DPDP Roles, explained simply

India's Digital Personal Data Protection Act. Who is who.

‹ All questions

Breach and enforcement

Is a system outage a personal data breach?

Short answer
It can be. A personal data breach includes any unauthorised processing or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access that compromises the confidentiality, integrity or availability of personal data. Availability is in that list.

The instinct is to treat a breach as a hack and an outage as an operational matter. The definition does not draw that line, because loss of access is expressly covered.

A ransomware event that encrypts your data without exfiltrating it is the clearest case. So is a failed migration that destroys records, or a backup that turns out to be unrestorable.

This is why an incident process that only triggers on suspected intrusion is incomplete. The trigger should be compromise of confidentiality, integrity or availability, whichever occurs.

Where this comes from

The mistake people make

Classifying an outage as downtime rather than an incident, and therefore never assessing whether it was reportable.

Related