Data privacy (DPDP Act, 2023) · Template

Data breach report to the Data Protection Board of India

Section 8(6) of the DPDP Act requires intimation to the Board and to affected data principals in the event of a personal data breach. The report you file is also the first evidence of how the organisation responded — which is why it should be factual, complete, and written while the timeline is still recoverable.

Generate this document See all 21 templates

When you need this

  • On becoming aware of any personal data breach, including one caused by a vendor
  • Where the incident is unauthorised access, disclosure, alteration or loss of personal data
  • When a processor notifies you under their DPA — your duty runs from the breach, not their email
  • Alongside notification to affected data principals, which is a separate limb of the same duty
  • Even where remediation is complete, since the duty is not discharged by having fixed it

What this document must contain

  • A factual incident description and timeline — What happened, when it began, when it was detected, and how. The gap between occurrence and detection is a fact the report should state rather than obscure.
  • The categories of personal data affected — Specific categories and, where possible, volume and number of data principals. An estimate stated as an estimate is better than silence.
  • Cause and the point of failure — Say what actually failed. A report that avoids the cause is not credible and does not help.
  • Remediation already taken — Containment, revocation, patching, notification. Chronological, with dates.
  • Measures to prevent recurrence — What is changing structurally, not merely that the incident was closed.
  • Notification to data principals — The duty extends to affected individuals. State what was sent, to whom, when and how.
  • A named contact — A person the Board can reach, with authority to answer.

The law that governs it

  • DPDP Act, 2023 — s. 8(6) — In the event of a personal data breach, the data fiduciary must give intimation to the Board and to each affected data principal, in the form and manner prescribed. Both limbs apply.
  • DPDP Act, 2023 — s. 8(4) and (5) — The fiduciary must implement appropriate technical and organisational measures and reasonable security safeguards, and engage processors only under a valid contract. A breach report is read against those duties.
  • DPDP Act, 2023 — the Schedule — Failure to take reasonable security safeguards, and failure to give the required breach intimation, are separately addressed in the Schedule of penalties.

Common mistakes

  • Waiting for full root-cause certainty before intimating, when the duty is triggered by the breach
  • Reporting to the Board but not notifying affected data principals, which leaves half the duty undischarged
  • Describing the incident in language that minimises it, which is transparent to any reader and damaging
  • Treating a vendor-caused breach as the vendor's report to make
  • No preserved timeline, so the sequence cannot be reconstructed later

Frequently asked questions

When must a data breach be reported in India?

Section 8(6) of the DPDP Act, 2023 requires the data fiduciary to give intimation to the Board and to each affected data principal in the event of a personal data breach, in the form and manner prescribed. Because the prescribed form and timing sit in the rules made under the Act, confirm the current requirement — the safe operating assumption is that it is short.

Do I have to tell affected customers as well as the Board?

Yes. Section 8(6) has two limbs: intimation to the Board, and intimation to each affected data principal. Reporting to the regulator alone does not discharge the duty.

What if the breach happened at my vendor?

The obligation sits with the data fiduciary. A processor's breach is still your breach to report, which is why a DPA should require the vendor to notify you within a window short enough to leave you able to comply.

Should I report if there was no apparent harm?

The duty in s. 8(6) is expressed by reference to a personal data breach rather than to demonstrated harm. Assessing an incident as harmless and staying silent is a judgement the Board may later review — and the failure to intimate is separately addressed in the Schedule.

Related documents