Back to Resources
Guide

Breach Response Playbook

An educational outline of steps to consider in the event of a personal data breach under the DPDPA.

1
Detection & Initial Response
Identify and confirm the occurrence of a personal data breach. The speed of detection directly impacts the organization's ability to contain the breach and meet notification obligations under the DPDPA.

Actions:

  • Activate the breach response team and notify the designated incident lead.
  • Verify the breach: confirm that unauthorized processing, disclosure, access, or loss of personal data has occurred.
  • Record the date and time of detection, the source of the alert, and initial findings.
  • Preserve all evidence - do not alter, delete, or overwrite logs, affected systems, or communications.
  • Conduct a preliminary assessment of the scope: which systems, data categories, and Data Principals are potentially affected.
Timeline: Immediately upon detection (within hours)
Responsible: IT Security / Incident Response Team
2
Containment
Take immediate steps to limit the scope and impact of the breach. Containment measures should be proportionate and should not destroy evidence needed for investigation.

Actions:

  • Isolate affected systems or networks to prevent further unauthorized access.
  • Revoke compromised credentials and access tokens.
  • Apply emergency patches or configuration changes if the breach exploits a known vulnerability.
  • If data has been exfiltrated, attempt to identify the destination and volume of data involved.
  • Document all containment actions taken, including timestamps and personnel involved.
Timeline: Within 24 hours of detection
Responsible: IT Security / System Administrators
3
Assessment & Investigation
Conduct a thorough investigation to understand the full scope, cause, and impact of the breach. This assessment informs notification decisions and remediation actions.

Actions:

  • Determine the root cause of the breach (technical vulnerability, human error, malicious action).
  • Identify all categories of personal data affected (names, email addresses, financial data, etc.).
  • Determine the number of Data Principals affected.
  • Assess whether the breach involved children's data or data subject to sector-specific regulation.
  • Evaluate the potential impact on Data Principals (financial loss, identity theft, reputational harm).
  • Determine whether data was encrypted or otherwise protected at the time of the breach.
  • Engage external forensic experts if the breach is complex or involves sophisticated threat actors.
Timeline: Within 48-72 hours of detection
Responsible: Incident Response Team / DPO / External Forensic Experts
4
Notification to the Data Protection Board
The DPDPA requires every Data Fiduciary to notify the Data Protection Board of India of a personal data breach in the prescribed form and manner per Rule 7. Timely notification is a legal obligation.

Actions:

  • Prepare the breach notification in the prescribed form, including: nature of the breach, categories of data affected, approximate number of Data Principals affected, likely consequences, and measures taken.
  • Submit the notification to the Data Protection Board within the prescribed timeframe.
  • Maintain a copy of the notification and proof of submission for compliance records.
  • Cooperate with any investigation or inquiry initiated by the Board.
Timeline: As prescribed under the Act (without undue delay)
Responsible: Data Protection Officer / Legal Team
5
Notification to Affected Data Principals
The DPDPA also requires notification to each affected Data Principal in the prescribed form and manner. This notification should be clear, accessible, and actionable.

Actions:

  • Prepare a notification to Data Principals that includes: a description of the breach in plain language, the categories of personal data affected, steps the organization is taking to address the breach, and recommended protective measures for the Data Principal.
  • Deliver the notification through appropriate channels (email, SMS, in-app notification, or other contact method on record).
  • Provide contact details for the Grievance Officer or DPO for further inquiries.
  • Document the notification process, including delivery method, timing, and any responses received.
Timeline: As prescribed under the Act (without undue delay after Board notification)
Responsible: DPO / Communications Team
6
Remediation
Implement measures to address the root cause of the breach, prevent recurrence, and mitigate ongoing impact on affected Data Principals.

Actions:

  • Patch vulnerabilities or fix the technical issue that enabled the breach.
  • Reset passwords and access credentials for affected accounts.
  • Enhance monitoring on affected systems to detect any further unauthorized activity.
  • Offer support to affected Data Principals where appropriate (e.g., credit monitoring if financial data was compromised).
  • Update security policies, procedures, and training based on lessons learned.
  • Review and update Data Processor agreements if a third party was involved in the breach.
Timeline: Within 1-4 weeks following containment
Responsible: IT Security / DPO / Management
7
Post-Incident Review
Conduct a comprehensive review of the breach incident and the organization's response. Use findings to strengthen the overall data protection framework and breach preparedness.

Actions:

  • Hold a post-incident review meeting with all relevant stakeholders.
  • Document the complete incident timeline, from detection through resolution.
  • Assess the effectiveness of the breach response plan - identify what worked and what needs improvement.
  • Update the breach response playbook based on lessons learned.
  • Report findings and recommendations to senior management and the Board of Directors.
  • Schedule follow-up assessments to verify that remediation measures are effective.
Timeline: Within 2-4 weeks after remediation is complete
Responsible: DPO / Senior Management / Internal Audit

Disclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.