Operations

Data breach readiness: the hour nobody rehearsed

Nobody builds a data map during an incident. Here is what a consumer brand needs on paper first, and the order the first day actually runs in.

Key takeaways
  • Write the system and data map, the named owner per system and the out-of-hours contact chain before you need them. Nobody assembles that list mid-incident.
  • Section 8(1) of the DPDP Act makes you responsible for processing done on your behalf by a processor, irrespective of any agreement to the contrary. A vendor breach is your breach.
  • Day one runs contain, scope, preserve, notify. The first three run fast because Rule 7 gives the Board a description without delay and the detail within seventy-two hours.
  • A first statement carrying a number you have to correct on Thursday is a second incident. Say what you know and when you will know more.

Most brands learn how their customer data is arranged in the week they can least afford it. The support lead knows the helpdesk holds phone numbers. Nobody is certain whether the cart recovery tool still has an export from last Diwali, or who at the courier can switch off an API key at eleven at night. The incident does not create that confusion. It exposes it.

India’s framework is now complete on paper. The Digital Personal Data Protection Rules, 2025 carry a notification dated 13 November 2025, described by the Press Information Bureau as notified on 14 November 2025. The commencement notification issued alongside them, G.S.R. 843(E), brings sections 3 to 17 of the Digital Personal Data Protection Act, 2023 apart from section 6(9), which carry the data fiduciary obligations, and sections 28 to 34, which carry penalties, into force eighteen months from that gazette. Rule 1 puts rules 3 and 5 to 16 on the same clock. A runway, not a reprieve. This is operational guidance and not legal advice.

Five things that have to exist before the phone rings

None of this is technical work. One morning with the ops lead and a shared document.

  • A system and data map. One line per system holding customer personal data: what it holds, which vendor runs it, what it connects to. Storefront, payment gateway, helpdesk, WhatsApp tool, email platform, courier panel, and the spreadsheet on somebody’s drive. The spreadsheet is usually the line that surprises the room.
  • An owner per system, by name. Not a team. Someone who can log in today, plus a named second for when the first is on a flight. Same habit as keeping a leaver’s access list current, which we cover in exit and access handover.
  • An out-of-hours contact chain that has been dialled at least once. Personal mobile numbers on the vendor side, not a portal that replies in two working days.
  • One named person who signs off anything said outside the company, and a named deputy. Two people giving two different numbers is how a contained incident becomes a story.
  • Pre-agreed access to logs. Rule 6 of the DPDP Rules, 2025 includes, among reasonable security safeguards, visibility on the accessing of personal data through logs, monitoring and review, and retention of those logs and the personal data for one year unless another law requires otherwise. Learning mid-incident that your platform keeps thirty days costs you the scoping day.

A breach at your vendor is a breach at you

The Act says this plainly. Section 8(1) makes the Data Fiduciary responsible for complying with the Act, irrespective of any agreement to the contrary, for any processing undertaken by it or on its behalf by a Data Processor. Your email platform leaking a list is your incident, not somebody else’s with your name on it.

Section 8(2) allows you to involve a processor only under a valid contract, and Rule 6 requires an appropriate provision in that contract for taking reasonable security safeguards. That moves a compliance line onto the procurement desk, next to service levels and exit, where our piece on vendor contract clauses picks it up.

Ask every vendor that touches customer data two questions in writing. How fast will you tell us. What will you hand over. A vendor who cannot answer either is a risk you are carrying.

The first day runs in one order

Contain, establish scope, preserve evidence, notify. The first three run fast precisely because the fourth is on a clock.

Contain means stopping the bleeding without destroying the scene. Rotate keys, kill the session, disable the integration. Do not wipe and rebuild the server while you still need to read it.

Scope means answering three questions with evidence rather than instinct. Which systems. Which data fields. How many people. Instinct is reliably wrong on the third, low on day one and high by day three.

Preserve means logs, access records and a written timeline from the first minute: times, who did what, what was known when. Notify is fourth in sequence, not in priority.

What the Rules ask you to send

Rule 7 of the DPDP Rules, 2025 splits the duty in two. On becoming aware of a personal data breach, the Data Fiduciary intimates each affected Data Principal, in a concise, clear and plain manner and without delay, through her user account or any mode of communication she registered. That intimation describes the breach including nature, extent and timing, the consequences relevant to her, what you are doing to mitigate risk, the safety measures she can take, and contact information for a person who can answer her questions.

The Board gets two rounds. Without delay, a description including nature, extent, timing, location and likely impact. Then within seventy-two hours of becoming aware, or a longer period the Board allows on a written request, the detail: an updated description, the facts and reasons behind it, measures implemented or proposed, findings on who caused it, and a report on the intimations you sent.

Reaching every affected customer through the account or number they registered is the same capability that carries order and refund updates, so the audit in our note on order to refund notifications does double duty. And the seventy-two hour package asks for facts, not adjectives. If nobody wrote the timeline on day one, day three is a reconstruction.

The Rules do not define without delay in hours, and whether an incident is a personal data breach for your business is a call on facts. Do not build a plan that needs a generous reading of either.

The wrong number is a second incident

The pressure on day one is to say something. The temptation is to say a number. A statement that says forty thousand accounts and gets corrected to four lakh on Thursday has manufactured a second story, about your credibility rather than the breach. Say what you know, say what you are still establishing, and when you will say more. Who speaks, and what a holding statement contains, sits in our note on crisis communication.

The reason to prepare sits in the Schedule to the Act. Breach of the obligation to take reasonable security safeguards under section 8(5) may attract a penalty extending to two hundred and fifty crore rupees. Breach of the obligation to give the Board or the affected Data Principal notice of a breach under section 8(6) may extend to two hundred crore rupees. Those are ceilings rather than tariffs. The second is worth reading twice: failing to tell people is priced separately from failing to protect them.

The daily brief

Never miss a move

The moves that move money, every morning.

One email a day. No spam, ever.

FAQ

Quick answers.

The duty in section 8(6) of the Act, and Rule 7 of the DPDP Rules, 2025, attaches to a personal data breach and covers both the Data Protection Board and each affected Data Principal. Whether a given incident meets that description turns on facts, so make the call with counsel rather than assuming a small one is out of scope.
In the way that matters, yes. Section 8(1) makes the Data Fiduciary responsible irrespective of any agreement to the contrary, including for processing carried out on its behalf by a Data Processor. A contract may let you recover from the vendor. It does not move the obligation.
Rule 7 asks for intimation to affected individuals without delay, and to the Board without delay for the initial description, then within seventy-two hours of becoming aware for the detailed report, unless the Board allows a longer period on a written request. The Rules do not define without delay in hours.
The commencement notification of 13 November 2025, G.S.R. 843(E), brings sections 3 to 17 and 28 to 34 of the Act into force eighteen months from the date of publication of that gazette, and Rule 1 of the Rules puts rules 3 and 5 to 16 on the same clock. The preparation takes longer than the drafting, so the runway is the point.

Related insights

From the wire

India's Commerce Engine

Put it
to work.

hello@zane.marketing

Book a meeting