You call one number. We investigate, draft the intimation to the Data Protection Board, write the notice to your affected users, build the playbook your team follows, and produce the report that closes the file. You approve and sign.
India stopped treating data protection as a policy exercise on 13 November 2025, when the Digital Personal Data Protection Rules, 2025 were notified. Rule 7 gave breach reporting a deadline. Section 8(6) of the Act made it apply to everyone. There is no severity threshold and no minimum number of affected people. If personal data is breached, it gets reported.
The Schedule to the DPDP Act sets two penalties that both land on the same incident. They are separate heads and they can be imposed together. CERT-In non-reporting carries a further exposure under the Information Technology Act.
Then there is everything the Schedule does not cover. Enterprise customers now write notification timelines into their contracts, so a missed regulatory deadline is usually a missed contractual one. A badly worded notice to your users generates more complaints than the breach did. And if an inquiry opens six months later, the only thing that helps is a written record of what you knew, when you knew it, and what you did.
We have sat inside enough of these to know how they go wrong. It is rarely the technology.
The Rules phase in over eighteen months, with the core obligations applying from May 2027. You can build this capability now, or you can build it during your first incident.
Report it through the platform or ring the response line. You do not need to know what kind of incident it is. A privacy consultant is assigned, takes a structured statement of what happened, and gives you an immediate do and do not list so nothing gets destroyed in the first hour. If CERT-In applies, we tell you inside the first conversation, because that deadline is six hours, not seventy-two.
A structured assessment runs across the control domains that matter for this incident. We establish scope: what data, whose data, how much, and whether the exposure is contained or still open. What you do not yet know is recorded as an information gap, not marked down as a failure, so the picture reflects reality rather than pessimism. You get a risk score and a written determination on whether this is reportable. The initial intimation to the Board goes to you for approval.
The detailed report to the Board covers the facts, the causes, the sequence of events, the remedial measures, findings on who caused it, and a summary of what your users were told. The intimations to affected individuals are written in plain language: what happened, what it means for them, what we have done, what they should do, and who to contact. If sectoral regulators or foreign law are in play, we identify those filings too. Holding statements for customers and staff on request.
The Master Investigation Report is the document that shuts the incident and the one that gets produced if anyone asks about it later. Alongside it comes a remediation roadmap with owners and dates, and a closure note recording why the file was closed. Retainer clients get a lesson learned session and an updated playbook.
We say this openly at the first meeting. The duty to notify sits with you as Data Fiduciary and no service provider can take it off you. What we can do is everything in the left column, which is all the work. The signature stays yours.
Not advice on a call. Documents you can file, send, and produce later.
The service runs on the DPO India AI Investigation Assistant. We built it, we use it on every engagement, and clients who prefer to run their own response can license it directly. It is designed for the moment before anyone knows anything. The assistant opens by asking you to describe your security concern and takes it from there, starting from something as unformed as a suspicion that the company may have been hacked.
Open incidents, pending tasks, your organisation risk position and recent activity in one view.
A title, and a type if you know it. Leave the type blank and the assistant work it out. It covers ransomware, phishing, data leaks, unauthorised access, insider threat, denial of service, malware, lost and stolen devices, and anything that does not fit a box.
A guided conversation that asks what it needs and remembers the whole incident, so you are not repeating yourself on day three.
A thousand-point questionnaire across seven domains, weighted by where the risk actually sits. It adapts as you answer.
A number you can take to your board instead of an impression.
A step-by-step response plan generated for the incident in front of you.
Your case file and your Master Investigation Report, kept as your record.
A named response team, an agreed response time, platform access for your people, an annual readiness review, a playbook built before you need it, and unlimited intake. Response hours come from a committed pool.
Anyone with real regulatory exposure and a board that expects a plan. The obvious step up for existing DPO as a Service clients.
End to end response for one declared incident, priced per engagement. No standing commitment.
Organisations that want cover without an annual line item, and organisations that reach us mid incident.
You run the response. We review the assessment, the reportability call and the draft notifications before anything goes out.
Teams with their own security capability who need privacy judgement rather than hands.
Reach out to us on dpo@dpo-india.com for customized paid plan.
If you already use our Outsourced DPO or DPO as a Service, this is the piece that was missing. The DPO engagement keeps the programme running. This one is what happens when the programme gets tested. Our people already know your data map, your processors and your retention schedule, so there is no ramp up on the worst day of your year.
Breach response is a legal determination supported by technical facts. Most vendors in this market come at it from the technical side and treat the privacy obligations as paperwork at the end. We come at it from the other direction, and the two hundred crore rupee exposure sits on our side of that line.
We built the platform ourselves, so when a client needs it to work differently, we change it. Every engagement ends with documents rather than opinions. And for clients already on DPO as a Service, the team responding to your breach is the team that wrote your ROPA.