Back to DPDP Rules
Breach Notification Framework (R.7)
Rule 7 two-tier breach notification - Level 1 preliminary report, 72-hour detailed report, Data Principal notification, and practical response procedures.
7 min read
Two-Tier Notification Framework
Rule 7 establishes a structured two-tier breach notification framework:
Level 1 - Preliminary Notification: The Data Fiduciary must notify the Data Protection Board without unreasonable delay upon becoming aware of a personal data breach. This initial notification provides preliminary details about the breach.
Level 2 - Detailed Report: Within 72 hours of the Level 1 notification, the Data Fiduciary must submit a detailed report to the Board including:
• Facts and circumstances of the breach
• Nature and category of personal data affected
• Estimated number of Data Principals affected
• Possible consequences of the breach
• Description of remedial measures taken or proposed
• Contact details of the Data Protection Officer or designated contact point
This two-tier approach balances the need for rapid notification with the time required to conduct a thorough assessment.
Notification to Data Principals
In addition to notifying the Board, the Data Fiduciary must notify affected Data Principals about the breach. The notification must include:
• A description of the personal data breach
• The possible consequences of the breach
• Risk mitigation measures that the Data Principal may undertake
• Safety measures taken by the Data Fiduciary in response to the breach
• Business contact information for the Data Fiduciary
The notification must be provided without unreasonable delay once the Data Fiduciary has identified the affected Data Principals.
Practical Breach Response Procedure
Organisations should establish the following breach response procedure:
1. Detection and Containment: Detect the breach through monitoring systems, contain the breach to prevent further data loss, and preserve evidence.
2. Assessment: Assess the nature and scope of the breach - what data was affected, how many Data Principals, and what are the potential consequences.
3. Level 1 Notification: Notify the Board with preliminary details as soon as the breach is confirmed.
4. Investigation: Conduct a thorough investigation within the 72-hour window to gather details for the Level 2 report.
5. Level 2 Report: Submit the detailed report to the Board within 72 hours of Level 1.
6. Data Principal Notification: Notify affected individuals with clear information and mitigation guidance.
7. Remediation: Implement measures to prevent recurrence and address the root cause.
8. Documentation: Maintain detailed records of the breach, response actions, and lessons learned.
Related Resources
Frequently Asked Questions
On This Page
Quick ResourcesDisclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.
