Section 8 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Section 8(6) says that in the event of a personal data breach, the Data Fiduciary shall give the Board and each affected Data Principal intimation of the breach, in such form and manner as may be prescribed. The Act itself sets no time limit; the detail is left to the rules. Planning the response before an incident is easier with a legal consultation.
After a personal data breach, the Data Fiduciary must give both the Data Protection Board and each affected Data Principal an intimation, in the form and manner prescribed (section 8(6)). The text of the Act does not state a deadline or content; these are left to the rules. Failure to give the notice is penalised separately from failure of security, at up to Rs 200 crore (Schedule, item 2).
Section 8(6) at a glance
| Point | What the text says |
|---|---|
| Trigger | "In the event of a personal data breach" |
| Who gives the notice | The Data Fiduciary |
| To whom | The Board, and each affected Data Principal |
| How | "In such form and manner as may be prescribed" |
| Time limit | Not stated in the Act |
| Penalty | Up to Rs 200 crore (Schedule, item 2) |
What triggers the duty
The trigger is a "personal data breach" as defined in section 2(u): any unauthorised processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises the confidentiality, integrity or availability of personal data. Read that definition with care because the section does not add a "risk" or "harm" threshold. The text says nothing about a minimum seriousness or number of people affected. The Act does not carve out minor incidents; if a rule does, it will be in the Rules, so check them.
The duty falls on the Data Fiduciary. If the breach occurs at a Data Processor, the fiduciary is still the one to intimate, since section 8(1) makes it responsible for processing on its behalf. Contracts should therefore oblige processors to report to you quickly so you can act. See section 8(1) and (2).
Two recipients, two notices
Section 8(6) requires intimation to:
- the Board, the Data Protection Board of India under section 18; and
- "each affected Data Principal".
The second is specific: each affected person, not a general public notice. That suggests you need to know who was affected, which depends on logs and data maps. The Act does not say whether the two notices must be identical or simultaneous. The form and manner are left to the rules. The DPDP Rules, 2025 (notified November 2025) prescribe the detail and different provisions commence on different dates; this article states nothing from them. Read the Rules for timing, content and method before relying on any internal template.
Why the Board needs the intimation
The notice is also how the Board learns about breaches. Under section 27(1)(a), on receipt of an intimation of personal data breach under section 8(6), the Board may direct urgent remedial or mitigation measures, inquire into the breach and impose penalty as provided in the Act. So a notice is not just a formality; it can start regulatory action. Conversely, section 33(2)(e) makes it relevant, in fixing a penalty, whether the person took action to mitigate the effects and consequences of the breach, and the timeliness and effectiveness of that action. Prompt, genuine mitigation helps; it does not replace the notice.
What the section does not say
- No time limit in the Act. Do not assume a number of hours or days from outside sources. The Rules address this, so check them.
- No stated content of the notice. "Such form and manner as may be prescribed" points to the Rules.
- No harm threshold. The duty is tied to a "personal data breach", as defined.
- No exemption for processors' incidents. The fiduciary's duty remains.
- No mention of police or other regulators. Other laws may require separate reports; section 8(6) does not deal with them. Section 38 says the Act is in addition to, and not in derogation of, other laws; see the article on section 38.
Interaction with security safeguards
A breach brings two questions: did you take reasonable security safeguards (section 8(5)), and did you intimate (section 8(6))? They are separate duties with separate Schedule entries. Item 1 (section 8(5)) may extend to two hundred and fifty crore rupees; item 2 (section 8(6)) may extend to two hundred crore rupees. In principle, one incident could lead to findings on both, though the Board must decide each on its own facts and under section 33. See reasonable security safeguards.
Section 17 and section 8(6)
Section 17(1) says Chapter II, except sub-sections (1) and (5) of section 8, does not apply in the situations listed there. Section 8(6) is not in that carved-out pair. So in those listed situations, the text of section 17(1) does not require the intimation. Section 17(3) notifications for certain Data Fiduciaries do not name section 8(6). Whether any of this helps a particular business depends on its facts; take advice before relying on it.
Consequence of breach
Item 2 of the Schedule: breach in observing the obligation to give the Board or affected Data Principal notice of a personal data breach under section 8(6) may extend to two hundred crore rupees. The Board acts after an inquiry and hearing, and only where the breach of the Act is significant (section 33(1)). An appeal lies to the Appellate Tribunal within sixty days under section 29. See penalties and the overview post on breach notification.
Practical examples
Example 1: lost laptop. An employee's laptop with unencrypted customer records is stolen. The data may be in unauthorised hands, which compromises confidentiality. The fiduciary needs to check the Rules on how, and to whom, intimation is made.
Example 2: ransomware. Systems are encrypted and customer data cannot be accessed for days. Even if nothing was copied, the definition covers loss of access that compromises availability.
Example 3: vendor incident. A processor tells the fiduciary it mailed a list to the wrong party. The fiduciary, not the processor, carries the duty to intimate the Board and affected Data Principals.
Common mistakes
- Waiting for certainty about what was taken before informing anyone.
- Assuming only the Board needs the notice, or only customers.
- Having no way to identify the affected individuals quickly.
- Leaving out vendors from incident plans.
Need help with a breach response plan?
A breach plan should say who decides, who drafts, who sends and what the vendors must tell you. We can help you put this together through our legal consultation service, and check the current Rules so that the plan reflects them.
Key takeaways
- A personal data breach requires intimation to both the Board and each affected Data Principal.
- The Act leaves form, manner and timing to the rules; check the DPDP Rules, 2025.
- The fiduciary must intimate even for a breach at its Data Processor.
- Penalty for failure to intimate may extend to Rs 200 crore, separate from the Rs 250 crore safeguards entry.
- The Board may direct urgent remedial measures on receiving the intimation.
Read next
- Section 8 of the DPDP Act, 2023: reasonable security safeguards
- Section 8 of the DPDP Act, 2023: erasure and retention of personal data
- Data breach notification obligation under the DPDP Act
- Section 27 of the DPDP Act, 2023: powers and functions of the Board
Disclaimer: Based on the Digital Personal Data Protection Act, 2023 (official text as enacted, No. 22 of 2023) as on 30 September 2026. The DPDP Rules, 2025 were notified in November 2025 and different provisions commence on different dates; this article does not state rule-level detail. Verify the current position in the Rules and the commencement notifications before acting.
