Next due
11 OCTGSTR-1 · Outward supplies · Sep 2026in 2 days 15 OCTPF & ESI · Contributions · Sep 2026in 6 days 20 OCTGSTR-3B · Summary return · Sep 2026in 11 days 21 OCTTax Audit Report · Form 3CA/3CB · AY 2026-27 · extended from 30 Sepin 12 days 30 OCTAOC-4 · Financial statements · FY 2025-26in 21 days 7 NOVTDS / TCS deposit · Deducted in Oct 2026in 29 days 21 NOVITR filing · Audit cases · AY 2026-27 · extended from 31 Octin 43 days 29 NOVMGT-7 / 7A · Annual return · FY 2025-26in 51 days
All due dates

Rule 7(1) of the Digital Personal Data Protection Rules, 2025: intimation of a personal data breach to affected Data Principals

Rule 7 is in the group that, under rule 1(4), comes into force eighteen months after the date of publication of the Gazette. On becoming aware of a breach, the Data Fiduciary...

Published
Updated
Reading time
7 min
Views
11
Questions
6 answered
  • Expert Reviewed
  • Medium Complexity
Topic
Data Protection
Published
October 2, 2026
Last updated
Oct 7, 2026
Reading time
7 min
0:00
Last updated: October 2026Verified against: Government sources

Rule 7(1) tells a Data Fiduciary what to do about each affected person after a personal data breach. It must tell her, in a concise, clear and plain manner and without delay, five things, through her user account or a mode of communication she registered with it.

Rule 7(1) and the Act

Section 8(6) of the Act requires a Data Fiduciary to give the Board and each affected Data Principal an intimation of a personal data breach, in the form and manner prescribed. Rule 7 is that prescription; sub-rule (1) is the Data Principal's half and sub-rule (2) is the Board's half. The Act's text is covered in Section 8 of the DPDP Act: intimation of personal data breach. The Board's half is in our article on rule 7(2) and the seventy-two-hour report.

Commencement: rule 1(4) puts rule 7 among the rules that come into force "eighteen months after the date of publication of this Gazette". Counting from the Gazette date of 13 November 2025, eighteen months end in mid-May 2027; confirm the exact date of publication before relying on a date. The staging is explained in rules 1 and 2.

For businesses that must prepare a breach response plan, a dispute resolution and legal support team can help with the notice and the follow-up.

The opening words

In summary, on becoming aware of any personal data breach, the Data Fiduciary shall, as far as it knows, intimate to each affected Data Principal, in a concise, clear and plain manner and without delay, through her user account or any mode of communication registered by her with the Data Fiduciary. Taking the phrases one by one:

PhraseWhat it means in practice
"On becoming aware"The duty starts when the Data Fiduciary becomes aware of the breach, not when the breach happened
"as far as it knows"The message reflects what the Data Fiduciary knows at that point; it need not wait for a complete investigation
"each affected Data Principal"Individual intimation, not a notice on the website alone
"concise, clear and plain"Short, readable, clear of jargon
"without delay"No number of hours is printed for the Data Principal, unlike the Board's seventy-two hours in rule 7(2)(b)
"user account or any mode of communication registered by her"The channels: the user account (defined in rule 2(1)(c)) or what she registered

The definition of "user account" in rule 2(1)(c) includes profiles, pages, handles, email address and mobile number; see rules 1 and 2. A Data Fiduciary that holds only an email address and a mobile number for a customer has both as registered modes.

The five items

The intimation must contain, under clauses (a) to (e):

  1. (a) A description of the breach, "including its nature, extent and the timing of its occurrence". Say what happened (for example, unauthorised access to a database), how much data and how many people, and when.
  2. (b) The consequences relevant to her "that are likely to arise from the breach". This is personal to the recipient: what could happen to her, given the data of hers that was affected.
  3. (c) The measures "implemented and being implemented by the Data Fiduciary, if any, to mitigate risk". The words "if any" accept that there may be none yet.
  4. (d) The safety measures that she may take "to protect her interests", such as changing a password or watching a card statement.
  5. (e) Business contact information "of a person who is able to respond on behalf of the Data Fiduciary, to queries, if any, of the Data Principal".

Note that item (e) works with rule 9, which requires every Data Fiduciary to publish business contact information; see our article on rule 9 and rule 14(3).

A worked example

BookNest, an invented online bookstore, finds that an unauthorised person copied the names, email addresses and order histories of customers who ordered in one month. It sends each affected customer a message through her account inbox and registered email. The message says what was copied and when (clause (a)); that she may receive phishing mails referring to her past orders (b); that BookNest has reset access keys and engaged a security firm (c); that she should be wary of unexpected links and may change her password (d); and gives a named contact and phone number at BookNest (e). The Rules contain no Illustration for rule 7; this example is ours.

What rule 7(1) does not say

  • It does not set a number of hours for the Data Principal's intimation; only "without delay".
  • It does not prescribe a form, a template or a language.
  • It does not tell the Data Fiduciary to wait for the Board before informing individuals. The Board's report is a separate duty.
  • It does not say what counts as a "personal data breach"; that term has the Act's meaning under rule 2(2). For the Act's definitions see section 2 definitions.
  • It states no penalty. For penalties see the Schedule to the Act and section 33 on monetary penalty.

For general context on breach duties written before the Rules, see data breach notification under the DPDP Act. It was written before the Rules were notified, so rely on the Rules for periods and steps.

Need help with a breach response?

A breach message goes to many customers at once and may be read by the Board later. Talk to our team on dispute resolution about drafting a response plan and the message itself before an incident occurs.

Key takeaways

  • Rule 7 starts eighteen months after the date of publication of the Gazette (rule 1(4)).
  • Each affected Data Principal is told, without delay, in a concise, clear and plain manner.
  • The channel is her user account or any mode of communication she registered.
  • The message has five items: description, consequences relevant to her, mitigation measures, safety measures she can take, and business contact information.
  • The Board is told separately under rule 7(2).
  • Later amendments and notifications should be checked.

Read next

Disclaimer: Based on the Digital Personal Data Protection Rules, 2025 as notified in the Gazette of India on 13 November 2025 (G.S.R. 846(E)), as consulted on 2 October 2026. The Rules come into force in three stages under rule 1; later amendments, notifications and anything published by the Data Protection Board of India should be checked. This article is general information, not legal advice; check the official text before acting.

Quick recapKey facts & short answers

Key Facts About Rule 7

  • Applies in: All states across India, under the relevant central law.
  • Mode: Mostly online via the official government portal.
  • Typical timeline: Ranges from a few days to a few weeks depending on the case.
  • Non-compliance: May attract penalties, interest or late fees.
  • Expert help: TaxClue completes the entire process end to end for you.

What must a breach message to a customer contain?

A description of the breach (nature, extent, timing), the likely consequences relevant to her, the mitigation measures, the safety measures she may take, and a business contact for queries.

How fast must a Data Principal be told?

"Without delay". Rule 7(1) prints no number of hours.

What is not written down will be remembered differently by everyone involved.

— TaxClue Compliance Desk

Rule 7: a key compliance topic in Indian tax and corporate law that businesses and individuals must understand to remain compliant.

Related Services & Guides

Was this article helpful?
About the author
13,350 articles
Vikas Sharma Verified expert Tax & Compliance Expert

Experienced in company registration, GST, trademark, and compliance. Helping Indian businesses stay compliant.

Last reviewed: Live

Disclaimer: This article is for general informational purposes only and does not constitute professional tax, legal or financial advice. Laws, rates and due dates change and can vary by individual case — always verify with the relevant government source (e.g. mca.gov.in, incometax.gov.in) or consult a qualified professional before acting. TaxClue accepts no liability for decisions taken based on this content.

People also ask

Questions, answered

Short, direct answers to the 6 questions readers ask most on this topic.

A description of the breach (nature, extent, timing), the likely consequences relevant to her, the mitigation measures, the safety measures she may take, and a business contact for queries.

"Without delay". Rule 7(1) prints no number of hours.

Rule 7(1) speaks of intimation to "each affected Data Principal" through her user account or registered mode of communication.

The duty is "as far as it knows". Further detail goes to the Board in the updated report under rule 7(2)(b).

Rule 7(1) speaks of "each affected Data Principal". The Rule does not elaborate on a breach that affects none.

Section 8(6).