The Business Case for DPDP Act Compliance

Read Now

Get privacy insights in your inbox.

Compliance

Breach Notification on the DPDP Clock

IQWorks ResearchSeptember 22, 20265 min read
Share
Breach Notification on the DPDP Clock

Under India's DPDP Act, a personal data breach triggers notification duties to the Data Protection Board and to affected data principals, on timelines set by the Act and its rules. ComplyIQ's incident module tracks that obligation: an incident record with severity, status, and an assignee; a 72-hour aging indicator that moves from amber to red as the deadline nears and passes; and a breach-notification section that timestamps when data principals and the regulator were actually notified. It is a tracking and workflow layer — it does not detect a breach on its own, and it does not file the regulatory notification for you.

Source: IQWorks Research | Last updated: September 2026

The obligation to notify begins the moment a data fiduciary becomes aware of a breach, and from that point two separate clocks start running: one for the Data Protection Board, one for every data principal whose data was exposed. Both deadlines have to be met, and the fact that each notice went out has to be recorded.

ComplyIQ's incident module does not shorten that clock, and it does not watch your systems for signs of a breach. It gives the privacy team one record to log what happened, see how close the deadline is, and show — later, to the Board or in an audit — exactly when notice went out.

What the DPDP Act asks for when a breach happens

The Act and its rules place two duties on a data fiduciary that becomes aware of a personal data breach. It must intimate the Data Protection Board, and it must intimate each affected data principal, in clear and plain language, covering what happened and what to do next.

The two notices do not run on identical clocks. The Board gets an initial description without delay, then a fuller account — the specifics of what happened, what caused it, and what has been done about it — within a 72-hour window measured from the moment the organisation became aware of the breach. That 72-hour figure comes from the DPDP Rules, which are still in draft and being finalised at the time of writing, rather than from a settled number in the Act itself. It is the window as those rules prescribe it, and it is the window ComplyIQ's incident module is built around.

Logging an incident: severity, status, owner

When something is flagged as a potential breach, a privacy team opens an incident record. It is a plain register: someone names what happened, rates how serious it is, and assigns an owner to drive it to closure.

FieldWhat it captures
SeverityLow, Medium, High, or Critical
StatusDetected → Investigating → Reported → Contained → Closed
AssigneeThe person accountable for driving the incident to closure
Occurred / detected / reported atSeparate timestamps for when the breach happened, when it was found, and when it was formally logged
Third partyWhether the breach originated with a vendor, and which one
Affected principalsThe count of data principals affected

Status moves through a fixed sequence rather than a free-text field, so an open incident always sits at a known stage between detection and closure. Closed is the only terminal state, and it is the state that stops every clock attached to the record.

The 72-hour aging clock

Every open incident carries an aging indicator measured against that 72-hour window, starting from when the breach occurred or was detected. Early in the window the record reads plainly. Past the halfway mark it shades amber; further in, a deeper amber; once the window has closed, the row turns red and the label switches from a countdown to how far overdue the incident is. A closed incident stops aging — the indicator only tracks incidents that are still open.

The point of the clock is visibility. It surfaces which open incidents are approaching their notification deadline and which have already passed it, so that decision sits in a shared view rather than in one person's memory of when the breach was first logged.

The breach-notification record

Logging an incident and clearing its aging indicator are two different things. ComplyIQ keeps a separate record of the notifications themselves: one entry for data principals, one for the Board, each holding a timestamp for when notice actually went out. Until that box is checked, the record reads "not yet notified"; once it is, it reads "notified," with the date and time.

This is the artefact a privacy team would produce if the Board asked, or if an auditor wanted evidence that a specific incident's notifications went out on time. It records the fact of notification, not the deadline for it.

What the module does not do

The incident module logs and ages a breach; it does not find one. It does not scan network traffic or system logs, it does not decide how severe an incident is, and it does not draft or transmit the notification to the Board or to affected data principals. A person still has to notice the breach, judge its severity, write the notice, send it, and come back to mark it sent. What the module removes is the risk of that deadline slipping unnoticed in an email thread or a spreadsheet while the incident sits open.

Key Takeaways

  • The DPDP Act and its rules require notification to the Data Protection Board and to affected data principals once a data fiduciary becomes aware of a personal data breach.
  • The Board's fuller notification is due within 72 hours of that awareness — the window ComplyIQ's incident aging clock tracks.
  • Incidents are logged with severity (Low/Medium/High/Critical), a fixed status sequence (Detected → Investigating → Reported → Contained → Closed), and an assignee.
  • The aging indicator shifts from plain to amber to red as an open incident approaches and passes the 72-hour window, and stops once the incident is closed.
  • A separate breach-notification record timestamps when data principals and the regulator were actually notified.
  • This is a tracking and workflow layer: it does not detect breaches and does not file the regulatory notification on its own.

The aging clock starts the moment an incident is logged as occurred or detected, and stays red until someone closes it out. See how ComplyIQ tracks a breach from log to notification: book a ComplyIQ demo.

Our verdict

ComplyIQ4.8out of 5

29 ratings, from Customer Success Research.

Ready to automate your compliance?

See how IQWorks helps enterprises manage data protection at scale.

Request Demo

Related Articles