Law note · India

Digital Personal Data Protection Act, 2023, breach notification duties

cite Digital Personal Data Protection Act, 2023 (DPDPA), No. 22 of 2023, breach notification, s.8(6) stage IMMINENT in force in 256 days effective 2027-05-13 kind Breach notification binds public and private bodies reviewed 2026-08-29

What it requires

  • India's data-breach notification duty, covering personal data including a biometric identifier, has not yet commenced and is scheduled to take effect 13 May 2027. Once in force, an app must notify the Data Protection Board and each affected data principal of a personal data breach without delay, and must supply the Board a detailed follow-up report within 72 hours of becoming aware of the breach.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • processes_biometrics
  • processes_voice

What we found

Section 8(6) requires a Data Fiduciary to give the Board and each affected Data Principal intimation of a personal data breach, in the form and manner prescribed. Rule 7 fills in that detail: notify each affected Data Principal without delay, notify the Board without delay with an initial description, then supply a detailed follow-up report within 72 hours of becoming aware of the breach, or such longer period as the Board allows.

Neither provision is currently in force: s.8 sits in the sections-3-to-17 bucket, appointed by Notification G.S.R. 843(E) (13 November 2025) to commence eighteen months after its own publication date, 13 May 2027; Rule 7 sits in the parallel rules-3-to-16 bucket, appointed to the same 13 May 2027 date by the Rules' own Rule 1(4).

← Back to the example  ·  Lint your app →