Breach management · DPDP S. 8(5), 8(6) · Rule 7

Report a personal data breach before the clock runs out.

When you become aware of a breach, the Rules start two duties at once: tell each affected person without delay, and tell the Data Protection Board. The detailed report is due within 72 hours. Promiz keeps the clock, the facts and the proof in one place.

72 h
for the detailed report to the Board
₹200 cr
maximum penalty for failing to notify
1
record for facts, notices and the Rule 7 report
Breach B-0012 · Severity high 41 hleft of 72 h ✓ Aware: 22 Sep, 09:10 ✓ Initial intimation to Board ✓ 1,240 people notified ○ Detailed report due ○ Root cause and fixes Rule 7 report ready to generate from your entries
Figure 1. A breach record with its countdown. Sample data.
What the law asks

What does Rule 7 ask you to do after a breach?

Rule 7 has two tracks that start together when you become aware of the breach. There is no order between them.

RequirementSourceWhat it meansHow Promiz helps
Tell each affected person Rule 7(1) Without delay, through their user account or registered contact. Describe the breach, likely consequences, your mitigation, safety steps they can take, and a contact. Record who is affected and track each notification you send.
Initial intimation to the Board Rule 7(2)(a) Without delay. Nature, extent, timing, location and likely impact. Log the breach with severity, scope and timing the moment you know.
Detailed report to the Board Rule 7(2)(b) Within 72 hours, or longer if the Board allows on written request. Updated facts, causes, mitigation, findings on who caused it, remedial steps, and a report on notices to people. A 72-hour countdown and a structured Rule 7 report built from your entries.
Reasonable security safeguards S. 8(5) · Rule 6 Protect personal data with safeguards such as encryption, access control and logs. Encryption, one-way codes, per-business isolation and an audit trail inside Promiz.
Penalty for not notifying Schedule Up to ₹200 crore for failing to notify the Board and affected people. Visible deadlines so notices are not missed.

Sources: Digital Personal Data Protection Act, 2023, sections 8(5) and 8(6) and the Schedule; DPDP Rules, 2025, Rules 6 and 7. CERT-In reporting under the IT Act is a separate duty with its own, shorter timeline.

In Promiz

How does Promiz run a breach response?

Log the breach the moment you become aware of it. The 72-hour clock in Promiz starts when you log it.

Breach response in Promiz Hour 0Log the breachSeverity, scope,timingWithout delayNotifyBoard and eachaffected personAs you goInvestigateCauses, fixes,notesTrackNotificationsWho was told,and whenBy 72 hRule 7 reportBuilt fromyour entries
Figure 2. The two Rule 7 tracks in one record.
  1. Step 1 Log the breach

    Record severity, who is affected and when you became aware. The countdown starts on screen.

  2. Step 2 Notify without delay

    Send the initial intimation to the Board and notices to affected people through your own channels. Record each one in Promiz.

  3. Step 3 Investigate

    Record causes, containment and remediation notes as they happen.

  4. Step 4 Track every notice

    Keep a log of each notification: to whom, how and when.

  5. Step 5 Generate the Rule 7 report

    Promiz builds the structured report from what you recorded.

Capabilities

What does the Breach module give you?

A visible 72-hour countdown

The clock shows on the breach record from the moment you log it, so nobody has to calculate it.

One record for the facts

Severity, people affected, timing, investigation notes and remediation, in one place.

Notification tracking

A record of each notification you send to the Board and to people.

Structured Rule 7 report

Promiz builds the report from your entries, so the content matches what you recorded.

Linked to your consent data

The same platform holds your notices, purposes, vendors and trackers, so you can see what data and which vendors are involved.

Audit trail

Every admin action on the breach record is written to the tamper-evident audit trail.

Compare

Why not run a breach from email and a spreadsheet?

Task Email, spreadsheets and a basic banner Promiz
Know the deadline Calculated by hand Countdown on the record
Keep one set of facts Spread across threads One breach record
Show who was told and when Search sent mail Notification log
Write the Rule 7 report Start from a blank page Structured report from your entries
FAQ

Breach management: frequent questions

Not answered here? Ask us in a demo.

How long do we have to report a personal data breach under the DPDP Act?

You must tell the Board and each affected person without delay. The detailed report to the Board is due within 72 hours of becoming aware of the breach, or longer if the Board allows on written request.

What goes in the 72-hour report?

Updated facts, the circumstances and reasons, mitigation, findings on who caused the breach, steps to prevent it again, and a report on the notices sent to affected people.

When does the 72-hour clock start?

When you become aware of the breach. In Promiz, the countdown starts when you log it, so log it as soon as you know.

Does Promiz send the notices for us?

No. You send notices through your own channels. Promiz tracks each notification and builds the Rule 7 report.

What is the penalty for not reporting a breach?

Up to ₹200 crore for failing to notify the Board and affected people. Failing to take reasonable security safeguards can reach ₹250 crore.

Run a breach drill with us.

In 30 minutes we log a sample breach, run the clock and build the Rule 7 report with you.

Book a 30-minute demo We reply within 1 business day.

This page explains the law in plain words. It is not legal advice. Your legal team decides how the Act applies to you. Last reviewed 21 September 2026.