Rule 7 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Rule 7(1) tells a Data Fiduciary what to do about each affected person after a personal data breach. It must tell her, in a concise, clear and plain manner and without delay, five things, through her user account or a mode of communication she registered with it.
Rule 7 is in the group that, under rule 1(4), comes into force eighteen months after the date of publication of the Gazette. On becoming aware of a breach, the Data Fiduciary must, as far as it knows, intimate each affected Data Principal without delay, in a concise, clear and plain manner, through her user account or registered mode of communication. The message covers the breach, consequences, mitigation, safety measures and a contact person. The Board is told separately under rule 7(2).
Rule 7(1) and the Act
Section 8(6) of the Act requires a Data Fiduciary to give the Board and each affected Data Principal an intimation of a personal data breach, in the form and manner prescribed. Rule 7 is that prescription; sub-rule (1) is the Data Principal's half and sub-rule (2) is the Board's half. The Act's text is covered in Section 8 of the DPDP Act: intimation of personal data breach. The Board's half is in our article on rule 7(2) and the seventy-two-hour report.
Commencement: rule 1(4) puts rule 7 among the rules that come into force "eighteen months after the date of publication of this Gazette". Counting from the Gazette date of 13 November 2025, eighteen months end in mid-May 2027; confirm the exact date of publication before relying on a date. The staging is explained in rules 1 and 2.
For businesses that must prepare a breach response plan, a dispute resolution and legal support team can help with the notice and the follow-up.
The opening words
In summary, on becoming aware of any personal data breach, the Data Fiduciary shall, as far as it knows, intimate to each affected Data Principal, in a concise, clear and plain manner and without delay, through her user account or any mode of communication registered by her with the Data Fiduciary. Taking the phrases one by one:
| Phrase | What it means in practice |
|---|---|
| "On becoming aware" | The duty starts when the Data Fiduciary becomes aware of the breach, not when the breach happened |
| "as far as it knows" | The message reflects what the Data Fiduciary knows at that point; it need not wait for a complete investigation |
| "each affected Data Principal" | Individual intimation, not a notice on the website alone |
| "concise, clear and plain" | Short, readable, clear of jargon |
| "without delay" | No number of hours is printed for the Data Principal, unlike the Board's seventy-two hours in rule 7(2)(b) |
| "user account or any mode of communication registered by her" | The channels: the user account (defined in rule 2(1)(c)) or what she registered |
The definition of "user account" in rule 2(1)(c) includes profiles, pages, handles, email address and mobile number; see rules 1 and 2. A Data Fiduciary that holds only an email address and a mobile number for a customer has both as registered modes.
The five items
The intimation must contain, under clauses (a) to (e):
- (a) A description of the breach, "including its nature, extent and the timing of its occurrence". Say what happened (for example, unauthorised access to a database), how much data and how many people, and when.
- (b) The consequences relevant to her "that are likely to arise from the breach". This is personal to the recipient: what could happen to her, given the data of hers that was affected.
- (c) The measures "implemented and being implemented by the Data Fiduciary, if any, to mitigate risk". The words "if any" accept that there may be none yet.
- (d) The safety measures that she may take "to protect her interests", such as changing a password or watching a card statement.
- (e) Business contact information "of a person who is able to respond on behalf of the Data Fiduciary, to queries, if any, of the Data Principal".
Note that item (e) works with rule 9, which requires every Data Fiduciary to publish business contact information; see our article on rule 9 and rule 14(3).
A worked example
BookNest, an invented online bookstore, finds that an unauthorised person copied the names, email addresses and order histories of customers who ordered in one month. It sends each affected customer a message through her account inbox and registered email. The message says what was copied and when (clause (a)); that she may receive phishing mails referring to her past orders (b); that BookNest has reset access keys and engaged a security firm (c); that she should be wary of unexpected links and may change her password (d); and gives a named contact and phone number at BookNest (e). The Rules contain no Illustration for rule 7; this example is ours.
What rule 7(1) does not say
- It does not set a number of hours for the Data Principal's intimation; only "without delay".
- It does not prescribe a form, a template or a language.
- It does not tell the Data Fiduciary to wait for the Board before informing individuals. The Board's report is a separate duty.
- It does not say what counts as a "personal data breach"; that term has the Act's meaning under rule 2(2). For the Act's definitions see section 2 definitions.
- It states no penalty. For penalties see the Schedule to the Act and section 33 on monetary penalty.
For general context on breach duties written before the Rules, see data breach notification under the DPDP Act. It was written before the Rules were notified, so rely on the Rules for periods and steps.
Need help with a breach response?
A breach message goes to many customers at once and may be read by the Board later. Talk to our team on dispute resolution about drafting a response plan and the message itself before an incident occurs.
Key takeaways
- Rule 7 starts eighteen months after the date of publication of the Gazette (rule 1(4)).
- Each affected Data Principal is told, without delay, in a concise, clear and plain manner.
- The channel is her user account or any mode of communication she registered.
- The message has five items: description, consequences relevant to her, mitigation measures, safety measures she can take, and business contact information.
- The Board is told separately under rule 7(2).
- Later amendments and notifications should be checked.
Read next
- Rule 7(2): intimation to the Board within seventy-two hours
- Rule 6: reasonable security safeguards
- Section 8 of the DPDP Act: intimation of personal data breach
- Data breach notification under the DPDP Act
Disclaimer: Based on the Digital Personal Data Protection Rules, 2025 as notified in the Gazette of India on 13 November 2025 (G.S.R. 846(E)), as consulted on 2 October 2026. The Rules come into force in three stages under rule 1; later amendments, notifications and anything published by the Data Protection Board of India should be checked. This article is general information, not legal advice; check the official text before acting.
