dPDP & tech 1.6: Breach Detection & 72-Hour Notification — When Seconds Count

A personal data breach has just occurred in your organisation. The 72-hour clock has started. Do your systems know yet?

Under Rule 7(2)(b) of the DPDP Rules, 2025, a Data Fiduciary must intimate the Data Protection Board within 72 hours of becoming aware of a breach — with a detailed, evidenced report covering nature, extent, timing, location, likely impact, root cause, findings about who caused it, remedial measures, and a report on notifications sent to affected Data Principals.

That is not a holding statement. It is a forensic-quality report — in 72 hours.

Without the right technology, that window is impossible to meet.

⏱ Technology Step 1 — Detection: making “becoming aware” happen immediately

The clock under DPDP starts from when the Data Fiduciary “becomes aware.” This distinction is critical. An organisation that discovers a breach 30 days after it occurred — through a manual review, a customer complaint, or a third party — has already lost the window.

SIEM generates alerts from correlating logs across servers, databases, applications, firewalls, and endpoints simultaneously. The 24×7 SOC monitoring team checks alerts against pre-set deviation criteria and declares an incident the moment a qualifying anomaly appears.

Alerts are also generated by DLP (Data Leakage Prevention), IPS/IDS (Intrusion Prevention/Detection Systems), and firewall systems — providing multiple, overlapping detection layers so that no single point of failure can delay awareness.

Technology’s role: compress the gap between breach occurrence and organisational awareness from days or weeks to minutes.

🔒 Technology Step 2 — Containment: stop the bleeding, fast

Once an incident is declared, the Incident Response Team must immediately contain its impact — isolating the affected system to prevent the breach from spreading. This means terminating all active sessions on the compromised system, blocking the source of the incident at the network level, and quarantining affected data from further access.

Automated containment playbooks — pre-built response workflows triggered by SIEM alerts — can execute these steps within seconds of incident declaration, without waiting for human decision chains. The performance of an incident response team, is judged precisely by how quickly identification and containment happen. Under DPDP, that speed directly determines compliance.

📋 Technology Step 3 — Investigation: building the Board’s report

Rule 7(2)(b) requires detailed information on the broad facts, events, circumstances, and reasons leading to the breach — along with any findings regarding the person who caused it. This is a forensic investigation obligation, not a narrative summary.

SIEM’s forensic investigation capability — correlated data stored in the security database across the full event timeline — enables investigators to reconstruct exactly what happened, when, in what sequence, and through which system.

Without a properly configured SIEM with log retention of at least one year (Rule 6(1)(e)), this reconstruction is impossible. With it, the investigation team can produce the full evidentiary basis for the Board’s report within the 72-hour window.

📣 Technology Step 4 — Data Principal Notification: automated and attributable

Rule 7(1) requires the Data Fiduciary to intimate each affected Data Principal without delay — through their registered user account or communication channel — with a description of the breach, its likely consequences, mitigation measures taken, safety steps they can take, and a contact point.

At scale — where a breach may affect thousands or millions of Data Principals — this notification is impossible to execute manually within any meaningful timeframe. Automated notification pipelines, triggered by the incident management system, must identify affected Data Principals from the breach scope, generate personalised communications in clear and plain language, and dispatch them immediately through the registered channel. Every notification must be logged as evidence for the Board’s report under Rule 7(2)(b)(vi).

⚠️ The penalty context — two separate ₹200 crore exposures

Failure to implement reasonable security safeguards including detection capabilities: up to ₹200 crore. Failure to notify the Board or affected Data Principals: up to ₹200 crore.

These are independent penalties under the DPDP Act Schedule — applicable simultaneously. A breach followed by delayed detection and missed notification creates a dual penalty exposure of up to ₹400 crore.

The technology stack that prevents this — SIEM, SOC, automated containment, forensic logging, and notification pipelines — is not a cost centre. It is the organisation’s single most important liability shield.

The four-step technology workflow your organisation needs:

🔍 Detection → SIEM + DLP + IDS generates real-time alert 🔒 Containment → Automated playbook isolates affected systems 🔬 Investigation → Forensic correlation builds the Board report 📣 Notification → Automated pipeline reaches affected Data Principals

Every step runs on technology. None of it can be done manually within 72 hours at scale.


Episode 6 of 9 | Technology & DPDP Compliance series Follow DSK Sustainability Tech LLP for the full series.

In association with our knowledge partners — Karthik & Sunil, Chartered Accountants.

Disclaimer

The contents of this post are intended for general awareness and informational purposes only. They do not constitute legal opinion, professional advice, consultancy, statutory interpretation, or a recommendation to act in any particular manner.

The Digital Personal Data Protection Act, 2023, related rules, notifications, regulatory guidance and judicial interpretations may evolve from time to time. The applicability of the law may also vary depending on the facts, sector, nature of data processing, organisational role, contractual terms and compliance framework.

Readers should not rely solely on this post for making legal, business, HR, technology, data-processing or compliance decisions. Specific advice from a qualified legal, privacy, cybersecurity, governance or compliance professional should be obtained before acting on any matter discussed.

The author / publisher shall not be responsible for any loss, liability, claim, penalty or consequence arising from reliance on the contents of this post without independent professional advice.

Leave a Reply

WP to LinkedIn Auto Publish Powered By : XYZScripts.com

Discover more from dsksustainabilitytech

Subscribe now to keep reading and get access to the full archive.

Continue reading