Breach Response
SL-07Round-the-clock intake, a war-room with the statutory clocks running, and both Board and Data Principal notifications drafted from real impact data. The 72-hour window starts when the organisation becomes aware, not when it finishes investigating.
INC-2026-0042 — active personal data breach
Bulk extraction of citizen records from the Family ID registry. 1.48 L Data Principals affected, including 6.41 K children. The initial Board notification is drafted but not yet filed.
Board deadline
--:--:--Open incidents
2
ViewPersonal data breaches
7
Assessed as reportable
Data Principals affected
2.24 L
Children affected
21.2 K
₹200 crore ceiling applies
Board notifications filed
6
Hotline
24×7
1-hour acknowledgement SLA
Open incidents
Ordered by severity, then by how much of the statutory window is left.
Detection source
Where incidents actually come from. The security modules detecting their own incidents is the point of running them.
- Database Activity Monitoring3
- Data Loss Prevention1
- SIEM / SOC1
- Reported by a Data Processor1
- Access Gateway1
- AI Processing Guard1
- Reported by a Data Principal1
- Access Assurance1
Incident volume
Incidents raised versus those assessed as reportable personal data breaches.
Statutory clocks
The three deadlines that matter, and what happens when each is missed.
- 1 hourAcknowledge the incidentContractual SLA. Missing it costs ₹25,000 per hour under the rate contract.
- 4 hoursPreliminary assessmentEstablish whether this is a personal data breach at all. The Board clock is already running either way.
- 72 hoursDetailed report to the BoardFrom becoming aware. Failure to notify carries a ceiling of ₹200 crore.
- Without delayNotify affected Data PrincipalsPlain language, in their language, with the nature, consequences, mitigation and contact.
- 30 daysPost-Incident ReviewFindings feed the gap register, which is what stops the same incident recurring.
Exposure across reportable breaches
The Schedule sets a ceiling of ₹200 Cr for failure to notify a personal data breach and ₹250 Cr for failure to take reasonable security safeguards. Notification is the one part that is entirely within the organisation's control after the fact.
Related
All incidentsEvery incident, whether or not it was ultimately assessed as a personal data breach.Response plansThe plan, the escalation contacts and the annexes for health and children's data.Tabletop exercisesTesting readiness before it is tested for you. Findings feed the gap register.Board correspondenceNotifications filed, information requests received and show-cause responses.