InfraVeritas360DPDPiq

DPDP Insights › Questions › One incident, many regulators: how do we meet every clock?

Question · Banking, financial services and insurance

One incident, many regulators: how do we meet every clock?

Short answer: Six hours for CERT-In; regulator as its rules say; DPDP without delay and 72 hours

Most BFSI incidents need a CERT-In report within six hours, a report to your regulator as its rules require (IRDAI asks within 24 hours of the CERT-In report), and DPDP messages to customers and the Data Protection Board without delay, with a detailed Board report in 72 hours. One playbook with one timeline avoids missed steps.

What the law says

Section 8(6) and Rule 7 set the DPDP steps. CERT-In and your regulator set the others.

Steps

  1. Put every clock on one page.
  2. Name who files each report.
  3. Keep templates ready.
  4. Rehearse with all filers present.
  5. Log the time each report went.

Evidence to keep

Common mistakes

From each seat

What a good answer from management sounds like

“One playbook covers CERT-In, our regulator and the Data Protection Board. It was rehearsed this year with every filer.” Effort and time: Light · 3 to 6 weeks.

Related questions

Explore our research-built assessment platformsEach one comes out of the same InfraVeritas360 Foundation Layer research. Human-led, with no AI used.