DPDPA 2023 — From Awareness to Compliance
Module 5 of 9 · 7 min read

Security safeguards and breach notification (72 hours)

The minimum controls the Rules expect, and the two-track breach reporting duty.

"Reasonable security safeguards" — the floor the Rules set

A Data Fiduciary must protect personal data in its possession or under its control (that includes your Processors) with at least:

  1. Encryption, obfuscation, masking or tokenisation of personal data,
  2. Access control to the computer resources used for processing,
  3. Logging and monitoring to detect, investigate and remediate unauthorised access — with logs retained for at least one year,
  4. Backups and continuity to restore availability after loss or compromise,
  5. Contractual provisions with Processors that impose equivalent safeguards, and
  6. Appropriate technical and organisational measures to ensure the above actually operate.

If you already run ISO 27001 or the RBI/SEBI cyber frameworks, map these six to existing controls and document the mapping — auditors will ask for it.

Breach notification — two audiences, two clocks

On becoming aware of a personal data breach, the Fiduciary must:

To each affected Data Principal — without delay, in plain language, through their registered contact channel:

  • what happened (nature, extent, timing, location),
  • the likely consequences for them,
  • the mitigation you have taken/are taking,
  • what they can do to protect themselves,
  • how to contact you.

To the Data Protection Board:

  • an initial intimation without delay, and
  • within 72 hours (or a longer period the Board permits on request): the facts, circumstances and reasons; mitigation; findings on who caused it; remedial measures to prevent recurrence; and a report of the intimations sent to affected Principals.

There is no materiality threshold — every breach is notifiable. This is stricter than GDPR's "risk to rights" test.

Don't forget CERT-In

CERT-In's 2022 directions independently require reporting of listed cyber incidents within 6 hours of noticing them. A ransomware event on a system holding personal data therefore triggers both clocks. Put both in the same runbook.

Penalty exposure

  • Failure to take reasonable security safeguards: up to ₹250 crore.
  • Failure to notify the Board / affected Principals: up to ₹200 crore.

Runbook additions

  • "Awareness" timestamp is logged the moment the SOC/IR lead classifies an event as a breach
  • Pre-approved Principal notification template in plain language (and Scheduled languages you serve)
  • Board intimation template with the Rules' mandatory fields
  • CERT-In 6-hour form pre-filled with organisational details
  • Processor contracts require them to inform you immediately — your clock runs from awareness, theirs must feed it