Security safeguards and breach notification (72 hours)
The minimum controls the Rules expect, and the two-track breach reporting duty.
"Reasonable security safeguards" — the floor the Rules set
A Data Fiduciary must protect personal data in its possession or under its control (that includes your Processors) with at least:
- Encryption, obfuscation, masking or tokenisation of personal data,
- Access control to the computer resources used for processing,
- Logging and monitoring to detect, investigate and remediate unauthorised access — with logs retained for at least one year,
- Backups and continuity to restore availability after loss or compromise,
- Contractual provisions with Processors that impose equivalent safeguards, and
- Appropriate technical and organisational measures to ensure the above actually operate.
If you already run ISO 27001 or the RBI/SEBI cyber frameworks, map these six to existing controls and document the mapping — auditors will ask for it.
Breach notification — two audiences, two clocks
On becoming aware of a personal data breach, the Fiduciary must:
To each affected Data Principal — without delay, in plain language, through their registered contact channel:
- what happened (nature, extent, timing, location),
- the likely consequences for them,
- the mitigation you have taken/are taking,
- what they can do to protect themselves,
- how to contact you.
To the Data Protection Board:
- an initial intimation without delay, and
- within 72 hours (or a longer period the Board permits on request): the facts, circumstances and reasons; mitigation; findings on who caused it; remedial measures to prevent recurrence; and a report of the intimations sent to affected Principals.
There is no materiality threshold — every breach is notifiable. This is stricter than GDPR's "risk to rights" test.
Don't forget CERT-In
CERT-In's 2022 directions independently require reporting of listed cyber incidents within 6 hours of noticing them. A ransomware event on a system holding personal data therefore triggers both clocks. Put both in the same runbook.
Penalty exposure
- Failure to take reasonable security safeguards: up to ₹250 crore.
- Failure to notify the Board / affected Principals: up to ₹200 crore.
Runbook additions
- "Awareness" timestamp is logged the moment the SOC/IR lead classifies an event as a breach
- Pre-approved Principal notification template in plain language (and Scheduled languages you serve)
- Board intimation template with the Rules' mandatory fields
- CERT-In 6-hour form pre-filled with organisational details
- Processor contracts require them to inform you immediately — your clock runs from awareness, theirs must feed it