Independent DPDP educationBrowser-only workspace · no accounts, analytics or submissions

01 Breach response

What the 72-hour breach detail window changes in incident response

The detailed Board update is one step in a wider response sequence. Teams need an awareness decision, an immediate evidence path and a disciplined way to update uncertain facts.

The incident evidence clock

Awareness, immediate communication, detailed update and recurrence work are connected but distinct tracks.

The incident evidence clockAwareness, immediate communication, detailed update and recurrence work are connected but distinct tracks.01Signalalert · report · provider02Awarenessdecision · time · rationale03Without delaypeople · Board · known facts04Detail windowupdate · reasons · measures05Recoveryremedy · recurrence · record
  1. 01
    Signalalert · report · provider
  2. 02
    Awarenessdecision · time · rationale
  3. 03
    Without delaypeople · Board · known facts
  4. 04
    Detail windowupdate · reasons · measures
  5. 05
    Recoveryremedy · recurrence · record
Editorial operating model. Replace it with your evidenced systems, owners and decisions.

02 Provision-aware reading

Three states that must not be flattened.

01Operative

What is operative now

· in force

Selected definitions, institutional machinery and rule-making provisions are in force. That does not make every substantive operating duty discussed in this article currently operative.

Check the phased ledger
02Scheduled · 18 months

What is notified for later

· notified future commencement

Most day-to-day Data Fiduciary duties discussed here sit in the notified eighteen-month cohort. The displayed date is derived from the status ledger and must be rechecked against later instruments.

Check the phased ledger

Rule 7 of the final Rules separates several actions. Affected Data Principals are to be informed without delay with specified information. The Board receives an initial description without delay, followed by updated and detailed information within seventy-two hours of awareness, unless the Board allows a longer period on a written request. Treating this as one deadline loses the structure of the rule.

Operational readiness therefore begins before the clock. The organisation needs a defensible awareness decision, access to system and provider evidence, named drafting and approval roles, and a method for recording how facts changed. This article describes an incident workflow; it does not determine whether a particular event is a personal data breach or whether a specific notification is legally sufficient.

Read the sequence before designing the clock

A timer alone is the wrong control. Rule 7 describes different recipients and information sets. The affected person communication addresses the breach, relevant consequences, mitigation, safety measures and a business contact. The Board path begins with a description without delay and then asks for updated detail, including facts, causes, mitigation, findings about the person who caused the breach, recurrence measures and a report on affected-person intimations.

The seventy-two-hour period runs from awareness for the detailed Board information, subject to a written-extension route that the Board may allow. The workflow should therefore display the source text and current status, avoid promising an extension and preserve what was known at each decision point.

Define awareness as an accountable decision

Signals arrive imperfectly: a cloud alert, customer report, vendor message, lost device or unusual export. The team needs a triage record that distinguishes receipt of a signal from the point at which available facts support awareness of a personal data breach. Record time, decision-maker, evidence considered, uncertainty and the next review. Do not manipulate the definition to delay work.

Set internal escalation thresholds that favour early investigation. Security, privacy, product and operations should know who can make the awareness decision and who acts if that person is unavailable. Run exercises outside office hours and include provider delay, missing logs and conflicting counts.

Build an evidence packet that can change safely

Open one incident record with controlled sections for scope, systems, data categories, people affected, locations, timeline, containment, likely impact, communication, provider evidence and decisions. Give every material fact a source and confidence state. Preserve earlier versions so corrections look like disciplined learning rather than concealed inconsistency.

Do not copy raw credentials, complete logs or unnecessary personal data into the management record. Link to approved forensic repositories with access controls. Record when evidence is unavailable because a log was disabled, a provider has not responded or an export cannot be reconciled; those gaps may shape both response and remediation.

Prepare communications as parallel workstreams

Affected-person communication should be plain, usable and specific to what is known. Draft safety measures that the person can reasonably take, provide a monitored contact and avoid minimising uncertainty. Accessibility, language and channel availability matter. A generic legal paragraph sent to an unmonitored address is not an operating response.

The Board record needs owners for the immediate description, detailed update and any written request for more time. Pre-build source-aware outlines, not fictional completed notices. Approval paths should be short, with a documented delegate. Communications, containment and investigation proceed together; none should wait for a perfect final narrative.

Make providers part of the response design

A Data Processor may see the first signal or hold essential logs, but the Data Fiduciary needs a response it can operate. Contract language should connect to a tested contact path, severity scheme, evidence format, preservation step and update cadence. Record sub-processors and time zones. A promise to notify “promptly” is weak if nobody knows which inbox is monitored.

Exercise a scenario in which the provider gives incomplete information. Can the team identify affected systems and persons from its own records? Can it preserve tokens, exports and logs? Does the provider understand the evidence needed for affected-person and Board communications? Capture the answer and the contract or architecture gap.

Close with recurrence evidence, not only a report

The detailed information includes remedial measures to prevent recurrence. Connect each finding to a control owner, change, test and residual risk decision. Verify that restored backups do not reintroduce the vulnerable state and that access or token changes reached connected systems. Preserve the affected-person communication report and later corrections.

Review the exercise after material architecture, provider or staffing changes. The objective is not to guarantee a deadline; it is to create a response that can surface facts quickly, communicate honestly and keep a defensible timeline under pressure.

Put the next review into somebody's working queue.

A role label is a starting point. Assign named internal owners, evidence locations and review dates in an approved system; this site stores none of them.

01

Founder

  • Confirm executive delegate and after-hours escalation.
  • Remove approval layers that block urgent evidence-led communication.
02

Legal / Privacy

  • Maintain source-aware communication outlines and decision records.
  • Review awareness, affected-person and Board tracks separately.
03

IT / Security

  • Preserve logs, scope systems and document containment times.
  • Test provider evidence and backup recovery before an incident.
04

Product / Engineering

  • Map identifiers to affected features and users.
  • Implement recurrence fixes with verifiable tests.
05

Operations

  • Maintain monitored contacts and communication channels.
  • Record support signals, downstream actions and affected-person queries.

The window rewards prepared evidence

Seventy-two hours is not a substitute for the without-delay steps, and it is not a reason to wait. Prepare the awareness decision, evidence packet, recipient-specific communications and provider path as one operating system.

The provisions remain in a notified future cohort in this preview’s source record. Use exercises to improve readiness, then obtain qualified advice for a real event.

Sources and change log

Gazette instruments govern the text and commencement. Government explainers are contextual; this field note remains editorial analysis.

  1. Act No. 22 of 2023Digital Personal Data Protection Act, 2023

    Section 8(6) and definition of personal data breach in section 2

  2. G.S.R. 846(E)Digital Personal Data Protection Rules, 2025

    Rule 6: reasonable security safeguards, logs, monitoring, backups and processor contract measures

  3. G.S.R. 846(E)Digital Personal Data Protection Rules, 2025

    Rule 7(1)–(2), Gazette pages 25–26: affected-person and Board intimations

  4. G.S.R. 843(E)DPDP Act commencement notification

    Paragraph (c): substantive breach provisions in the eighteen-month cohort

  5. G.S.R. 892(E)Corrigendum to the Digital Personal Data Protection Rules, 2025

    Corrigendum review: no change to Rule 7 timing summarised here

Change log

Initial private-preview article created against the final Rules, commencement notification and published corrigendum.

Human-review gate: pinpoints, status and fact-specific interpretations must be rechecked before public reliance.

12 Continue with evidence

Turn the reading into a bounded operating record.

Use a template, inspect the mapped controls or answer the readiness assessment with only what your team can retrieve.

Operating templates32-control catalogue90-day route