Back to the desk

Analysis

Data breach reporting in India: CERT-In's six-hour rule and the DPDP timeline explained

Severity: MediumIndiaPolicy2026-0929-IN05 min readBy Vivek Kumar
Conceptual illustration: policy documents and digital security imagery. Text: INDIA'S BREACH REPORTING RULES.

AI-generated editorial illustration by CyberShitty. Not a photograph or a document from the organisations named.

India has two breach-reporting regimes: CERT-In's six-hour rule, in force since 2022, and DPDP breach notice to a new Data Protection Board and affected people, which starts in May 2027.

01 / Two regimes, one breach

An organisation in India that suffers a data breach today answers to two separate reporting regimes. The first, run by the Indian Computer Emergency Response Team (CERT-In), has applied since 2022 and covers cyber incidents in general. The second, under the Digital Personal Data Protection (DPDP) Act, 2023 and the DPDP Rules, 2025, covers breaches of personal data and is being switched on in phases.

The two overlap but serve different ends. CERT-In reporting is about national cyber security and incident response. DPDP reporting is about the rights of the people whose data was exposed. A single ransomware attack that steals customer records can therefore trigger both. This explainer sets out what each regime requires, when it applies and what individuals can do. It is not legal advice.

02 / CERT-In: the six-hour rule

CERT-In issued its directions under section 70B(6) of the Information Technology Act, 2000 on 28 April 2022. They took effect 60 days after issue. They apply to service providers, intermediaries, data centres, body corporate and government organisations.

The core requirements are:

  • Report within 6 hours of noticing an incident, or of being told about it, by email to incident@cert-in.org.in, by phone or by fax.
  • Reportable incidents are listed in Annexure I. They include compromise of critical systems, unauthorised access to IT systems or data, website defacement, ransomware and other malicious code, identity theft and phishing, DDoS attacks, attacks on cloud, IoT and digital payment systems, and explicitly data breach and data leak.
  • Keep logs for 180 days. Logs of all ICT systems must be enabled and kept securely for a rolling 180 days within Indian jurisdiction, and handed to CERT-In when an incident is reported or on request.
  • Synchronise clocks to the NIC or NPL time servers, or to sources traceable to them.
  • Name a point of contact to deal with CERT-In.

Data centres, VPS, cloud and VPN providers must also keep validated subscriber details for five years. Virtual asset service providers must keep KYC and transaction records for five years. Failing to comply can lead to action under section 70B(7) of the IT Act.

03 / DPDP: telling the Board and the people affected

Parliament passed the DPDP Act on 11 August 2023. The DPDP Rules, 2025 were published in the Gazette under G.S.R. 846(E), dated 13 November 2025, and the government announced them on 14 November. Rule 7 sets out how a Data Fiduciary, the organisation that decides how personal data is used, must report a personal data breach.

  • To each affected person, without delay: a plain-language account of what happened, when and how much, the likely consequences for them, what the organisation is doing about it, steps they can take to protect themselves, and a contact person.
  • To the Data Protection Board, without delay: a first description of the breach covering its nature, extent, timing, location and likely impact.
  • To the Board within 72 hours: a detailed report covering the facts and causes, mitigation, any findings about who caused the breach, steps to prevent it happening again, and the notices sent to affected people. The Board can allow more time if asked in writing.

CERT-In asks for six hours; the DPDP Rules ask for a detailed report within 72 hours. A company needs to be ready for both.

Rule 7 applies to any personal data breach. It does not set a minimum level of harm before notice is required.

04 / When it all starts, and what it costs

The DPDP Rules come into force in stages, set out in Rule 1:

  • On publication (13 November 2025): Rules 1, 2 and 17 to 21, which set up and run the Data Protection Board.
  • After one year (November 2026): Rule 4, on consent managers.
  • After 18 months (May 2027): Rules 3, 5 to 16, 22 and 23. These include Rule 7 on breach reporting and the security safeguards in Rule 6.

So, as of September 2026, the DPDP duty to notify breaches has not yet started. The CERT-In six-hour rule already applies.

Under the Act, according to the Press Information Bureau, the largest penalty is up to ₹250 crore for failing to maintain reasonable security safeguards. Failing to notify the Board or affected people of a breach can draw up to ₹200 crore, as can breaching obligations towards children. Other violations can draw up to ₹50 crore. The Data Protection Board, which will be fully digital, imposes the penalties. Appeals go to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT).

05 / What companies should do now

  • Write one incident-response runbook that covers a CERT-In report within 6 hours and, from May 2027, DPDP notice to the Board and to affected people, including the 72-hour detailed report.
  • Check that ICT logs are switched on, kept for 180 days in India and synchronised to NIC/NPL time, so an investigation can rebuild a timeline.
  • Register and keep current the CERT-In point of contact. Name the person who will speak for the organisation to affected people.
  • Map where personal data sits, including with processors and SaaS vendors. Many 2026 breaches began at a contractor or third-party platform.
  • Draft plain-language notice templates now. Rule 7 specifies what they must contain.
  • Check sector rules as well. Regulators such as SEBI and RBI have their own reporting requirements for the entities they oversee.

06 / What individuals can do

  • If you are told your data was exposed, change passwords and turn on two-factor authentication, starting with email, banking and UPI apps.
  • Expect targeted phishing. Scammers often use leaked details to pose as the breached company, a bank or a government agency. Check any message through a channel you already know.
  • If you lose money to online fraud, call 1930, the national cyber fraud helpline, as soon as possible. Fast reports give the best chance of stopping the transfer.
  • Report cybercrime on the National Cyber Crime Reporting Portal at cybercrime.gov.in.
  • Once DPDP breach duties start, you can raise a grievance with the organisation first and then complain to the Data Protection Board through its online portal.

Source log / 2026-0929-IN

More from the archive