DPDP breach detection and the 72-hour rule
Under the DPDP Act, you must notify the Data Protection Board of India and affected users when a personal data breach occurs. To do that, you first have to know a breach happened, which means detection has to be built into the product in advance. A breach covers any loss of confidentiality, integrity, or availability, not only an external hack.
The question most breach planning skips
Most breach planning starts at the notification step and skips the harder question: how would you even know? You cannot report what you cannot detect, and detection is not automatic. It has to be instrumented before anything goes wrong.
What detection means in practice
- ✓Logging and alerting on unusual data access.
- ✓Monitoring for unexpected exports.
- ✓Detecting failed-then-successful intrusion patterns.
- ✓Tracking changes to permissions.
- ✓Alerting on loss of access to systems that hold personal data.
The notification runbook
Once you can detect, the notification runbook has to be ready to run. Who is told, in what order, within what window. What information goes to the Board and what goes to affected users. Who decides, who drafts, who sends. A breach is the worst time to design this process, so it is written and rehearsed in advance.
"Detection instrumentation plus a documented notification runbook turns a breach from a crisis into a procedure."
The penalty for silence
Failure to report a personal data breach can draw up to INR 200 crore, separate from any penalty for the breach itself. The silence is its own offence.
Next step
Ready to scope the work?
Book a free 30-minute call. We will map your gaps and tell you exactly what needs building.
Written by Smoketrees Digital LLP, a product engineering studio based in Bengaluru. We implement DPDP compliance directly into codebases for Indian product companies.