27.  STEP 10 – Set up breach response and notification
ISSUE #110Published: 10/3/2026

27. STEP 10 – Set up breach response and notification

Ankur Srivastava

Ankur Srivastava

Deputy-CISO / CISSP

Cyber Security & Business Continuity Expert with over 15 years of experience orchestrating InfoSec Governance, risk mitigation frameworks, and disaster recovery architectures. CISSP | M.S. in Cyber Laws & Information Security (IIIT).

Access Price

₹40
Preview

Description

Step 10 of DPDPA compliance is building your breach response and notification plan under Rule 7—you must inform both the Data Protection Board and affected individuals without delay.

Report basic breach details immediately, then submit updated facts, mitigation steps, root cause, and remedial actions within 72 hours of becoming aware.

Create a Personal Data Breach Management SOP covering what counts as a breach, internal escalation, triage, notification templates, and reporting to users and the Board.

Penalties are steep: ₹250 crore for failing to implement security safeguards and ₹200 crore for failing to notify a breach