Question · Banking, financial services and insurance
One incident, many regulators: how do we meet every clock?
Short answer: Six hours for CERT-In; regulator as its rules say; DPDP without delay and 72 hours
Most BFSI incidents need a CERT-In report within six hours, a report to your regulator as its rules require (IRDAI asks within 24 hours of the CERT-In report), and DPDP messages to customers and the Data Protection Board without delay, with a detailed Board report in 72 hours. One playbook with one timeline avoids missed steps.
What the law says
Section 8(6) and Rule 7 set the DPDP steps. CERT-In and your regulator set the others.
Section 8(6) · Rule 7: On becoming aware of a personal data breach, tell each affected person and the Data Protection Board without delay. Send the Board a detailed report within 72 hours, or a longer period if the Board allows on request.
Section 8(5) · Rule 6: Protect personal data with reasonable security safeguards. Rule 6 lists the minimum: encryption, masking or tokenisation; access control; logs and monitoring; backups for continuity; keeping logs for at least one year; and security terms in contracts with processors.
Steps
Put every clock on one page.
Name who files each report.
Keep templates ready.
Rehearse with all filers present.
Log the time each report went.
Evidence to keep
Clock page
Templates
Drill record
Common mistakes
Separate playbooks per regulator
DPO told last
No customer message template
From each seat
DPO / Privacy lead: You decide on customer and Board messages.
CISO / Security head: You start the clocks; keep the timeline evidence.
Director: Ask when all filers last rehearsed together.
Chief risk officer: Keep the clock page in the risk register.
What a good answer from management sounds like
“One playbook covers CERT-In, our regulator and the Data Protection Board. It was rehearsed this year with every filer.” Effort and time: Light · 3 to 6 weeks.