Legal Register
Interactive Tool
Incident Response Engine

Personal Data Breach Dual-Clock Simulator

A security incident triggers two separate legal clocks with different recipients, contents, and deadlines. Calculate your exact statutory windows in real-time.

Dual-Clock Breach Incident Simulator

Simulate the parallel statutory notification clocks for CERT-In (6 hours) and DPDP Section 8(6) / Rule 7 (without delay & 72h).

Clock 1 · CERT-In (IT Act s.70B)6 Hours
Hard Statutory Deadline:
12:18:00 AM (9/17/2026)
Mandatory Initial Report:
  • Time of occurrence and initial detection
  • Nature of incident and affected critical systems/IPs
  • Initial containment steps deployed
  • Recipient: incident@cert-in.org.in
Clock 2 · DPDP Board & Principals (s.8(6) / r.7)Without Delay / 72h
Full DPDP Intimation Deadline:
06:18 PM (9/19/2026)
Mandatory Two-Step Intimation:
  • Intimate Data Protection Board via online digital office
  • Direct intimation to all 50,000 Data Principals in clear language
  • Description of nature, extent, consequences, and mitigation
  • Contact details of DPO / grievance contact for inquiries
⚠️
Statutory Exposure Note: Under Section 33 read with Item 2 of the Schedule, failure to intimate a personal data breach carries a penalty ceiling of up to ₹200 Crore.Read Chapter 16 Playbook →