Version 1.0 • CURRENT
DPDP Rules 2025 Reasonable Security Safeguards & Breach Intimation
RULE 7

Intimation of personal data breach

Official Statutory Text MeitY Gazette Notified Section 40 Delegated Authority
Plain-Language Compliance Breakdown (Editorial Analysis)

What this means: If a hack or leak happens, the company cannot cover it up.

- They must notify users "without delay" via email/app, explaining what was stolen and how the user can protect themselves (e.g., change passwords).
- They must notify the Data Protection Board immediately, and follow up with a detailed forensic report within 72 hours explaining exactly how the breach happened and who caused it.

Key Practical Takeaways for Compliance Teams

  • Delegated Specificity: This rule provides concrete operational criteria that must be reflected in technical architectures and compliance records.
  • Audit Readiness: Ensure written SOPs, consent logs, and security controls correspond directly to the statutory wording of Rule 7.
  • Statutory Traceability: In any legal interpretation, the exact Gazette text above takes precedence over internal summaries.
← PREVIOUS RULE Rule 6: Reasonable security safeguards NEXT RULE → Rule 8: Time period for specified purpose to be deemed as no longer being served
Statutory text reproduced under open access public domain principles. This reader is designed for educational and compliance decision support.