Breach Response for Sensitive Data Under DPDP and GDPR
Compare DPDP Act breach notice duties and GDPR Articles 33-34 for sensitive-data breaches: awareness clocks, Board vs SA notice, individual communication, and a website playbook. Detailed Rules were still awaited.
- GDPR: Notify the supervisory authority within 72 hours if risk is not unlikely; notify individuals if high risk (encryption can help avoid that step).
- DPDP Rule 7: Notify affected Principals and the Board without delay, then send the Board a detailed package within 72 hours of awareness.
- Filter difference: GDPR has an “unlikely risk” skip for authority notice; Rule 7 as published ties Board intimation to awareness of a breach.
- Triage: Identify high-harm categories, encryption status, and jurisdictions in the first hours.
- Rehearse: Public KYC bucket, wrong-recipient health export, ransomware on passport fields, vendor ticket leaks.
Why sensitive data changes breach severity
A personal data breach is a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. When the records include health data, government IDs, biometrics, credentials with access codes, or other high-harm fields, the risk to people rises quickly. Your playbook must detect faster, assess risk with those categories in mind, and notify the right authorities and individuals on time.
This guide compares India DPDP Act section 8(6) and Rule 7 with GDPR Articles 33 and 34. Regime definitions of “sensitive” differ; see DPDP, GDPR Article 9, CCPA SPI, and security controls in consent, encryption, and access.
GDPR: notify the authority, then (if needed) the people
Article 33: supervisory authority
The controller must notify the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of the breach, unless the breach is unlikely to result in a risk to individuals’ rights and freedoms. Late notifications need reasons. Processors must tell the controller without undue delay (Article 33(2)).
The notification must at least describe the nature of the breach (categories and approximate numbers of people and records where possible), DPO or contact details, likely consequences, and measures taken or proposed. Information may be provided in phases (Article 33(3)-(4)). Controllers must document all breaches, effects, and remediation (Article 33(5)).
EDPB Guidelines 9/2022 explain that “aware” means a reasonable degree of certainty that a security incident compromised personal data, and that you should assess risk within the 72-hour window.
Article 34: communication to individuals
If the breach is likely to result in a high risk to rights and freedoms, the controller must communicate it to affected data subjects without undue delay, in clear language, covering at least the Article 33(3)(b)-(d) points (contact, consequences, measures).
Communication to individuals may be skipped if any of these apply (Article 34(3)):
- Appropriate technical and organisational measures were applied to the affected data, especially measures that make it unintelligible to unauthorised persons (for example encryption).
- Subsequent measures ensure the high risk is no longer likely.
- Individual notice would involve disproportionate effort, in which case a public communication or similar equally effective measure is required instead.
Special category or other high-harm data often pushes an incident into the “high risk” lane unless strong encryption or equivalent protections applied to the compromised copy.
DPDP: Board and Data Principals, without delay
Section 8(6) of the Digital Personal Data Protection Act, 2023 requires a Data Fiduciary to give the Board and each affected Data Principal notice of a personal data breach in such form and manner as may be prescribed. Penalties for failing that notice duty can extend to two hundred crore rupees under the Act’s Schedule.
Rule 7 of the forthcoming DPDP Rules from MeitY sets the prescribed process:
- To each affected Data Principal, without delay: concise, clear, plain notice via user account or registered communication mode, covering description (nature, extent, timing), consequences relevant to her, mitigation measures, safety steps she can take, and business contact details for queries.
- To the Board, without delay: description including nature, extent, timing, location of occurrence, and likely impact.
- To the Board, within 72 hours of awareness (or longer if the Board allows in writing): updated detail, facts and reasons leading to the breach, mitigation measures, findings on who caused it, remedial measures to prevent recurrence, and a report on intimations given to Data Principals.
Unlike GDPR Article 33’s “unless unlikely to result in a risk” filter for authority notice, Rule 7 as published ties intimation duties to becoming aware of any personal data breach. Confirm commencement: Rule 7 and section 8(6) sit in the staged DPDP commencement group (commonly tracked toward a later commencement window once MeitY notifies Rules). Build the playbook now; lock calendar dates when official commencement confirms.
Side-by-side differences that affect your runbook
- Authority notice filter: GDPR allows skipping SA notice if risk is unlikely; DPDP Rule 7 contemplates Board intimation on awareness of a breach, plus a 72-hour detailed package.
- Individual notice: GDPR uses a high-risk threshold (with encryption-style exceptions); DPDP Rule 7 requires without-delay Principal notice covering listed content fields.
- Sensitive categories: GDPR risk scoring weighs special category data heavily; DPDP has no statutory sensitive tier but the same fields still drive “likely impact” and Principal harm in Rule 7 notices. See the DPDP guide.
- Processors: GDPR Article 33(2) is explicit; under DPDP, contracts and Rule 6 security duties still require Processors to surface incidents so Fiduciaries can meet Rule 7 clocks.
Operational playbook for websites
1. Detect and declare “aware”
- Centralise alerts from WAF, IdP, cloud audit logs, ransomware detection, and vendor incident emails.
- Define when an incident becomes a personal data breach (personal data confirmed compromised).
- Start the 72-hour clock when awareness criteria are met; do not wait for full forensics.
2. Triage with a sensitive-data lens
- Identify categories involved: health, biometrics, government IDs, passwords, precise location, children’s data.
- Check whether compromised stores were encrypted or tokenised (GDPR Article 34(3)(a) mitigation argument; DPDP Rule 6 expectation).
- Estimate volume and jurisdictions (EU/UK SA vs India Board vs both).
3. Contain and preserve evidence
- Rotate keys and credentials; isolate affected hosts; block exfil paths.
- Preserve logs required for DPDP Rule 6 investigation retention and GDPR Article 33(5) documentation.
- Engage forensics under privilege as counsel directs.
4. Notify on the correct tracks
- GDPR track: SA within 72 hours if risk not unlikely; individuals if high risk; phased updates allowed.
- DPDP track: Principals without delay with Rule 7(1) content; Board without delay then detailed 72-hour report under Rule 7(2).
- Use pre-approved templates; name categories honestly when health or ID data was involved.
5. Vendors and marketing stacks
- Require processors to notify you without undue delay in Article 28 / DPDP contracts.
- Check whether analytics or ad platforms received copies of the compromised fields; revoke tokens and purge where possible. See also minimisation and retention and sensitive data in analytics tools.
6. After-action
- Root cause, access-control fixes, encryption gaps, and phishing training.
- Update DPIAs / risk registers where special category or high-harm processing continues.
- File internal breach register entries even when you conclude GDPR SA notice was not required.
Tabletop scenarios worth rehearsing
- Unencrypted database backup with KYC images left in a public bucket.
- Support export of health questionnaire answers emailed to the wrong recipient.
- Ransomware on a CRM that stores passport numbers.
- Vendor ticketing tool breach exposing customer disability notes.
Sources
- Regulation (EU) 2016/679, Articles 33 and 34; EDPB Guidelines 9/2022 on personal data breach notification.
- Digital Personal Data Protection Act, 2023, section 8(5)-(6) and Schedule penalties for notice failures.
- forthcoming DPDP Rules from MeitY, Rule 7 (intimation of personal data breach); commencement tracking via G.S.R. notifications and Rule 1 timelines.
- ICO / EDPB SME materials summarising 72-hour awareness and high-risk individual notice.
Disclaimer
This article was prepared by Imran using publicly available information. It is for general education only and is not legal advice. Do not rely on it alone when implementing cookie compliance, DSAR handling, consent flows, sensitive-data controls, breach response, or other privacy and data-protection measures. Consult your own legal counsel for advice that fits your business, jurisdictions, and systems.
Last updated on 21 September 2026
