A DPDPA breach notification SOP for NBFCs comes down to named owners, pre-built artefacts, and three parallel clocks — CERT-In, the Data Protection Board, and Data Principal intimation — rehearsed before 13 May 2027.
TL;DR
- One breach at an NBFC starts multiple legal clocks: CERT-In within 6 hours, a detailed report to the Data Protection Board within 72 hours, and intimation to affected Data Principals without delay under Section 8(6) of the DPDPA 2023. The why is covered in our dual-clock pillar; this article is the how.
- The Schedule sets penalties of up to ₹250 crore for failing reasonable security safeguards under Section 8(5) and up to ₹200 crore for failing breach notification under Section 8(6) — a single incident can attract both slabs.
- Your SOP needs named owners: incident commander (CISO), regulatory filings (Compliance Officer), Data Principal notices (DPO/Grievance Officer), and vendor escalation (collections and LSP liaison).
- RBI obligations do not pause — supervisory incident reporting and KYC retention run in parallel with DPDPA, not under it.
- Everything below is rehearsable before 13 May 2027, the phased commencement date for the breach and Data Principal rights provisions. Run the tabletop twice before it’s live law.
What does a DPDPA breach notification SOP actually need to contain?
A DPDPA breach notification SOP for an NBFC is not a policy document — it is a runbook: who does what, by which hour, producing which artefact. The DPDPA 2023 defines a personal data breach broadly under Section 2(u): any unauthorised processing, or accidental disclosure, acquisition, sharing, use, alteration, destruction, or loss of access that compromises personal data. That breadth matters for NBFCs, because a misdirected collections file, a ransomware hit on the LMS, and an LSP leaking borrower phone numbers are all breaches — not just “hacks.”
The SOP must cover six phases: detection and triage, containment, CERT-In filing, Data Principal intimation, the detailed DPB report, and post-incident evidence closure. Each phase needs a named owner and a pre-built artefact. If your team is drafting notification text at hour 4 of a live incident, the SOP has already failed.
Who owns each step when the clock starts?
The single biggest failure mode in breach tabletops is ambiguity between the CISO, Compliance Officer, and DPO in the first two hours. Fix ownership on paper now:
| Phase | Owner | Deadline | Artefact produced |
|---|---|---|---|
| T+0 Detection & triage | SOC / CISO | Continuous | Incident ticket with severity, systems, data classes |
| T+0 to T+2h Containment | CISO + IT | ASAP | Containment log (isolation, credential rotation, snapshot) |
| CERT-In filing | Compliance Officer (CISO inputs) | 6 hours from noticing | CERT-In incident report (prescribed format) |
| Data Principal intimation | DPO / Grievance Officer | Without delay — Sec 8(6) | Plain-language notice: nature, consequences, mitigation, contact |
| DPB detailed report | Compliance Officer + Legal | 72 hours | Detailed report: facts, circumstances, remediation, notice copies |
| Vendor / processor escalation | Vendor liaison | Per contract SLA (target ≤ 2h notice inbound) | Processor incident declaration + data-flow map |
| Evidence closure | Company Secretary + Legal | T+30 days | Sealed evidence pack, board note, RCA |
Two clarifications NBFC teams routinely get wrong. First, the Data Principal notice is not “within 72 hours” — Section 8(6) read with the DPDP Rules 2025 requires intimation without delay; the 72-hour window applies to the detailed report to the Data Protection Board. Second, the Data Fiduciary (your NBFC) owns notification even when the breach happened at a Data Processor — your collections agency, LSP, or cloud vendor. Contracts should oblige processors to declare incidents to you within hours, because their delay consumes your statutory clock.
How do you file with CERT-In and the DPB without duplicating work?
Treat the CERT-In report as the factual skeleton and the DPB report as the fleshed-out narrative. The 6-hour CERT-In filing (mandated by the CERT-In Directions of April 2022, not by the DPDPA itself) needs incident type, affected systems, and preliminary impact — it tolerates incomplete information, and you can supplement. The DPB detailed report at 72 hours must add the circumstances, the personal data and Data Principals affected, remediation taken, and confirmation that affected individuals were intimated.
A practical pattern: maintain one living incident facts register (timestamped, append-only) from T+0. The CERT-In filing is a snapshot of it at hour 6; the DPB report is a structured export at hour 72. This prevents the two filings contradicting each other — a discrepancy the Board will notice, since penalty determination considers the nature, gravity, and duration of the breach and the Data Fiduciary’s conduct.
Remember the exposure math: inadequate security safeguards under Section 8(5) carry a slab of up to ₹250 crore, and notification failure under Section 8(6) a separate slab of up to ₹200 crore. A sloppy response converts one liability into two.
What goes into the Data Principal notice for borrowers?
For an NBFC, the affected Data Principals are borrowers, co-applicants, guarantors, and rejected applicants whose KYC you still hold under RBI retention norms. The Rules require the intimation to be in clear, plain language and to state the nature and extent of the breach, likely consequences, mitigation measures taken, safety steps the individual can take, and contact details of a person able to respond.
Pre-draft three templates now — one for credential/KYC exposure, one for financial-data exposure, one for contact-data exposure — in English plus the languages of your borrower base. Route them through your existing grievance channel so replies land with the DPO, not a no-reply inbox. This is also where consent architecture pays off: if you can query exactly which Data Principals’ data lived in the affected system, your notice list is precise instead of “all customers, out of caution.” Our breakdown of consent across the NBFC wealth stack covers how to build that queryability.
How does the SOP interact with RBI obligations?
It does not replace them. RBI’s IT governance and outsourcing directions carry their own incident-reporting expectations to the supervisor, and KYC master directions mandate retention periods that continue regardless of DPDPA erasure requests during a live regulatory retention obligation. Frame the SOP as parallel compliance: one incident register, three reporting lanes — CERT-In, DPB, RBI. Do not let anyone on the response team assume that filing with one regulator “covers” another, and do not claim DPDPA overrides RBI retention — it doesn’t; retention required by law is a recognised ground for continued processing.
If your NBFC is later notified as a Significant Data Fiduciary, additional obligations attach — a resident DPO, Data Protection Impact Assessments, and the Rule 13 annual audit, which applies to SDFs only, not to every Data Fiduciary. Breach handling is exactly the kind of evidence an SDF audit will examine, so build the evidence pack to audit grade from day one. See our explainer on the Significant Data Fiduciary threshold for whether you’re likely in scope.
What should the evidence pack contain when the dust settles?
The Board’s penalty inquiry looks at conduct: how fast you detected, whether safeguards were reasonable, whether notification was honest and timely. Your evidence pack is your defence file. Close every incident — real or tabletop — with:
| Area | Owner | Status |
|---|---|---|
| Incident facts register (timestamped, append-only) | CISO | ☐ |
| CERT-In filing copy + acknowledgement | Compliance Officer | ☐ |
| DPB 72-hour report + annexures | Compliance Officer | ☐ |
| Data Principal notice copies + dispatch logs | DPO / Grievance Officer | ☐ |
| Board / committee briefing note | Company Secretary | ☐ |
| Legal privilege log + external counsel notes | Legal | ☐ |
| Processor incident declarations + remediation SLAs | Collections / vendor liaison | ☐ |
| Root-cause analysis + safeguard uplift plan | CISO + Compliance | ☐ |
Architecture determines how painful this pack is to assemble. If borrower PII sits in a sealed vault with cryptographically immutable consent records and an evidentiary-grade audit trail, the register, the affected-user list, and the notice dispatch proof are exports — not forensics. That architectural stance is the core of how we build for lenders; see the Privigo financial-services solution for the vault and audit-trail design.
Closing
Three things to do this quarter, well before 13 May 2027:
- Name the owners. Put the RACI above into an approved SOP with phone numbers, alternates, and processor escalation contacts — then socialise it beyond the security team.
- Pre-draft the artefacts. CERT-In template, three Data Principal notice variants, DPB report skeleton, and the incident facts register format. Blank pages are for peacetime.
- Run the tabletop. Simulate an LSP leaking a collections file on a Friday evening. Time every phase against the table above, log the gaps, fix, and re-run in 90 days.
If you’d rather rehearse this with people who do it weekly, book a 30-minute DPDPA discovery call and we’ll walk your team through the runbook against your actual stack.
Frequently Asked Questions
Does an NBFC have to notify CERT-In and the Data Protection Board separately for the same breach?
Yes. CERT-In reporting (6 hours, under the CERT-In Directions 2022) and DPDPA breach notification to the Data Protection Board and affected Data Principals under Section 8(6) are separate legal obligations. One incident triggers both, and filing one does not discharge the other.
How fast must an NBFC inform affected customers after a personal data breach under DPDPA?
No fixed hour-count applies to Data Principals — Section 8(6) of the DPDPA 2023, read with the DPDP Rules 2025, requires intimation to each affected Data Principal without delay, in plain language, with the nature of the breach, likely consequences, and mitigation steps. The detailed report to the Data Protection Board follows within 72 hours.
What is the penalty for failing DPDPA breach notification obligations?
Up to ₹200 crore. The Schedule to the DPDPA 2023 provides a penalty of up to ₹200 crore for failure to notify a personal data breach under Section 8(6), while failure to maintain reasonable security safeguards under Section 8(5) carries a separate slab of up to ₹250 crore — a single incident can attract both.
Do RBI incident-reporting and KYC retention rules stop applying once DPDPA commences?
No. RBI master directions on IT governance, outsourcing, and KYC retention continue to apply in parallel with the DPDPA. An NBFC breach SOP must satisfy RBI supervisory reporting, CERT-In’s 6-hour clock, and DPDPA’s Board and Data Principal notifications together — not choose between them.
Sources
- Digital Personal Data Protection Act, 2023 — Official Act PDF, MeitY
- Digital Personal Data Protection Rules, 2025 — Gazette notification PDF, MeitY
- Press Information Bureau — DPDP Act background release
This article is for general information only and is not legal advice. Obligations vary by entity classification, RBI licence category, and notified rules; consult qualified counsel for your specific circumstances.

