Back to Resources
Guide

Breach Response Playbook

An educational outline of steps to consider in the event of a personal data breach under the DPDPA.

1
Detection & Initial Response
Identify and confirm the occurrence of a personal data breach. The speed of detection directly impacts the organization's ability to contain the breach and meet notification obligations under the DPDPA.

Actions:

  • •Activate the breach response team and notify the designated incident lead.
  • •Verify the breach: confirm that unauthorized processing, disclosure, access, or loss of personal data has occurred.
  • •Record the date and time of detection, the source of the alert, and initial findings.
  • •Preserve all evidence - do not alter, delete, or overwrite logs, affected systems, or communications.
  • •Conduct a preliminary assessment of the scope: which systems, data categories, and Data Principals are potentially affected.
Timeline: Immediately upon detection (within hours)
Responsible: IT Security / Incident Response Team
2
Containment
Take immediate steps to limit the scope and impact of the breach. Containment measures should be proportionate and should not destroy evidence needed for investigation.

Actions:

  • •Isolate affected systems or networks to prevent further unauthorized access.
  • •Revoke compromised credentials and access tokens.
  • •Apply emergency patches or configuration changes if the breach exploits a known vulnerability.
  • •If data has been exfiltrated, attempt to identify the destination and volume of data involved.
  • •Document all containment actions taken, including timestamps and personnel involved.
Timeline: Within 24 hours of detection
Responsible: IT Security / System Administrators
3
Assessment & Investigation
Conduct a thorough investigation to understand the full scope, cause, and impact of the breach. This assessment informs notification decisions and remediation actions.

Actions:

  • •Determine the root cause of the breach (technical vulnerability, human error, malicious action).
  • •Identify all categories of personal data affected (names, email addresses, financial data, etc.).
  • •Determine the number of Data Principals affected.
  • •Assess whether the breach involved children's data or data subject to sector-specific regulation.
  • •Evaluate the potential impact on Data Principals (financial loss, identity theft, reputational harm).
  • •Determine whether data was encrypted or otherwise protected at the time of the breach.
  • •Engage external forensic experts if the breach is complex or involves sophisticated threat actors.
Timeline: Within 48-72 hours of detection
Responsible: Incident Response Team / DPO / External Forensic Experts
4
Notification to Affected Data Principals
Under Rule 7(1) of the DPDP Rules, 2025, the Data Fiduciary must, without delay, intimate each affected Data Principal of the personal data breach in the manner specified by the Data Protection Board. This notification should be clear, accessible, and actionable.

Actions:

  • •Prepare a notification to Data Principals that includes: a description of the breach in plain language, the categories of personal data affected, steps the organization is taking to address the breach, and recommended protective measures for the Data Principal.
  • •Deliver the notification through appropriate channels (email, SMS, in-app notification, or other contact method on record).
  • •Provide contact details for the Grievance Officer or DPO for further inquiries.
  • •Document the notification process, including delivery method, timing, and any responses received.
Timeline: Without delay, as prescribed under Rule 7(1) of the DPDP Rules (the deadline is fixed by the Rules, not the Act)
Responsible: DPO / Communications Team
5
Initial Intimation to the Data Protection Board
Under Rule 7(2)(a) of the DPDP Rules, 2025, the Data Fiduciary must, without delay, intimate the Data Protection Board of India of a personal data breach in the manner specified by the Board. This is the preliminary intimation, separate from the detailed report that follows.

Actions:

  • •Prepare the initial intimation in the prescribed form, including: nature of the breach, categories of data affected, approximate number of Data Principals affected, likely consequences, and measures taken so far.
  • •Submit the intimation to the Data Protection Board without delay.
  • •Maintain a copy of the intimation and proof of submission for compliance records.
Timeline: Without delay, as prescribed under Rule 7(2)(a) of the DPDP Rules (the deadline is fixed by the Rules, not the Act)
Responsible: Data Protection Officer / Legal Team
6
Detailed 72-Hour Report to the Data Protection Board
Under Rule 7(2)(b) of the DPDP Rules, 2025, the Data Fiduciary must submit a detailed report to the Board within 72 hours of becoming aware of the breach, unless the Board permits a longer period on written request. The clock runs from becoming aware of the breach, not from the initial intimation.

Actions:

  • •Complete the investigation needed to compile the detailed report: facts and circumstances of the breach, categories and estimated number of Data Principals affected, possible consequences, remedial measures taken or proposed, and DPO or designated contact details.
  • •Submit the detailed report to the Data Protection Board within 72 hours of becoming aware of the breach, or request a longer period in writing from the Board before the deadline if more time is needed.
  • •Maintain a copy of the detailed report and proof of submission for compliance records.
  • •Cooperate with any investigation or inquiry initiated by the Board.
Timeline: Within 72 hours of becoming aware of the breach, per Rule 7(2)(b) of the DPDP Rules, unless the Board permits a longer period on written request
Responsible: Data Protection Officer / Legal Team
7
Remediation
Implement measures to address the root cause of the breach, prevent recurrence, and mitigate ongoing impact on affected Data Principals.

Actions:

  • •Patch vulnerabilities or fix the technical issue that enabled the breach.
  • •Reset passwords and access credentials for affected accounts.
  • •Enhance monitoring on affected systems to detect any further unauthorized activity.
  • •Offer support to affected Data Principals where appropriate (e.g., credit monitoring if financial data was compromised).
  • •Update security policies, procedures, and training based on lessons learned.
  • •Review and update Data Processor agreements if a third party was involved in the breach.
Timeline: Within 1-4 weeks following containment
Responsible: IT Security / DPO / Management
8
Post-Incident Review
Conduct a comprehensive review of the breach incident and the organization's response. Use findings to strengthen the overall data protection framework and breach preparedness.

Actions:

  • •Hold a post-incident review meeting with all relevant stakeholders.
  • •Document the complete incident timeline, from detection through resolution.
  • •Assess the effectiveness of the breach response plan - identify what worked and what needs improvement.
  • •Update the breach response playbook based on lessons learned.
  • •Report findings and recommendations to senior management and the Board of Directors.
  • •Schedule follow-up assessments to verify that remediation measures are effective.
Timeline: Within 2-4 weeks after remediation is complete
Responsible: DPO / Senior Management / Internal Audit

Disclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.