Rule 7 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Rule 7(2) is the Board's half of the breach duty. A Data Fiduciary that becomes aware of a personal data breach must tell the Board in two steps: a description without delay, then six items of detail within seventy-two hours of becoming aware, or within a longer period the Board allows on a written request.
Rule 7 is in the group that, under rule 1(4), comes into force eighteen months after the date of publication of the Gazette. On becoming aware of a breach the Data Fiduciary intimates the Board without delay (nature, extent, timing, location and likely impact), and then within seventy-two hours, or a longer period the Board allows on a written request, gives the six items in clause (b), including a report on the intimations given to Data Principals.
Rule 7(2) and the Act
Section 8(6) of the Act requires intimation of a personal data breach to the Board and to each affected Data Principal in the manner prescribed. The Act's text is in Section 8 of the DPDP Act: intimation of personal data breach. The Data Principal's half is in our article on rule 7(1). This article covers only sub-rule (2).
Commencement: rule 1(4) puts rule 7 in the group that comes into force "eighteen months after the date of publication of this Gazette". Counting from the Gazette date of 13 November 2025, eighteen months end in mid-May 2027; confirm the exact date of publication before relying on a date. The three stages are set out in rules 1 and 2.
A breach report is a document that the Board may read closely. A team that has dispute resolution support lined up before an incident can answer in the time the Rule allows.
The two steps
| Step | When | What is given | Rule |
|---|---|---|---|
| 1 | "without delay" | A description of the breach, including its nature, extent, timing and location of occurrence and the likely impact | 7(2)(a) |
| 2 | "within seventy-two hours of becoming aware of the breach, or within such longer period as the Board may allow on a request made in writing" | Six items, (i) to (vi) | 7(2)(b) |
Both steps run from the same moment: "On becoming aware of any personal data breach". The seventy-two hours are counted "of becoming aware of the breach", not from the end of the investigation or from the breach itself.
Step 1: the description without delay
Clause (a) asks for "a description of the breach, including its nature, extent, timing and location of occurrence and the likely impact". Compare rule 7(1)(a) for Data Principals, which asks for nature, extent and timing but not location, and which lists consequences "relevant to her" separately. For the Board there are five elements: nature, extent, timing, location and likely impact. "Without delay" has no number of hours. The Rule does not say that the first description must be complete; it follows that the seventy-two-hour report is where updated detail goes.
Step 2: the six items
Within seventy-two hours (or the longer period), the Data Fiduciary gives:
- (i) "updated and detailed information in respect of such description";
- (ii) "the broad facts related to the events, circumstances and reasons leading to the breach";
- (iii) "measures implemented or proposed, if any, to mitigate risk";
- (iv) "any findings regarding the person who caused the breach";
- (v) "remedial measures taken to prevent recurrence of such breach"; and
- (vi) "a report regarding the intimations given to affected Data Principals".
Item (vi) joins the two halves of rule 7. By the time the Board's detailed report is due, the Data Fiduciary should have sent, or be sending, the messages required by rule 7(1), and it must report on them. A Data Fiduciary that has not told Data Principals has to say so in that report.
Item (iv) asks for "any findings", which means what the investigation has found so far. If no finding about the person who caused the breach exists at seventy-two hours, the text does not say what to write; the sensible course is to state that none has yet been made. The Rule is silent on the point.
The longer period
The seventy-two hours can be extended only by the Board, and only "on a request made in writing in this behalf". So the Data Fiduciary cannot extend the period by itself. It must ask in writing, and the Board decides. The Rules do not say how long a longer period may be, what form the request takes or when the Board must answer. Those details are not in the text. Anything the Board publishes on the subject should be checked.
Example
SwiftPay, an invented wallet app, discovers on a Monday at 9:00 that a vendor's server held a misconfigured database for three days. It intimates the Board that morning with the nature, extent, timing and location of the breach and its likely impact. By Thursday at 9:00 (seventy-two hours after becoming aware) it sends the updated details, the chain of events, mitigation and remedial steps, any findings on the person responsible and a report on the messages sent to affected users. If SwiftPay's forensic work is not finished, it may ask the Board in writing for a longer period before that time ends. The Rules contain no Illustration for rule 7; the example is ours.
Related duties
- Rule 6 requires logs and monitoring to detect unauthorised access, and retention for one year; see reasonable security safeguards.
- The consequences of non-compliance with the Act are in the Schedule to the Act and in section 33 on monetary penalty. Rule 7 itself states no penalty.
- For older general background, see data breach notification under the DPDP Act.
Need help preparing for a breach report?
Seventy-two hours is short when logs, vendors and legal review all need to move together. Speak to our dispute resolution team about a breach-response protocol with named owners, drafting templates and a route for the written request for a longer period.
Key takeaways
- Rule 7 starts eighteen months after the date of publication of the Gazette (rule 1(4)).
- Step 1: intimate the Board without delay with nature, extent, timing, location and likely impact.
- Step 2: within seventy-two hours of becoming aware, or a longer period the Board allows on a written request, give the six items in clause (b).
- Item (vi) is a report on the intimations given to affected Data Principals.
- Only the Board can allow a longer period.
- Later amendments and notifications should be checked.
Read next
- Rule 7(1): intimation of a breach to affected Data Principals
- Rule 6: reasonable security safeguards
- Section 8 of the DPDP Act: intimation of personal data breach
- Penalties under the DPDP Act
Disclaimer: Based on the Digital Personal Data Protection Rules, 2025 as notified in the Gazette of India on 13 November 2025 (G.S.R. 846(E)), as consulted on 2 October 2026. The Rules come into force in three stages under rule 1; later amendments, notifications and anything published by the Data Protection Board of India should be checked. This article is general information, not legal advice; check the official text before acting.
