Interactive Tool
Incident Response Engine
Personal Data Breach Dual-Clock Simulator
A security incident triggers two separate legal clocks with different recipients, contents, and deadlines. Calculate your exact statutory windows in real-time.
Dual-Clock Breach Incident Simulator
Simulate the parallel statutory notification clocks for CERT-In (6 hours) and DPDP Section 8(6) / Rule 7 (without delay & 72h).
Clock 1 · CERT-In (IT Act s.70B)6 Hours
Hard Statutory Deadline:
12:18:00 AM (9/17/2026)
Mandatory Initial Report:
- Time of occurrence and initial detection
- Nature of incident and affected critical systems/IPs
- Initial containment steps deployed
- Recipient: incident@cert-in.org.in
Clock 2 · DPDP Board & Principals (s.8(6) / r.7)Without Delay / 72h
Full DPDP Intimation Deadline:
06:18 PM (9/19/2026)
Mandatory Two-Step Intimation:
- Intimate Data Protection Board via online digital office
- Direct intimation to all 50,000 Data Principals in clear language
- Description of nature, extent, consequences, and mitigation
- Contact details of DPO / grievance contact for inquiries
⚠️
Statutory Exposure Note: Under Section 33 read with Item 2 of the Schedule, failure to intimate a personal data breach carries a penalty ceiling of up to ₹200 Crore.Read Chapter 16 Playbook →