Law note · India
Digital Personal Data Protection Act, 2023, breach notification duties
What it requires
- India's data-breach notification duty, covering personal data including a biometric identifier, has not yet commenced and is scheduled to take effect 13 May 2027. Once in force, an app must notify the Data Protection Board and each affected data principal of a personal data breach without delay, and must supply the Board a detailed follow-up report within 72 hours of becoming aware of the breach.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotprocesses_biometricsprocesses_voice
What we found
Section 8(6) requires a Data Fiduciary to give the Board and each affected Data Principal intimation of a personal data breach, in the form and manner prescribed. Rule 7 fills in that detail: notify each affected Data Principal without delay, notify the Board without delay with an initial description, then supply a detailed follow-up report within 72 hours of becoming aware of the breach, or such longer period as the Board allows.
Neither provision is currently in force: s.8 sits in the sections-3-to-17 bucket, appointed by Notification G.S.R. 843(E) (13 November 2025) to commence eighteen months after its own publication date, 13 May 2027; Rule 7 sits in the parallel rules-3-to-16 bucket, appointed to the same 13 May 2027 date by the Rules' own Rule 1(4).