OBL-12: Personal Data Breach Detection & Intimation
Mandates prompt notification to the Data Protection Board and affected principals upon breach.
Statutory scope: Section 8(6) · Assigned to Incident commander / Legal · Systems: SIEM & Security Telemetry Store (SYS-012)
Recommended interface: Remove required notice content or assume an unallowed extension; expected outcome is validation failure and the original detailed deadline preserved.
Remove required notice content or assume an unallowed extension; expected outcome is validation failure and the original detailed deadline preserved.
Governance & Architecture
Verification Specification & Workpaper
proposed per-row review/acceptance specification; not a claim of executed statutory coverage
populated hypothetical decision/specimen; not actual enterprise execution
Canonical Statutory Grounding
Source references verified against the official Gazette of India publication baseline.
Data Fiduciary
Processing by it or its processor
Responsibility despite agreements/principal default; valid processor contract; conditional data accuracy; safeguards; breach intimation; erasure; contact and grievance mechanism.
s8(7) lawful-retention exception; s17 preserves s8(1),(5) under subsection (1).