Outsourced Data Breach Management and Response
Data Secure IND | DPO India
Data Secure IND  |  DPO India

A breach is not the time to be reading your own policy for the first time.

You call one number. We investigate, draft the intimation to the Data Protection Board, write the notice to your affected users, build the playbook your team follows, and produce the report that closes the file. You approve and sign.

DETAILED REPORT DUE
72:00:00
Within 72 hours, extendable only on a written request the Board accepts. The clock started before you called.
YOU HAVE 72 HOURS

You have 72 hours. The clock started before you called.

India stopped treating data protection as a policy exercise on 13 November 2025, when the Digital Personal Data Protection Rules, 2025 were notified. Rule 7 gave breach reporting a deadline. Section 8(6) of the Act made it apply to everyone. There is no severity threshold and no minimum number of affected people. If personal data is breached, it gets reported.

STAGE 1
Data Protection Board of India, initial intimation
Without delay, covering the nature, extent, timing and location of the breach and its likely impact
STAGE 2
Data Protection Board of India, detailed report
Within 72 hours, extendable only on a written request the Board accepts
ALONGSIDE
Every affected Data Principal
Without delay, through the user account or a channel they have registered with you
SEPARATELY
CERT-In, if it is also a cyber security incident
Within 6 hours, under CERT-In Direction No. 20(3)/2022
Read that first line again. The clock starts when you become aware, not when your investigation finishes. Awareness means you have confirmed that an incident involving personal data has happened. Most organisations lose a day and a half arguing about whether they are there yet.
GETTING IT WRONG

Getting it wrong is expensive twice over.

₹200 Cr
Up to two hundred crore rupees for failing to notify the Board and the affected individuals.
₹250 Cr
Up to two hundred and fifty crore rupees for the inadequate safeguards that let the breach happen.

The Schedule to the DPDP Act sets two penalties that both land on the same incident. They are separate heads and they can be imposed together. CERT-In non-reporting carries a further exposure under the Information Technology Act.

Then there is everything the Schedule does not cover. Enterprise customers now write notification timelines into their contracts, so a missed regulatory deadline is usually a missed contractual one. A badly worded notice to your users generates more complaints than the breach did. And if an inquiry opens six months later, the only thing that helps is a written record of what you knew, when you knew it, and what you did.

EVERYONE FAILS AT THE SAME FIVE POINTS

Everyone fails at the same five points.

We have sat inside enough of these to know how they go wrong. It is rarely the technology.

01
Nobody will make the call on whether it is a personal data breach, so nobody starts the clock.
02
No one on the team has drafted a Board intimation before. The first attempt gets written at midnight.
03
Evidence collects in a WhatsApp group and a shared inbox. Half of it is gone by the time anyone needs it.
04
The notice to users is either frightening or so vague it triggers a second round of questions.
05
Once the fire is out, nothing gets written down. There is no record to show a regulator.

The Rules phase in over eighteen months, with the core obligations applying from May 2027. You can build this capability now, or you can build it during your first incident.

WHAT HAPPENS WHEN YOU CALL US

What happens when you call us?

HOUR 0–2

We pick it up.

Report it through the platform or ring the response line. You do not need to know what kind of incident it is. A privacy consultant is assigned, takes a structured statement of what happened, and gives you an immediate do and do not list so nothing gets destroyed in the first hour. If CERT-In applies, we tell you inside the first conversation, because that deadline is six hours, not seventy-two.

HOUR 2–24

We work out what you are actually dealing with.

A structured assessment runs across the control domains that matter for this incident. We establish scope: what data, whose data, how much, and whether the exposure is contained or still open. What you do not yet know is recorded as an information gap, not marked down as a failure, so the picture reflects reality rather than pessimism. You get a risk score and a written determination on whether this is reportable. The initial intimation to the Board goes to you for approval.

BY HOUR 72

Everything that has to be filed is drafted.

The detailed report to the Board covers the facts, the causes, the sequence of events, the remedial measures, findings on who caused it, and a summary of what your users were told. The intimations to affected individuals are written in plain language: what happened, what it means for them, what we have done, what they should do, and who to contact. If sectoral regulators or foreign law are in play, we identify those filings too. Holding statements for customers and staff on request.

DAY FOUR ON

We close it properly.

The Master Investigation Report is the document that shuts the incident and the one that gets produced if anyone asks about it later. Alongside it comes a remediation roadmap with owners and dates, and a closure note recording why the file was closed. Retainer clients get a lesson learned session and an updated playbook.

WHAT WE HANDLE. WHAT STAYS WITH YOU.

What we handle. What stays with you.

WE DO THIS
YOU DO THIS
Take the incident report and triage it
Make the call to bring us in
Classify the incident type
Give us access to the people who know your systems
Run the risk and control assessment
Contain it technically inside your environment
Determine whether it is a reportable personal data breach
Approve anything that leaves your organisation
Draft the initial intimation and the 72-hour report
Sign and file in your own name
Draft the intimation to affected Data Principals
Send it from your registered channels
Write the response playbook for this incident
Execute the technical steps in it
Produce the Master Investigation Report and closure record
Keep the record and act on the recommendations
Build the remediation roadmap
Fund and own the remediation

We say this openly at the first meeting. The duty to notify sits with you as Data Fiduciary and no service provider can take it off you. What we can do is everything in the left column, which is all the work. The signature stays yours.

WHAT LANDS ON YOUR DESK

What lands on your desk

Not advice on a call. Documents you can file, send, and produce later.

Incident Intake Record
Fixes the point of awareness. Who reported what, and at what time.
Incident Assessment and Risk Score
A weighted read of your controls, with information gaps kept separate from real failures.
Reportability Determination
A written view on whether this needs notifying, and why.
Initial Intimation to the Board
Drafted and ready for your approval.
Detailed 72 Hour Report
The full Rule 7 report, drafted and ready to file.
Data Principal Intimation
Plain language notice for your users, written for the channel you will send it on.
Breach Response Playbook
A task list for your team for this incident. Not a template.
Master Investigation Report
Timeline, root cause, actions taken, notifications made, evidence references.
Remediation Roadmap
What to fix, in what order, with owners and dates.
Closure Note
The formal record that the incident was closed, and on what basis.
BUILT ON OUR OWN INVESTIGATION PLATFORM

Built on our own investigation platform

The service runs on the DPO India AI Investigation Assistant. We built it, we use it on every engagement, and clients who prefer to run their own response can license it directly. It is designed for the moment before anyone knows anything. The assistant opens by asking you to describe your security concern and takes it from there, starting from something as unformed as a suspicion that the company may have been hacked.

Dashboard

Open incidents, pending tasks, your organisation risk position and recent activity in one view.

Incident reporting

A title, and a type if you know it. Leave the type blank and the assistant work it out. It covers ransomware, phishing, data leaks, unauthorised access, insider threat, denial of service, malware, lost and stolen devices, and anything that does not fit a box.

AI Investigation Assistant

A guided conversation that asks what it needs and remembers the whole incident, so you are not repeating yourself on day three.

Incident Assessment

A thousand-point questionnaire across seven domains, weighted by where the risk actually sits. It adapts as you answer.

Risk Score

A number you can take to your board instead of an impression.

Breach Playbook

A step-by-step response plan generated for the incident in front of you.

My Incidents and Reports

Your case file and your Master Investigation Report, kept as your record.

How the assessment is weighted
Password and Access Control
250 pts
4 questions
Software and Patch Status
200 pts
3 questions
Employee Security Training
150 pts
3 questions
Data Encryption
150 pts
3 questions
Incident History
100 pts
2 questions
Backup and Recovery
100 pts
3 questions
Third Party Risk
50 pts
2 questions
Total (7 domains)
1,000 pts
20 questions
A word on the AI, since you will ask. Every output the assistant produces on a managed engagement is reviewed by a qualified privacy consultant before it reaches you or a regulator. AI generated content can contain errors and omissions, it is there for decision support, and it does not replace professional advice. The platform says so on every screen rather than burying it in the terms. It carries a published AI Transparency notice, an Acceptable Use Policy, a Privacy Notice, Terms of Use and a Cookie Policy, and it is hosted on Microsoft Azure in the Central India region.
THREE WAYS TO WORK WITH US

Three ways to work with us.

Breach Response Retainer
STEP UP FOR DPO AS A SERVICE CLIENTS
WHAT YOU GET

A named response team, an agreed response time, platform access for your people, an annual readiness review, a playbook built before you need it, and unlimited intake. Response hours come from a committed pool.

WHO IT SUITS

Anyone with real regulatory exposure and a board that expects a plan. The obvious step up for existing DPO as a Service clients.

Incident Response on Call
NO STANDING COMMITMENT
WHAT YOU GET

End to end response for one declared incident, priced per engagement. No standing commitment.

WHO IT SUITS

Organisations that want cover without an annual line item, and organisations that reach us mid incident.

A Platform with Assisted Review
YOU RUN THE RESPONSE
WHAT YOU GET

You run the response. We review the assessment, the reportability call and the draft notifications before anything goes out.

WHO IT SUITS

Teams with their own security capability who need privacy judgement rather than hands.

Reach out to us on dpo@dpo-india.com for customized paid plan.

If you already use our Outsourced DPO or DPO as a Service, this is the piece that was missing. The DPO engagement keeps the programme running. This one is what happens when the programme gets tested. Our people already know your data map, your processors and your retention schedule, so there is no ramp up on the worst day of your year.

WHO WE BUILT THIS FOR

Who we built this for

Existing DPO India clients
You have the programme. This closes the gap between the policy and the response.
Companies with no internal privacy or security team
Startups, mid-sized businesses and family run firms where compliance has landed on whoever runs finance or operations.
Data heavy and regulated sectors
Healthcare, financial services, insurance, education, e-commerce, software as a service and staffing, where sectoral reporting duties stack on top of DPDP.
Processors serving Indian Data Fiduciaries
Your contracts commit you to reporting to your customer on a tight clock. This makes that clock achievable.
Significant Data Fiduciaries
More scrutiny, a duty to demonstrate process, and a need for records that survive an audit.
Anyone who has already had one
We take engagements mid incident. If the clock is running, call first and we will work out the sequence with you.
WHY DPO INDIA

Why DPO India

Breach response is a legal determination supported by technical facts. Most vendors in this market come at it from the technical side and treat the privacy obligations as paperwork at the end. We come at it from the other direction, and the two hundred crore rupee exposure sits on our side of that line.

We built the platform ourselves, so when a client needs it to work differently, we change it. Every engagement ends with documents rather than opinions. And for clients already on DPO as a Service, the team responding to your breach is the team that wrote your ROPA.

QUESTIONS WE GET ASKED

Questions we get asked.

Do you report to the Board on our behalf? +
We prepare everything and advise on all of it. You file, because the obligation sits with the Data Fiduciary under the Act and cannot be handed over. In practice we draft, you review and approve, you file.
What if we are not sure it is even a breach? +
That is the most common call we get and exactly the right moment to make it. Working out whether an incident is reportable is part of the service, not a prerequisite for engaging us.
We already have an incident response plan. +
Most incident response plans handle containment well and the privacy obligations thinly. This covers the second half, which is the half carrying the penalty.
Can we use the platform without the managed service? +
Yes, with or without our review layer on top.
Is our incident data confidential? +
Yes. It is client confidential information under our engagement terms, and the platform Privacy Notice sets out exactly how it is handled.

Report it through the platform or ring the response line.

You do not need to know what kind of incident it is. A privacy consultant is assigned, takes a structured statement of what happened, and gives you an immediate do and do not list.

Contact Us