Ayati One — Managed Cyber Defence

DPDP Act & Rules 2025: Breach Detection & 72-Hour Notification

17 July 2026 · 3 min read · Cloud Armor Security Team

  • DPDP Act
  • Compliance
  • Data Protection
  • Managed SOC
  • Ayati One

TL;DR — India's Digital Personal Data Protection (DPDP) Rules, 2025 were notified in November 2025, operationalising the DPDP Act, 2023. The obligation that reshapes security operations: on discovering a personal data breach, a Data Fiduciary must notify the Data Protection Board (and affected individuals) — with breach reporting expected within a 72-hour window. You cannot report a breach you never detected, which makes continuous monitoring a de-facto DPDP requirement, not just a security nicety. Penalties run up to ₹250 crore.

The DPDP Act spent two years as principle without procedure. That changed when the Rules were notified in late 2025: the operational obligations — on consent, security safeguards, cross-border transfer and, critically, breach notification — are now live. For a CISO, the breach-notification clock is the requirement that lands hardest on the SOC.

The obligation that changes security operations

The detection dependency Rule 7 requires notifying the Data Protection Board on discovery of a breach, with reporting expected inside 72 hours, plus informing every affected individual in plain language. Here's the uncomfortable truth: the clock starts at discovery — and without real monitoring, discovery can take weeks or never happen at all. "We didn't know" is not a defence; it's an admission the monitoring wasn't there.

"Reasonable security safeguards" has teeth now

The Act requires Data Fiduciaries to implement reasonable security safeguards to prevent breaches. With the Rules notified and a digital Data Protection Board able to take online complaints, that once-vague phrase is now enforceable — and penalties reach ₹250 crore. A demonstrable detection-and-response capability is the clearest evidence that safeguards are real.

How Ayati One supports DPDP A 24×7 managed SOC so breaches are detected in hours, not discovered in headlines — giving you a fighting chance at the 72-hour clock — plus dark-web monitoring to catch leaked data early, asset telemetry, and deployment that keeps personal data in India. Auditable case history is your evidence of "reasonable safeguards."

What a Data Fiduciary needs operationally

DPDP obligation Operational requirement Ayati One
Detect breaches promptly 24×7 monitoring + triage Managed SIEM + AI-SOC
Notify Board within 72h Fast, evidenced detect-to-report Real-time analyst triage
Inform affected individuals Scoped impact assessment Case history + forensics
Reasonable security safeguards Demonstrable controls Continuous VA, monitoring, DLP
Cross-border transfer control In-country data In-region / on-prem

Frequently asked questions

Does the DPDP Act explicitly require a SIEM or SOC?

Not by name — it requires "reasonable security safeguards" and breach notification. But a 72-hour notification obligation is unworkable without monitoring that detects breaches quickly, so a SOC is the practical means of compliance. Sectoral regulators (RBI, IRDAI) are more explicit.

Who is a "Data Fiduciary"?

Broadly, any entity that determines the purpose and means of processing personal data — most organisations handling customer or employee data in India. Significant Data Fiduciaries face additional obligations.

How does DPDP interact with the DLP we already run?

Directly — DLP reduces the chance and scope of a reportable breach. See our BFSI DLP compliance guide for how data controls and monitoring reinforce each other.


Preparing for the DPDP Rules 2025? Talk to our SOC engineers about breach-detection monitoring that makes the 72-hour clock achievable, with data kept in India and flat per-asset pricing.

This article is general information, not legal advice — validate your specific DPDP obligations with qualified counsel.

Blog timeline

Explore the full series

  1. 27 July 2026 · 4 min read

    Wazuh vs Commercial SIEM: The Real Enterprise Trade-off

  2. 27 July 2026 · 3 min read

    Managed SOC & SIEM With Data Residency in India

  3. 26 July 2026 · 3 min read

    Choosing an MSSP in Hyderabad, Dubai & the GCC

  4. 26 July 2026 · 8 min read

    IBM QRadar Alternatives: Ayati One as a Managed SIEM + AI-SOC

  5. 25 July 2026 · 3 min read

    An Arctic Wolf Alternative for India: Pricing & Residency

  6. 24 July 2026 · 2 min read

    A Rapid7 InsightIDR Alternative: Managed, In-Region SIEM

  7. 23 July 2026 · 3 min read

    A Microsoft Sentinel Cost Alternative: Beyond Per-GB Pricing

  8. 22 July 2026 · 3 min read

    IBM QRadar Migration: A Practical Path Off QRadar

  9. 21 July 2026 · 3 min read

    RBI Cybersecurity Framework: SOC Monitoring & 6-Hour Reporting

  10. 20 July 2026 · 3 min read

    SEBI CSCRF Compliance: SIEM, SOC & the M-SOC Option

  11. 19 July 2026 · 3 min read

    UAE NESA/SIA & Dubai ISR: Security Monitoring for Compliance

  12. 18 July 2026 · 3 min read

    IRDAI 2023 Cyber Security Guidelines: SOC, VAPT & Reporting

  13. 18 July 2026 · 3 min read

    The Enterprise DLP Implementation Checklist: What Most Rollouts Miss

  14. 17 July 2026 · Currently reading

    DPDP Act & Rules 2025: Breach Detection & 72-Hour Notification

  15. 15 July 2026 · 4 min read

    Data Loss Prevention for BFSI in India: The RBI, IRDAI and DPDP Act Compliance Guide

  16. 12 July 2026 · 3 min read

    Forcepoint vs Safetica: How to Choose Between Enterprise DLP and Cloud-Native SaaS DLP

  17. 10 July 2026 · 3 min read

    IAM vs SSO: What's the Difference, and What Does Your Enterprise Actually Need?

  18. 8 July 2026 · 3 min read

    Business Email Compromise in BFSI and Pharma: A Layered Defence Playbook

  19. 5 July 2026 · 3 min read

    Pharma Cybersecurity: Protecting Drug IP, Clinical Trial Data and GxP Systems

Put this into practice.

Our engineers deliver what these guides describe — from assessment to a running control. Bring us your environment.

Tip: tell us your current cyber security requirement — what you are trying to protect, roughly how large the estate is, and any audit or deadline driving it. The more specific you are, the more useful our first reply will be.

We reply from a named engineer, not a sales queue. Your details are used only to answer this enquiry — see our privacy policy.