Breach and enforcement
Is a system outage a personal data breach?
- Short answer
- It can be. A personal data breach includes any unauthorised processing or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access that compromises the confidentiality, integrity or availability of personal data. Availability is in that list.
The instinct is to treat a breach as a hack and an outage as an operational matter. The definition does not draw that line, because loss of access is expressly covered.
A ransomware event that encrypts your data without exfiltrating it is the clearest case. So is a failed migration that destroys records, or a backup that turns out to be unrestorable.
This is why an incident process that only triggers on suspected intrusion is incomplete. The trigger should be compromise of confidentiality, integrity or availability, whichever occurs.
Where this comes from
- Section 2(u), DPDP Act 2023
- Rule 7, DPDP Rules 2025
The mistake people make
Classifying an outage as downtime rather than an incident, and therefore never assessing whether it was reportable.