Cloud Armor IT Consultancy logo

DPDP Act & Rules 2025: Breach Detection & 72-Hour Notification

17 July 2026 · 3 min read · Cloud Armor Security Team

  • DPDP Act
  • Compliance
  • Data Protection
  • Managed SOC
  • Ayati One

TL;DR — India's Digital Personal Data Protection (DPDP) Rules, 2025 were notified in November 2025, operationalising the DPDP Act, 2023. The obligation that reshapes security operations: on discovering a personal data breach, a Data Fiduciary must notify the Data Protection Board (and affected individuals) — with breach reporting expected within a 72-hour window. You cannot report a breach you never detected, which makes continuous monitoring a de-facto DPDP requirement, not just a security nicety. Penalties run up to ₹250 crore.

The DPDP Act spent two years as principle without procedure. That changed when the Rules were notified in late 2025: the operational obligations — on consent, security safeguards, cross-border transfer and, critically, breach notification — are now live. For a CISO, the breach-notification clock is the requirement that lands hardest on the SOC.

The obligation that changes security operations

The detection dependency Rule 7 requires notifying the Data Protection Board on discovery of a breach, with reporting expected inside 72 hours, plus informing every affected individual in plain language. Here's the uncomfortable truth: the clock starts at discovery — and without real monitoring, discovery can take weeks or never happen at all. "We didn't know" is not a defence; it's an admission the monitoring wasn't there.

"Reasonable security safeguards" has teeth now

The Act requires Data Fiduciaries to implement reasonable security safeguards to prevent breaches. With the Rules notified and a digital Data Protection Board able to take online complaints, that once-vague phrase is now enforceable — and penalties reach ₹250 crore. A demonstrable detection-and-response capability is the clearest evidence that safeguards are real.

How Ayati One supports DPDP A 24×7 managed SOC so breaches are detected in hours, not discovered in headlines — giving you a fighting chance at the 72-hour clock — plus dark-web monitoring to catch leaked data early, asset telemetry, and deployment that keeps personal data in India. Auditable case history is your evidence of "reasonable safeguards."

What a Data Fiduciary needs operationally

DPDP obligation Operational requirement Ayati One
Detect breaches promptly 24×7 monitoring + triage Managed SIEM + AI-SOC
Notify Board within 72h Fast, evidenced detect-to-report Real-time analyst triage
Inform affected individuals Scoped impact assessment Case history + forensics
Reasonable security safeguards Demonstrable controls Continuous VA, monitoring, DLP
Cross-border transfer control In-country data In-region / on-prem

Frequently asked questions

Does the DPDP Act explicitly require a SIEM or SOC?

Not by name — it requires "reasonable security safeguards" and breach notification. But a 72-hour notification obligation is unworkable without monitoring that detects breaches quickly, so a SOC is the practical means of compliance. Sectoral regulators (RBI, IRDAI) are more explicit.

Who is a "Data Fiduciary"?

Broadly, any entity that determines the purpose and means of processing personal data — most organisations handling customer or employee data in India. Significant Data Fiduciaries face additional obligations.

How does DPDP interact with the DLP we already run?

Directly — DLP reduces the chance and scope of a reportable breach. See our BFSI DLP compliance guide for how data controls and monitoring reinforce each other.


Preparing for the DPDP Rules 2025? Talk to our SOC engineers about breach-detection monitoring that makes the 72-hour clock achievable, with data kept in India and flat per-asset pricing.

This article is general information, not legal advice — validate your specific DPDP obligations with qualified counsel.

Blog timeline

Explore the full series

  1. 27 July 2026 · 4 min read

    Wazuh vs Commercial SIEM: The Real Enterprise Trade-off

  2. 27 July 2026 · 3 min read

    Managed SOC & SIEM With Data Residency in India

  3. 26 July 2026 · 3 min read

    Choosing an MSSP in Hyderabad, Dubai & the GCC

  4. 26 July 2026 · 8 min read

    IBM QRadar Alternatives: Ayati One as a Managed SIEM + AI-SOC

  5. 25 July 2026 · 3 min read

    An Arctic Wolf Alternative for India: Pricing & Residency

  6. 24 July 2026 · 2 min read

    A Rapid7 InsightIDR Alternative: Managed, In-Region SIEM

  7. 23 July 2026 · 3 min read

    A Microsoft Sentinel Cost Alternative: Beyond Per-GB Pricing

  8. 22 July 2026 · 3 min read

    IBM QRadar Migration: A Practical Path Off QRadar

  9. 21 July 2026 · 3 min read

    RBI Cybersecurity Framework: SOC Monitoring & 6-Hour Reporting

  10. 20 July 2026 · 3 min read

    SEBI CSCRF Compliance: SIEM, SOC & the M-SOC Option

  11. 19 July 2026 · 3 min read

    UAE NESA/SIA & Dubai ISR: Security Monitoring for Compliance

  12. 18 July 2026 · 3 min read

    IRDAI 2023 Cyber Security Guidelines: SOC, VAPT & Reporting

  13. 18 July 2026 · 3 min read

    The Enterprise DLP Implementation Checklist: What Most Rollouts Miss

  14. 17 July 2026 · Currently reading

    DPDP Act & Rules 2025: Breach Detection & 72-Hour Notification

  15. 15 July 2026 · 4 min read

    Data Loss Prevention for BFSI in India: The RBI, IRDAI and DPDP Act Compliance Guide

  16. 12 July 2026 · 3 min read

    Forcepoint vs Safetica: How to Choose Between Enterprise DLP and Cloud-Native SaaS DLP

  17. 10 July 2026 · 3 min read

    IAM vs SSO: What's the Difference, and What Does Your Enterprise Actually Need?

  18. 8 July 2026 · 3 min read

    Business Email Compromise in BFSI and Pharma: A Layered Defence Playbook

  19. 5 July 2026 · 3 min read

    Pharma Cybersecurity: Protecting Drug IP, Clinical Trial Data and GxP Systems

Put this into practice.

Our engineers deliver what these guides describe — from assessment to a running control. Bring us your environment.