By Adv. K J Muhammed Aslam · Advocate, Ernakulam (Bar Council of Kerala)
India’s breach-reporting regime is not one clock but two — and the most common compliance mistake Kerala businesses make is preparing for only one of them. The CERT-In Directions dated 28 April 2022 under Section 70B(6) of the IT Act require reporting of specified cyber incidents, including data breaches, to CERT-In within six hours of noticing them. The DPDP Rules, 2025 — Rule 7 — require notification of every personal data breach to the Data Protection Board of India without delay, with a detailed report within 72 hours, plus notification to each affected individual without delay. Where a personal data breach is also a cyber incident, both duties apply in parallel on different clocks to different authorities.
What are the two breach duties, in one table?
| Feature | CERT-In Directions (28 April 2022) | DPDP Act + Rule 7 (G.S.R. 846(E), 13 Nov 2025) |
|---|---|---|
| Legal basis | Section 70B(6) IT Act, 2000 | Sections 2(u), 8(5), 8(6) DPDP Act, 2023 + Rule 7 DPDP Rules, 2025 |
| Who must report | Service providers, intermediaries, data centres, body corporates, government organisations — the Directions’ broad covered-entity definition | Every Data Fiduciary (any person determining the purpose and means of processing digital personal data) — Section 2(i) DPDP Act |
| What triggers the duty | Cyber incidents listed in Annex I to the Directions — expressly includes data breach, data leak, attacks on digital payment systems, compromise of critical systems, malware, IoT attacks, and others | Every personal data breach — Section 2(u): any unauthorised processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises the confidentiality, integrity or availability of personal data. No threshold |
| Clock starts | On noticing the incident or being brought to notice of it | On becoming aware of the personal data breach |
| Deadline to CERT-In / Board | Within 6 hours (report to the extent available; supplement later) | Without delay — initial intimation to Board describing nature, extent, timing and likely impact; detailed report within 72 hours of becoming aware (extendable only on Board’s written allowance on good-cause request) |
| Deadline to affected individuals | No direct individual-notification duty under the Directions | Without delay — each affected Data Principal must be informed in concise, clear, plain language through their user account or registered contact details, covering what happened, likely consequences, mitigation and a contact person |
| Form and channel | CERT-In incident reporting form at cert-in.org.in; email [email protected]; phone 1800-11-4949 | As prescribed by the Rules and Board procedure — intimation to Board and to individuals through usual contact channels |
| Confidentiality defence | On one interpretive view, reporting as a statutory duty overrides confidentiality clauses in contracts (Section 81 IT Act, FAQ Q22 May 2022) — treated here as interpretation; FAQ Q30 itself supports only extent-available reporting with later supplementation | Same interpretive position — statutory duty overrides contractual confidentiality |
| Penalty for failure to report | Section 70B(7) IT Act: imprisonment up to one year, or fine up to one crore rupees (raised from one lakh by the Jan Vishwas Act, 2023, w.e.f. 30 Nov 2023), or both | Section 8(6) read with Section 33 and the Schedule: up to two hundred crore rupees per breach, plus up to two hundred and fifty crore rupees exposure for the underlying failure of reasonable security safeguards under Section 8(5) |
Who exactly must report under each regime?
CERT-In casts a deliberately wide net. The Directions apply to intermediaries (which under Section 2(1)(w) of the IT Act includes social media platforms, hosting providers, ISPs, cloud services and many SaaS providers), data centres, body corporates (which under Section 43A of the IT Act means any company or firm handling sensitive data), and government organisations. In practice, any Kerala business that runs a website handling user data, uses a cloud provider, or operates an app is within the covered-entity description, and the FAQs confirm that even service providers without a physical presence in India but serving users in India are covered.
DPDP turns on a different test — whether the entity is a Data Fiduciary under Section 2(i): a person who alone or with others determines the purpose and means of processing personal data. A company deciding what customer data to collect and why is a fiduciary. A vendor processing purely on instructions is a Data Processor under Section 2(k), but the fiduciary remains responsible under Section 8(1) for the processor’s compliance. There is no turnover or headcount threshold. A two-person startup processing digital personal data is a fiduciary for the data it controls.
The overlap is therefore large: most Data Fiduciaries that suffer a breach are also covered entities under the CERT-In Directions. The result is dual reporting, not a choice between the two.
What counts as a reportable incident under each?
Under CERT-In, the trigger is whether the event falls in Annex I. The list is longer than most teams realise and was deliberately expanded in 2022. It includes, among others: data breach, data leak, unauthorised access to IT systems or data, attacks on internet-of-things devices, attacks on digital payment systems, compromise of critical information infrastructure, phishing or identity theft, malware or ransomware, denial-of-service, and scanning or probing of systems. The FAQs clarify that incidents meeting criteria such as severe nature, impact on safety, or large-scale or frequent occurrence should be reported within the six-hour window.
Under DPDP, the trigger is whether there is a personal data breach under Section 2(u). That definition is intentionally wide: any unauthorised processing of personal data, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises the confidentiality, integrity or availability of personal data. It covers a misdirected email containing personal data, an accidental S3 bucket exposure, and a ransomware encryption of a customer database alike. The Rules add no de minimis exception — every breach triggers the notification duties, unlike the GDPR where the authority notification can be excused where the breach is unlikely to result in a risk to rights and freedoms.
How do the clocks actually work in a real incident?
An example helps because the two clocks start at the same conceptual moment — awareness — but run to different deadlines with different content:
- T+0 — detection. Your SOC or an engineer notices a database has been exposed, or a customer reports receiving another customer’s invoice. You are now aware for both regimes.
- T+0 to T+6 hours — CERT-In window. File the CERT-In incident report with whatever facts are available: incident type, time of detection, affected systems, brief description, contact person. The Directions and the May 2022 FAQs expressly contemplate that you report to the extent available within six hours and supplement with additional details within reasonable time. Do not wait for a forensics report to send the first notification.
- T+0 without delay — DPDP individual and Board initial notifications. Rule 7 requires you to inform each affected Data Principal without delay, in plain language, through their user account or registered contact details — what happened, likely consequences, mitigation done, steps they can take, and a contact person. In parallel, send the Board an initial intimation without delay describing the breach’s nature, extent, timing and likely impact.
- T+72 hours — DPDP detailed report to Board. Within 72 hours of becoming aware, submit the detailed particulars to the Board: facts, circumstances, causes, findings on the person responsible, mitigation, remedial steps to prevent recurrence, and a summary of intimations sent to individuals. The Board may extend this only if you make a written request showing good cause — do not assume an automatic extension.
A common mistake is to treat the 72-hour report as the first notification. It is not — the without-delay intimations to individuals and to the Board are due immediately, and the 72-hour filing is the detailed follow-up. Another mistake is to inform only the Board and assume individuals will learn from it. Rule 7 requires separate, direct intimation to each affected individual.
How should a Kerala business build one playbook for both?
The efficient approach is not two separate runbooks but one integrated breach-response plan with both notifications built into the same timeline, owned by named roles and rehearsed before an incident:
- Pre-incident — designate and publish. Name the CERT-In point of contact and the DPDP grievance contact (Section 8(9) DPDP Act) and publish them. Ensure ICT system logs are retained for at least 180 days within India and systems are synced to Indian NTP time — both are CERT-In Directions requirements — and that Rule 6 DPDP security safeguards (encryption or masking, access controls, logging for one year, backups) are in place.
- Detection to 6 hours — contain, assess, report to CERT-In. Containment and preservation come first, but the six-hour report goes in parallel. Keep a one-page CERT-In reporting template pre-filled with entity details so the on-call engineer only adds incident-specific facts.
- Without delay — notify individuals and the Board under DPDP. Keep plain-language breach-notification templates in English and Malayalam so the without-delay notice to affected Data Principals does not stall on drafting. The initial Board intimation should use the fields CERT-In already requires plus the DPDP-specific points: purpose for which the breached data was collected, categories of data and data principals affected, and likely consequences for individuals.
- 72-hour — detailed Board report. Prepare a second template for the detailed report covering causes, findings, mitigation, preventive steps and a log of individual intimations. File within 72 hours even if forensics is incomplete, noting what remains under investigation — you can supplement, but you cannot miss the deadline.
- Post-incident — document everything. Under Section 6(10) of the DPDP Act the burden of proving notice and consent in related matters sits on the fiduciary, and Section 33(2) makes mitigation and good-faith response a factor in penalty decisions. A dated, logged response file is itself a mitigation factor.
For the substantive preparation that the 72-hour clock assumes — consent logs, retention schedules, vendor contracts — see the DPDP countdown for Indian businesses and for the platform duties that sit alongside breach handling, the guides on sextortion reporting and takedown and synthetically generated information labelling.
Primary sources
- Information Technology Act, 2000 — India Code (Section 70B, Section 43A, Section 2(1)(w))
- CERT-In Directions dated 28 April 2022 under Section 70B(6) and FAQs dated 18 May 2022 — cert-in.org.in (six-hour reporting, 180-day log retention, NTP sync, five-year subscriber data retention)
- Digital Personal Data Protection Act, 2023 — India Code (Sections 2(i), 2(k), 2(u), 8(5), 8(6), 33 and the Schedule)
- Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E), 13 November 2025) — MeitY (Rule 6 on security safeguards, Rule 7 on breach notification, Rule 14 on rights and grievance)
- AZB & Partners summary of DPDP Rules enforcement timelines — Mondaq, 21 November 2025 (phased commencement: Rule 7 from ≈13 May 2027 (displayed as 14 May 2027 on this site))
FAQ
