CERT-In six hours, DPDP seventy two hours
In short
They are different obligations, to different recipients, on different triggers, and they can both attach to one incident.
The CERT-In Directions issued in April 2022 under section 70B(6) of the Information Technology Act 2000 require a service provider, intermediary, data centre, body corporate or government organisation to report specified cyber incidents within six hours of noticing them or being brought to notice. That obligation applies now.
Rule 7 of the DPDP Rules 2025 requires intimation of a personal data breach to affected Data Principals without delay, and to the Data Protection Board without delay and then in detail within seventy two hours of becoming aware.
01The two clocks side by side
| CERT-In Directions 2022 | DPDP Rules 2025, Rule 7 | |
|---|---|---|
| Trigger | Occurrence of a specified cyber incident | A personal data breach |
| Starts on | Noticing the incident or being brought to notice | Becoming aware of the breach |
| Window | 6 hours | Without delay, then 72 hours |
| Reported to | CERT-In | The Data Protection Board, and each affected Data Principal |
| Personal data required | No. A cyber incident need involve no personal data | Yes. The trigger is a personal data breach |
| In force | Yes | Rule 1(4) group, eighteen months from 13 November 2025 |
The categories of reportable incident under the Directions are specified, not general. Ransomware, data breaches, unauthorised access to IT systems and compromise of critical systems are among them. Check the current list against the Directions before deciding an incident is out of scope.
02Why the collision matters
The two windows are not sequential. They run from a shared moment, and the six hour one closes while the incident is still being characterised.
The failure mode is consistent and it is organisational rather than technical. Security triages the incident. Privacy waits for confirmation that personal data was involved. By the time the two functions speak, the six hour window has closed on an incident nobody had classified as reportable, because each function assumed the other owned the filing.
A second compounding factor is processor delay. Where a Data Processor holds the affected data, the Data Fiduciary is often told hours or days after the event. Both clocks then start on a delayed awareness, on facts the Data Fiduciary does not control, and the seventy two hour report has to be written from someone else's forensics.
03Sectoral clocks on top
For a regulated entity these two are rarely the whole picture. Depending on the entity, incident reporting obligations may also arise under the RBI Master Direction on information security and cyber incident reporting, the SEBI Cybersecurity and Cyber Resilience Framework, or the IRDAI framework for insurers. Each has its own recipient, format and window.
The practical control is a single incident intake that records one awareness timestamp and then fans out to every applicable obligation from it, with a named owner for each filing. If the owner of the CERT-In filing cannot be named in a sentence, that filing has no owner.
04Common questions
Does reporting to CERT-In satisfy the DPDP obligation?
No. They are separate obligations to separate recipients under separate instruments. One filing does not discharge the other.
Can an incident trigger CERT-In but not DPDP?
Yes. A specified cyber incident involving no personal data can be reportable to CERT-In without engaging Rule 7.
Which clock starts first?
Both run from the same awareness anchor in practice. The six hour window simply closes first.
Ask an AI assistant about this page
Each button opens the assistant with the prompt below already written.
Answers are generated by third party systems and are not published or verified by this site. Check anything load bearing against the gazette text.