Skip to content
🚨 DPDP Rules 2025: Compliance Deadline 36 weeks awayRead handbook →

SafePal Waited Three Months to Disclose. India's DPDP Breach Notification Rules Give You Hours

SafePal disclosed a 39,798-customer breach on 16 August, months after the first report. Here is what DPDP breach notification would have demanded.

D
DPDPBot Research Team
🕐 12 min read

#SafePal Waited Three Months to Disclose. India's DPDP Breach Notification Rules Give You Hours

Crypto wallet maker SafePal told 39,798 customers on 16 August 2026 that their names, email addresses, phone numbers, shipping addresses and purchase histories had been exposed by an authorisation flaw in an order-tracking plug-in. The company received its first report of the problem in early May — and its customers were already posting about phishing attacks aimed at them in the first week of July. Under India's DPDP breach notification regime, that gap between "we knew" and "we told you" is not a public relations judgment call. It is a priced offence, and the price is up to ₹200 crore.

SafePal is not an Indian company and, as far as published reporting goes, has released no country-wise breakdown of who was affected. That does not put the incident outside India's reach — and the sequence of decisions it made is a near-perfect worked example of what the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 are designed to make illegal for anyone selling to Indians.

#What SafePal actually disclosed

The technical fault was mundane. An authorisation flaw in the plug-in SafePal used to let customers track their hardware wallet orders allowed one customer to pull up another customer's order record. Anyone who placed an order between 2 March 2025 and 11 April 2026 was in scope. The Block and CoinDesk both put the affected count at 39,798.

Seed phrases, private keys, wallet passwords, bank details, card numbers and government IDs were not in the exposed set, and SafePal said it has no evidence that funds were taken directly. That distinction matters technically and is worth stating plainly. It matters far less legally than the company's framing suggests, because what did leak is a delivery-verified list of people who own a hardware wallet, complete with the home address the device shipped to and the phone number attached to the order.

That is not a low-grade marketing list. It is a targeting file. SafePal's own remediation confirms it: the company says it has identified and taken down more than 30 fraudulent websites and phishing links tied to the incident, and it advised anyone who handed over a seed phrase to a phishing email, call or letter to treat their wallet as compromised and move their assets. The exposed data did not steal anything. It told criminals precisely whom to call.

SafePal did several things right once it moved. It emailed every affected customer individually from a named security address, published an incident report, hired an independent third-party firm to audit the fix, stood up a lookup tool so customers could check their own exposure, and cut personal data retention to 90 days. Under Indian law, almost none of that would rescue the timeline.

#The three months are the story

Reconstruct the clock from the company's own account. Early May 2026: SafePal receives the first report tied to the breach and treats it as an isolated case. 3–4 July: customers begin posting publicly on Reddit and Trustpilot about phishing attempts referencing their orders. July: SafePal begins a full review of its order-processing pipeline and confirms the root cause. 16 August: disclosure.

Awareness is the trigger that matters. Rule 7 of the DPDP Rules, 2025 starts running when a data fiduciary becomes aware of a personal data breach — not when it finishes its investigation, not when it has a clean root-cause narrative, and not when the legal review clears the incident report. A report arriving in early May is awareness of something. Customers being phished with order-specific detail in early July is awareness of everything.

Rule 7 imposes two obligations in parallel, and Indian data fiduciaries routinely underestimate the first one.

To every affected individual, without delay. The fiduciary must give each affected data principal a concise, plain-language description of the breach: its nature, extent, timing and location; the likely consequences for that person; the mitigation the fiduciary has implemented; the safety measures the individual can take; and contact details for someone who can answer questions. There is no severity threshold and no materiality filter. If personal data was breached, everyone whose data it was gets told.

To the Data Protection Board, without delay and then in detail. An initial intimation goes to the Board immediately, covering nature, extent, timing, location and likely impact. A fuller report follows within 72 hours — or a longer period the Board specifically permits on a written, justified request — setting out the broad facts and causes, the mitigation taken or proposed, findings on who or what was responsible, the steps taken to prevent recurrence, and a summary of the intimations sent to affected individuals.

The Schedule to the Act prices the two failure modes separately. Failing to take reasonable security safeguards to prevent a breach draws up to ₹250 crore. Failing to notify the Board or affected data principals draws up to ₹200 crore. An authorisation flaw that lets one customer read another's record, left live across a 13-month ordering window, is squarely a safeguards question. A three-month delay between first signal and disclosure is squarely a notification question. In India, those are two penalties, not one.

#Timing: this is not yet enforceable, and that is the point

Be precise about where India actually is. The DPDP Act and the DPDP Rules were notified on 13 November 2025 with a phased commencement. The administrative provisions and the Board's own constitution took effect immediately. Rule 4, governing consent manager registration, takes effect on 13 November 2026. Rule 7 and the rest of the substantive obligations — notice, consent, security safeguards, data principal rights, breach intimation, penalties — commence on 13 May 2027.

So an identically-behaving Indian company today would face no DPDP penalty for the same three-month silence. That is exactly why the incident is worth studying now rather than in May 2027, when the learning happens under an open penalty schedule.

The regulator gap compounds it. The Data Protection Board of India was legally established on 13 November 2025. MeitY solicited nominations for its Chairperson and four Members on 6 May 2026 and issued a further process notification on 6 June 2026, with a search-cum-selection committee chaired by the Cabinet Secretary. As LiveLaw reported on 1 August 2026, no Chairperson and no Members had been appointed nine months after the Rules were notified. There is currently no one at the address to which a Rule 7 intimation would be sent. Companies building breach playbooks in 2026 are building them against a counterparty that does not yet exist — which is precisely why the playbook has to be built on internal clocks and evidence, not on regulator prompting.

#CERT-In's six-hour clock is already running

The comforting reading — "nothing bites until May 2027" — is wrong for this incident type, and dangerously wrong for anyone in the virtual assets business.

CERT-In's 2022 directions under Section 70B of the IT Act have been in force for years and are entirely independent of the DPDP timeline. They require reportable cyber security incidents to be reported to CERT-In within six hours of noticing them or being notified about them. The directions apply expressly to virtual asset service providers, virtual asset exchange providers and custodian wallet providers, alongside intermediaries, data centres, body corporates and government organisations. They also carry a 180-day ICT log retention duty and five-year KYC and transaction record retention for virtual asset entities. Non-compliance under Section 70B(7) is not a civil penalty — it carries imprisonment of up to one year, a fine, or both.

For an Indian crypto business, this means the operative deadline is not 72 hours and it is not May 2027. It is six hours, today, with criminal exposure attached, and the DPDP obligations will stack on top of it in 2027 rather than replace it. A single incident will trigger a six-hour report to CERT-In, an immediate intimation to the Board, individual notices to every affected data principal, and a 72-hour detailed report — four distinct outputs from one incident, on three different clocks. Almost no Indian company has that choreography written down, let alone rehearsed.

#Why a foreign wallet vendor is an Indian compliance problem

India has the world's largest crypto user base — roughly 119 million owners, ranking first in Chainalysis's global adoption index, with a domestic wallet market crossing the billion-dollar mark. A hardware wallet vendor shipping to consumers worldwide is, in practice, shipping to Indians.

Section 3(b) of the DPDP Act settles the jurisdictional question. The Act applies to processing of digital personal data outside India where the processing relates to any activity of offering goods or services to data principals within India. No Indian subsidiary, no Indian servers, no Indian employees, no local domain and no rupee payment rail is required for the Act to attach. A foreign e-commerce operation that ships goods to Indian addresses is processing Indian personal data in connection with offering goods to people in India, and the shipping addresses in this specific breach are the evidence of exactly that connection.

From May 2027, a foreign vendor in SafePal's position that sells into India owes Indian customers a Rule 7 intimation on the same terms as an Indian company, and owes the Board a 72-hour report — regardless of what its home regulator requires or when. Indian buyers of foreign hardware and services should read this incident as a preview of a right they will hold in under two years, and Indian businesses with foreign vendors in their supply chain should read it as a reason to write breach-notification turnaround times into vendor contracts now. Data processors do not owe the Board anything directly under the Act; the fiduciary that engaged them carries the liability. If your overseas processor takes three months to tell you, you are the one who missed the 72 hours.

#Where India is stricter than the GDPR — and where it is not

The reflex comparison is that India copied the GDPR's 72-hour rule. On regulator notification, roughly true: Article 33 of the GDPR requires notification to the supervisory authority within 72 hours of awareness, and India lands in the same place with an additional "without delay" initial intimation in front of it.

On individual notification, India is materially stricter. Article 34 of the GDPR requires notifying data subjects only where the breach is likely to result in a high risk to their rights and freedoms — a threshold that lets a controller document a risk assessment and decline to notify. The DPDP framework contains no such gate. Every affected data principal gets an intimation, every time. A company that has built its incident response around the GDPR's high-risk assessment has built a discretionary step that Indian law does not grant it, and that step is exactly where months of delay tend to hide.

Where India is weaker is enforcement maturity, not statutory text. European regulators have levied billions in cumulative GDPR fines across a decade of practice. India's Board has yet to seat a single member. The text is sharp; the enforcement machinery is not built. That asymmetry will not last, and building compliance to the enforcement level rather than the text is how organisations end up in the first enforcement cohort.

#The retention footnote worth copying

One line in SafePal's remediation deserves more attention than it got: the company cut personal data retention to 90 days.

That is a post-hoc admission that it did not need 13 months of order records sitting in a queryable system. Section 8(7) of the DPDP Act requires a data fiduciary to erase personal data once the data principal withdraws consent or as soon as it is reasonable to assume the specified purpose is no longer being served — whichever is earlier — unless retention is required by law. The Third Schedule adds hard erasure timelines for specified classes of large fiduciaries, including e-commerce operators above two crore registered users.

The scale of a breach is a function of retention policy. SafePal's exposure window was 13 months wide because 13 months of orders were live in the plug-in's reach. Under a 90-day policy — the one it adopted after the fact — the same flaw would have exposed a fraction of the records. Storage limitation is not filing hygiene. It is the single cheapest control for capping the blast radius of a vulnerability you have not found yet, and it is the control most Indian fiduciaries have deferred to the end of their DPDP roadmaps.

#What to do before May 2027

Four things, in order of how badly they are usually missed:

  1. Define "aware" in writing and log it. Name the roles whose knowledge counts as the organisation's knowledge, and record the timestamp when a report first lands — including reports that look isolated. SafePal's early-May report is the moment its clock should have started, and the only reason anyone can say so is that the company documented it.
  2. Pre-draft the intimations. Rule 7's content requirements — nature, extent, timing, likely consequences, mitigation, user-side safety steps, contact point — are known today. Drafting them during an incident is how 72 hours becomes three months. Template them now, per data category.
  3. Map the three clocks per incident type. Six hours to CERT-In, immediate intimation plus 72 hours to the Board, without-delay notice to every data principal. Write down which incidents trigger which, and who owns each output.
  4. Shorten retention before you need to. Every month of data you do not hold is a month of breach you cannot suffer.

The organisations that treat the phased DPDP timeline as time to prepare will be fine. The ones that treat it as time before the rules apply will be running SafePal's playbook in an environment where the Schedule to the Act, not a press cycle, decides what silence costs.


Working out where your organisation sits on breach readiness? Our resources library covers the Rule 7 intimation templates, the CERT-In six-hour reporting workflow, and retention-schedule design under Section 8(7). If consent lifecycle management is the gap — and with Rule 4 commencing on 13 November 2026 it is the next deadline on the calendar — start with our consent manager guidance.

Automate your DPDP compliance

Capture consent, honour data principal rights, and stay audit-ready — all in one platform.

Start free trial