Next dueCompany / ROC
14 OCTADT-1 · Auditor appointment (after AGM)in 4 days 30 OCTAOC-4 · Financial statements · FY 2025-26in 20 days 31 OCTMSME-1 · Dues to MSMEs · Apr–Sep 2026in 21 days 21 NOVITR filing · Audit cases · AY 2026-27 · extended from 31 Octin 42 days 29 NOVMGT-7 / 7A · Annual return · FY 2025-26in 50 days 30 JUNDPT-3 · Return of deposits · FY 2026-27in 263 days 11 OCTGSTR-1 · Outward supplies · Sep 2026tomorrow 15 OCTPF & ESI · Contributions · Sep 2026in 5 days
All due dates

Section 8 of the Digital Personal Data Protection Act, 2023: Intimation of personal data breach

After a personal data breach, the Data Fiduciary must give both the Data Protection Board and each affected Data Principal an intimation, in the form and manner prescribed...

Published
Updated
Reading time
7 min
Views
11
Questions
6 answered
  • Expert Reviewed
  • Medium Complexity
Topic
Data Protection
Published
September 30, 2026
Last updated
Oct 8, 2026
Reading time
7 min
0:00
Last updated: October 2026Verified against: Government sources

Section 8(6) says that in the event of a personal data breach, the Data Fiduciary shall give the Board and each affected Data Principal intimation of the breach, in such form and manner as may be prescribed. The Act itself sets no time limit; the detail is left to the rules. Planning the response before an incident is easier with a legal consultation.

Section 8(6) at a glance

PointWhat the text says
Trigger"In the event of a personal data breach"
Who gives the noticeThe Data Fiduciary
To whomThe Board, and each affected Data Principal
How"In such form and manner as may be prescribed"
Time limitNot stated in the Act
PenaltyUp to Rs 200 crore (Schedule, item 2)

What triggers the duty

The trigger is a "personal data breach" as defined in section 2(u): any unauthorised processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises the confidentiality, integrity or availability of personal data. Read that definition with care because the section does not add a "risk" or "harm" threshold. The text says nothing about a minimum seriousness or number of people affected. The Act does not carve out minor incidents; if a rule does, it will be in the Rules, so check them.

The duty falls on the Data Fiduciary. If the breach occurs at a Data Processor, the fiduciary is still the one to intimate, since section 8(1) makes it responsible for processing on its behalf. Contracts should therefore oblige processors to report to you quickly so you can act. See section 8(1) and (2).

Two recipients, two notices

Section 8(6) requires intimation to:

  1. the Board, the Data Protection Board of India under section 18; and
  2. "each affected Data Principal".

The second is specific: each affected person, not a general public notice. That suggests you need to know who was affected, which depends on logs and data maps. The Act does not say whether the two notices must be identical or simultaneous. The form and manner are left to the rules. The DPDP Rules, 2025 (notified November 2025) prescribe the detail and different provisions commence on different dates; this article states nothing from them. Read the Rules for timing, content and method before relying on any internal template.

Why the Board needs the intimation

The notice is also how the Board learns about breaches. Under section 27(1)(a), on receipt of an intimation of personal data breach under section 8(6), the Board may direct urgent remedial or mitigation measures, inquire into the breach and impose penalty as provided in the Act. So a notice is not just a formality; it can start regulatory action. Conversely, section 33(2)(e) makes it relevant, in fixing a penalty, whether the person took action to mitigate the effects and consequences of the breach, and the timeliness and effectiveness of that action. Prompt, genuine mitigation helps; it does not replace the notice.

What the section does not say

  • No time limit in the Act. Do not assume a number of hours or days from outside sources. The Rules address this, so check them.
  • No stated content of the notice. "Such form and manner as may be prescribed" points to the Rules.
  • No harm threshold. The duty is tied to a "personal data breach", as defined.
  • No exemption for processors' incidents. The fiduciary's duty remains.
  • No mention of police or other regulators. Other laws may require separate reports; section 8(6) does not deal with them. Section 38 says the Act is in addition to, and not in derogation of, other laws; see the article on section 38.

Interaction with security safeguards

A breach brings two questions: did you take reasonable security safeguards (section 8(5)), and did you intimate (section 8(6))? They are separate duties with separate Schedule entries. Item 1 (section 8(5)) may extend to two hundred and fifty crore rupees; item 2 (section 8(6)) may extend to two hundred crore rupees. In principle, one incident could lead to findings on both, though the Board must decide each on its own facts and under section 33. See reasonable security safeguards.

Section 17 and section 8(6)

Section 17(1) says Chapter II, except sub-sections (1) and (5) of section 8, does not apply in the situations listed there. Section 8(6) is not in that carved-out pair. So in those listed situations, the text of section 17(1) does not require the intimation. Section 17(3) notifications for certain Data Fiduciaries do not name section 8(6). Whether any of this helps a particular business depends on its facts; take advice before relying on it.

Consequence of breach

Item 2 of the Schedule: breach in observing the obligation to give the Board or affected Data Principal notice of a personal data breach under section 8(6) may extend to two hundred crore rupees. The Board acts after an inquiry and hearing, and only where the breach of the Act is significant (section 33(1)). An appeal lies to the Appellate Tribunal within sixty days under section 29. See penalties and the overview post on breach notification.

Practical examples

Example 1: lost laptop. An employee's laptop with unencrypted customer records is stolen. The data may be in unauthorised hands, which compromises confidentiality. The fiduciary needs to check the Rules on how, and to whom, intimation is made.

Example 2: ransomware. Systems are encrypted and customer data cannot be accessed for days. Even if nothing was copied, the definition covers loss of access that compromises availability.

Example 3: vendor incident. A processor tells the fiduciary it mailed a list to the wrong party. The fiduciary, not the processor, carries the duty to intimate the Board and affected Data Principals.

Common mistakes

  • Waiting for certainty about what was taken before informing anyone.
  • Assuming only the Board needs the notice, or only customers.
  • Having no way to identify the affected individuals quickly.
  • Leaving out vendors from incident plans.

Need help with a breach response plan?

A breach plan should say who decides, who drafts, who sends and what the vendors must tell you. We can help you put this together through our legal consultation service, and check the current Rules so that the plan reflects them.

Key takeaways

  • A personal data breach requires intimation to both the Board and each affected Data Principal.
  • The Act leaves form, manner and timing to the rules; check the DPDP Rules, 2025.
  • The fiduciary must intimate even for a breach at its Data Processor.
  • Penalty for failure to intimate may extend to Rs 200 crore, separate from the Rs 250 crore safeguards entry.
  • The Board may direct urgent remedial measures on receiving the intimation.

Read next

Disclaimer: Based on the Digital Personal Data Protection Act, 2023 (official text as enacted, No. 22 of 2023) as on 30 September 2026. The DPDP Rules, 2025 were notified in November 2025 and different provisions commence on different dates; this article does not state rule-level detail. Verify the current position in the Rules and the commencement notifications before acting.

Quick recapKey facts & short answers

Key Facts About Section 8

  • Applies in: All states across India, under the relevant central law.
  • Mode: Mostly online via the official government portal.
  • Typical timeline: Ranges from a few days to a few weeks depending on the case.
  • Non-compliance: May attract penalties, interest or late fees.
  • Expert help: TaxClue completes the entire process end to end for you.

Who must be informed of a personal data breach?

Section 8(6) says the Board and each affected Data Principal.

What is the deadline for intimation?

The Act states none. The form and manner are prescribed by rules. Check the DPDP Rules, 2025.

A privacy notice should describe what you actually do, not what a template says.

— TaxClue Data Protection Desk

Section 8: a key compliance topic in Indian tax and corporate law that businesses and individuals must understand to remain compliant.

Related Services & Guides

Was this article helpful?
About the author
13,350 articles
Vikas Sharma Verified expert Tax & Compliance Expert

Experienced in company registration, GST, trademark, and compliance. Helping Indian businesses stay compliant.

Last reviewed: Live

Disclaimer: This article is for general informational purposes only and does not constitute professional tax, legal or financial advice. Laws, rates and due dates change and can vary by individual case — always verify with the relevant government source (e.g. mca.gov.in, incometax.gov.in) or consult a qualified professional before acting. TaxClue accepts no liability for decisions taken based on this content.

People also ask

Questions, answered

Short, direct answers to the 6 questions readers ask most on this topic.

Section 8(6) says the Board and each affected Data Principal.

The Act states none. The form and manner are prescribed by rules. Check the DPDP Rules, 2025.

Section 8(6) applies "in the event of a personal data breach" as defined in section 2(u). The Act sets no separate harm threshold.

The Data Fiduciary. Section 8(1) makes it responsible for processing by a Data Processor on its behalf.

Item 2 of the Schedule: up to two hundred crore rupees, subject to an inquiry and section 33.

Under section 27(1)(a), direct urgent remedial or mitigation measures, inquire into the breach and impose penalty as provided in the Act.