Next due
11 OCTGSTR-1 · Outward supplies · Sep 2026tomorrow 15 OCTPF & ESI · Contributions · Sep 2026in 5 days 20 OCTGSTR-3B · Summary return · Sep 2026in 10 days 21 OCTTax Audit Report · Form 3CA/3CB · AY 2026-27 · extended from 30 Sepin 11 days 30 OCTAOC-4 · Financial statements · FY 2025-26in 20 days 7 NOVTDS / TCS deposit · Deducted in Oct 2026in 28 days 21 NOVITR filing · Audit cases · AY 2026-27 · extended from 31 Octin 42 days 29 NOVMGT-7 / 7A · Annual return · FY 2025-26in 50 days
All due dates

Rule 7(2) of the Digital Personal Data Protection Rules, 2025: intimation of a personal data breach to the Board within seventy-two hours

Rule 7 is in the group that, under rule 1(4), comes into force eighteen months after the date of publication of the Gazette. On becoming aware of a breach the Data Fiduciary...

Published
Updated
Reading time
7 min
Views
14
Questions
6 answered
  • Expert Reviewed
  • Medium Complexity
Topic
Data Protection
Published
October 2, 2026
Last updated
Oct 10, 2026
Reading time
7 min
0:00
Last updated: October 2026Verified against: Government sources

Rule 7(2) is the Board's half of the breach duty. A Data Fiduciary that becomes aware of a personal data breach must tell the Board in two steps: a description without delay, then six items of detail within seventy-two hours of becoming aware, or within a longer period the Board allows on a written request.

Rule 7(2) and the Act

Section 8(6) of the Act requires intimation of a personal data breach to the Board and to each affected Data Principal in the manner prescribed. The Act's text is in Section 8 of the DPDP Act: intimation of personal data breach. The Data Principal's half is in our article on rule 7(1). This article covers only sub-rule (2).

Commencement: rule 1(4) puts rule 7 in the group that comes into force "eighteen months after the date of publication of this Gazette". Counting from the Gazette date of 13 November 2025, eighteen months end in mid-May 2027; confirm the exact date of publication before relying on a date. The three stages are set out in rules 1 and 2.

A breach report is a document that the Board may read closely. A team that has dispute resolution support lined up before an incident can answer in the time the Rule allows.

The two steps

StepWhenWhat is givenRule
1"without delay"A description of the breach, including its nature, extent, timing and location of occurrence and the likely impact7(2)(a)
2"within seventy-two hours of becoming aware of the breach, or within such longer period as the Board may allow on a request made in writing"Six items, (i) to (vi)7(2)(b)

Both steps run from the same moment: "On becoming aware of any personal data breach". The seventy-two hours are counted "of becoming aware of the breach", not from the end of the investigation or from the breach itself.

Step 1: the description without delay

Clause (a) asks for "a description of the breach, including its nature, extent, timing and location of occurrence and the likely impact". Compare rule 7(1)(a) for Data Principals, which asks for nature, extent and timing but not location, and which lists consequences "relevant to her" separately. For the Board there are five elements: nature, extent, timing, location and likely impact. "Without delay" has no number of hours. The Rule does not say that the first description must be complete; it follows that the seventy-two-hour report is where updated detail goes.

Step 2: the six items

Within seventy-two hours (or the longer period), the Data Fiduciary gives:

  1. (i) "updated and detailed information in respect of such description";
  2. (ii) "the broad facts related to the events, circumstances and reasons leading to the breach";
  3. (iii) "measures implemented or proposed, if any, to mitigate risk";
  4. (iv) "any findings regarding the person who caused the breach";
  5. (v) "remedial measures taken to prevent recurrence of such breach"; and
  6. (vi) "a report regarding the intimations given to affected Data Principals".

Item (vi) joins the two halves of rule 7. By the time the Board's detailed report is due, the Data Fiduciary should have sent, or be sending, the messages required by rule 7(1), and it must report on them. A Data Fiduciary that has not told Data Principals has to say so in that report.

Item (iv) asks for "any findings", which means what the investigation has found so far. If no finding about the person who caused the breach exists at seventy-two hours, the text does not say what to write; the sensible course is to state that none has yet been made. The Rule is silent on the point.

The longer period

The seventy-two hours can be extended only by the Board, and only "on a request made in writing in this behalf". So the Data Fiduciary cannot extend the period by itself. It must ask in writing, and the Board decides. The Rules do not say how long a longer period may be, what form the request takes or when the Board must answer. Those details are not in the text. Anything the Board publishes on the subject should be checked.

Example

SwiftPay, an invented wallet app, discovers on a Monday at 9:00 that a vendor's server held a misconfigured database for three days. It intimates the Board that morning with the nature, extent, timing and location of the breach and its likely impact. By Thursday at 9:00 (seventy-two hours after becoming aware) it sends the updated details, the chain of events, mitigation and remedial steps, any findings on the person responsible and a report on the messages sent to affected users. If SwiftPay's forensic work is not finished, it may ask the Board in writing for a longer period before that time ends. The Rules contain no Illustration for rule 7; the example is ours.

Related duties

Need help preparing for a breach report?

Seventy-two hours is short when logs, vendors and legal review all need to move together. Speak to our dispute resolution team about a breach-response protocol with named owners, drafting templates and a route for the written request for a longer period.

Key takeaways

  • Rule 7 starts eighteen months after the date of publication of the Gazette (rule 1(4)).
  • Step 1: intimate the Board without delay with nature, extent, timing, location and likely impact.
  • Step 2: within seventy-two hours of becoming aware, or a longer period the Board allows on a written request, give the six items in clause (b).
  • Item (vi) is a report on the intimations given to affected Data Principals.
  • Only the Board can allow a longer period.
  • Later amendments and notifications should be checked.

Read next

Disclaimer: Based on the Digital Personal Data Protection Rules, 2025 as notified in the Gazette of India on 13 November 2025 (G.S.R. 846(E)), as consulted on 2 October 2026. The Rules come into force in three stages under rule 1; later amendments, notifications and anything published by the Data Protection Board of India should be checked. This article is general information, not legal advice; check the official text before acting.

Quick recapKey facts & short answers

Key Facts About Rule 7

  • Applies in: All states across India, under the relevant central law.
  • Mode: Mostly online via the official government portal.
  • Typical timeline: Ranges from a few days to a few weeks depending on the case.
  • Non-compliance: May attract penalties, interest or late fees.
  • Expert help: TaxClue completes the entire process end to end for you.

When does the seventy-two-hour clock start?

On the Data Fiduciary becoming aware of the breach (rule 7(2)(b)).

Is a report due if I am still investigating?

Step 1 is due without delay in any case. Step 2 is due within seventy-two hours or any longer period the Board allows.

If a rule seems to have changed, check the date of what you are reading before you act on it.

— TaxClue Compliance Desk

Rule 7: a key compliance topic in Indian tax and corporate law that businesses and individuals must understand to remain compliant.

Related Services & Guides

Was this article helpful?
About the author
13,350 articles
Vikas Sharma Verified expert Tax & Compliance Expert

Experienced in company registration, GST, trademark, and compliance. Helping Indian businesses stay compliant.

Last reviewed: Live

Disclaimer: This article is for general informational purposes only and does not constitute professional tax, legal or financial advice. Laws, rates and due dates change and can vary by individual case — always verify with the relevant government source (e.g. mca.gov.in, incometax.gov.in) or consult a qualified professional before acting. TaxClue accepts no liability for decisions taken based on this content.

People also ask

Questions, answered

Short, direct answers to the 6 questions readers ask most on this topic.

On the Data Fiduciary becoming aware of the breach (rule 7(2)(b)).

Step 1 is due without delay in any case. Step 2 is due within seventy-two hours or any longer period the Board allows.

By a request made in writing to the Board. The Board decides; the Data Fiduciary cannot extend on its own.

Updated and detailed information, broad facts and reasons, mitigation measures, findings on the person who caused the breach, remedial measures, and a report on intimations to affected Data Principals.

Rule 7 sets no order. Sub-rule (1) requires intimation to Data Principals without delay and sub-rule (2)(a) requires intimation to the Board without delay.

Section 8(6).