Every organisation will eventually face a personal data breach. Under the DPDP Act, what separates a managed incident from a compliance failure is not whether it happened — it is how you responded, how fast, and whether you can prove it.
This playbook assumes the worst has occurred and walks through what a defensible response looks like.
What counts as a breach
A personal data breach is any unauthorised processing, accidental disclosure, acquisition, sharing, use, alteration, destruction, or loss of access to personal data that compromises its confidentiality, integrity or availability. Note what that includes:
- An attacker exfiltrating a customer table — obviously.
- An employee emailing a spreadsheet of personal data to the wrong recipient — also a breach.
- Ransomware that merely denies you access to personal data — a breach of availability, even if nothing left the building.
Defining this narrowly is a common and costly mistake.
The clock starts at awareness
This is the single most important operational fact: your reporting timeline begins the moment your organisation becomes aware of the breach — not when it is convenient, fully investigated, or comfortably understood. That means the mechanism by which awareness travels from a junior analyst to the people who must report has to be fast and unambiguous.
The most expensive hour in a breach is the one lost deciding who to tell.
The first hour
- Contain, do not destroy. Stop the bleeding, but preserve evidence. An overzealous cleanup can erase the forensic trail you will need later.
- Start the timeline. From this minute, log every action with a timestamp. This log is both your operational tool and your proof of diligence.
- Convene the decision-makers. Know in advance who they are: security, legal, the Data Protection Officer, communications. A breach is the wrong time to assemble a committee.
- Assess scope. What data, how many principals, what sensitivity. Early numbers will be rough — record them as rough, and update.
The first day: what the Board needs
Your internal leadership and, where required, the Data Protection Board will want a clear picture:
- What happened, in plain language.
- What data was affected, and how many data principals.
- What you have done to contain and remediate.
- What the risk to affected individuals is.
- How you will notify them and by when.
Notice how much of this depends on records you either kept or did not. An organisation with a live data map answers "what data was affected" in minutes. One without it guesses for days.
Notifying affected principals
Where a breach is likely to result in harm, affected data principals must be told — clearly, without jargon, and with enough information to protect themselves. A good breach notice states what happened, what data was involved, what you are doing, and what they should do. It does not bury the substance in legal hedging.
The forensic timeline is your evidence
After the incident is contained, the question becomes: can you show what happened and that you handled it correctly? A forensic timeline — an append-only record of detection, decisions, containment steps, and notifications — is the difference between "we responded appropriately" and being able to prove it. If any part of that record can be quietly edited after the fact, it stops being evidence.
Rehearse before you need it
The organisations that handle breaches well are the ones that practised. Run a tabletop exercise:
- Inject a realistic scenario (ransomware, a misdirected export, a vendor compromise).
- Time how long awareness takes to reach the decision-makers.
- See whether the data map answers "what was affected" quickly.
- Check that the timeline is being recorded by default, not reconstructed afterward.
A breach-readiness checklist
- Is there a fast, unambiguous path from "someone noticed something" to the people who must act?
- Can you determine what data and how many principals were affected in minutes, not days?
- Do you have pre-identified decision-makers and a contact tree?
- Is every action timestamped into an append-only timeline from the first minute?
- Do you have breach-notice templates ready, in plain language?
- Have you rehearsed in the last twelve months?
You cannot prevent every breach. You can decide, in advance, to be the organisation that responds like it has done this before — because it has.
