DPDP Insights › Questions › Something has gone wrong. What happens in the first 72 hours
Question
Something has gone wrong. What happens in the first 72 hours?
Short answer: Six hours for CERT-In; without delay for people and the Board; 72 hours for the detailed report
Contain it, then tell people. A reportable cyber incident goes to CERT-In within six hours of being noticed. Under DPDP, each affected person and the Data Protection Board must be told without delay, and the Board needs a detailed report within 72 hours. Sector regulators may have their own clock too.
What the law says
Section 8(6) and Rule 7 set the DPDP steps. The CERT-In Directions of 28 April 2022 set the six-hour report. A breach includes accidental disclosure and loss of access, not only hacking.
Section 8(6) · Rule 7: On becoming aware of a personal data breach, tell each affected person and the Data Protection Board without delay. Send the Board a detailed report within 72 hours, or a longer period if the Board allows on request.
Section 8(5) · Rule 6: Protect personal data with reasonable security safeguards. Rule 6 lists the minimum: encryption, masking or tokenisation; access control; logs and monitoring; backups for continuity; keeping logs for at least one year; and security terms in contracts with processors.
Steps
Name one incident lead and a back-up, with phone numbers that work at night.
Write the first-hour steps: isolate, preserve logs, tell the DPO and the incident lead.
Keep ready-made drafts for CERT-In, the regulator, the Board and affected people.
Decide in advance who signs off each message.
Rehearse once a year with the people who would actually be called.
Evidence to keep
Incident plan with clocks
Rehearsal record
Incident log with times of each step
Common mistakes
Waiting to finish the investigation before telling anyone
Treating a wrong email or a lost laptop as 'not a breach'
Healthcare and hospitals: A ransomware attack on the HIS needs a CERT-In report in six hours and the DPDP messages.
From each seat
DPO / Privacy lead: You decide whether people and the Data Protection Board must be told, so you must be on the first call, not informed the next morning.
CISO / Security head: You start the six-hour CERT-In clock and feed the DPO what is needed for the people and Board messages. Keep the timeline evidence: who saw what, and when.
CEO / MD: You will be the public face if something goes wrong. Know who calls you, at what hour, and who speaks to customers and the media.
Director: Ask when the plan was last rehearsed, who took part, and what went wrong in the drill. A drill with no findings was probably too easy.
HR head: A leaked salary sheet or ID folder is a breach. Make sure HR knows to call the DPO at once.
Branch / business head: Wrong sends and lost papers happen on your floor first. Make reporting quick and safe.
Chief risk officer: Map every reporting clock that applies to you on one page: CERT-In, your regulator and the Data Protection Board.
IT department: IT usually notices first. Know the first-hour steps and who to call.
Administration department: A lost register or a stolen laptop is a breach. Call the DPO the same day.
Finance department: A misdirected salary file or payment list is a breach. Report it to the DPO at once.
Procurement department: Vendor contracts need a short incident-notice time, in hours.
What a good answer from management sounds like
“We have one plan that meets every clock. It was rehearsed this year, and the next rehearsal date is fixed.” Effort and time: Medium · 4 to 8 weeks, then a yearly drill.