2 plans are untested or past their test date
Health data breach annexe; Children's data breach annexe. The children's data annexe in particular has never been exercised, and it covers the obligation with the ₹200 crore ceiling.
Plans
Main plan plus scope-specific annexes.
Departmental Breach Response Plan
All systems and directorates · version 4.1 · owner Meera Iyer
Plan sections
1
Activation criteria
What constitutes a personal data breach and who may declare one.
2
Roles and authority
Incident lead, DPO, communications, legal, and who signs the Board notification.
3
The first hour
Acknowledge, convene, contain, preserve evidence.
4
Impact assessment
Identify affected Data Principals and assess volume and sensitivity from the classified inventory.
5
Board notification
Without delay, and the detailed report within 72 hours of becoming aware.
6
Data Principal notification
Plain-language, bilingual, without delay; channels and approval path.
7
Evidence and chain of custody
What to preserve, how, and who may access it.
8
Post-Incident Review
Within 30 days, with findings feeding the gap register.
Escalation contacts
An out-of-date contact list is the single most common reason a well-written plan fails on the night.
- Meera IyerData Protection Officer+91 172 292 4410
- Vikram SaxenaChief Information Security Officer+91 172 292 4422
- Arjun MalhotraPrincipal Secretary+91 172 292 4400
- Sentinel SOC24x7 monitoring partner1800-XXX-2255