4

Breach Response

SL-07

Round-the-clock intake, a war-room with the statutory clocks running, and both Board and Data Principal notifications drafted from real impact data. The 72-hour window starts when the organisation becomes aware, not when it finishes investigating.

DischargesS.8(6)R.7S.27
Open incidents
2
View
Personal data breaches
7

Assessed as reportable

Data Principals affected
2.24 L
Children affected
21.2 K

₹200 crore ceiling applies

Board notifications filed
6
Hotline
24×7

1-hour acknowledgement SLA

Detection source

Where incidents actually come from. The security modules detecting their own incidents is the point of running them.

  • Database Activity Monitoring3
  • Data Loss Prevention1
  • SIEM / SOC1
  • Reported by a Data Processor1
  • Access Gateway1
  • AI Processing Guard1
  • Reported by a Data Principal1
  • Access Assurance1
Incident volume

Incidents raised versus those assessed as reportable personal data breaches.

Statutory clocks

The three deadlines that matter, and what happens when each is missed.

  • 1 hour
    Acknowledge the incident
    Contractual SLA. Missing it costs ₹25,000 per hour under the rate contract.
  • 4 hours
    Preliminary assessment
    Establish whether this is a personal data breach at all. The Board clock is already running either way.
  • 72 hours
    Detailed report to the Board
    From becoming aware. Failure to notify carries a ceiling of ₹200 crore.
  • Without delay
    Notify affected Data Principals
    Plain language, in their language, with the nature, consequences, mitigation and contact.
  • 30 days
    Post-Incident Review
    Findings feed the gap register, which is what stops the same incident recurring.

Related