DPDP Glossary
Personal Data Breach
A breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of or access to personal data that compromises confidentiality, integrity or availability.
Section 2(u); Section 8(6); Rule 7
What it means
Section 2(u) defines personal data breach. Section 8(6) requires the Fiduciary to intimate the Board and affected Data Principals of a personal data breach in the manner the Rules provide. Rule 7 elaborates intimation content and process. Prevention sits in reasonable security safeguards (Section 8(5); Rule 6).
Worked example
An unauthorised dump of customer emails from a misconfigured bucket is a classic confidentiality compromise. A ransomware encryption event that locks Principals’ data can implicate availability. Both need incident classification against Section 2(u) and a rehearsed Rule 7 intimation path — not only a PR draft.
In practice
Maintain detection, triage, legal assessment and intimation runbooks. Align security controls with Rule 6. See the Rule 7 page for operational breach-notification framing.
Source
Section 2(u); Section 8(6); Rule 7 · Official text (PDF)
Educational summary based on the Digital Personal Data Protection Act, 2023 and Rules, 2025. Not legal advice.