---
title: "CERT-In 6-Hour vs DPDP 72-Hour Breach Reporting in India"
description: "India has two breach clocks that both apply: CERT-In's 6 hours and DPDP Rule 7's 72 hours. Who reports to whom, when each starts, and one playbook for both."
url: "https://advaslam.com/writing/cert-in-6-hour-vs-dpdp-72-hour-breach-reporting/"
image: "https://advaslam.com/og/writing/cert-in-6-hour-vs-dpdp-72-hour-breach-reporting.png"
---

[Data protection & DPDP compliance](https://advaslam.com/practice/data-protection/)

# CERT-In 6-Hour vs DPDP 72-Hour Breach Reporting: Which Clock Applies to Your Business?

By [**Adv. K J Muhammed Aslam**](https://advaslam.com/profile/) · Advocate, Ernakulam (Bar Council of Kerala)

Published 1 September 2026

India’s breach-reporting regime is not one clock but two — and the most common compliance mistake Kerala businesses make is preparing for only one of them. The [CERT-In Directions dated 28 April 2022](https://www.cert-in.org.in/Directions70B.jsp) under Section 70B(6) of the IT Act require reporting of specified cyber incidents, including data breaches, to CERT-In within **six hours** of noticing them. The [DPDP Rules, 2025](https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf) — Rule 7 — require notification of every personal data breach to the [Data Protection Board of India](https://www.meity.gov.in) without delay, with a detailed report within **72 hours**, plus notification to each affected individual without delay. Where a personal data breach is also a cyber incident, **both duties apply in parallel** on different clocks to different authorities.

## What are the two breach duties, in one table?

| Feature | CERT-In Directions (28 April 2022) | DPDP Act + Rule 7 (G.S.R. 846(E), 13 Nov 2025) |
| --- | --- | --- |
| **Legal basis** | [Section 70B(6) IT Act, 2000](https://indiacode.gov.in/handle/123456789/496511) | [Sections 2(u), 8(5), 8(6) DPDP Act, 2023](https://indiacode.gov.in/handle/123456789/496508) + Rule 7 DPDP Rules, 2025 |
| **Who must report** | Service providers, intermediaries, data centres, body corporates, government organisations — the Directions’ broad covered-entity definition | Every Data Fiduciary (any person determining the purpose and means of processing digital personal data) — Section 2(i) DPDP Act |
| **What triggers the duty** | Cyber incidents listed in Annex I to the Directions — expressly includes data breach, data leak, attacks on digital payment systems, compromise of critical systems, malware, IoT attacks, and others | Every personal data breach — Section 2(u): any unauthorised processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises the confidentiality, integrity or availability of personal data. No threshold |
| **Clock starts** | On noticing the incident or being brought to notice of it | On becoming aware of the personal data breach |
| **Deadline to CERT-In / Board** | **Within 6 hours** (report to the extent available; supplement later) | **Without delay** — initial intimation to Board describing nature, extent, timing and likely impact; **detailed report within 72 hours** of becoming aware (extendable only on Board’s written allowance on good-cause request) |
| **Deadline to affected individuals** | No direct individual-notification duty under the Directions | **Without delay** — each affected Data Principal must be informed in concise, clear, plain language through their user account or registered contact details, covering what happened, likely consequences, mitigation and a contact person |
| **Form and channel** | CERT-In incident reporting form at cert-in.org.in; email [incident@cert-in.org.in](mailto:incident@cert-in.org.in); phone 1800-11-4949 | As prescribed by the Rules and Board procedure — intimation to Board and to individuals through usual contact channels |
| **Confidentiality defence** | On one interpretive view, reporting as a statutory duty overrides confidentiality clauses in contracts (Section 81 IT Act, FAQ Q22 May 2022) — treated here as interpretation; FAQ Q30 itself supports only extent-available reporting with later supplementation | Same interpretive position — statutory duty overrides contractual confidentiality |
| **Penalty for failure to report** | [Section 70B(7) IT Act](https://indiacode.gov.in/handle/123456789/496511): imprisonment up to one year, or fine up to one crore rupees (raised from one lakh by the Jan Vishwas Act, 2023, w.e.f. 30 Nov 2023), or both | Section 8(6) read with Section 33 and the Schedule: up to **two hundred crore rupees** per breach, plus up to **two hundred and fifty crore rupees** exposure for the underlying failure of reasonable security safeguards under Section 8(5) |

## Who exactly must report under each regime?

**CERT-In** casts a deliberately wide net. The Directions apply to intermediaries (which under Section 2(1)(w) of the IT Act includes social media platforms, hosting providers, ISPs, cloud services and many SaaS providers), data centres, body corporates (which under Section 43A of the IT Act means any company or firm handling sensitive data), and government organisations. In practice, any Kerala business that runs a website handling user data, uses a cloud provider, or operates an app is within the covered-entity description, and the FAQs confirm that even service providers without a physical presence in India but serving users in India are covered.

**DPDP** turns on a different test — whether the entity is a **Data Fiduciary** under Section 2(i): a person who alone or with others determines the purpose and means of processing personal data. A company deciding what customer data to collect and why is a fiduciary. A vendor processing purely on instructions is a Data Processor under Section 2(k), but the fiduciary remains responsible under Section 8(1) for the processor’s compliance. There is no turnover or headcount threshold. A two-person startup processing digital personal data is a fiduciary for the data it controls.

The overlap is therefore large: most Data Fiduciaries that suffer a breach are also covered entities under the CERT-In Directions. The result is dual reporting, not a choice between the two.

## What counts as a reportable incident under each?

**Under CERT-In**, the trigger is whether the event falls in Annex I. The list is longer than most teams realise and was deliberately expanded in 2022. It includes, among others: data breach, data leak, unauthorised access to IT systems or data, attacks on internet-of-things devices, attacks on digital payment systems, compromise of critical information infrastructure, phishing or identity theft, malware or ransomware, denial-of-service, and scanning or probing of systems. The FAQs clarify that incidents meeting criteria such as severe nature, impact on safety, or large-scale or frequent occurrence should be reported within the six-hour window.

**Under DPDP**, the trigger is whether there is a **personal data breach** under Section 2(u). That definition is intentionally wide: any unauthorised processing of personal data, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises the confidentiality, integrity or availability of personal data. It covers a misdirected email containing personal data, an accidental S3 bucket exposure, and a ransomware encryption of a customer database alike. The Rules add no de minimis exception — every breach triggers the notification duties, unlike the GDPR where the authority notification can be excused where the breach is unlikely to result in a risk to rights and freedoms.

## How do the clocks actually work in a real incident?

An example helps because the two clocks start at the same conceptual moment — awareness — but run to different deadlines with different content:

-   **T+0 — detection.** Your SOC or an engineer notices a database has been exposed, or a customer reports receiving another customer’s invoice. You are now aware for both regimes.
-   **T+0 to T+6 hours — CERT-In window.** File the CERT-In incident report with whatever facts are available: incident type, time of detection, affected systems, brief description, contact person. The Directions and the May 2022 FAQs expressly contemplate that you report to the extent available within six hours and supplement with additional details within reasonable time. Do not wait for a forensics report to send the first notification.
-   **T+0 without delay — DPDP individual and Board initial notifications.** Rule 7 requires you to inform each affected Data Principal without delay, in plain language, through their user account or registered contact details — what happened, likely consequences, mitigation done, steps they can take, and a contact person. In parallel, send the Board an initial intimation without delay describing the breach’s nature, extent, timing and likely impact.
-   **T+72 hours — DPDP detailed report to Board.** Within 72 hours of becoming aware, submit the detailed particulars to the Board: facts, circumstances, causes, findings on the person responsible, mitigation, remedial steps to prevent recurrence, and a summary of intimations sent to individuals. The Board may extend this only if you make a written request showing good cause — do not assume an automatic extension.

A common mistake is to treat the 72-hour report as the first notification. It is not — the without-delay intimations to individuals and to the Board are due immediately, and the 72-hour filing is the detailed follow-up. Another mistake is to inform only the Board and assume individuals will learn from it. Rule 7 requires separate, direct intimation to each affected individual.

## How should a Kerala business build one playbook for both?

The efficient approach is not two separate runbooks but one integrated breach-response plan with both notifications built into the same timeline, owned by named roles and rehearsed before an incident:

1.  **Pre-incident — designate and publish.** Name the CERT-In point of contact and the DPDP grievance contact (Section 8(9) DPDP Act) and publish them. Ensure ICT system logs are retained for at least **180 days** within India and systems are synced to Indian NTP time — both are CERT-In Directions requirements — and that Rule 6 DPDP security safeguards (encryption or masking, access controls, logging for one year, backups) are in place.
2.  **Detection to 6 hours — contain, assess, report to CERT-In.** Containment and preservation come first, but the six-hour report goes in parallel. Keep a one-page CERT-In reporting template pre-filled with entity details so the on-call engineer only adds incident-specific facts.
3.  **Without delay — notify individuals and the Board under DPDP.** Keep plain-language breach-notification templates in English and Malayalam so the without-delay notice to affected Data Principals does not stall on drafting. The initial Board intimation should use the fields CERT-In already requires plus the DPDP-specific points: purpose for which the breached data was collected, categories of data and data principals affected, and likely consequences for individuals.
4.  **72-hour — detailed Board report.** Prepare a second template for the detailed report covering causes, findings, mitigation, preventive steps and a log of individual intimations. File within 72 hours even if forensics is incomplete, noting what remains under investigation — you can supplement, but you cannot miss the deadline.
5.  **Post-incident — document everything.** Under Section 6(10) of the DPDP Act the burden of proving notice and consent in related matters sits on the fiduciary, and Section 33(2) makes mitigation and good-faith response a factor in penalty decisions. A dated, logged response file is itself a mitigation factor.

For the substantive preparation that the 72-hour clock assumes — consent logs, retention schedules, vendor contracts — see [the DPDP countdown for Indian businesses](https://advaslam.com/writing/dpdp-act-deadline-businesses/) and for the platform duties that sit alongside breach handling, the guides on [sextortion reporting and takedown](https://advaslam.com/writing/sextortion-blackmail-kerala-legal-remedies/) and [synthetically generated information labelling](https://advaslam.com/writing/deepfake-sgi-it-rules-2026-labelling-takedown/).

## Primary sources

-   [Information Technology Act, 2000 — India Code](https://indiacode.gov.in/handle/123456789/496511) (Section 70B, Section 43A, Section 2(1)(w))
-   [CERT-In Directions dated 28 April 2022 under Section 70B(6) and FAQs dated 18 May 2022 — cert-in.org.in](https://www.cert-in.org.in/Directions70B.jsp) (six-hour reporting, 180-day log retention, NTP sync, five-year subscriber data retention)
-   [Digital Personal Data Protection Act, 2023 — India Code](https://indiacode.gov.in/handle/123456789/496508) (Sections 2(i), 2(k), 2(u), 8(5), 8(6), 33 and the Schedule)
-   [Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E), 13 November 2025) — MeitY](https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf) (Rule 6 on security safeguards, Rule 7 on breach notification, Rule 14 on rights and grievance)
-   [AZB & Partners summary of DPDP Rules enforcement timelines — Mondaq, 21 November 2025](https://www.mondaq.com/india/privacy-protection/1708314/update-indias-digital-personal-data-protection-framework-comes-into-effect) (phased commencement: Rule 7 from ≈13 May 2027 (displayed as 14 May 2027 on this site))

FAQ

## Common questions

**Do I need to report a data breach under both CERT-In Directions and the DPDP Act?**

Yes, where both apply. CERT-In Directions dated 28 April 2022 require reporting of specified cyber incidents — including data breaches and data leaks — to CERT-In within six hours of noticing them. DPDP Rule 7 requires notification of every personal data breach to the Data Protection Board without delay, with a detailed report within 72 hours, and notification to each affected Data Principal without delay. The two duties run in parallel to different authorities on different clocks, and compliance with one does not excuse the other.

**When does the CERT-In 6-hour clock start?**

Within six hours of noticing the incident or being brought to notice of it. The FAQs issued in May 2022 (Q30) clarify that you report to the extent information is available within six hours and supplement later within reasonable time. The clock is not from the breach occurrence, which may have been earlier, but from awareness. On one interpretive view, based on FAQ Q22 read with Section 81 of the IT Act, a statutory reporting duty overrides conflicting contractual confidentiality clauses — but that override is an interpretation, not express Directions text, and Q30 itself supports only extent-available reporting with later supplementation.

**When does the DPDP 72-hour clock start?**

From when the Data Fiduciary becomes aware of the personal data breach. Rule 7 requires intimation to each affected Data Principal without delay in clear, plain language, an initial intimation to the Data Protection Board without delay describing the nature, extent, timing and likely impact, and a detailed report to the Board within 72 hours of becoming aware, extendable only if the Board allows a written request showing good cause.

**What is the penalty for failing to report a breach under the DPDP Act?**

Failure to notify the Board or affected Data Principals of a personal data breach under Section 8(6) of the DPDP Act carries a penalty of up to two hundred crore rupees, imposed by the Data Protection Board after inquiry and hearing under Section 33, weighing factors under Section 33(2) including gravity, duration, data type, repetition, gains and mitigation. Non-compliance with CERT-In Directions can attract punishment under Section 70B(7) of the IT Act — imprisonment up to one year, fine up to one crore rupees (raised from one lakh by the Jan Vishwas (Amendment of Provisions) Act, 2023, w.e.f. 30 November 2023), or both.

**Does every small breach need to be reported under the DPDP Act?**

Yes. Unlike the GDPR, which has a risk-to-rights threshold for notification to the authority, DPDP Rule 7 has no materiality filter in its text — every personal data breach as defined in Section 2(u), which includes unauthorised processing and accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access that compromises the confidentiality, integrity or availability of personal data, triggers the notification duties. There is no exception for small or low-risk breaches in the notified text.

**A note on this article.** It is general legal information, not legal advice. The law may have changed since the date shown; before acting on anything here, take advice on your specific situation from an advocate of your choice.

## Related guides

-   [DPDP Readiness Checklist for Kerala Small Businesses](https://advaslam.com/guides/dpdp-readiness-checklist-small-business/)

[All procedure guides →](https://advaslam.com/guides/)

Keep reading

Data protection & DPDP compliance

### DPDP Compliance Guide for Kerala Businesses to May 2027

DPDP readiness for Kerala SMEs: phased timeline to May 2027, notices, safeguards, breach response, rights, children, SDF, transfer, contracts, penalties.

25 Sept 2026

[DPDP Compliance Guide for Kerala Businesses to May 2027](https://advaslam.com/writing/dpdp-compliance-guide-kerala-businesses/)

Data protection & DPDP compliance

### Your Personal Data Was Leaked by a Company: What You Can Do Under the DPDP Act

Company leaked your Aadhaar, phone or health data? DPDP Sections 11-14 rights, Board complaint, IT Act 43A compensation, consumer and civil remedies.

6 Sept 2026

[Your Personal Data Was Leaked by a Company: What You Can Do Under the DPDP Act](https://advaslam.com/writing/data-breach-victim-rights-dpdp-compensation/)

Contact

[WhatsApp](https://wa.me/919497240215?text=Hello%2C%20I%20found%20advaslam.com%20and%20would%20like%20to%20discuss%20a%20matter.) [contact@advaslam.com](mailto:contact@advaslam.com) [+91 94972 40215](tel:+919497240215)

3rd Floor, Lalan Towers (KGL Builders), Vanchi Square, High Court Junction, Ernakulam, Kerala 682031 · Monday – Saturday, 10:00 – 18:30 (by appointment)

```json
{"@context":"https://schema.org","@graph":[{"@type":"WebSite","@id":"https://advaslam.com/#website","url":"https://advaslam.com","name":"Adv. K J Muhammed Aslam","alternateName":"advaslam.com","publisher":{"@id":"https://advaslam.com/#person"},"inLanguage":"en-IN"},{"@type":"Person","@id":"https://advaslam.com/#person","name":"K J Muhammed Aslam","alternateName":["Adv. K J Muhammed Aslam","Advocate K J Muhammed Aslam","Muhammed Aslam K J","Adv. Aslam"],"honorificPrefix":"Adv.","jobTitle":"Advocate","description":"Advocate enrolled with the Bar Council of Kerala, practising from High Court Junction, Ernakulam: cyber and technology law, data protection (DPDP), business, banking and IPR, and litigation before the High Court of Kerala and the courts at Ernakulam.","url":"https://advaslam.com/profile/","image":"https://advaslam.com/og.png","telephone":"+919497240215","email":"contact@advaslam.com","address":{"@type":"PostalAddress","streetAddress":"3rd Floor, Lalan Towers (KGL Builders), Vanchi Square, High Court Junction","addressLocality":"Ernakulam","addressRegion":"Kerala","postalCode":"682031","addressCountry":"IN"},"alumniOf":{"@type":"CollegeOrUniversity","name":"Bharata Mata School of Legal Studies"},"memberOf":[{"@type":"Organization","name":"Bar Council of Kerala","url":"https://barcouncilkerala.org/lawyer-registry-list"},{"@type":"Organization","name":"Kerala High Court Advocates' Association","url":"https://khcaa.com/"}],"identifier":[{"@type":"PropertyValue","propertyID":"Bar Council of Kerala Enrolment No.","value":"K/001823/2026"},{"@type":"PropertyValue","propertyID":"KHCAA Membership No.","value":"OAJ 358"}],"knowsAbout":["Information Technology Act 2000","Cyber crime law","Technology law and technology contracts","Digital Personal Data Protection Act 2023","DPDP compliance","Data protection and privacy law","Business and commercial law","Contract drafting and negotiation","Banking and finance law","Negotiable Instruments Act cheque dishonour","SARFAESI Act","Intellectual property law","Copyright and trademark law","Patent infringement","GST and income-tax law","Blockchain and cryptocurrency technology","Web3 wallets and NFTs","Drone regulation and DigitalSky framework","Writ petitions under Article 226","Criminal law","Civil and consumer litigation","Family and succession law","Service and labour law","Legal drafting","Mediation and dispute resolution"],"knowsLanguage":["en","ml"],"workLocation":{"@id":"https://advaslam.com/#practice"},"hasCredential":[{"@type":"EducationalOccupationalCredential","credentialCategory":"Enrolment as an advocate","identifier":"K/001823/2026","recognizedBy":{"@type":"Organization","name":"Bar Council of Kerala"},"description":"Enrolled as an advocate with the Bar Council of Kerala (K/001823/2026), 2026"},{"@type":"EducationalOccupationalCredential","credentialCategory":"degree","educationalLevel":"Bachelor","recognizedBy":{"@type":"CollegeOrUniversity","name":"Bharata Mata School of Legal Studies"},"description":"BBA LLB (Hons.), Bharata Mata School of Legal Studies (2025)"},{"@type":"EducationalOccupationalCredential","credentialCategory":"Remote Pilot Certificate","recognizedBy":{"@type":"Organization","name":"Directorate General of Civil Aviation, India"},"description":"DGCA Remote Pilot Certificate, issued 2022"}],"subjectOf":[{"@type":"CreativeWork","name":"Govind Babu v. State of Kerala (Crl.M.C. No. 5640 of 2026, 2026:KER:69496)","url":"https://indiankanoon.org/doc/151180872/","datePublished":"2026-09-10","publisher":{"@type":"Organization","name":"High Court of Kerala"}},{"@type":"CreativeWork","name":"Viji Sagar v. State of Kerala (Crl.M.C. No. 1603 of 2026, 2026:KER:20803)","url":"https://indiankanoon.org/doc/193042273/","datePublished":"2026-03-09","publisher":{"@type":"Organization","name":"High Court of Kerala"}},{"@type":"CreativeWork","name":"Anjana v. Manoharan A.P. (C.R.P. No. 442 of 2025, 2026:KER:10054)","url":"https://indiankanoon.org/doc/68585852/","datePublished":"2026-02-05","publisher":{"@type":"Organization","name":"High Court of Kerala"}}],"sameAs":["https://www.linkedin.com/in/azlubro","https://portal.khcaa.com/advocate?id=10480","https://lexosys.com"]},{"@type":"LegalService","@id":"https://advaslam.com/#practice","name":"Adv. K J Muhammed Aslam — Advocate, Ernakulam","url":"https://advaslam.com","image":"https://advaslam.com/og.png","telephone":"+919497240215","email":"contact@advaslam.com","address":{"@type":"PostalAddress","streetAddress":"3rd Floor, Lalan Towers (KGL Builders), Vanchi Square, High Court Junction","addressLocality":"Ernakulam","addressRegion":"Kerala","postalCode":"682031","addressCountry":"IN"},"geo":{"@type":"GeoCoordinates","latitude":9.9889,"longitude":76.2748},"hasMap":"https://www.google.com/maps/search/?api=1&query=Lalan+Towers+High+Court+Junction+Ernakulam","areaServed":[{"@type":"City","name":"Ernakulam"},{"@type":"City","name":"Kochi"},{"@type":"State","name":"Kerala"},{"@type":"Country","name":"India"}],"openingHoursSpecification":{"@type":"OpeningHoursSpecification","dayOfWeek":["Monday","Tuesday","Wednesday","Thursday","Friday","Saturday"],"opens":"10:00","closes":"18:30"},"founder":{"@id":"https://advaslam.com/#person"},"knowsAbout":["Cyber crime and IT Act matters","Data protection and DPDP Act compliance","Business, banking, intellectual property and tax","Legal drafting","Criminal law: bail, quash and appeals","Writ petitions before the High Court of Kerala","Civil, property and consumer matters","Family and succession matters","Service and labour matters"]},{"@type":"BlogPosting","@id":"https://advaslam.com/writing/cert-in-6-hour-vs-dpdp-72-hour-breach-reporting/#article","isPartOf":{"@id":"https://advaslam.com/#website"},"headline":"CERT-In 6-Hour vs DPDP 72-Hour Breach Reporting: Which Clock Applies to Your Business?","description":"India has two breach clocks that both apply: CERT-In's 6 hours and DPDP Rule 7's 72 hours. Who reports to whom, when each starts, and one playbook for both.","url":"https://advaslam.com/writing/cert-in-6-hour-vs-dpdp-72-hour-breach-reporting/","mainEntityOfPage":"https://advaslam.com/writing/cert-in-6-hour-vs-dpdp-72-hour-breach-reporting/","datePublished":"2026-09-01T00:00:00.000Z","dateModified":"2026-09-01T00:00:00.000Z","keywords":"CERT-In 6 hour reporting, DPDP 72 hour breach notification, CERT-In vs DPDP breach reporting, CERT-In Directions 2022 reporting, DPDP Rule 7 breach intimation, India data breach reporting timeline","inLanguage":"en-IN","author":{"@id":"https://advaslam.com/#person"},"publisher":{"@id":"https://advaslam.com/#person"},"image":"https://advaslam.com/og/writing/cert-in-6-hour-vs-dpdp-72-hour-breach-reporting.png","about":{"@type":"Service","@id":"https://advaslam.com/practice/data-protection/#service","name":"Data protection & DPDP compliance","url":"https://advaslam.com/practice/data-protection/","provider":{"@id":"https://advaslam.com/#practice"}}},{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://advaslam.com/"},{"@type":"ListItem","position":2,"name":"Articles","item":"https://advaslam.com/writing/"},{"@type":"ListItem","position":3,"name":"CERT-In 6-Hour vs DPDP 72-Hour Breach Reporting: Which Clock Applies to Your Business?","item":"https://advaslam.com/writing/cert-in-6-hour-vs-dpdp-72-hour-breach-reporting/"}]},{"@type":"FAQPage","mainEntity":[{"@type":"Question","name":"Do I need to report a data breach under both CERT-In Directions and the DPDP Act?","acceptedAnswer":{"@type":"Answer","text":"Yes, where both apply. CERT-In Directions dated 28 April 2022 require reporting of specified cyber incidents — including data breaches and data leaks — to CERT-In within six hours of noticing them. DPDP Rule 7 requires notification of every personal data breach to the Data Protection Board without delay, with a detailed report within 72 hours, and notification to each affected Data Principal without delay. The two duties run in parallel to different authorities on different clocks, and compliance with one does not excuse the other."}},{"@type":"Question","name":"When does the CERT-In 6-hour clock start?","acceptedAnswer":{"@type":"Answer","text":"Within six hours of noticing the incident or being brought to notice of it. The FAQs issued in May 2022 (Q30) clarify that you report to the extent information is available within six hours and supplement later within reasonable time. The clock is not from the breach occurrence, which may have been earlier, but from awareness. On one interpretive view, based on FAQ Q22 read with Section 81 of the IT Act, a statutory reporting duty overrides conflicting contractual confidentiality clauses — but that override is an interpretation, not express Directions text, and Q30 itself supports only extent-available reporting with later supplementation."}},{"@type":"Question","name":"When does the DPDP 72-hour clock start?","acceptedAnswer":{"@type":"Answer","text":"From when the Data Fiduciary becomes aware of the personal data breach. Rule 7 requires intimation to each affected Data Principal without delay in clear, plain language, an initial intimation to the Data Protection Board without delay describing the nature, extent, timing and likely impact, and a detailed report to the Board within 72 hours of becoming aware, extendable only if the Board allows a written request showing good cause."}},{"@type":"Question","name":"What is the penalty for failing to report a breach under the DPDP Act?","acceptedAnswer":{"@type":"Answer","text":"Failure to notify the Board or affected Data Principals of a personal data breach under Section 8(6) of the DPDP Act carries a penalty of up to two hundred crore rupees, imposed by the Data Protection Board after inquiry and hearing under Section 33, weighing factors under Section 33(2) including gravity, duration, data type, repetition, gains and mitigation. Non-compliance with CERT-In Directions can attract punishment under Section 70B(7) of the IT Act — imprisonment up to one year, fine up to one crore rupees (raised from one lakh by the Jan Vishwas (Amendment of Provisions) Act, 2023, w.e.f. 30 November 2023), or both."}},{"@type":"Question","name":"Does every small breach need to be reported under the DPDP Act?","acceptedAnswer":{"@type":"Answer","text":"Yes. Unlike the GDPR, which has a risk-to-rights threshold for notification to the authority, DPDP Rule 7 has no materiality filter in its text — every personal data breach as defined in Section 2(u), which includes unauthorised processing and accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access that compromises the confidentiality, integrity or availability of personal data, triggers the notification duties. There is no exception for small or low-risk breaches in the notified text."}}]}]}
```
