DPDP Comply gives you a breach register to record and track every personal data breach — and to notify the Data Protection Board of India and each affected Data Principal, as Section 8(6) requires, with a tamper-evident trail behind every step.
Record incidents · Notify the Board · Prove your response
What counts as a breach?
Under India's DPDP Act 2023, a personal data breach is any unauthorised processing, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data that compromises its confidentiality, integrity or availability. Section 8 obliges every Data Fiduciary to keep reasonable security safeguards to prevent one — and, when it happens, to notify the Board and affected principals.
Read the guideIncident management
A purpose-built breach register that turns a stressful incident into a documented, defensible process — mapped to your Section 8 obligations.
Log every personal data breach in one place — title, description, severity, affected data types, an estimate of how many principals are affected, and when you discovered it. Track each incident from detection through to resolution.
Record notification to the Data Protection Board of India directly from the incident. The action is timestamped and routed through your organisation's Grievance Officer, leaving a dated record that the Board was informed.
Intimate every affected Data Principal in scope by email in a single step, as Section 8(6) requires — then capture the date they were notified on the incident record.
Each incident carries an append-only timeline of every action — creation, status change, Board and principal notification — recording who did it and when, backed by a tamper-evident audit trail.
Track the whole incident lifecycle
Section 8 in practice
Section 8 of the DPDP Act requires reasonable security safeguards to protect personal data, and Section 8(6) requires notifying both the Data Protection Board of India and each affected Data Principal of a personal data breach. Section 8(7) separately requires erasing personal data once its purpose is served or consent is withdrawn, unless another law requires you to retain it. DPDP Comply's breach register is built around the notification duty — recording the incident, the people affected, and each notification you send.
One nuance worth planning for: the Act itself sets no fixed numeric deadline for breach reporting. The form, manner and timing are left to the DPDP Rules — the draft DPDP Rules 2025 propose specifics, but they are draft and may change. By timestamping discovery and every notification, DPDP Comply lets you evidence timeliness against whatever the final Rules require. This is general information about the DPDP Act, not legal advice.
FAQ
The Digital Personal Data Protection Act, 2023 defines a personal data breach as any unauthorised processing of personal data, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises its confidentiality, integrity or availability. Under Section 8, a Data Fiduciary must keep reasonable security safeguards to prevent such breaches — and if one occurs, act on it.
Section 8(6) requires a Data Fiduciary to notify the Data Protection Board of India and each affected Data Principal of a personal data breach. DPDP Comply supports both: a Board-notification action routed via your Grievance Officer, and an affected-principals notification that emails every principal in scope, with each notification dated on the incident.
The Act itself sets no fixed numeric time limit — Section 8(6) requires notification in the form and manner to be prescribed, leaving the specifics to the DPDP Rules. The draft DPDP Rules 2025 propose reporting timelines, but they are draft and may change. DPDP Comply records the discovery time and stamps when you notified the Board and affected principals, so you can evidence timeliness against whatever the final Rules set. This is general information, not legal advice.
It provides a breach register where you record each incident — title, description, severity, affected data types, an estimate of affected principals, and the discovery date. From the incident you can log notification to the Data Protection Board and notify affected data principals by email, and update the status as you investigate, contain and resolve the breach.
Yes. Every incident carries an append-only timeline that captures each action — creation, status changes, Board notification and principal notification — with who performed it and when. Combined with DPDP Comply's tamper-evident audit trail, that gives you an inspection-ready record of exactly how you responded.
Set up your breach register in DPDP Comply so that when an incident hits, notifying the Board and affected principals — and proving you did — is already in place.
Get Started — It's FreeNo credit card required · Setup in under 10 minutes