Skip to content
🚨 DPDP Rules 2025: Compliance Deadline 36 weeks awayRead handbook →

₹25.5 Crore and 236 Days: India's Record Breach Costs Meet the DPDP Act's 72-Hour Clock

India's breach cost hit a record ₹25.5 crore while detection takes 236 days. DPDP Act breach notification allows 72 hours. The compliance math is brutal.

D
DPDPBot Research Team
🕐 11 min read

#₹25.5 Crore and 236 Days: India's Record Breach Costs Meet the DPDP Act's 72-Hour Clock

IBM released the India cut of its Cost of a Data Breach Report on 3 August 2026, and one pair of numbers should reorganise every Indian CISO's quarter: the average breach now costs ₹25.5 crore, and companies without security automation take 236 days to even notice they have been breached. DPDP Act breach notification rules give those same companies 72 hours to file a detailed report with the Data Protection Board — and the clock does not start until you know, which means slow detection buys you nothing except 236 days of unmitigated harm the Board gets to weigh when it sets your penalty.

That is the story. Not the headline cost figure, which is bad but survivable. The story is that India's detection capability and India's new statutory reporting duty are calibrated to completely different timescales, and the gap between them is where ₹250 crore penalties will be decided from May 2027 onward.

#What the IBM report actually found in India

The study, conducted by Ponemon Institute for IBM across 600-plus breached organisations globally between March 2025 and February 2026, puts India's average breach cost at ₹25.5 crore — a 15.9% jump from ₹22 crore last year, and the highest figure recorded for India in the report's history. The average Indian breach exposed 39,500 records, up from 38,200.

The detail matters more than the headline:

  • Financial services took the worst hit at ₹40.9 crore per breach, followed by technology (₹35.7 crore) and communications (₹34.5 crore). All three sectors sit squarely in the pool likely to be designated Significant Data Fiduciaries.
  • Phishing, including voice and SMS variants, was the top initial vector at 19%, ahead of drive-by compromise (16%) and supply chain compromise (15%).
  • 26% of malicious breaches in India involved AI-generated attacks. Attackers have industrialised; defenders largely have not.
  • Only 32% of Indian organisations use AI and automation extensively in security. Another 32% use none at all — and that last group paid ₹31.6 crore per breach against ₹21.3 crore for the extensive-use group. A ₹10.3 crore delta, on the same incident type.

Globally, the average breach reached $4.99 million, up 12% and the highest across 21 editions of the report. India's rise outpaced it.

#The 236-day problem versus DPDP Act breach notification

Here is where the report stops being a cybersecurity story and becomes a compliance story.

Rule 7 of the DPDP Rules 2025 sets up a two-stage obligation. On becoming aware of any personal data breach, a Data Fiduciary must intimate the Data Protection Board without delay, describing the nature, extent, timing and location of the breach and its likely impact. Then, within 72 hours — or a longer window only if the Board grants one on a written, justified request — it must file a detailed report covering the broad facts, the causes, the mitigation measures taken or proposed, and findings on who was responsible. Affected Data Principals must be told as soon as practicable after the Board is notified.

Two features of that rule are routinely misread.

First, there is no severity threshold. Unlike the GDPR, which lets a controller skip notifying the supervisory authority where a breach is unlikely to result in risk to rights and freedoms, Rule 7 applies to every personal data breach. One record or nine crore records, the duty is identical. There is no internal "we assessed it as low risk" off-ramp.

Second, the trigger is awareness, not occurrence. This is where the 236-day figure becomes dangerous. A company that cannot detect intrusions is not sheltered by its own blindness — the 72-hour clock simply starts eight months late, by which point the exfiltrated data has been sold, the affected individuals have suffered downstream fraud, and the fiduciary has to explain to a quasi-judicial body why nobody noticed.

Section 33(2) of the DPDP Act tells the Board what to weigh when deciding penalty quantum, and the list includes the gravity and duration of the breach, the type of personal data affected, and whether the person took action to mitigate — and the timeliness and effectiveness of that action. Read that against 236 days. A detection lag of that length is not a neutral technical fact at the adjudication stage. It is an aggravating one, evidence going directly to two of the statutory factors.

The organisations with extensive automation cut identification to 175 days. Better, and still nowhere near a timeframe that makes a 72-hour reporting rule feel comfortable.

#₹25.5 crore is the floor, not the ceiling

Every board presentation that cites the IBM number as "our exposure" is understating it, badly. The ₹25.5 crore is the operational cost of a breach — detection, response, notification, business disruption, lost customers. It is measured mostly in a pre-enforcement India, from a study window that closed in February 2026, before the Act's substantive obligations bite.

Layer the statutory penalties on top:

Failure Maximum penalty
Failure to take reasonable security safeguards (Section 8(5)) ₹250 crore
Failure to notify the Board or affected Data Principals of a breach ₹200 crore
Breach of obligations relating to children's data ₹200 crore
Residual breach of the Act or Rules ₹50 crore

A single incident can implicate more than one line of that table. The same ransomware event that proves your safeguards were unreasonable can also produce a late notification and, if minors' data was in the affected set, a children's-data failure. Ten times the IBM figure is a more honest planning number for a serious breach at a large fiduciary.

And unlike the GDPR's tiered structure — €20 million or 4% of global turnover, whichever is higher — DPDP penalties are fixed rupee ceilings, not turnover-linked. That cuts in an unexpected direction. For a global platform, ₹250 crore is roughly $30 million and comfortably survivable. For a Series B Indian fintech with the same security failure and the same class of data, the same ceiling is existential. India's structure is regressive by design: the smaller you are, the more the maximum hurts.

For a walkthrough of how those penalty heads map to specific operational controls, see our resources library.

#Shadow AI has become a data protection problem

The most consequential new finding is about AI usage that never went through governance. IBM found that shadow AI was a top-three cost amplifier in India, adding ₹1.79 crore to the average breach where it was present. Globally, security incidents involving shadow AI climbed to 43% from 20% a year earlier, averaging $5.39 million.

The governance picture behind that is grim: 68% of breached organisations had no AI governance policy at all, and only 19% reported their governance and security teams actually working together.

Under the DPDP Act, unsanctioned AI use is not merely an IT hygiene issue. It is a set of live statutory exposures:

  • Purpose limitation. Consent under Section 6 is tied to the specified purpose for which data was collected. An employee pasting a customer support transcript into an unapproved third-party model is processing personal data for a purpose no Data Principal ever agreed to.
  • Cross-border transfer. Most consumer AI tools process data outside India. Rule 15 lets the Central Government impose conditions or restrictions on transfers to specified states and entities. Shadow AI makes it impossible to even map where your data went — which means you cannot demonstrate compliance, and demonstrability is the whole game with a regulator.
  • Reasonable security safeguards. Section 8(5) requires safeguards regardless of whether a breach occurs. A fiduciary that cannot enumerate which AI tools touch personal data cannot credibly claim its safeguards are reasonable.
  • Processor contracts. Section 8(2) requires processing through a Data Processor to rest on a valid contract. An employee's personal ChatGPT or Gemini account is not a contracted processor. There is no agreement, no flow-down of obligations, no audit right.

An AI acceptable-use policy has quietly become a DPDP compliance artefact. Most Indian organisations do not have one.

#The regulator that still isn't there

There is a strange asymmetry running through all of this. The obligations are hardening. The enforcer is not yet in the room.

The Data Protection Board of India was formally notified on 13 November 2025. As of August 2026 — nine months on — it has no appointed Chairperson and no appointed Members. MeitY invited applications for those posts by notification dated 6 May 2026, and a Search-cum-Selection Committee chaired by the Cabinet Secretary, with the Secretaries of Legal Affairs and MeitY plus two domain experts, is to make the picks.

This produces a genuinely odd situation: Rule 7 tells you to intimate a body that currently has no adjudicating members to receive the intimation. In practice that means today's breach reporting is a paper exercise. It also means the backlog of unadjudicated conduct is accumulating, and the Board's first cohort of cases will be drawn from breaches that happened during the interregnum.

Compounding the uncertainty, MeitY floated a proposal in January 2026 to compress the compliance runway for Significant Data Fiduciaries from 18 months to 12, with feedback sought by 4 February 2026. If adopted, obligations including DPO appointment and Data Protection Impact Assessments move from May 2027 to November 2026 — three months from now. No final decision has been published. Planning to May 2027 while a November 2026 acceleration sits unresolved on a ministry's desk is a risk that belongs on an audit committee agenda, not a compliance team's backlog.

#Two clocks, not one

One more operational trap the IBM data exposes. The DPDP 72-hour duty does not replace CERT-In's six-hour incident reporting requirement under the 2022 Directions issued pursuant to the IT Act 2000. It stacks on it.

Most real breaches are simultaneously a cyber incident and a personal data breach. So a single ransomware event triggers: CERT-In notification within six hours of detection, preliminary DPBI intimation without delay, a detailed DPBI report within 72 hours, and individual notifications to every affected Data Principal. Regulated sectors add more — RBI, SEBI and IRDAI each impose their own incident timelines on their licensees.

Four clocks, three regulators, one incident, and — per IBM — a security function that on average needed 236 days to find the incident in the first place. The mismatch is not subtle.

#What to do before the enforcement window opens

The IBM data points at the interventions that actually change outcomes, and they line up neatly with DPDP obligations:

  1. Buy detection time, not just prevention. The ₹10.3 crore cost gap between extensive-automation and no-automation organisations is the single largest lever in the report. Reducing mean time to detect is simultaneously a cost control and a Section 33(2) mitigation argument.
  2. Inventory and sanction AI tools now. Publish an AI acceptable-use policy, name approved tools, block the rest at the network layer, and add AI processing to your record of processing activities. The ₹1.79 crore shadow-AI premium is avoidable.
  3. Pre-build the Rule 7 notification pack. Draft the preliminary intimation and the 72-hour detailed report as templates today, with named owners across legal, security, engineering and communications. Nobody drafts a competent regulatory filing under 72-hour pressure for the first time.
  4. Run the four-clock tabletop. Rehearse a scenario that trips CERT-In, DPDP and your sectoral regulator at once, and time it. Most teams discover their internal escalation alone eats the six-hour CERT-In window.
  5. Fix consent plumbing before the November 2026 Consent Manager milestone. Rule 4 obligations for Consent Managers arrive on 13 November 2026, and consent records are the first thing an adjudicating officer asks to see. Our consent manager breakdown covers what the registration and interoperability requirements actually demand.

#The bottom line

IBM's report is usually read as a cybersecurity benchmark. In post-Rules India it is something else: an admission, in numbers, that the median Indian organisation is not capable of meeting a duty that becomes fully enforceable on 13 May 2027 — or possibly on 13 November 2026, if MeitY's compression proposal lands.

₹25.5 crore is what a breach costs today, in a country whose data protection regulator has not yet been staffed. Once the Data Protection Board is constituted and Section 33 penalties start being imposed, that figure becomes a rounding error against a ₹250 crore ceiling. The 236 days is the variable to attack, because it is the only one that improves both numbers at once.

Working out where your organisation stands against Rule 7, Section 8(5) and the November 2026 Consent Manager deadline? Start with our DPDP compliance resources — including breach response templates and readiness checklists built against the notified Rules, not the draft.

#Sources

Automate your DPDP compliance

Capture consent, honour data principal rights, and stay audit-ready — all in one platform.

Start free trial