DPDP Breach Clock Calculator
The DPDP breach clock, from one timestamp.
Enter the moment your organisation became aware. The four statutory clocks compute from it, live. Nothing is stored and nothing is sent — this runs in your browser.
Incident parameters
CERT-In runs in parallel and closes first: six hours from noticing, in the prescribed format.
On awareness
The hardest question in Rule 7 is not what to file. It's when the clock started. Awareness begins when the organisation becomes aware that a breach involving personal data has occurred — not when an incident is first suspected, and not when forensics conclude. If your processor tells you on day eleven, your exposure may already be retroactive.
Read our note on Rule 7Guidance, not legal advice. Verify against the current rule text.
Breach response deadlines
Awareness: Mon 17 Aug, 2026, 09:00 IST
Sector: Lending & NBFC · Not an SDF · CERT-In reportable
| Filing | Rule | Due by |
|---|---|---|
| CERT-In initial report | Direction 20(3)/2022 · 6h | Mon 17 Aug, 2026, 15:00 IST |
| Initial intimation to the Board | Rule 7(1) · without delay | Thu 20 Aug, 2026, 09:00 IST |
| Notification to data principals | Rule 7(1)(b) · without delay | Thu 20 Aug, 2026, 09:00 IST |
| Detailed report to the Board | Rule 7(2) · 72h | Thu 20 Aug, 2026, 09:00 IST |
Awareness begins when the organisation becomes aware that a breach involving personal data has occurred — not when an incident is first suspected, and not when forensics conclude.
Generated Mon 17 Aug, 2026, 21:41 IST · riskfortis.com/tools/breach-clock · Guidance, not legal advice.