Personal Data Breach Register · DPDP §8.6

Notify DPB within 72hr · notify affected data principals · CERT-In notify within 6hr · auto-template ready
0
Active breaches
0
90-day count
4
Lifetime breaches
100%
72hr notify compliance
15d
Days since drill

Breach register · last 12 months

Breach IDDetectedSeverityAffectedRoot causeDPB notifiedStatus
BRC-2025-000422 Aug 2025 · 14:32MEDIUM1,847 customers · names+masked PANvendor (Karza) SQL injection patched23 Aug · 09:15 (within 19hr)closed · 30 Sep
BRC-2025-000314 Jun 2025 · 02:18LOW1 internal user · log accessmisconfigured S3 bucket policynot required (low severity)closed · 15 Jun
BRC-2024-000218 Nov 2024 · 22:05HIGH42 customers · selfie photos exposedmisconfigured CDN cache, exposed to crawlers19 Nov · 08:30 (within 11hr)closed · 22 Jan 2025
BRC-2024-00013 Mar 2024 · 11:42LOW1 customer · DOB visible in confirmation emailemail template bugnot requiredclosed · 4 Mar

72hr DPB notification runbook

Trigger: Breach detected → severity ≥ MEDIUM
SLA: Notify DPB (Data Protection Board) within 72 hours of becoming aware · CERT-In within 6 hours
  1. Detect & contain (T+0 to T+1hr) — isolate affected systems · stop bleeding
  2. Triage (T+1 to T+6hr) — classify severity, count affected, identify root cause
  3. CERT-In notify (T+6hr) — file at cert-in.org.in/incident-report · template auto-filled from breach data
  4. Stakeholder brief (T+12hr) — DPO, CISO, Legal, CEO informed
  5. DPB notify (T+72hr max) — file at dpb.gov.in/breach-notify · include scope, cause, mitigation, customer impact
  6. Customer notify (T+72hr max) — affected customers emailed · masked PII via DSAR channel
  7. Mitigation (T+30d) — root cause fix, vendor remediation, audit trail update
  8. Post-mortem (T+45d) — RCA published internally, controls updated, drill scheduled

Auto-detect monitors

MonitorThresholdLast triggeredStatus
Unusual bulk data export (>10K rows / hr)10K rowsarmed
API key compromise (anomalous geo)request from non-IN region22 Aug 2025armed
S3 bucket public-read enabledany bucket toggles public14 Jun 2025armed
Failed login burst (single user, >20 attempts)20 / hourarmed
DB query returning PII without WHERE clausefull-table scan + PII columnsarmed
Vendor API 5xx burst (potential SQLi)50 errors / min22 Aug 2025armed
Audit chain hash mismatchany Merkle breakarmed
Cross-border data transfer to non-whitelisted regionany non-IN destinationarmed

Drill schedule · tabletop exercises

DateScenarioParticipantsOutcome
30 Apr 2026Vendor compromise (Karza) · 5,000 customer recordsDPO, CISO, Legal, Eng, CEOpassed · DPB form filed in 18hr (sim)
30 Jan 2026Insider exfiltration · 200 customer selfiesHR, Legal, DPO, CISOpassed · 31hr to notify (sim)
30 Oct 2025Ransomware on KYC DBEng, CISO, DPO, Legalgap · backup restore took 8hr (target 4hr)
30 Jun 2026 (next)UPI vendor outage + PII spillscheduledupcoming