DPDP Act & Rules 2025: Breach Detection & 72-Hour Notification
17 July 2026 · 3 min read · Cloud Armor Security Team
- DPDP Act
- Compliance
- Data Protection
- Managed SOC
- Ayati One
TL;DR — India's Digital Personal Data Protection (DPDP) Rules, 2025 were notified in November 2025, operationalising the DPDP Act, 2023. The obligation that reshapes security operations: on discovering a personal data breach, a Data Fiduciary must notify the Data Protection Board (and affected individuals) — with breach reporting expected within a 72-hour window. You cannot report a breach you never detected, which makes continuous monitoring a de-facto DPDP requirement, not just a security nicety. Penalties run up to ₹250 crore.
The DPDP Act spent two years as principle without procedure. That changed when the Rules were notified in late 2025: the operational obligations — on consent, security safeguards, cross-border transfer and, critically, breach notification — are now live. For a CISO, the breach-notification clock is the requirement that lands hardest on the SOC.
The obligation that changes security operations
"Reasonable security safeguards" has teeth now
The Act requires Data Fiduciaries to implement reasonable security safeguards to prevent breaches. With the Rules notified and a digital Data Protection Board able to take online complaints, that once-vague phrase is now enforceable — and penalties reach ₹250 crore. A demonstrable detection-and-response capability is the clearest evidence that safeguards are real.
What a Data Fiduciary needs operationally
| DPDP obligation | Operational requirement | Ayati One |
|---|---|---|
| Detect breaches promptly | 24×7 monitoring + triage | Managed SIEM + AI-SOC |
| Notify Board within 72h | Fast, evidenced detect-to-report | Real-time analyst triage |
| Inform affected individuals | Scoped impact assessment | Case history + forensics |
| Reasonable security safeguards | Demonstrable controls | Continuous VA, monitoring, DLP |
| Cross-border transfer control | In-country data | In-region / on-prem |
Frequently asked questions
Does the DPDP Act explicitly require a SIEM or SOC?
Not by name — it requires "reasonable security safeguards" and breach notification. But a 72-hour notification obligation is unworkable without monitoring that detects breaches quickly, so a SOC is the practical means of compliance. Sectoral regulators (RBI, IRDAI) are more explicit.
Who is a "Data Fiduciary"?
Broadly, any entity that determines the purpose and means of processing personal data — most organisations handling customer or employee data in India. Significant Data Fiduciaries face additional obligations.
How does DPDP interact with the DLP we already run?
Directly — DLP reduces the chance and scope of a reportable breach. See our BFSI DLP compliance guide for how data controls and monitoring reinforce each other.
Preparing for the DPDP Rules 2025? Talk to our SOC engineers about breach-detection monitoring that makes the 72-hour clock achievable, with data kept in India and flat per-asset pricing.
This article is general information, not legal advice — validate your specific DPDP obligations with qualified counsel.
Blog timeline
Explore the full series
27 July 2026 · 4 min read
Wazuh vs Commercial SIEM: The Real Enterprise Trade-off
27 July 2026 · 3 min read
Managed SOC & SIEM With Data Residency in India
26 July 2026 · 3 min read
Choosing an MSSP in Hyderabad, Dubai & the GCC
26 July 2026 · 8 min read
IBM QRadar Alternatives: Ayati One as a Managed SIEM + AI-SOC
25 July 2026 · 3 min read
An Arctic Wolf Alternative for India: Pricing & Residency
24 July 2026 · 2 min read
A Rapid7 InsightIDR Alternative: Managed, In-Region SIEM
23 July 2026 · 3 min read
A Microsoft Sentinel Cost Alternative: Beyond Per-GB Pricing
22 July 2026 · 3 min read
IBM QRadar Migration: A Practical Path Off QRadar
21 July 2026 · 3 min read
RBI Cybersecurity Framework: SOC Monitoring & 6-Hour Reporting
20 July 2026 · 3 min read
SEBI CSCRF Compliance: SIEM, SOC & the M-SOC Option
19 July 2026 · 3 min read
UAE NESA/SIA & Dubai ISR: Security Monitoring for Compliance
18 July 2026 · 3 min read
IRDAI 2023 Cyber Security Guidelines: SOC, VAPT & Reporting
18 July 2026 · 3 min read
The Enterprise DLP Implementation Checklist: What Most Rollouts Miss
17 July 2026 · Currently reading
DPDP Act & Rules 2025: Breach Detection & 72-Hour Notification
15 July 2026 · 4 min read
Data Loss Prevention for BFSI in India: The RBI, IRDAI and DPDP Act Compliance Guide
12 July 2026 · 3 min read
Forcepoint vs Safetica: How to Choose Between Enterprise DLP and Cloud-Native SaaS DLP
10 July 2026 · 3 min read
IAM vs SSO: What's the Difference, and What Does Your Enterprise Actually Need?
8 July 2026 · 3 min read
Business Email Compromise in BFSI and Pharma: A Layered Defence Playbook
5 July 2026 · 3 min read
Pharma Cybersecurity: Protecting Drug IP, Clinical Trial Data and GxP Systems
Put this into practice.
Our engineers deliver what these guides describe — from assessment to a running control. Bring us your environment.