Back to Resources
Guide
Breach Response Playbook
An educational outline of steps to consider in the event of a personal data breach under the DPDPA.
1
Detection & Initial Response
Identify and confirm the occurrence of a personal data breach. The speed of detection directly impacts the organization's ability to contain the breach and meet notification obligations under the DPDPA.
Actions:
- •Activate the breach response team and notify the designated incident lead.
- •Verify the breach: confirm that unauthorized processing, disclosure, access, or loss of personal data has occurred.
- •Record the date and time of detection, the source of the alert, and initial findings.
- •Preserve all evidence - do not alter, delete, or overwrite logs, affected systems, or communications.
- •Conduct a preliminary assessment of the scope: which systems, data categories, and Data Principals are potentially affected.
Timeline: Immediately upon detection (within hours)
Responsible: IT Security / Incident Response Team
2
Containment
Take immediate steps to limit the scope and impact of the breach. Containment measures should be proportionate and should not destroy evidence needed for investigation.
Actions:
- •Isolate affected systems or networks to prevent further unauthorized access.
- •Revoke compromised credentials and access tokens.
- •Apply emergency patches or configuration changes if the breach exploits a known vulnerability.
- •If data has been exfiltrated, attempt to identify the destination and volume of data involved.
- •Document all containment actions taken, including timestamps and personnel involved.
Timeline: Within 24 hours of detection
Responsible: IT Security / System Administrators
3
Assessment & Investigation
Conduct a thorough investigation to understand the full scope, cause, and impact of the breach. This assessment informs notification decisions and remediation actions.
Actions:
- •Determine the root cause of the breach (technical vulnerability, human error, malicious action).
- •Identify all categories of personal data affected (names, email addresses, financial data, etc.).
- •Determine the number of Data Principals affected.
- •Assess whether the breach involved children's data or data subject to sector-specific regulation.
- •Evaluate the potential impact on Data Principals (financial loss, identity theft, reputational harm).
- •Determine whether data was encrypted or otherwise protected at the time of the breach.
- •Engage external forensic experts if the breach is complex or involves sophisticated threat actors.
Timeline: Within 48-72 hours of detection
Responsible: Incident Response Team / DPO / External Forensic Experts
4
Notification to the Data Protection Board
The DPDPA requires every Data Fiduciary to notify the Data Protection Board of India of a personal data breach in the prescribed form and manner per Rule 7. Timely notification is a legal obligation.
Actions:
- •Prepare the breach notification in the prescribed form, including: nature of the breach, categories of data affected, approximate number of Data Principals affected, likely consequences, and measures taken.
- •Submit the notification to the Data Protection Board within the prescribed timeframe.
- •Maintain a copy of the notification and proof of submission for compliance records.
- •Cooperate with any investigation or inquiry initiated by the Board.
Timeline: As prescribed under the Act (without undue delay)
Responsible: Data Protection Officer / Legal Team
5
Notification to Affected Data Principals
The DPDPA also requires notification to each affected Data Principal in the prescribed form and manner. This notification should be clear, accessible, and actionable.
Actions:
- •Prepare a notification to Data Principals that includes: a description of the breach in plain language, the categories of personal data affected, steps the organization is taking to address the breach, and recommended protective measures for the Data Principal.
- •Deliver the notification through appropriate channels (email, SMS, in-app notification, or other contact method on record).
- •Provide contact details for the Grievance Officer or DPO for further inquiries.
- •Document the notification process, including delivery method, timing, and any responses received.
Timeline: As prescribed under the Act (without undue delay after Board notification)
Responsible: DPO / Communications Team
6
Remediation
Implement measures to address the root cause of the breach, prevent recurrence, and mitigate ongoing impact on affected Data Principals.
Actions:
- •Patch vulnerabilities or fix the technical issue that enabled the breach.
- •Reset passwords and access credentials for affected accounts.
- •Enhance monitoring on affected systems to detect any further unauthorized activity.
- •Offer support to affected Data Principals where appropriate (e.g., credit monitoring if financial data was compromised).
- •Update security policies, procedures, and training based on lessons learned.
- •Review and update Data Processor agreements if a third party was involved in the breach.
Timeline: Within 1-4 weeks following containment
Responsible: IT Security / DPO / Management
7
Post-Incident Review
Conduct a comprehensive review of the breach incident and the organization's response. Use findings to strengthen the overall data protection framework and breach preparedness.
Actions:
- •Hold a post-incident review meeting with all relevant stakeholders.
- •Document the complete incident timeline, from detection through resolution.
- •Assess the effectiveness of the breach response plan - identify what worked and what needs improvement.
- •Update the breach response playbook based on lessons learned.
- •Report findings and recommendations to senior management and the Board of Directors.
- •Schedule follow-up assessments to verify that remediation measures are effective.
Timeline: Within 2-4 weeks after remediation is complete
Responsible: DPO / Senior Management / Internal Audit
Disclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.
