Glossary · Personal Data Breach

What Is a Personal Data Breach Under DPDPA?

From a leaked spreadsheet to ransomware, DPDPA treats unauthorised loss or disclosure of personal data as a Personal Data Breach — and starts four notification lanes the moment you discover it.

Last reviewed: 14 August 2026

Definition

A Personal Data Breach is any unauthorised processing of personal data — or any accidental disclosure, acquisition, sharing, use, alteration, destruction, or loss of access to it — that compromises its confidentiality, integrity, or availability. It's defined under Section 2(u) of the DPDPA, 2023. In plain terms: a hacked database, a stolen laptop, an employee emailing customer records to the wrong person, or ransomware locking your files all count. Critically, the definition doesn't distinguish between malicious attacks and honest mistakes — and unlike GDPR, DPDPA requires you to notify every breach, regardless of how minor the risk seems.

How this matters in practice

A personal data breach starts four lanes at once: CERT-In within 6 hours, each affected Data Principal without delay (Rule 7(1)), an initial Board intimation without delay (Rule 7(2)(a)), and a detailed Board report within 72 hours (Rule 7(2)(b)) — impossible without a pre-built playbook. Privigo prepares your breach-response plan, notification templates, and the security-safeguard documentation that reduces penalty exposure. Our free gap analysis flags your weakest points first. Fully remote delivery, anywhere in India.

Frequently asked questions

Who must I notify after a data breach, and how fast?

Four lanes run together, not as alternatives. CERT-In within 6 hours of becoming aware; Rule 7(1) intimation to each affected Data Principal without delay; Rule 7(2)(a) initial intimation to the Data Protection Board without delay; and Rule 7(2)(b) the detailed report to the Board within 72 hours covering nature, cause, mitigation and remedial measures. Section 8(6) is the Act-level duty. Failure to notify sits in a separate Schedule slab of up to ₹200 crore.

Do I have to report even small breaches with no real harm?

Yes. DPDPA has no risk-based threshold — unlike GDPR, which exempts breaches unlikely to harm individuals, the Indian law requires notifying every personal data breach to affected users and the Board. This makes detection capability and a ready notification process essential even for small businesses.

What are the penalties related to data breaches?

Two separate exposures under the Act's Schedule: up to ₹250 crore for failing to maintain reasonable security safeguards that would have prevented the breach, and up to ₹200 crore for failing to notify the Board or affected individuals. Prompt notification and documented safeguards are also mitigating factors under Section 33.

Official sources

Build a breach playbook before you need one

Book a 30-minute call to map the four notification lanes, templates, and security evidence so CERT-In's 6-hour clock and both Board intimations are achievable.

Book a demo Free Gap Analysis

Disclaimer: Privigo is not a law firm. This page provides operational compliance guidance only. For institution-specific obligations, work with qualified Indian legal counsel.