Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
When must you report a CERT-In incident or a DPDP breach?
Updated
Two regimes: CERT-In Directions (ii) set a 6-hour report from noticing a reportable cyber incident (in force since 27 June 2022). DPDP s.8(6) and Rule 7 intimation is not in force until 13 May 2027. Not legal advice; does not start a clock.
India DPDP / CERT-In jurisdiction guide, last verified 8 September 2026 against CERT-In Directions No. 20(3)/2022-CERT-In dated 28 April 2022 (issued under s. 70B(6) of the Information Technology Act, 2000; PDF on cert-in.org.in), the Digital Personal Data Protection Act, 2023 (Act 22 of 2023), MeitY G.S.R. 843(E) of 13 November 2025 (enforcement timeline), G.S.R. 844(E) of 13 November 2025 (Data Protection Board of India established), and the Digital Personal Data Protection Rules, 2025 notified G.S.R. 846(E) 13 November 2025 (draft was G.S.R. 02(E) 3 January 2025; a corrigendum dated 16 December 2025 exists — this page does not invent that corrigendum's contents). CERT-In FAQs on the 28.04.2022 Directions are CERT-In materials, not the Directions. It is not legal advice, not a filing, not an Annexure I classification, not a determination that DPDP or the Directions apply, and not a substitute for counsel.
Two parallel regimes — not YOUR determination, not the same clock
Audience: a founder, CISO, privacy officer, or counsel at a service provider, intermediary, data centre, body corporate, or Government organisation that may sit under CERT-In Directions 2022, or at a Data Fiduciary that may sit under the DPDP Act 2023 when those provisions are in force, triaging an incident that may be an Annexure I cyber incident, a personal data breach, or both. This page is not legal advice. It does not start a clock. Reading it does not start a clock. Mapping a row is not a determination that the Directions apply, that DPDP applies, that an Annexure I type is present, that a personal data breach occurred, or that a named human must file.
These are two parallel regimes. They are not the same clock. Filing one does not discharge the other. A personal data breach that is also an Annexure I 'Data Breach' or 'Data Leak' can sit under both. Last verified 8 September 2026. Not legal advice.
- CERT-In Directions dated 28 April 2022, No. 20(3)/2022-CERT-In, MeitY / CERT-In, issued under s. 70B(6) of the Information Technology Act, 2000: legal requirement only if those Directions apply. Effective 60 days after issuance → 27 June 2022. Still in force as of last-verified 8 September 2026.
- DPDP Act 2023 s.8(6) is the Act-level intimation duty (Board + each affected Data Principal, form and manner as prescribed). Rule 7 of the DPDP Rules, 2025 is that prescription. s.8 is in the 13 May 2027 commencement bucket under G.S.R. 843(E). As of 8 September 2026, DPDP personal-data-breach intimation is NOT yet in force. Do not write Rule 7's 72-hour limb as current enforceable law.
- CERT-In FAQs on the 28.04.2022 Directions are CERT-In materials, not Direction (ii). This page quotes which kind of text it is relying on.
- This page does not start a 6-hour clock, does not convert 6 hours into 72 hours, and does not paste GDPR Article 33 onto CERT-In or DPDP.
- The reporting-deadlines page on this site is the statute table of clocks. The who-to-notify page on this site is the recipient-class map. The which-jurisdictions-apply page on this site is the applicability map. The reporting-decision-tree page on this site is the branching tree. The document-your-decision page on this site is the decision record.
- The signed-in CRA ladder tracks recorded awareness for findings the organisation classified as CRA-in-scope. That tracker is not a CERT-In 6-hour clock and not a DPDP Rule 7 clock. A named human still files.
DPDP versus CERT-In — two-regime comparison
Walk this table with counsel. It is not a determination that either regime applies to YOUR facts. Last verified 8 September 2026. Not legal advice.
| Regime | What it covers | Clock | Recipient | In force as of 8 Sep 2026 | Kind of text |
|---|---|---|---|---|---|
| CERT-In Directions (ii) | Cyber incidents mentioned in Annexure I, including Data Breach and Data Leak, among other types listed in those Directions. | Within 6 hours of noticing such incidents or being brought to notice about such incidents. Not confirmation. Not end of investigation. Not GDPR-style 'aware of a personal data breach'. | CERT-In. Channels named in the Directions: email incident@cert-in.org.in, Phone 1800-11-4949, Fax 1800-11-6969. Details of methods and formats also on www.cert-in.org.in. | Yes. In force since 27 June 2022 (60 days after 28 April 2022 issuance). Still in force as of last-verified. | Legal requirement — Direction (ii), only if the Directions apply. |
| DPDP s.8(6) + Rule 7(1) — Data Principal | Personal data breach. s.8(6): the Data Fiduciary shall give the Board and each affected Data Principal intimation of such breach in such form and manner as may be prescribed. | Rule 7(1): on becoming aware of any personal data breach, intimate each affected Data Principal, to the best of its knowledge, in a concise, clear and plain manner and without delay. | Each affected Data Principal, through her user account or any mode of communication registered by her with the Data Fiduciary. | No. s.8 is in the eighteen-month bucket of G.S.R. 843(E) (13 November 2025) → 13 May 2027. Not in force as of 8 September 2026. | Notified Rules / Act text, not yet in force. Legal requirement only when in force and only if DPDP applies. |
| DPDP Rule 7(2) — Board | The same personal data breach. Rule 7 operationalises s.8(6) for the Board. | Rule 7(2)(a): without delay, a description including nature, extent, timing and location of occurrence and the likely impact. Rule 7(2)(b): within seventy-two hours of becoming aware of the breach, or within such longer period as the Board may allow on a request made in writing in this behalf — then the detailed limbs. | The Data Protection Board of India (established G.S.R. 844(E) 13 November 2025; head office in the National Capital Region). | No. Same 13 May 2027 commencement for ss.7–10. Do not treat the 72-hour limb as current enforceable law. | Notified Rules, not yet in force. Legal requirement only when in force and only if DPDP applies. |
| Parallel overlap | A personal data breach that is also an Annexure I 'Data Breach' or 'Data Leak' can sit under both CERT-In Direction (ii) and, when in force, DPDP s.8(6) + Rule 7. | Two clocks. CERT-In 6 hours from noticing. DPDP (when in force) without delay to Data Principals and to the Board, then 72 hours for Rule 7(2)(b). Not the same start event. | CERT-In is not the Board. The Board is not CERT-In. Data Principals are a third recipient class. | CERT-In limb: in force. DPDP limb: not in force until 13 May 2027. | This page. Filing one never discharges the other. Not a determination on YOUR facts. |
| GDPR Article 33 | EU personal-data-breach notice to a supervisory authority. A different instrument. | Without undue delay and, where feasible, not later than 72 hours after having become aware. That 72-hour outer mark does not discharge CERT-In's 6 hours from noticing, and it does not start DPDP Rule 7. | An EU supervisory authority is not CERT-In and not the Data Protection Board of India. | GDPR applies on its own facts. It is not an India filing. | This page. GDPR 72 hours does not discharge either Indian regime. The GDPR breach-notification guide on this site is Articles 33–34 of EU GDPR. |
CERT-In 6 hours from noticing — current law, in force
Direction (ii) of the CERT-In Directions dated 28 April 2022: 'Any service provider, intermediary, data centre, body corporate and Government organisation shall mandatorily report cyber incidents as mentioned in Annexure I to CERT-In within 6 hours of noticing such incidents or being brought to notice about such incidents.' That sentence is the Directions. This page does not convert 6 hours into 72 hours. Last verified 8 September 2026. Not legal advice.
| Element | What the text says | Kind of text | Last verified |
|---|---|---|---|
| Who Direction (ii) names | Any service provider, intermediary, data centre, body corporate and Government organisation. | Legal requirement — Direction (ii), only if the Directions apply. This page does not decide that YOU are any of those bodies. | 8 September 2026 |
| What to report | Cyber incidents as mentioned in Annexure I. Annexure I includes Data Breach and Data Leak. The list is the Directions, not a blog. | Legal requirement — Direction (ii) + Annexure I. This page does not classify YOUR event as Annexure I. | 8 September 2026 |
| Clock start | Within 6 hours of noticing such incidents or being brought to notice about such incidents. | Legal requirement — Direction (ii). Not confirmation. Not end of investigation. Not GDPR-style 'aware of a personal data breach'. | 8 September 2026 |
| Recipient and channels | Report to CERT-In. Channels named in the Directions: email incident@cert-in.org.in, Phone 1800-11-4949, Fax 1800-11-6969. Details of methods and formats also on www.cert-in.org.in. | Legal requirement — the Directions name those channels. A named human still files. This page does not file. | 8 September 2026 |
| What this page does not convert | 6 hours is 6 hours from noticing or being brought to notice. It is not 72 hours. It is not GDPR Article 33(1). CERT-In FAQs saying entities may report information available at the time and follow up are FAQ, not Direction (ii). | This page. FAQ is guidance. Direction (ii) is the Directions. | 8 September 2026 |
Annexure I reportable types — the Directions, not a blog
Annexure I of the CERT-In Directions dated 28 April 2022 lists reportable types. Quote the list. This page does not classify YOUR event. Last verified 8 September 2026. Not legal advice.
- Targeted scanning / probing of critical networks / systems; compromise of critical systems / information; unauthorised access of IT systems / data; defacement of website or intrusion into a website and unauthorised changes such as inserting malicious code, links, or deface pages; malicious code attacks (including virus / worm / Trojan / Bots / Spyware / Ransomware / Cryptominers); attacks on servers (Database, Mail, DNS) and network devices (Routers); identity theft, spoofing and phishing attacks; denial of Service (DoS) and Distributed Denial of Service (DDoS) attacks; attacks on Critical infrastructure, SCADA, operational technology systems and wireless networks; attacks on applications (including e-Governance and UPI); Data Breach; Data Leak; attacks on Internet of Things (IoT) devices and associated systems, networks, servers, and software; attacks or incidents affecting digital payment systems; attacks through malicious mobile apps; unauthorised access to social media accounts; attacks or suspicious activities affecting cloud computing systems / servers / software / applications; attacks or malicious / suspicious activities affecting systems / servers / networks / software / applications related to Big Data, blockchain, virtual assets, robotics, 3D and 4D printing, additive manufacturing, drones; attacks or malicious / suspicious activities affecting systems / servers / software / applications related to artificial intelligence and machine learning.
- Data Breach and Data Leak are in that Annexure I list. They are CERT-In incident types. They are not, by themselves, a DPDP personal-data-breach finding, and a DPDP finding (when that duty is in force) is not a substitute for Annexure I classification. This page does not run either test on YOUR facts.
Other CERT-In Directions — not a KYC guide
The 28 April 2022 instrument is more than Direction (ii). These other directions exist. This page does not turn them into a KYC or logging product. Last verified 8 September 2026. Not legal advice.
- Direction (i): synchronise ICT system clocks to Network Time Protocol (NTP) of the National Informatics Centre (NIC) or National Physical Laboratory (NPL). Entities with ICT infrastructure spanning multiple geographies may use another accurate and standard time source, provided the time source does not deviate from NPL or NIC.
- Direction (iii): designate a Point of Contact (format in Annexure II) to interface with CERT-In, emailed to info@cert-in.org.in, and comply with CERT-In orders and directions.
- Direction (iv): enable logs of all ICT systems, maintain them securely for a rolling 180 days, maintained within the Indian jurisdiction, and provide them to CERT-In along with incident reports or when ordered. The product does not keep those 180-day logs.
- Directions (v) and (vi): registration / KYC duties for data centres, virtual private server providers, cloud service providers, VPN service providers, and virtual asset service providers. They exist. This page is not a KYC guide and does not invent their contents beyond naming that they exist.
- Non-compliance: the Directions text says failure to furnish information or non-compliance 'may invite punitive action under sub-section (7) of the section 70B of the IT Act, 2000 and other laws as applicable.' That is the Directions' own words. This page does not invent a typical CERT-In fine or a rupee-per-day figure as if it had fetched current s.70B(7) maxima.
DPDP s.8(6) and Rule 7 — notified, not in force until 13 May 2027
This is the accuracy trap. Rule 7's 72-hour limb is notified text. It is not current enforceable law as of last-verified 8 September 2026. G.S.R. 843(E) of 13 November 2025 appointed eighteen months from that gazette — 13 May 2027 — as the date ss.3–5, s.6(1)–(8) and (10), ss.7–10, ss.11–17, s.27 except (1)(d), ss.28–34, 36, 37, and s.44(2) come into force. s.8 is in that bucket. Do not treat 'you notify the Board within 72 hours' as the law today. Last verified 8 September 2026. Not legal advice.
| Element | What the text says | Kind of text | Last verified |
|---|---|---|---|
| Act-level duty | s.8(6): In the event of a personal data breach, the Data Fiduciary shall give the Board and each affected Data Principal, intimation of such breach in such form and manner as may be prescribed. | Act text — DPDP Act 2023 s.8(6). Legal requirement only when in force and only if DPDP applies. Not in force as of 8 September 2026. | 8 September 2026 |
| G.S.R. 843(E) — what is already in force | Immediate from 13 November 2025: s.1(2), s.2, ss.18–26, ss.35, 38–43, s.44(1) and (3) — Board establishment, definitions, some miscellaneous. One year (13 November 2026): s.6(9) and s.27(1)(d). | Gazette — MeitY G.S.R. 843(E) 13 November 2025. Not the breach-intimation duty. | 8 September 2026 |
| G.S.R. 843(E) — eighteen months | 13 May 2027: ss.3–5, s.6(1)–(8) and (10), ss.7–10, ss.11–17, s.27 except (1)(d), ss.28–34, 36, 37, s.44(2). That is the bucket that contains s.8. | Gazette. The DPDP personal-data-breach intimation is not in force until that date. | 8 September 2026 |
| Board established | G.S.R. 844(E), 13 November 2025: Data Protection Board of India established with effect from gazette publication; head office in the National Capital Region. | Gazette. Establishing the Board is not the same as commencing s.8(6). | 8 September 2026 |
| Rule 7(1) — Data Principal | On becoming aware of any personal data breach, the Data Fiduciary shall, to the best of its knowledge, intimate each affected Data Principal, in a concise, clear and plain manner and without delay, through her user account or any mode of communication registered by her with the Data Fiduciary: (a) description of the breach including nature, extent and timing of occurrence; (b) consequences relevant to her that are likely to arise; (c) measures implemented and being implemented to mitigate risk; (d) safety measures she may take; (e) business contact information of a person able to respond on behalf of the Data Fiduciary. | Notified Rules — G.S.R. 846(E) 13 November 2025, Rule 7(1). Not yet in force for this duty. A corrigendum dated 16 December 2025 exists; this page does not invent its contents. | 8 September 2026 |
| Rule 7(2) — Board | On becoming aware, intimate the Board: (a) without delay, a description including nature, extent, timing and location of occurrence and the likely impact; (b) within seventy-two hours of becoming aware of the breach, or within such longer period as the Board may allow on a request made in writing in this behalf — (i) updated and detailed information in respect of such description; (ii) the broad facts related to the events, circumstances and reasons leading to the breach; (iii) measures implemented or proposed, if any, to mitigate risk; (iv) any findings regarding the person who caused the breach; (v) remedial measures taken to prevent recurrence of such breach; and (vi) a report regarding the intimations given to affected Data Principals. | Notified Rules — Rule 7(2). The 72-hour limb is Rule 7(2)(b) as published 13 November 2025. Not yet in force. Do not paste it onto CERT-In, and do not paste CERT-In's 6 hours onto Rule 7. | 8 September 2026 |
Legal requirement versus guidance versus this page
This page labels each cited text. Last verified 8 September 2026. Not legal advice.
| Text | Kind | What it is not |
|---|---|---|
| CERT-In Directions No. 20(3)/2022-CERT-In dated 28 April 2022, including Direction (ii) and Annexure I | Legal requirement, only if the Directions apply. In force since 27 June 2022. | Not DPDP. Not GDPR. Not a FAQ. Not a 72-hour clock. |
| Information Technology Act, 2000 s. 70B(6) (the power under which the Directions issued) and s. 70B(7) as the Directions themselves cite it | The Directions quote that non-compliance may invite punitive action under s. 70B(7) and other laws as applicable. This page quotes the Directions' own words. It does not invent current s.70B(7) maxima. | Not a typical fine. Not an average Indian breach cost. |
| CERT-In FAQs on the 28.04.2022 Directions | CERT-In materials. Guidance. They say entities may report information available at the time and follow up. | Not Direction (ii). Follow-up language in a FAQ does not rewrite the 6-hour sentence. |
| DPDP Act 2023 (Act 22 of 2023) s.8(6) and the Schedule | Act text. s.8(6) is the intimation duty once commenced. The Schedule lists statutory maxima for, among other limbs, failure to take reasonable security safeguards under s.8(5) and failure to give the Board or affected Data Principal notice under s.8(6). Those figures are maxima, not typical outcomes. This page does not invent typical Data Protection Board fines or an average Indian breach cost. | Not in force for s.8 as of 8 September 2026. Not CERT-In. The product does not prosecute and does not issue fines. |
| DPDP Rules, 2025 (G.S.R. 846(E) 13 November 2025), Rule 7 | Notified Rules. Prescription for s.8(6). Not yet in force for this duty (13 May 2027). A corrigendum dated 16 December 2025 exists; this page does not invent its contents. | Not current enforceable law as of last-verified. Not Direction (ii). |
| MeitY G.S.R. 843(E) and G.S.R. 844(E) (13 November 2025) | Gazette. Commencement timeline and Board establishment. | Not Rule 7. Establishing the Board does not commence s.8(6). |
| This page | A jurisdiction guide. Last verified 8 September 2026. | Not legal advice. Not a filing. Not YOUR clock. Not an Annexure I classification. |
GDPR 72 hours, HIPAA, and Form 8-K do not discharge CERT-In or DPDP
Overlapping duties may all attach. Filing one never discharges the others. Last verified 8 September 2026. Not legal advice.
- GDPR Article 33(1)'s 72 hours from becoming aware is not CERT-In Direction (ii)'s 6 hours from noticing, and it is not DPDP Rule 7 (when in force). The GDPR breach-notification guide on this site is Articles 33–34 of EU GDPR. The UK GDPR jurisdiction guide on this site is Articles 33–34 to the Commissioner.
- Form 8-K Item 1.05 is securities-law disclosure to investors within four business days of a materiality determination. The SEC cyber-disclosure guide on this site is Item 1.05 and Item 106. An Item 1.05 filing does not discharge CERT-In.
- HIPAA 45 CFR §§164.400–414, when it applies, is a different regime. The HIPAA breach-notification guide on this site. A HIPAA notice does not discharge CERT-In or DPDP.
- The Canada PIPEDA jurisdiction guide on this site is PIPEDA ss. 10.1–10.3 and SOR/2018-64. PIPEDA 'as soon as feasible' is not CERT-In 6 hours.
- The Australia NDB jurisdiction guide on this site is Part IIIC. A dedicated UAE/Dubai guide is not on this site yet. Naming them is not a link.
- This page is not an RBI / SEBI CSCRF guide. rbi_sebi is a different bundled key.
- Document the walk, including a no-notification decision. The document-your-decision page on this site is the decision record. This page does not keep YOUR file.
Checklist
This is a question list, not a filing, and not YOUR notice. Walk it with counsel. The which-jurisdictions-apply page on this site is the applicability map. The who-to-notify page on this site is the recipient-class map. The reporting-deadlines page on this site is the statute table. The reporting-decision-tree page on this site is the branching tree. The document-your-decision page on this site is the decision record.
- Do the CERT-In Directions apply to this organisation (service provider, intermediary, data centre, body corporate, or Government organisation)? This page does not run that test.
- Is the event a cyber incident mentioned in Annexure I, including Data Breach or Data Leak? This page does not classify it.
- If Direction (ii) applies: 6 hours from noticing such incidents or being brought to notice about such incidents, to CERT-In. Do not convert 6 hours into 72 hours. Do not wait for confirmation or the end of investigation.
- Does DPDP apply to this processing, and has s.8 commenced? As of last-verified 8 September 2026, s.8 is not in force (13 May 2027). When it is in force, s.8(6) + Rule 7 is a separate intimation to the Board and each affected Data Principal. Filing CERT-In does not discharge that duty.
- Direction (iv) 180-day logs within the Indian jurisdiction, if the Directions apply. The product does not keep those logs.
- Who is authorised to file, and who is not. A named human files. The product does not. This page does not file.
Where this shows up in ShipReady Metrics
The signed-in app does not decide that DPDP or CERT-In applies, does not classify Annexure I, does not start a 6-hour clock, does not file with CERT-In, does not file with the Data Protection Board, does not notify Data Principals, and does not keep the 180-day CERT-In logs. None of the surfaces below is a Direction (ii) report, a Rule 7 intimation, or an instruction to submit a filing.
If you already have a session: signed-in app → Compliance → CRA reporting tracks the Article 14 24-hour and 72-hour stages from recorded awareness, and the 14-day final-report mark from recorded measure availability, for findings the organization has classified as CRA-in-scope. That is one product tracker for the CRA actively-exploited ladder. It is not a CERT-In 6-hour clock and not a DPDP Rule 7 clock. It tracks a clock the organization already recorded. It is not a determination that CRA applies. The CRA Article 14 reporting guide on this site is that ladder's statute. A named human still submits. There is no signed-in app route that mentions CERT-In.
The obligation map lists frameworks the organization has marked in-scope. That in-scope mark is not a determination that DPDP applies, not a determination that the CERT-In Directions apply, and not a legal opinion that an Annexure I incident or a personal data breach has occurred. The bundled framework key `dpdp` exists. Its version label is DPDP Act 2023 + CERT-In 6h (starter subset). It is region-tagged `india`. It is in INTERNAL_TESTER_ONLY_FRAMEWORKS — internal-tester-only until reviewed on real estates. Customer surfaces hide it (`isFrameworkCustomerVisible`). It is not a customer-visible DPDP filing pack. Control `§8(6) Breach notification` has evidenceType `manual`. Control `CERT-In 6h` has evidenceType `manual`. Defining a control never asserts it is met. There is also `rbi_sebi` (internal-tester-only) — this page is not an RBI / SEBI CSCRF guide. The cyber risk register lives under Security. It is a cyber risk register. It is not a CERT-In log store, not a Rule 7 intimation, and not an Annexure I worksheet.
A pure clock exists in product code: CERT_IN_REPORT_HOURS = 6 from a recorded `noticedAt` for incidents the organisation classified `reportable`. Unknown or future noticedAt yields `unknown_clock` (never a fabricated overdue). That clock does not start for the reader of this page. It does not start because you opened this guide. A named human / counsel still files.
Key terms used on this page
Short labels. They are not a glossary of every privacy-law or incident-reporting term. Last verified 8 September 2026. Not legal advice.
| Term | How this page uses it |
|---|---|
| CERT-In Directions (ii) | The 6-hour cyber-incident report to CERT-In in the Directions dated 28 April 2022. Clock start: noticing or being brought to notice. In force since 27 June 2022. |
| Annexure I | The Directions' list of reportable cyber-incident types, including Data Breach and Data Leak. This page does not classify YOUR event against it. |
| Noticing | Direction (ii) start event: 'noticing such incidents or being brought to notice about such incidents.' Not confirmation. Not end of investigation. Not GDPR-style awareness of a personal data breach. |
| DPDP s.8(6) | Act-level intimation to the Board and each affected Data Principal, form and manner as prescribed. In the 13 May 2027 commencement bucket. Not in force as of last-verified 8 September 2026. |
| Rule 7 | DPDP Rules, 2025, G.S.R. 846(E): Data Principal without delay; Board without delay then 72 hours. Notified. Not in force for this duty until 13 May 2027. |
| Data Protection Board | Established G.S.R. 844(E) 13 November 2025. Head office in the National Capital Region. Not CERT-In. Establishing the Board did not commence s.8(6). |
Primary sources (last verified 8 September 2026)
Every regulatory or guidance claim on this page is taken from one of these. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.
CERT-In Directions No. 20(3)/2022-CERT-In dated 28 April 2022 (PDF on cert-in.org.in), issued under s. 70B(6) of the Information Technology Act, 2000, effective 27 June 2022, still in force as of last-verified: Direction (ii) is the 6-hour report of Annexure I cyber incidents to CERT-In from noticing or being brought to notice. CERT-In FAQs on those Directions are CERT-In materials, not the Directions. Digital Personal Data Protection Act, 2023 (Act 22 of 2023) s.8(6) is the Act-level intimation duty. MeitY G.S.R. 843(E) 13 November 2025 is the enforcement timeline; ss.7–10 including s.8 commence 13 May 2027. G.S.R. 844(E) 13 November 2025 established the Data Protection Board of India. DPDP Rules, 2025 notified G.S.R. 846(E) 13 November 2025; Rule 7 is Intimation of personal data breach; a corrigendum dated 16 December 2025 exists and this page does not invent its contents. As of 8 September 2026, DPDP personal-data-breach intimation is not yet in force. These are the Indian provisions this page treats, not a complete world list of breach laws. Not legal advice.
The reporting-deadlines page on this site is the statute table of clocks. The how-regulators-determine-knowledge page on this site is the clock-start analysis. The failure-to-report-consequences page on this site is the maxima table. The do-I-have-to-report page on this site is the class map. The reporting-decision-tree page on this site is the branching tree. The who-to-notify page on this site is the recipient-class map. The regulator-customer-individual page on this site is the three-stream comparison. The which-jurisdictions-apply page on this site is the applicability map. The prepare-regulatory-report page on this site is the field checklist. The document-your-decision page on this site is the decision record. The supporting-evidence page on this site is the evidentiary record. The GDPR breach-notification guide on this site is Articles 33–34 of EU GDPR. The NIS2 incident-reporting guide on this site. The DORA incident-reporting guide on this site is the jurisdiction treatment of Articles 18–19. The CRA Article 14 reporting guide on this site. The UK GDPR jurisdiction guide on this site is Articles 33–34 to the Commissioner. The US-state-laws guide on this site is the representative high-variance comparison. The SEC cyber-disclosure guide on this site is Form 8-K Item 1.05 and Item 106. The HIPAA breach-notification guide on this site. The Canada PIPEDA jurisdiction guide on this site is PIPEDA ss. 10.1–10.3 and SOR/2018-64. The Australia NDB jurisdiction guide on this site is Part IIIC. A dedicated UAE/Dubai guide is not on this site yet. Naming them is not a link.
Frequently asked questions
When must you report a CERT-In incident or a DPDP breach?
If the CERT-In Directions apply, Direction (ii) sets a report to CERT-In within 6 hours of noticing an Annexure I cyber incident or being brought to notice of it — in force since 27 June 2022. DPDP s.8(6) and Rule 7 intimation to the Board and each affected Data Principal is not in force until 13 May 2027. Two regimes; filing one does not discharge the other. Last verified 8 September 2026. Not legal advice.
Is this legal advice?
No. It is an India DPDP / CERT-In jurisdiction guide distilled from the CERT-In Directions dated 28 April 2022, the DPDP Act 2023, G.S.R. 843(E) and 844(E), and the DPDP Rules, 2025 labelled by kind of text. Whether the Directions apply, whether DPDP applies, whether an Annexure I type is present, and whether a clock has started are legal questions for counsel on your facts. This page does not start a reporting clock.
Does ShipReady file with CERT-In?
No. The signed-in app does not file with CERT-In, does not classify Annexure I, does not start a 6-hour clock for the reader, and does not keep the 180-day CERT-In logs. There is no signed-in app route that mentions CERT-In. Compliance → CRA reporting tracks the Article 14 ladder from recorded awareness for findings the org classified as CRA-in-scope — one product tracker, not a CERT-In clock. A named human still files.
Does ShipReady file with the Data Protection Board?
No. The signed-in app does not file with the Data Protection Board and does not notify Data Principals. DPDP s.8(6) + Rule 7 is not in force until 13 May 2027 as of last-verified 8 September 2026. The bundled `dpdp` framework is internal-tester-only until reviewed on real estates; it is not a customer-visible DPDP filing pack. A named human still files.
Is the CERT-In 6-hour clock the same as DPDP Rule 7?
No. CERT-In Direction (ii) is 6 hours from noticing a reportable cyber incident or being brought to notice of it, in force since 27 June 2022. DPDP Rule 7 (when in force) is without delay to each affected Data Principal and to the Board, then 72 hours for the detailed Board intimation. Different start events, different recipients, different instruments. Filing one does not discharge the other. Not legal advice.
Is DPDP breach notification in force today?
No. As of last-verified 8 September 2026, DPDP personal-data-breach intimation is not yet in force. G.S.R. 843(E) of 13 November 2025 puts ss.7–10, including s.8, in the eighteen-month bucket that arrives on 13 May 2027. Rule 7 is notified text, not current enforceable law. CERT-In Direction (ii) is a separate regime and is in force.
Does a GDPR Article 33 notice discharge CERT-In?
No. GDPR Article 33(1) is without undue delay and, where feasible, not later than 72 hours after having become aware, to an EU supervisory authority. CERT-In Direction (ii) is 6 hours from noticing, to CERT-In. A GDPR notice does not discharge CERT-In, and it does not discharge DPDP Rule 7 when that duty is in force. Not legal advice.
Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.