DPDP Section 6 · Rule 6

The DPDP breach clock starts at detection, not confirmation - here's how Custelis tracks it

Section 6 of the DPDP Act gives you 72 hours to report a personal data breach to the Data Protection Board of India in detail, and requires an immediate preliminary notification the moment you become aware of one - with no minimum-affected-users threshold. "Aware" starts the clock before your investigation is finished, which is exactly when a manual process breaks down.

What the Act actually requires

Where a manual process actually breaks

Most firms don't miss the 72-hour window because they don't know the rule - they miss it because "awareness" isn't a single clean event. It's a Slack message, a DLP alert, a partner mentioning something in a hallway. Nobody starts a stopwatch. By the time it's written down as an official incident, hours or days have already passed against a clock nobody was tracking.

How Custelis's breach workflow handles this

Record it

A compliance officer opens a breach record: title, nature, affected data categories, affected data-principal count, likely consequences, mitigation steps taken. This is a deliberate action, not an automatic classification from a DLP or risk event.

Set the awareness point

The detection timestamp defaults to the moment the record is created, but can be backdated to when your team actually became aware - matching Section 6's "awareness, not confirmation" standard instead of quietly resetting the clock to whenever the paperwork got done.

72-hour deadline, computed

The Board-report deadline is calculated as detection time + 72 hours and shown on the record throughout, so a compliance officer always knows exactly how much runway is left.

Your team files it

Custelis generates the Board-report payload (nature and extent, affected categories, likely consequences, mitigation) and tracks notification status - it does not submit anything to the Data Protection Board on your behalf. Filing the report is a decision for your compliance officer and counsel, every time.

What this isn't: an automated regulator-filing tool, and not a general-purpose breach register for incidents that have nothing to do with monitoring or DLP data. It's a timed workflow state attached to Custelis's own incident and DLP-alert handling - built so the 72-hour clock is something your team can see, not something they have to remember to start.

Related reading

This page explains our understanding of DPDP Act Section 6 and the DPDP Rules, 2025, and is not legal advice. Confirm your organization's specific breach-notification obligations with your own counsel.

See the breach workflow live

No credit card to start. Intrusive features stay off until your own DPIA is recorded.

Try for free