72-Hour Breach Notification: DPDP Playbook
What Triggers a Breach Notification?
Unauthorized access to personal data causing risk to individuals:
- Financial loss
- Identity theft
- Reputational harm
- Physical harm
- Emotional distress
Note: Authorized staff access is NOT a breach.
The 72-Hour Window
Clock starts: When you discover the breach
Deadline: Within 72 hours of discovery
Hour 0-1: Confirm & Respond
- Isolate affected systems
- Stop ongoing unauthorized access
- Preserve evidence (logs, forensic data)
- Activate incident response team
Hour 1-24: Investigate
- Determine breach scope (how many users, what data)
- Identify root cause
- Quantify risk to individuals
- Engage legal/compliance team
Hour 24-48: Prepare Notification
- Draft notification message
- Include: what data breached, risk, protective steps
- Prepare FAQ for users
- Set up communication channels
Hour 48-72: Notify Affected Individuals
- Email notification
- Phone calls for high-risk cases
- Social media announcement if widespread
- Website banner
Hour 72+: Regulatory Reporting
- Report to Data Protection Board (DPB)
- File formal incident report
- Continue investigation
Documentation
Maintain records:
- Breach discovery date/time
- Notification date/time (proof of compliance)
- List of affected individuals
- Notification method
- Regulatory reports submitted
- Remediation steps
- Forensic investigation report
Disclaimer: General informational article. Consult legal/forensic experts during breach. what is dpdp act 2023
Prepare Now: Start your free DPDP compliance assessment dpdp penalties explained dpdp vs gdpr DPDP Compliance Hub