Cybersecurity9 min readAugust 14, 2026

The 250 Crore Clause: DPDPA Security Safeguards and Breach Notification as an Architecture Problem

M
Mohammed UsmanFounder & CEO

Mohammed Usman is the founder and CEO of Masarrati with 15+ years in product engineering. He has led the development of 10+ production AI, blockchain, and cybersecurity platforms for enterprise clients across UAE, MENA, and Europe.

AI/ML ArchitectureBlockchain SystemsEnterprise Security

TL;DR

The DPDPA's top penalty — up to 250 crore rupees — attaches to inadequate security safeguards and can apply without a breach, while notification failures carry up to 200 crore and a 72-hour duty to affected individuals. The engineering response: demonstrable controls with continuous evidence, detection sized to the notification clock, data inventory that scopes incidents fast, rehearsed notification at production scale, and one control library covering DPDPA alongside ISO 27001, SOC 2 and PDPL.

Updated August 14, 2026

Most data protection statutes punish the breach. India's punishes the absence of defence. The DPDP Act's highest penalty band — up to 250 crore rupees under the schedule attached to Section 8(5) — applies to a data fiduciary's failure to take reasonable security safeguards to prevent personal data breach, and analyses of the Act make a point that changes how the obligation should be read: the penalty can be triggered by the inadequacy of the safeguards themselves, whether or not an incident has occurred. A separate band of up to 200 crore rupees attaches to failing the breach notification duties, which reporting describes as notice to the Data Protection Board with prescribed detail and notification to affected data principals within 72 hours.

Read together, those two clauses convert security architecture from an IT budget line into a regulatory position. The questions a fiduciary must be able to answer are no longer just "were we breached?" but "can we demonstrate our safeguards were reasonable?" and "could we execute a compliant notification inside 72 hours?" Both are answered in systems, built in advance.

What "reasonable safeguards" means when a regulator is reading

The Act does not hand over a checklist, which means the operative standard will be what a fiduciary can evidence. Our reading — as builders of security platforms rather than lawyers — is that demonstrability is the design requirement. Controls that exist but cannot be shown to operate are, from a penalty-hearing standpoint, barely better than controls that do not exist.

Access control with records. Least-privilege access to personal data stores, role reviews with dated evidence, and logs that show who touched what. The safeguard is the control plus its record.

Encryption as posture, not exception. At rest and in transit as the default for personal data, with key management that survives scrutiny — documented custody, rotation and access.

Detection sized to the obligation. A 72-hour clock to notify affected individuals starts when a breach becomes aware. An organisation whose detection lags by weeks has already spent its notification window before it knows the clock started. Telemetry across endpoints, identity, cloud and applications, correlated into incidents, is what makes the deadline physically meetable.

Processor and vendor safeguards. The fiduciary answers for the chain. Scoped credentials, monitored data flows to processors, and contractual duties mirrored by technical controls.

Evidence generation as a feature. Every control emitting its own audit trail — because Section 33's penalty factors reward an organisation that can show the Board a functioning, monitored, improving security operation, and the Act's structure allows doubled penalties for repeat failures.

The 72-hour drill, decomposed

A compliant notification requires, in sequence: detection and triage fast enough to establish that a personal data breach occurred; scoping — which systems, which data categories, approximately how many data principals; drafting notices with the prescribed content for both the Board and affected individuals; and delivery at scale, potentially to millions of users, inside the window. Each step is an engineering capability. The scoping step in particular depends on data inventory work done long before any incident: if you cannot map compromised systems to affected principals quickly, the 72 hours evaporate in forensics.

The organisations that meet this consistently are the ones that have rehearsed it — tabletop exercises against realistic scenarios, with the notification tooling tested at production scale, and the evidence of those rehearsals retained. Under a demonstrability standard, the drill records are themselves safeguards.

Where this intersects the rest of the regime

Security safeguards do not live alone. The consent systems arriving through 2026 and 2027 are themselves personal-data stores that need protecting; erasure obligations interact with backup and log retention design; and Significant Data Fiduciaries face audit cycles where the security evidence gets examined annually. Treating the DPDPA as one control library — security, consent, rights, audit — mapped once and evidenced continuously is dramatically cheaper than four parallel compliance projects.

Where Masarrati fits

This is the platform layer Masarrati builds. Our CSOC and security operations platforms give enterprises the detection pipelines, correlation and case management that make a 72-hour clock meetable; our cybersecurity product work spans XDR and monitoring platforms built for regulated environments; and our GRC and compliance automation maps DPDPA safeguards into the same control library as ISO 27001, SOC 2 and the UAE's PDPL, with evidence collected continuously rather than assembled before audits. We build, document and hand over — your team operates the platform, and your counsel owns the legal reading. What we deliver is an architecture whose records answer the Board's questions.

Frequently Asked Questions

What is the maximum penalty under India's DPDPA?

The highest band in the Act's penalty schedule is up to 250 crore rupees, attached to a data fiduciary's failure to take reasonable security safeguards under Section 8(5). Analyses note it can be triggered by the inadequacy of safeguards themselves, without an actual breach, and the Act's structure allows penalties to be doubled for repeat or grave failures.

What are the DPDPA breach notification requirements?

Reporting on the regime describes notification to the Data Protection Board with prescribed detail — the nature of the breach, categories and approximate number of affected data principals, likely consequences and mitigation — and notification to affected data principals within 72 hours. Failure of the notification duties carries its own penalty band of up to 200 crore rupees.

What counts as reasonable security safeguards under the DPDPA?

The Act does not publish a checklist, so the practical standard is what a fiduciary can evidence: least-privilege access with records, default encryption with managed keys, detection and monitoring sized to a 72-hour notification clock, technical controls over processors, and audit trails generated continuously by the controls themselves.

How should companies prepare for the 72-hour notification window?

Decompose it into capabilities: detection fast enough to start the clock knowingly, data inventory that maps compromised systems to affected principals quickly, notice templates with the prescribed content, and delivery tooling tested at production scale — then rehearse the sequence and retain the rehearsal evidence, which itself demonstrates safeguards.

++++