What must a Data Fiduciary do when a personal data breach occurs under the DPDP Rules 2025?
Answer:
On becoming aware of a personal data breach, the Data Fiduciary must intimate each affected Data Principal without delay in clear language - describing the breach, the data involved, possible consequences, mitigation measures taken, safety steps the individual can take, and contact details. It must also notify the Data Protection Board without delay, and provide the Board with detailed particulars (facts, mitigation, findings) within 72 hours, or such longer period as the Board may allow on request.
data breach notification 72 hours board data principal rule 7
Related Questions:
- By when do organizations need to technically integrate with Board-registered Consent Managers?
- Is the consent notice required to give contact details?
- What makes consent valid under Section 6 of the DPDP Act?
- Must a Data Fiduciary maintain data accuracy?
- What is the right to correction and erasure?
- How are DPDP penalties determined by the Board?