Breach Response Playbook
An educational outline of steps to consider in the event of a personal data breach under the DPDPA.
Actions:
- •Activate the breach response team and notify the designated incident lead.
- •Verify the breach: confirm that unauthorized processing, disclosure, access, or loss of personal data has occurred.
- •Record the date and time of detection, the source of the alert, and initial findings.
- •Preserve all evidence - do not alter, delete, or overwrite logs, affected systems, or communications.
- •Conduct a preliminary assessment of the scope: which systems, data categories, and Data Principals are potentially affected.
Actions:
- •Isolate affected systems or networks to prevent further unauthorized access.
- •Revoke compromised credentials and access tokens.
- •Apply emergency patches or configuration changes if the breach exploits a known vulnerability.
- •If data has been exfiltrated, attempt to identify the destination and volume of data involved.
- •Document all containment actions taken, including timestamps and personnel involved.
Actions:
- •Determine the root cause of the breach (technical vulnerability, human error, malicious action).
- •Identify all categories of personal data affected (names, email addresses, financial data, etc.).
- •Determine the number of Data Principals affected.
- •Assess whether the breach involved children's data or data subject to sector-specific regulation.
- •Evaluate the potential impact on Data Principals (financial loss, identity theft, reputational harm).
- •Determine whether data was encrypted or otherwise protected at the time of the breach.
- •Engage external forensic experts if the breach is complex or involves sophisticated threat actors.
Actions:
- •Prepare a notification to Data Principals that includes: a description of the breach in plain language, the categories of personal data affected, steps the organization is taking to address the breach, and recommended protective measures for the Data Principal.
- •Deliver the notification through appropriate channels (email, SMS, in-app notification, or other contact method on record).
- •Provide contact details for the Grievance Officer or DPO for further inquiries.
- •Document the notification process, including delivery method, timing, and any responses received.
Actions:
- •Prepare the initial intimation in the prescribed form, including: nature of the breach, categories of data affected, approximate number of Data Principals affected, likely consequences, and measures taken so far.
- •Submit the intimation to the Data Protection Board without delay.
- •Maintain a copy of the intimation and proof of submission for compliance records.
Actions:
- •Complete the investigation needed to compile the detailed report: facts and circumstances of the breach, categories and estimated number of Data Principals affected, possible consequences, remedial measures taken or proposed, and DPO or designated contact details.
- •Submit the detailed report to the Data Protection Board within 72 hours of becoming aware of the breach, or request a longer period in writing from the Board before the deadline if more time is needed.
- •Maintain a copy of the detailed report and proof of submission for compliance records.
- •Cooperate with any investigation or inquiry initiated by the Board.
Actions:
- •Patch vulnerabilities or fix the technical issue that enabled the breach.
- •Reset passwords and access credentials for affected accounts.
- •Enhance monitoring on affected systems to detect any further unauthorized activity.
- •Offer support to affected Data Principals where appropriate (e.g., credit monitoring if financial data was compromised).
- •Update security policies, procedures, and training based on lessons learned.
- •Review and update Data Processor agreements if a third party was involved in the breach.
Actions:
- •Hold a post-incident review meeting with all relevant stakeholders.
- •Document the complete incident timeline, from detection through resolution.
- •Assess the effectiveness of the breach response plan - identify what worked and what needs improvement.
- •Update the breach response playbook based on lessons learned.
- •Report findings and recommendations to senior management and the Board of Directors.
- •Schedule follow-up assessments to verify that remediation measures are effective.
Disclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.