)).DPDP deadline 21:30 IST: met.
Following weeksFurther information to CERT-In as the forensic picture firms up; answers to any direction it issues; root-cause fix evidenced.Directions give CERT-In power to set further deadlines.

A worked example with invented facts. Weekdays are real: T0 falls on a Friday night, which is exactly when a process that depends on one person's inbox fails.

Two things decide the outcome: who owns T0, because an alert left in a queue until Monday blows every clock, and whether the facts exist, because the 02:10 report depends on logs with agreeing timestamps. To get your own dates, put your detection time into the breach notification deadline calculator.

05

Sector regulators add their own clocks

Banks, payment operators, market intermediaries and insurers answer to a regulator as well as to CERT-In and the Board. Each has set its own reporting window, mostly six hours, with a fuller report within 24 hours. These run in parallel with the CERT-In and DPDP duties.

RegulatorWhoClockSource
RBINon-bank payment system operatorsUnusual incidents, including cyber attacks, to RBI within 6 hours of detection in the Annex 1 format; cyber security incidents also to CERT-In. Phased in: large PSOs from 1 April 2025, medium from 1 April 2026, small from 1 April 2028.RBI Master Directions, 30 July 2024, para 22(4)
RBIBanks and NBFCs covered by the IT governance direction'Pro-actively notify CERT-In and RBI regarding incidents, as per regulatory requirements.' The direction itself states no hour count, so the CERT-In six hours is the fixed clock; confirm any RBI-specific window for your entity with your supervisor.RBI Master Direction, 7 November 2023, para 27(d)
SEBISEBI-regulated entities under CSCRFIncidents within the CERT-In Directions to SEBI (mkt_incidents@sebi.gov.in) and CERT-In within 6 hours; details on the SEBI Incident Reporting Portal within 24 hours. Stock brokers and depository participants also tell their exchange or depository within 6 hours. Other incidents within 24 hours.SEBI CSCRF circular, 20 August 2024
IRDAIInsurers and other IRDAI-regulated entitiesTo CERT-In within 6 hours with a copy to IRDAI; available details to IRDAI in its format within 24 hours, and updated versions within 24 hours of new forensic information.IRDAI circular, 13 June 2023

Sector rules sit on top of CERT-In and DPDP; they do not replace them. Where we could not find an hour figure in the primary text, we say so rather than repeat one.

A regulated entity can owe four reports inside the first day. Our guides to the RBI cyber security framework, SEBI's CSCRF and the IRDAI cyber security guidelines cover the rest of each regime.

06

What must each breach notification contain?

CERT-In wants technical facts, the Board wants cause and response, people want to know what to do, and a GDPR authority wants numbers and consequences. One incident record captures them all:

  • Times: occurrence, detection, and each notification sent, all from clocks synchronised to a standard source, with time zones recorded
  • Systems: domain or URL, IP addresses, operating system, cloud or make and model, affected application, location and ISP (the CERT-In form)
  • Incident type: which Annexure I category, or 'other' with a description
  • Data: the categories of personal data, approximate number of people and records, whether children's data is involved, and where the data resided
  • Impact: likely consequences for the people affected, in plain language for them and in fuller terms for the Board
  • Response: mitigation done and planned, remedial measures against recurrence, and any findings about who caused it
  • Advice to people: the safety steps they can take, such as changing a password or watching for phishing
  • Contact: a named person or role who can answer questions for the business
  • Intimation log: when and how each affected person was told, which the 72-hour report needs

Ready-to-edit wording for the Board, the Data Principal notice and the CERT-In report is in the data breach notification template for India. The clocks and roles to wrap around it are in the incident response plan template.

07

Where the platform fits, and where it does not

Most of what decides these deadlines is process: someone owning T0, a named CERT-In point of contact, and logs that exist. Software helps at the edges. TryTrustable's data discovery engine includes a breach simulator that drafts the notification against your real data map, naming the stores, categories and residencies involved, so the first draft is written on a quiet day. The standalone consent platform tracks breach notification to the Board and to affected people with the 72-hour clock running from awareness. And the evidence ledger is hash-chained and timestamped at collection, which is what lets you show a control was operating before an incident rather than after it.

None of this files a report with CERT-In, the Board or a regulator for you, and none of it replaces counsel's judgement about when you became aware. For the penalty side, the DPDP penalty calculator prices each obligation, and the DPDP Act guide covers the rest of the duties that start on 13 May 2027.

Questions

The things people ask us

Do I have to report the same breach to both CERT-In and the Data Protection Board?

Usually, yes. A personal data breach at an Indian company is normally also a data breach or data leak under Annexure I of the CERT-In Directions. The two duties come from different laws, go to different bodies and neither report satisfies the other. From 13 May 2027 you owe CERT-In a report within six hours and the Board an intimation without delay plus a detailed report within 72 hours.

When does the CERT-In 6-hour clock start?

From noticing the incident or being brought to notice of it, not from when it happened and not from when your investigation concludes. CERT-In's FAQs say you may report what you know at the six-hour mark and send further details later within reasonable time. An incident nobody noticed for months still gets six hours from the moment it is noticed.

Is DPDP breach notification in force yet?

Not yet. Section 8(6) of the DPDP Act and Rule 7 of the DPDP Rules 2025 apply from 13 May 2027, eighteen months after the Rules were published on 13 November 2025. Until then the CERT-In Directions, the GDPR where it applies, and your sector regulator's rules are the clocks that bind. Build the DPDP process now, because it runs alongside the others rather than replacing them.

Is there a minimum size of breach before DPDP notification applies?

No. The DPDP Act requires every personal data breach to be intimated to the Board and to each affected Data Principal. There is no risk threshold like the GDPR's 'unlikely to result in a risk' exception, and no de minimis carve-out. A misdirected email containing one customer's personal data is, on the text, a notifiable breach.

What is the penalty for missing each deadline?

Failing to notify under the DPDP Act carries a maximum of ₹200 crore per instance. Failing to comply with a CERT-In direction is punishable under section 70B(7) of the IT Act with imprisonment of up to one year, a fine of up to ₹1 lakh, or both. Under the GDPR, breaching Articles 33 or 34 can cost up to €10 million or 2% of worldwide turnover.

Can our cloud provider or vendor report to CERT-In for us?

No. CERT-In's FAQs say any entity that notices the incident must report it, and that the obligation is not transferable, cannot be indemnified and cannot be dispensed with by contract. If your vendor is breached and your data is affected, expect both of you to report. Under DPDP, the duty to notify sits with the Data Fiduciary, not the processor.

Do banks have to report to RBI within six hours?

It depends on the entity. RBI's 2024 Master Directions for non-bank payment system operators require unusual incidents to be reported to RBI within six hours of detection. The 2023 IT governance Master Direction for banks and NBFCs requires them to notify CERT-In and RBI as per regulatory requirements, without stating hours itself. Check the direction that governs your entity.

Book a walkthrough

Rehearse the breach before you have one.

Thirty minutes. We run the breach simulator against a sample data map and show you the notification draft it produces, with the stores and residencies named.