DPDP Rule 7: Three Breach Intimations, One Extendable Clock
One breach starts three intimations under DPDP Rule 7. Two are owed without delay; the seventy-two-hour Board filing is extendable on written request.
On this page (11)
- The three intimations, side by side
- Hour zero is a declaration, and someone signs it
- The six-hour filing runs alongside
- Sub-limb (vi) pulls customer notification inside seventy-two hours
- The named responder in limb (e)
- Asking for the longer period
- Attribution at hour seventy-two is a logging decision made a year earlier
- Your processor's hours come out of yours
- What we put in a processor contract
- The penalty head all three intimations sit under
- Where to start
One personal data breach starts three separate intimations under Rule 7 of the Digital Personal Data Protection Rules, 2025. Two of them are owed "without delay", one to each affected Data Principal and one to the Data Protection Board. The third is the Board's seventy-two hour pack, and the clause writes its own extension into the same sentence: seventy-two hours, "or within such longer period as the Board may allow on a request made in writing in this behalf". A response plan built around a single seventy-two hour deadline is short two filings and the one request that can move the third.
The three intimations, side by side
| Intimation | Owed to | Timing as written | What it carries |
|---|---|---|---|
| Rule 7(1) | each affected Data Principal | "without delay" | five items, owed "to the best of its knowledge" and "in a concise, clear and plain manner", ending in a named person's business contact information |
| Rule 7(2)(a) | the Data Protection Board | "without delay" | nature, extent, timing, and "location of occurrence and the likely impact" |
| Rule 7(2)(b) | the Data Protection Board | seventy-two hours, or a longer period the Board allows on a written request | six items, including attribution and a report on the Rule 7(1) intimations |
The first two rows describe the same event to different readers, which makes them two fields in the case record, on two approval paths.
Rule 7 commences eighteen months after G.S.R. 846(E) is published in the Official Gazette, which reads as 13 or 14 May 2027. The notification and the gazette masthead are both dated 13 November 2025; the e-gazette identifier printed on page 1, CG-DL-E-14112025-267650, and the PIB release both give 14 November. Our Rule 6 piece carries the tranche map and the case for each reading; plan to the earlier date.
Hour zero is a declaration, and someone signs it
Rule 7(1) and Rule 7(2) open on the same trigger, "On becoming aware of any personal data breach". One recorded timestamp, carrying the name of whoever declared it, is the input to all three deadlines and the first thing a later reconstruction looks for. Make it a step in the escalation matrix with an owner, alongside the severity call it rides on.
What starts hour zero is wider than exfiltration. Section 2(u) of the Act reaches "accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data" that compromises confidentiality, integrity or availability. An encryption event with no exfiltration evidence, a destructive misconfiguration, a restore that fails: each is inside that definition.
The six-hour filing runs alongside
An Indian entity reporting a cyber incident under the CERT-In Directions of 28 April 2022 is working to six hours. Those facts and the ones the Board's first limb asks for overlap almost completely, so sequence the runbook to produce the six-hour filing first and build the Rule 7(2)(a) description from the same record, adding the location and likely-impact elements that limb names. One drafting pass, two regulators, each filing owed on the terms of its own instrument.
Sub-limb (vi) pulls customer notification inside seventy-two hours
The hour-72 pack includes "a report regarding the intimations given to affected Data Principals". That sub-limb sets the sequencing for everything else, because the Board's filing reports on how the Data Principal side was handled. By hour seventy-two the notification workstream has to have produced auditable output: the cohort identified, the channel used for each person, send timestamps, and the treatment of addresses that failed.
This is a data problem before it is a communications problem. Rule 7(1) fixes the channel — "through her user account or any mode of communication registered by her with the Data Fiduciary" — and Rule 2(1)(c) reads user account to include "profiles, pages, handles, email address, mobile number". Whether you can enumerate the affected cohort before hour seventy-two is what decides whether sub-limb (vi) has anything to report.
The named responder in limb (e)
Rule 7(1)(e) puts "business contact information of a person who is able to respond on behalf of the Data Fiduciary" inside the notice. Whoever is named there takes inbound volume scaled to the cohort. Rule 9 separately requires every Data Fiduciary to publish the business contact information of the Data Protection Officer, if applicable, or a person able to answer questions about processing. Settle in advance whether those are the same person, and who covers the second queue while the first is saturated.
Asking for the longer period
The extension in Rule 7(2)(b) has three moving parts: it is the Board's to allow, it has to be requested, and the request is in writing. Each is a runbook item.
- Draft the request before an incident. A template that exists at hour 60 is a document; one written at hour 60 competes with the investigation for the same people.
- Fix the decision checkpoint. Set an internal hour, well short of the deadline, at which the response lead judges whether all six sub-limbs can be answered.
- Name the signer, and a deputy. A written request to the Board needs authority behind it at an hour nobody chose.
- Write it on the facts in hand. What is established, what is being established, and the date by which the sub-limbs will be answered.
Attribution at hour seventy-two is a logging decision made a year earlier
Sub-limb (iv) asks for "any findings regarding the person who caused the breach". Whether that is answerable on the third day depends on telemetry that existed before the incident. Rule 6(1)(c) requires visibility on the accessing of personal data through logs, monitoring and review, "for enabling detection of unauthorised access, its investigation and remediation to prevent recurrence". Rule 6(1)(e) retains those logs and the personal data "for a period of one year, unless compliance with any law for the time being in force requires otherwise". Rule 8(3) sets a separate floor for "personal data, associated traffic data and other logs of the processing for a minimum period of one year" on the purposes specified in the Seventh Schedule.
A cheap test. Take a closed incident from six months ago and ask what you could say today about who caused it, using only the logs you still hold. That is your sub-limb (iv) answer.
Your processor's hours come out of yours
Section 8(5) puts the safeguards duty on the Data Fiduciary for personal data "in its possession or under its control, including in respect of any processing undertaken by it or on its behalf by a Data Processor", and Rule 7 addresses the Data Fiduciary throughout. A breach inside a processor is the fiduciary's filing, and the processor's detection-to-notification lag is spent out of the same seventy-two hours. Rule 6(1)(f) makes the contract a control surface, requiring "appropriate provision in the contract entered into between such Data Fiduciary and such a Data Processor, wherever applicable", for taking reasonable security safeguards.
What we put in a processor contract
Our position, rather than a clause reading:
- Notification in hours, measured from the processor's own awareness, with that declaration recorded on their side the way it is on yours.
- The six sub-limbs as a delivery schedule, so their output maps onto the Board pack instead of arriving as a narrative.
- Cohort identification as a deliverable, with a stated turnaround, because sub-limb (vi) and the Rule 7(1) intimation both stand on it.
- Log retention matched to Rule 6(1)(e) and Rule 8(3), reachable by you during an investigation.
- A named responder at the processor, mirroring limb (e).
- Cooperation with an extension request, since the supporting facts will often be theirs.
The penalty head all three intimations sit under
Section 8(6) is the parent duty; Rule 7 is its prescribed form and manner. Entry 2 of the Schedule covers a breach of the obligation to give "the Board or affected Data Principal" notice under section 8(6), with a penalty that "May extend to two hundred crore rupees". Entry 1 is separate, covering the section 8(5) safeguards duty, and "May extend to two hundred and fifty crore rupees". Each figure is an upper limit the Board works down from.
Where to start
Rule 7 is a drafting and evidence obligation before it is a technical one, so most of it can be finished ahead of commencement:
- Write the three intimations as templates, and the extension request as a fourth.
- Add the awareness declaration to the escalation matrix, with an owner and a recorded timestamp.
- Run the six-month log test and see what sub-limb (iv) would have returned.
- Reopen processor contracts at the next renewal with the six items above.
Security Brigade has been CERT-In empanelled continuously since 2008. We test the controls Rule 6 names, and we read instruments clause by clause against the runbook that has to satisfy them. If you want the Rule 7 templates walked through against your incident-response plan, that is one working session with your response lead and your DPO.
About the authors
Founder & Chief Technology Officer
Founded Security Brigade in 2006 with the thesis that security assessment quality should be structural, not dependent on individual testers. 16+ years building platforms, teams, and methodologies that make enterprise security consistent.
Offensive Security Research · Security Brigade
A rotating byline for collaborative analysis pieces from Security Brigade's offensive security and threat-research practice.
Continue reading
All articles →SEBI's MII subsidiary proposal: three tests, one narrow exemption
Three tests decide whether an MII's IT and cyber framework reaches a subsidiary. SEBI's proposal, and the one narrow exemption.
The Significant Data Fiduciary's Four Duties Under Rule 13
Rule 13's four duties for a Significant Data Fiduciary: a twelve-month DPIA and audit, a Board report, algorithmic due diligence, an India-only restriction.
DPDP Rule 6: the seven security safeguards, and the runway to May 2027
Rule 6's seven minimum safeguards commence 13 or 14 May 2027. What each limb must produce, and the two that need a budget.