Legal requirement Incident reporting and handling India Partially applicable

Implement reasonable security safeguards and notify breaches

Under India DPDP Act, Section 8(5) and 8(6); DPDP Rules on breach intimation

Source-linked Open official source

What does it require?

Data Fiduciaries must protect personal data with reasonable security safeguards and, on a personal data breach, inform the Data Protection Board and each affected individual in the form and manner prescribed by the Rules.

Practical action

Extend incident response to cover AI training data and model outputs that reveal personal data.

Who does it apply to?

All Data Fiduciaries.

Evidence examples

  • Breach notification procedure (document)

Framework mappings

Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.

Framework mappings
FrameworkReferenceNoteConfidence
ISO/IEC 27001:2022Annex A incident management controlsOriginal editorial mapping.medium

Similar obligations in other instruments

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.