Report a personal data breach before the clock runs out.
When you become aware of a breach, the Rules start two duties at once: tell each affected person without delay, and tell the Data Protection Board. The detailed report is due within 72 hours. Promiz keeps the clock, the facts and the proof in one place.
- 72 h
- for the detailed report to the Board
- ₹200 cr
- maximum penalty for failing to notify
- 1
- record for facts, notices and the Rule 7 report
What does Rule 7 ask you to do after a breach?
Rule 7 has two tracks that start together when you become aware of the breach. There is no order between them.
Sources: Digital Personal Data Protection Act, 2023, sections 8(5) and 8(6) and the Schedule; DPDP Rules, 2025, Rules 6 and 7. CERT-In reporting under the IT Act is a separate duty with its own, shorter timeline.
How does Promiz run a breach response?
Log the breach the moment you become aware of it. The 72-hour clock in Promiz starts when you log it.
- Step 1 Log the breach
Record severity, who is affected and when you became aware. The countdown starts on screen.
- Step 2 Notify without delay
Send the initial intimation to the Board and notices to affected people through your own channels. Record each one in Promiz.
- Step 3 Investigate
Record causes, containment and remediation notes as they happen.
- Step 4 Track every notice
Keep a log of each notification: to whom, how and when.
- Step 5 Generate the Rule 7 report
Promiz builds the structured report from what you recorded.
What does the Breach module give you?
A visible 72-hour countdown
The clock shows on the breach record from the moment you log it, so nobody has to calculate it.
One record for the facts
Severity, people affected, timing, investigation notes and remediation, in one place.
Notification tracking
A record of each notification you send to the Board and to people.
Structured Rule 7 report
Promiz builds the report from your entries, so the content matches what you recorded.
Linked to your consent data
The same platform holds your notices, purposes, vendors and trackers, so you can see what data and which vendors are involved.
Audit trail
Every admin action on the breach record is written to the tamper-evident audit trail.
Why not run a breach from email and a spreadsheet?
How long do we have to report a personal data breach under the DPDP Act?
You must tell the Board and each affected person without delay. The detailed report to the Board is due within 72 hours of becoming aware of the breach, or longer if the Board allows on written request.
What goes in the 72-hour report?
Updated facts, the circumstances and reasons, mitigation, findings on who caused the breach, steps to prevent it again, and a report on the notices sent to affected people.
When does the 72-hour clock start?
When you become aware of the breach. In Promiz, the countdown starts when you log it, so log it as soon as you know.
Does Promiz send the notices for us?
No. You send notices through your own channels. Promiz tracks each notification and builds the Rule 7 report.
What is the penalty for not reporting a breach?
Up to ₹200 crore for failing to notify the Board and affected people. Failing to take reasonable security safeguards can reach ₹250 crore.
Run a breach drill with us.
In 30 minutes we log a sample breach, run the clock and build the Rule 7 report with you.
This page explains the law in plain words. It is not legal advice. Your legal team decides how the Act applies to you. Last reviewed 21 September 2026.