CERT-In Requires a Six-Hour Incident Report. The DPDP Act Requires a 72-Hour Notification. Both Apply to You Simultaneously

The Data Protection Board of India became operational in late 2025, ending the grace period that had given organisations theoretical breathing room since the Digital Personal Data Protection Act was passed in August 2023. Active enforcement began in early 2026 and the penalty structure under the DPDP Act is unprecedented in Indian business regulation. Maximum penalties of $29 million (₹250 crore) per violation for failure to implement reasonable security safeguards that result in a personal data breach are not a notional ceiling. They are the framework within which the first major enforcement actions are now being assessed.

Running in parallel is the CERT-In incident reporting mandate, which has been in force since June 2022 and applies to every organisation in India without size-based exemptions. The CERT-In Directions require reporting of 20 categories of cybersecurity incidents within 6 hours of detection. The penalty for non-compliance is up to $1100 (₹1 lakh) and imprisonment of up to one year under Section 70B of the Information Technology Act.

The complexity that most Indian organisations have not adequately prepared for is that both obligations can be triggered by the same incident simultaneously. A ransomware attack that encrypts systems containing personal data is both a CERT-In reportable incident and a DPDP Act personal data breach. The 6-hour CERT-In report must go to CERT-In. The 72-hour DPDP notification must go to the Data Protection Board and to affected individuals. Both require documentation. Both require a classification decision made under time pressure in the middle of an active incident response.

The Dual Compliance Flow

The diagram below maps both compliance tracks side by side. The central observation it illustrates is that the two regimes run in parallel rather than sequentially. An incident team managing a significant breach must simultaneously drive the technical response, prepare the 6-hour CERT-In report and assess whether the incident also constitutes a personal data breach triggering DPDP obligations. These are three distinct workstreams that must proceed concurrently.

Diagram 1: India dual compliance flowchart showing parallel CERT-In and DPDP Act obligations triggered by the same incident

The 6-Hour CERT-In Report: What It Must Contain

The CERT-In Directions specify 20 categories of reportable incidents including targeted scanning or probing of critical networks, compromise of critical systems or information, unauthorised access to IT systems, defacement of websites, malware attacks, attacks on servers and network infrastructure, identity theft and denial of service attacks.

The 6-hour report does not require a complete investigation. It requires notification that an incident has occurred, a preliminary classification of the incident type, the systems and data believed to be affected and the initial containment steps taken. CERT-In uses this early notification to assess whether the incident has national significance and whether coordinated response support is required. Organisations that wait for a full investigation to be complete before reporting will almost certainly miss the 6-hour window and expose themselves to the penalties attached to non-compliance.

The 72-Hour DPDP Notification: When It Applies

The DPDP Act notification obligation is triggered by a personal data breach, which the act defines as any unauthorised processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data. This is a broad definition and it is intentionally so any incident that results in personal data being accessed, copied, exposed or made unavailable may constitute a personal data breach regardless of whether the organisation believes the data was actually misused.

Significant Data Fiduciaries face enhanced obligations. These are organisations designated by the government based on the volume of personal data they process, the risk to individuals they present, their use of new technologies or their impact on national interest. Significant Data Fiduciaries must comply with additional obligations around data protection impact assessments, appointment of a data protection officer and periodic audits. The penalty for non-compliance by a Significant Data Fiduciary reaches $17 million (₹150 crore).

CERT-In vs DPDP: Key Differences Side by Side

RequirementCERT-In DirectionsDPDP Act 2023
Reporting deadline6 hours from detection72 hours for notification to Data Protection Board and affected individuals
Who receives the reportCERT-In via designated portalData Protection Board of India and affected data principals
What triggers the obligationAny of 20 specified incident categories regardless of personal data involvementUnauthorised access to or exposure of personal data specifically
Who is coveredAll organisations in India without size exemptionsAll data fiduciaries processing digital personal data in India; also foreign entities serving Indian individuals
Maximum penalty$1100 (₹1 lakh) fine and up to 1 year imprisonmentUp to $29 million (₹250 crore) per violation for data breach failures; $17 million (₹150 crore) for Significant Data Fiduciaries
Log retention requirement180 days minimum for all ICT infrastructure logsRetention period for personal data governed by purpose limitation principle under the Act
NTP synchronisationAll systems must sync to CERT-In designated NTP serversNo equivalent requirement

Table 1: Side-by-side comparison of CERT-In and DPDP Act compliance obligations for Indian organisations in 2026

What to Build Into Your Incident Response Process Now

The first change required is a classification decision point at the very start of every incident response. Within the first hour the incident response team must answer two questions. First, does this incident fall into any of the 20 CERT-In reportable categories? Second, does it involve or potentially involve personal data? The answers determine which reporting clocks are running and allow the team to begin preparing notifications in parallel with the technical response.

The second change is to assign dedicated regulatory reporting responsibility to a named individual in the incident response team. In most organisations the person managing the technical response should not also be responsible for drafting regulatory notifications under time pressure. Having a designated regulatory reporting lead who can manage the CERT-In submission and assess the DPDP notification requirement while the technical team focuses on containment and investigation significantly improves the quality and timeliness of both.

The third change is to establish and test the reporting channels before an incident occurs. The CERT-In incident reporting portal, the contact details for the Data Protection Board notification process and the template for affected individual notifications should all be documented, accessible and tested in a tabletop exercise at least once every six months.

Leave a Reply

Your email address will not be published.