Breach notification deadline calculator
for India and the GDPR.
Enter when you noticed the incident. Get every reporting clock that applies, with the exact deadline and the authority: CERT-In's six hours, the DPDP Act's 72 hours, the GDPR, and the RBI, SEBI and IRDAI windows.
How the calculator works
You give it one time: when your organisation noticed the incident, or was told about it. Every Indian breach clock runs from that moment of awareness, not from when the attack happened and not from when your investigation ends. The calculator adds each regime's window to that time and lists the deadlines earliest first, in IST and UTC.
It covers the clocks we could verify in the primary text as of September 2026:
- CERT-In: six hours from noticing any of the 20 Annexure I incident types, under the Directions of 28 April 2022. Applies to every service provider, intermediary, data centre, body corporate and government organisation.
- DPDP Act: each affected Data Principal and the Board without delay, and a detailed report to the Board within 72 hours, under Rule 7 of the DPDP Rules 2025. In force from 13 May 2027; for earlier dates the calculator flags the clock as not yet in force.
- GDPR: the supervisory authority without undue delay and where feasible within 72 hours, under Article 33, unless the breach is unlikely to result in a risk.
- RBI: six hours from detection for non-bank payment system operators, under the 2024 Master Directions. For banks and NBFCs, the 2023 IT governance direction requires notice to CERT-In and RBI 'as per regulatory requirements' without an hour count, so the calculator shows it without a timestamp.
- SEBI: six hours to SEBI and CERT-In, and details on the portal within 24 hours, under the CSCRF circular of 20 August 2024.
- IRDAI: six hours to CERT-In with a copy to IRDAI, and details to IRDAI within 24 hours of intimation, under the circular of 13 June 2023.
Assumptions it makes
A deadline calculator is only as good as the time you give it, so the assumptions are stated here rather than buried.
- One awareness time for every regime. CERT-In says 'noticing'; Rule 7 and the GDPR say 'becoming aware'. We treat them as the same moment, which is the cautious reading. Counsel may argue for a later point for DPDP or GDPR in a specific case; do not rely on that argument for CERT-In.
- 'Without delay' has no number. Rule 7 gives no hour count for telling people or for the Board's first intimation. We show those as 'Without delay' rather than invent a figure.
- Hours are clock hours. None of these windows pause for weekends or public holidays.
- The IRDAI 24 hours runs from intimation. We show the latest time assuming you intimate at the six-hour mark; report earlier and the 24 hours starts earlier.
- Your role is fixed by the tick boxes. The DPDP clock assumes you are the Data Fiduciary. A Data Processor's duty to tell the Fiduciary comes from the contract, and under the GDPR a processor tells the controller instead of the authority.
It does not cover the Data Protection Board's own form, other countries' laws, the UK GDPR, or sector regulators beyond RBI, SEBI and IRDAI.
The worked example
The calculator opens on a real-looking case: an alert acknowledged at 21:30 IST on Friday 4 June 2027, a general business, personal data of people in India and in the EU affected. The CERT-In report falls due at 03:30 IST on Saturday. The DPDP detailed report and the GDPR notification both fall due at 21:30 IST on Monday 7 June, which is 18:00 in Central Europe. The CERT-In vs DPDP breach reporting guide walks through the same incident hour by hour, including when each report was actually sent.
Change the sector to see how a regulated entity's first day fills up. A stock broker, for example, has four reports due at the six-hour mark or within the following day: CERT-In, SEBI, its exchange or depository, and the SEBI portal.
What to do with the deadlines
Put them in the incident channel the moment you have them, with a named owner for each. Then write the reports from one incident record so the facts agree. The breach notification template for India has the Board intimation, the Data Principal notice and a CERT-In report skeleton ready to fill in. If you have no plan yet, start from the incident response plan template, which has these clocks built in. For what a missed DPDP deadline could cost, use the DPDP penalty calculator.
The things people ask us
Does the CERT-In six-hour clock pause overnight or at weekends?
No. The Directions say six hours from noticing the incident or being brought to notice of it, with no exclusion for nights, weekends or holidays. An alert acknowledged at 21:30 on a Friday is due at 03:30 on Saturday. That is why the plan needs a named point of contact who can be reached at any hour.
Which deadline comes first after a personal data breach in India?
The CERT-In report, six hours after noticing, is the first fixed deadline for almost every organisation. Regulated entities usually owe their regulator a report in the same six hours. The DPDP duties to tell each affected person and the Board carry no hour count, only 'without delay', and the DPDP detailed report is due at 72 hours.
Does the DPDP 72-hour clock apply today?
Not before 13 May 2027, when Rule 7 of the DPDP Rules 2025 commences. For a detection date before then, the calculator still shows the DPDP clocks but marks them as not yet in force, so you can rehearse the process now. The CERT-In, GDPR and sector clocks already apply.
Can we ask for more time for the DPDP detailed report?
Yes. Rule 7(2)(b) allows a longer period if the Board permits it on a written request. Make the request before the 72 hours run out and explain why, for example because forensic analysis is still under way. The without-delay duties to tell people and give the Board an initial description are not extended by it.
Is the GDPR 72-hour deadline strict?
Article 33 says without undue delay and, where feasible, not later than 72 hours after becoming aware. A late notification must give reasons for the delay, and information may be provided in phases. It does not apply if the breach is unlikely to result in a risk to people's rights and freedoms, a judgement you should record.
Is this calculator legal advice?
No. It applies published deadlines to the time you enter. Whether a duty arises, when you became aware, and which authority is competent depend on facts only you and your counsel can judge. Use it to plan and to rehearse, and check the primary text linked on this page before you rely on any deadline.
Stop calculating deadlines. Start rehearsing them.
The breach simulator drafts the notification against your real data map, so the first draft is written on a quiet day rather than inside the six hours.