
DPDP Act Compliance for Indian Startups
72-Hour Breach Reporting Checklist
If your startup handles Indian user data, you have exactly 72 hours to report a data breach once you discover it. Miss this deadline, and you're looking at penalties up to ₹250 crore under India's Digital Personal Data Protection (DPDP) Act, 2023.
Here's the reality most founders don't know: the 72-hour clock starts ticking the moment anyone in your company becomes aware of a breach, whether it's your CTO at 3 AM, an intern who notices suspicious logs, or a customer who reports phishing. There's no business hours exemption. No let's investigate first grace period.
This checklist cuts through the legal jargon and gives you a step-by-step, founder-friendly guide to DPDP Act compliance. Whether you're a SaaS startup in Bangalore, a fintech in Mumbai, or an e-commerce platform in Hyderabad, this is your playbook for staying compliant without hiring a ₹10 lakh consultant.
DPDP Act Compliance for Indian Startups
What Founders Need to Know Right Now
The DPDP Act isn't some distant regulation, it's enforceable from May 13, 2027 for breach reporting obligations, but smart startups are preparing now. Here's why:
Who It Applies To:
- Every startup processing digital personal data of Indian users
- No revenue threshold, even pre-revenue startups must comply
- Includes foreign companies serving Indian customers
- Covers employees' personal data too
What Counts as Personal Data:
- Names, emails, phone numbers
- Payment information, addresses
- Device IDs, IP addresses, cookies
- Any data that can identify an individual
The Two Reporting Timelines You Can't Mix Up:
-
CERT-In (6 hours): Report to India's cybersecurity agency within 6 hours of discovering certain incidents (data breaches, ransomware, unauthorized access)
-
DPDP Act (72 hours): File a detailed report with the Data Protection Board of India within 72 hours, plus notify affected users
Most founders confuse these or think they're the same. They're not. You might need to file both, and the deadlines don't align.
Penalties That Keep CEOs Awake:
- Up to ₹250 crore for significant data breaches
- Penalties apply to the company AND responsible officers
- No "first-time offender" leniency
Step-by-Step 72-Hour Breach Checklist
Hour 0–1: Discover & Contain
What Triggers the Clock:
- Employee reports suspicious activity
- Customer complains about phishing emails
- Monitoring tool (Wazuh, Bitdefender) alerts on unusual access
- Third-party vendor notifies you of their breach affecting your data
Immediate Actions:
- Document the exact time: someone became aware this is your T=0 for the 72-hour countdown
- Activate your incident response team : even if it's just you, your CTO, and a shared Slack channel
- Contain the breach : disable compromised accounts, isolate affected servers, revoke suspicious API keys
- Preserve evidence : don't delete logs, screenshots, or communications. You'll need these for the DPDP report
Pro Tip: Create a breach war room Slack channel beforehand. Pre-invite your CTO, legal advisor, and customer support lead. When a breach hits, you're already organized.
Hour 1–6: CERT-In Reporting (If Applicable)
Do You Need to Report to CERT-In? Yes, if the incident involves:
- Data breach affecting user information
- Ransomware or malware infection
- Unauthorized access to systems
- DDoS attacks disrupting services
- Phishing campaigns targeting your users
How to Report:
- Email: incident@cert-in.org.in
- Phone: 1800-11-4949 (toll-free)
- Format: Use CERT-In's prescribed template (Annexure I of their 2022 directions)
What to Include:
- Time of incident discovery
- Type of incident (breach, ransomware, etc.)
- Systems affected
- Approximate number of users impacted
- Immediate containment actions taken [
Critical: This 6-hour deadline is absolute. CERT-In doesn't care if it's 2 AM on a Sunday. Set up automated alerts so you're notified immediately when something suspicious happens.
Hour 6–24: Initial Assessment & Board Intimation
What the DPDP Rules Require: Under Rule 7, you must intimate the Data Protection Board "without delay" once aware of a breach – this is separate from the 72-hour detailed report .
Initial Intimation Should Include:
- Brief description of the breach
- Categories of data potentially exposed (emails, payment info, etc.)
- Rough estimate of affected users
- Your contact information for follow-up
Internal Assessment Checklist:
- [ ] Identify which systems were compromised
- [ ] Determine what data was accessed or exfiltrated
- [ ] List affected user segments (Indian users only, or global?)
- [ ] Check if children's data (under 18) was involved – this escalates severity
- [ ] Review vendor contracts – did a third party (AWS, Stripe, Razorpay) cause this?
Founder Reality Check: You don't need a forensics team to send the initial intimation. A 2-paragraph email to the Board describing what you know so far is enough. The detailed report comes later.
Hour 24–48: Prepare User Notifications
DPDP Rule: Notify each affected Data Principal (user) within 72 hours.
What to Tell Users:
- What happened (in plain language, no legalese)
- What data was exposed (be specific: email addresses and phone numbers, not just personal data)
- What protective steps they should take (change passwords, monitor bank statements, etc.)
- How to reach you for questions (dedicated email like privacy@yourcompany.com)
Notification Channels:
- Email (primary method)
- In-app notification (if users are active on your platform)
- SMS (for critical breaches involving payment data)
- Public announcement on your website (if breach affects 10,000+ users)
Legal Note: Don't downplay the breach or make promises you can't keep ("Your data is 100% safe now"). Be honest, be specific, be helpful.
Hour 48–72: File Detailed Report with Data Protection Board
This Is the Big One: The 72-hour deadline is for the comprehensive report, not a grace period .
Required Contents (Rule 7):
- Facts and circumstances : How the breach occurred, timeline of events
- Categories and approximate number of affected Data Principals : Be as accurate as possible
- Likely consequences : Risk of identity theft, financial fraud, reputational harm
- Mitigation and remedial measures : What you've done to contain and fix the issue
- Findings on responsibility : If you've identified who caused it (internal error, external hacker, vendor failure)
- Summary of user notifications : How many users you notified, via which channels
Submission Format:
- File through the Data Protection Board's online portal (once operational)
- Or email to the designated address (monitor dpdprules.org for updates)
- Keep a timestamped copy – you may need to prove you met the deadline
Can You Get an Extension? Technically, yes – but only if the Board grants written permission for a longer period. Don't count on this. Assume 72 hours is absolute.
What If You Don't Know Everything Yet? File what you know by hour 72. You can submit a supplementary report later with additional findings. Missing the deadline is worse than filing an incomplete report.
Hour 72+: Post-Breach Compliance & Prevention
After You've Filed:
- [ ] Document lessons learned – what went wrong, what worked, what didn't
- [ ] Update your incident response SOP based on this experience
- [ ] Conduct a security audit – fix vulnerabilities that enabled the breach
- [ ] Review vendor contracts – ensure they have breach notification clauses
- [ ] Train your team – run a tabletop exercise so everyone knows their role next time
Ongoing DPDP Compliance (Beyond Breaches):
- Map your data flows : Know what personal data you collect, where it's stored, who accesses it
- Publish a privacy notice : Plain-language disclosure of how you use data (no legalese)
- Implement consent mechanisms : Explicit opt-in, no pre-ticked boxes, easy withdrawal
- Enable user rights : Let users view, correct, export, and delete their data
- Appoint a grievance officer : Publish privacy@yourcompany.com with a 48-hour response SLA
- Handle children's data carefully : Age verification + parental consent for users under 18
- Retain logs for 180 days : CERT-In requirement for incident investigation.
Common Mistakes Founders Make (And How to Avoid Them)
Mistake 1: We're Too Small for DPDP to Apply
Reality: No revenue threshold. No SME exemption. If you process Indian user data, DPDP applies.
Fix: Assume you're in scope until a lawyer tells you otherwise.
Mistake 2: We'll Investigate First, Report Later
Reality: The 72-hour clock starts at discovery, not after your investigation concludes.
Fix: File the initial intimation "without delay," then submit the detailed report by hour 72 with whatever you know.
Mistake 3: Our Vendor Handled It, So We're Fine
Reality: You're still liable as the Data Fiduciary, even if a processor (AWS, Razorpay, etc.) caused the breach.
Fix: Have breach notification clauses in all vendor contracts. Require them to alert you within 24 hours so you can meet your 72-hour deadline.
Mistake 4: We'll Send a Generic 'We Take Security Seriously' Email
Reality: DPDP requires specific, actionable information to users .
Fix: Be transparent. Tell users exactly what happened, what data was exposed, and what they should do.
Mistake 5: We Store Everything in the Cloud, So We're Compliant
Reality: Data localization rules require certain logs (especially for CERT-In) to be stored within India.
Fix: Use Indian data centers (AWS Mumbai, Azure Pune) for logs and backups. Document where data resides.
Tools & Resources for Budget-Conscious Startups
Free Resources:
- DPDP Rules Text: dpdprules.org – Full Act and Rules with free compliance tools
- CERT-In Reporting Template: cert-in.org.in – Download Annexure I for incident reporting
- Privacy Policy Generators: Termly.io, PrivacyPolicies.com – Basic templates for startups
- Consent Management: Cookiebot (free tier), Osano (startup discounts)
Low-Cost Tools (Under ₹50k/year):
- Breach Detection: Wazuh (open-source SIEM), Bitdefender GravityZone (₹200–500/user/month)
- Log Management: Grafana + Loki (self-hosted), Datadog (startup credits)
- Incident Response: Notion templates for breach playbooks, Slack war room channels
When to Hire a Consultant:
- If you handle sensitive data (health, financial, children's information)
- If you're raising Series A+ and investors demand compliance audits
- If you've already had a breach and need forensic analysis
Typical Costs: ₹50k–₹2L for a full DPDP compliance audit, ₹1–5L for breach forensics.
FAQ: DPDP Act Compliance for Indian Startups
Q: Does DPDP apply to startups with foreign users?
A: Only for Indian users' data. If you have 10,000 users but only 500 are in India, DPDP applies to those 500. Segment your data flows accordingly .
Q: What happens if I miss the 72-hour deadline?
A: Penalties up to ₹250 crore, plus reputational damage. The Data Protection Board can also order remedial actions (mandatory audits, public disclosures).
Q: Do I need a Data Protection Officer (DPO)?
A: Not mandatory for startups unless you're a "Significant Data Fiduciary" (high-risk, large-scale processing). But appointing a privacy@ email contact is wise.
Q: How do I report a breach to CERT-In?
A: Email incident@cert-in.org.in within 6 hours using their prescribed format. Include incident type, time of discovery, systems affected, and immediate actions taken.
Q: Can I get an extension on the 72-hour deadline?
A: Only with written permission from the Data Protection Board. Don't plan on this – assume 72 hours is absolute.
Q: What if the breach was caused by a vendor (e.g., AWS, Razorpay)?
A: You're still liable as the Data Fiduciary. Ensure vendor contracts include breach notification clauses (they must alert you within 24 hours).
Q: Do I need to notify users if only employee data was breached?
A: Yes. Employee personal data (names, emails, salaries, PAN numbers) falls under DPDP. Notify affected employees within 72 hours .
Q: Is there a DPDP compliance certificate for startups?
A: No official certification exists yet. However, you can document your compliance (privacy policy, consent logs, breach SOPs) for investor due diligence .
Final Thoughts: Compliance Is a Competitive Advantage
Most founders see DPDP as a burden. Smart founders see it as a moat.
When you can tell investors, customers, and partners: We're DPDP-compliant, with a tested 72-hour breach response playbook, you're signaling maturity, trustworthiness, and operational excellence.
The startups that win in 2027 won't be the ones that scramble to comply after a breach. They'll be the ones that built compliance into their DNA from day one.
Your Next Steps:
- Download our free DPDP breach checklist (link to downloadable PDF)
- Map your data flows – know what personal data you hold and where
- Draft your incident response SOP – who does what when a breach hits
- Test your playbook – run a tabletop exercise with your team
- Publish your privacy notice – make it clear, concise, and user-friendly
The 72-hour clock is ticking. Start now.



