Skip to content
🚨 DPDP Rules 2025: Compliance Deadline 36 weeks awayRead handbook →

Four Breach Clocks Start Before the DPDP Act's Does — And Only One of Them Wants to Hear About Personal Data

India's DPDP Act breach notification duty starts 13 May 2027. Sector regulators already run 2- and 6-hour clocks. The reports don't match.

D
DPDPBot Research Team
🕐 11 min read

#Four Breach Clocks Start Before the DPDP Act's Does — And Only One of Them Wants to Hear About Personal Data

The Central Electricity Authority's new cyber security regulations, notified in August, put a six-hour incident-reporting duty on Indian power utilities with effect from 1 April 2027. The DPDP Act breach notification duty under Rule 7 of the Digital Personal Data Protection Rules, 2025 switches on six weeks later, on 13 May 2027.

That ordering is not a curiosity. It is the clearest illustration yet of something Indian compliance teams have been slow to price in: by the time the Data Protection Board of India is legally entitled to hear about a personal data breach, most regulated Indian entities will already be operating under two, three or four faster reporting clocks — run by different regulators, triggered by different events, and demanding a report that is not the same document.

#The stack, as it actually stands today

Here is every incident-reporting obligation a large Indian regulated entity may already be subject to, with what is verified about each:

Instrument What triggers it Clock Reported to In force
CERT-In Directions, 28 April 2022 Any listed cyber security incident 6 hours CERT-In Yes, since 2022
SEBI CSCRF Cyber incident at a SEBI-regulated entity 6 hours (email), 24 hours (portal) SEBI, CERT-In; brokers and DPs also tell exchanges/depositories Yes, phased from 2025
TRAI direction, 27 February 2026 Suspected spam / unsolicited commercial communication signal 2 hours Other access providers, via the DLT platform Yes, from 29 March 2026
RBI Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026 Cyber incident at a regulated entity 6 hours RBI's DAKSH portal Yes, immediately on 31 July 2026
CEA (Cyber Security in Power Sector) Regulations, 2026 Cyber incident / cyber sabotage of critical systems 6 hours / 24 hours CSIRT-Power and CERT-In From 1 April 2027
DPDP Rules, 2025, Rule 7 Personal data breach "Without delay", then 72 hours for the detailed report Data Protection Board and affected Data Principals From 13 May 2027

Four of those six are running now. The DPDP one — the only one that exists to protect the individual whose data was exposed — is last in the queue.

#What the DPDP Act breach notification rule actually requires

Rule 7 is genuinely two obligations wearing one number, and the widely-repeated shorthand "India has a 72-hour breach rule" gets it wrong in both directions.

To affected Data Principals, on becoming aware of the breach, the data fiduciary must give notice without delay — not within 72 hours. The rule requires a description of the breach including its nature, extent and timing; the likely consequences for that individual; the mitigation measures implemented and being implemented; the safety steps the individual should take; and contact details for queries. There is no threshold. There is no risk-of-harm carve-out of the kind GDPR Article 34 provides. Every affected person hears about it.

To the Board, the fiduciary must also report without delay — a first-stage description of the breach, its extent, timing, location and likely impact. The 72 hours attaches only to the second-stage detailed report: the facts and circumstances that caused the breach, mitigation measures taken or proposed, findings on who was responsible, steps to prevent recurrence, and a summary of the intimations already sent to Data Principals. That window can be extended, but only on a written request the Board agrees to.

So Rule 7's real clock is "without delay," twice over, with a 72-hour deadline for the forensic write-up. Under the Schedule to the Act, failing to notify carries a penalty of up to ₹200 crore. Failure to take reasonable security safeguards in the first place is the ₹250 crore item — the two are separate, and a single incident can attract both.

#Why the six-hour clocks make the 72-hour one harder, not easier

The instinctive reaction is that this is fine: if you already report to CERT-In in six hours, you will comfortably make a 72-hour DPDP deadline. That reasoning fails on three counts.

The trigger is different. CERT-In, RBI and CEA clocks start on a cyber incident. Rule 7 starts on a personal data breach — defined in Section 2(u) of the Act as any unauthorised processing, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data that compromises its confidentiality, integrity or availability. Those sets overlap heavily but neither contains the other. A ransomware event that encrypts a database without exfiltration is a cyber incident and, because it compromises availability of personal data, very likely a Rule 7 breach too. An employee emailing a customer spreadsheet to the wrong recipient is a Rule 7 breach and, for most sector regimes, not a reportable cyber incident at all. Teams that build one detection pipeline against the cyber-incident definition will systematically miss the second category.

The recipient is different, and so is the document. DAKSH wants supervisory information about a regulated entity's technology estate. CSIRT-Power wants operational-technology threat intelligence. CERT-In wants indicators of compromise. The Board wants to know whose personal data was affected, what it means for them, and what you told them. A six-hour DAKSH filing is not a draft of a Rule 7 report; drafting one does not advance the other.

The hardest obligation has no clock at all. Notifying every affected Data Principal individually, with tailored consequences and recommended actions, is far more operationally demanding than filing a regulator report — and it is the one governed by "without delay" rather than a fixed number of hours. An organisation that cannot enumerate which individuals sit behind an affected system within days does not have a 72-hour problem. It has a data-mapping problem that no amount of incident-response tooling fixes after the fact.

None of the sector instruments cross-reference Rule 7, and Rule 7 does not cross-reference them. There is no single-window filing, no deemed-compliance provision, and no mechanism by which reporting to CERT-In or DAKSH discharges anything owed to the Board. As one comparative reading of the framework puts it plainly, DPDP penalties sit in addition to sector penalties, not instead of them.

#The new instruments are the ones to read

Two 2026 instruments deserve attention because they are recent, in force or imminent, and materially widen the population of entities carrying a six-hour clock.

The RBI Directions, 31 July 2026. The Reserve Bank issued a set of entity-class-specific Directions under a single title — Cybersecurity, Technology: Risk, Resilience and Assurance Framework — covering commercial banks, small finance banks, payments banks, urban co-operative banks, NBFCs and credit information companies. The NBFC instrument, the Reserve Bank of India (Non-Banking Financial Companies — Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026, requires that an NBFC "shall report cyber incidents on DAKSH platform... within six hours of detection," and came into effect immediately on issue. It repeals the earlier IT Framework and IT Governance instructions applicable to NBFCs via circular DoS.CO.PPG.66/11.01.005/2026-27 of the same date. Obligations are tiered by Scale Based Regulation layer, so a Base Layer NBFC below ₹500 crore carries a lighter chapter than Middle Layer and above — but the reporting clock is not the part that scales down.

The CEA Regulations, August 2026. Notified under Section 177 read with Section 73(c) of the Electricity Act, 2003 with MeitY's concurrence, the Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026 come into force on 1 April 2027. They bind transmission utilities, distribution licensees, load dispatch centres, power exchanges and OTC platforms, and reach generating companies, captive plants and energy storage systems at 50 MW and above. All cyber security incidents go to CSIRT-Power and CERT-In within six hours; incidents classified as cyber sabotage of critical systems within 24. The regulations also require logical or physical segregation of OT from IT and the internet, procurement of hardware and software from trusted sources with a bill of materials, and annual audits.

That last regime is the one that produces the ordering in this article's opening. A discom's cyber clock starts 1 April 2027. Its DPDP clock — for the same incident, if consumer data is touched — starts 13 May 2027. For six weeks, Indian power utilities will be legally obliged to tell CSIRT-Power within six hours and legally unable to owe the Data Protection Board anything at all.

#The regulator at the end of the queue is also the one that doesn't exist yet

There is a further complication that no amount of process design solves. The Data Protection Board of India was legally established on 13 November 2025. As of today it has no Chairperson and no Members. MeitY invited applications for one Chairperson and four Members in May 2026, followed up in June, and no shortlist or appointment order has been published. There is no notified list of Significant Data Fiduciaries under Section 10(1), no restricted-country list under Section 16, and no consent manager registration portal — the registration route under Rule 4 opens on 13 November 2026, now roughly ten weeks away, with no registrar in place.

A note of caution for anyone researching this: unsourced claims that the Board's Chairperson and Members were appointed in June 2026, and that a grievance portal is live, are circulating through AI-summarised search results and at least one wiki infobox. They are not supported by any gazette notification or MeitY appointment order. Treat a Board appointment as real only against a primary document.

Meanwhile the timeline itself may move. MeitY floated a proposal at a January 2026 stakeholder consultation to compress the general compliance runway from 18 months to 12 and to bring Section 16 cross-border restrictions into immediate effect, which would pull Significant Data Fiduciary obligations back to 13 November 2026 from 13 May 2027. That proposal remains ungazetted. Until it is notified, 13 May 2027 is the operative date, and any vendor telling you the SDF deadline has already moved is ahead of the Gazette.

#What to actually do in the next eight months

The gap between now and 13 May 2027 is not spare time. It is the only window in which the following can be built calmly rather than during an incident.

  1. Run one detection funnel, two classification tests. Every incident should be assessed twice: is this a reportable cyber incident under our sector regime, and separately, is this a personal data breach under Section 2(u)? Record both answers and the reasoning. The second test is the one organisations do not currently have.

  2. Pre-build the Data Principal notice. Rule 7 specifies its contents. Draft the template now, in the languages you serve, with placeholders for nature, extent, timing, consequences and recommended actions. "Without delay" is not a deadline you negotiate at 2 a.m.

  3. Solve enumeration before you solve notification. Can you produce, from a given system or table, the list of individuals whose data it holds and a working contact channel for each? If not, that is the project — everything downstream of it depends on it.

  4. Map the clocks you are actually on. A single group can sit under CERT-In, RBI, SEBI, TRAI and CEA obligations across different subsidiaries. Write down, per entity, which clocks run, what triggers them, and who signs the filing.

  5. Keep the reports separate. Resist the tempting single-template approach. A DAKSH filing and a Rule 7 report to the Board answer different questions for different regulators, and a document that tries to do both will do neither well.

  6. Do not wait for enforcement to define the standard. With no Board precedent and no decided cases, the reference points available are the text of Rule 7, the Schedule's penalty tiers, and the sector regimes already in force. That is enough to build against.

#The pattern worth naming

India's data protection statute is arriving last into a space its sector regulators have already occupied. RBI moved in July. CEA moved in August. TRAI moved in February. NPCI's UPI number-masking mandate took effect yesterday, 4 September, on privacy grounds, under no data protection statute at all. Each of these is narrower than the DPDP Act, faster to take effect, and enforced by a regulator that is fully constituted and has been issuing penalties for years.

The practical consequence for Indian businesses is that "we will get ready for DPDP in 2027" describes a compliance posture that is already two clocks behind. The obligations that will govern your next incident are, for most regulated entities, live today — and the one that will govern how you treat the people whose data was exposed is the one nobody has built for.

For a consolidated view of the instruments referenced here and their current status, see our resources library. If you are working through what the November 2026 consent manager registration route means for your consent architecture, start with our consent manager guidance — it is the next DPDP milestone with a hard date, and unlike the breach rules, it arrives before the Act's substantive provisions rather than after them.


Sources: DPDP Rules, 2025, Rule 7; RBI NBFC Cybersecurity Directions, 2026; CEA (Cyber Security in Power Sector) Regulations, 2026 and implementation guidance; TRAI's February 2026 UCC direction; SEBI CSCRF reporting requirements; CERT-In six-hour reporting direction; MeitY's proposed timeline compression.

Automate your DPDP compliance

Capture consent, honour data principal rights, and stay audit-ready — all in one platform.

Start free trial