Legal Register
Visual Infographic
I-09 Incident & Breach Governance 👤 CISO, Incident Response & DPO Teams

The Dual Breach Clocks

DPDP Rule 7 Intimation vs CERT-In 6-Hour Cyber Incident Mandate

Indian enterprises face dual, concurrent breach reporting obligations that run on different clocks with different scopes. Under CERT-In Directions 2022, cybersecurity incidents must be reported to CERT-In within 6 hours of discovery. Under DPDP Act s.8(6) and Rule 7, personal data breaches require immediate intimation without delay to both the Data Protection Board and affected Data Principals, followed by a comprehensive 72-hour technical forensic dossier.

Statutory Source: Ch. 16, Ch. 31
Archetype: dual clock
I-09 DiagramArchetype: DUAL CLOCK

The Dual Breach Clocks

CERT-IN CLOCK6 Hours

Clock 1: CERT-In Cyber Incident Clock

Cybersecurity incidents (ransomware, DDoS, unauthorized access)
Recipient: CERT-In (Indian Computer Emergency Response Team)
DPDP RULE 7 CLOCKImmediate / Without Delay + 72h Final Report

Clock 2: DPDP Personal Data Breach Clock

Unauthorized processing, disclosure, destruction, or loss of personal data
Recipient: Data Protection Board of India + All Affected Data Principals

💡 Core Architectural Insights & Takeaways

Key technical and regulatory takeaways established by this architecture diagram.

A cybersecurity incident may not be a personal data breach, but a personal data breach often triggers CERT-In.
DPDP requires notifying the individual victims directly, whereas CERT-In is regulator-facing.
Failure to notify carries up to ₹200 Crore penalty under DPDP Schedule Item 2.

📜 Statutory Grounding & Legal Perimeter

Primary Act and subordinate Rule provisions establishing the enforceable legal mandate for this diagram.

Enforceable Provisions:
Section 8(6)Rule 7Schedule I (Rules)IT Act s.70B

🏗️ Target Architecture & Impacted Systems

Enterprise nodes and store topologies impacted by this architectural pattern.

View Complete Topology (SYS-001..014) →

⚙️ Associated Operational Controls

Control Master Matrix obligations enforcing the standards illustrated in this infographic.

Open Control Matrix →

🛠️ Implementation Guidance & Traps

Recommended technical sequencing and operational failure modes to avoid.

Recommended Implementation Sequence

  1. Establish a unified incident triaging runbook connecting SOC analysts with the DPO.
  2. Pre-draft multilingual breach notification templates for Data Principals.
  3. Implement automated forensic snapshot tools to compile the 72-hour DPDP Rule 7 dossier.

Enterprise Traps & Failure Modes

  • ⚠️ Waiting for 72 hours before issuing initial notification to the Board.
  • ⚠️ Sending technical jargon to Data Principals instead of clear remedial safety guidance.

📁 Verifiable Evidence Artifacts Vault

Required evidentiary workpapers for regulatory inspections and SDF audits.

📄 CERT-In Incident Report Acknowledgement (INCIDENT-001)
📄 DPBI Rule 7 Initial & 72-Hour Breach Filing
📄 Data Principal Notification Dispatch Logs