HomeNewsTechnologyNew DPDP rules may mandate immediate reporting of data breaches to Data Protection Board

New DPDP rules may mandate immediate reporting of data breaches to Data Protection Board

The details that a platform will need to communicate to the DPB, on a best-effort basis, should include a description of the breach, the date and time when the platform became aware of the breach, the location of the breach, its extent, and potential impact.

December 27, 2023 / 11:34 IST
Story continues below Advertisement
The Digital Personal Data Protection (DPDP) Act was passed in both the houses of Parliament in August 2023
The Digital Personal Data Protection (DPDP) Act was passed in both the houses of Parliament in August 2023

Any platform processing personal data of users, whether a private or government entity, must immediately notify the Data Protection Board (DPB) of any data breach upon becoming aware, according to an unreleased version of the draft Digital Personal Data Protection (DPDP) rules.

The DPB is an adjudicating body set up under the DPDP Act.

Story continues below Advertisement

The details that a platform will need to communicate to the DPB, on a best-effort basis, should include a description of the breach, the date and time when the platform became aware of the breach, the location of the breach, its extent, and potential impact.

These details are included in a version of the draft DPDP rules currently circulating internally among various sectors of industry and governance. The rules will define the DPDP Act's parameters.