A client's data is involved in an incident. Who tells whom?
Short answer: Client first, within contract hours; CERT-In in six hours
Tell the client first, within the time your contract sets, because the client is the fiduciary and must tell its own customers and the Board. Report to CERT-In within six hours if the incident is reportable. Give the client logs and facts quickly; do not contact the client's customers yourself unless the client asks.
What the law says
Section 8(6) puts the duty to tell people on the fiduciary. As processor, your contract decides your duty to the client.
Section 8(6) · Rule 7: On becoming aware of a personal data breach, tell each affected person and the Data Protection Board without delay. Send the Board a detailed report within 72 hours, or a longer period if the Board allows on request.
Section 8(1)–(2): The organisation that decides why and how data is used (the Data Fiduciary) stays responsible, even when a vendor (Data Processor) does the work. A processor may be engaged only under a valid contract.
Steps
Keep a list of client notice times.
Name who calls each client.
Prepare a client incident template.
File CERT-In if reportable.
Share logs and a written account.
Evidence to keep
Client notice list
Incident timeline
CERT-In record
Common mistakes
Waiting to finish the investigation before telling the client
Contacting the client's customers directly
Missing the CERT-In clock
From each seat
CISO / Security head: Start both clocks: client and CERT-In.
Director: Ask for the fastest and slowest client notice in the last drill.
Legal & compliance: Check contract notice times are realistic.
Delivery head: You call the client; have the number ready.
What a good answer from management sounds like
“We know each client's notice time, and in our last drill the client was told within two hours.” Effort and time: Light · 3 to 4 weeks.