Breach and enforcement
Do I have to report every data breach?
- Short answer
- Yes. The Rules require intimation to the Data Protection Board and to every affected Data Principal for a personal data breach, without a materiality threshold to filter out small ones. You notify without delay, then give detailed particulars within seventy two hours.
There is no de minimis exception written into the obligation, which is stricter than the position many organisations expect. A misdirected email containing personal data is a personal data breach.
The intimation to the affected individual must be in plain language and must describe the nature and extent of the breach, when and where it occurred, the likely consequences, what you are doing about it, what they can do to protect themselves, and how to contact you.
The seventy two hour figure is for the detailed particulars to the Board, and it can be extended on a written request. The initial intimation is due without delay.
Where this comes from
- Rule 7, DPDP Rules 2025
- Section 8(6), DPDP Act 2023
The mistake people make
Applying a severity threshold borrowed from another regime and deciding internally that a small breach need not be reported.