On discovering a data breach, which regulators or other government agencies should be notified?
List:
-
When a data breach occurs in India, any person, including a company affected by it, should report it to the Indian Computer Emergency Response Team (CERT-In) established under the Information Technology Act, 2000 within a reasonable time. Certain cyber security incidents, for example, compromise of critical systems or information, malicious code attacks, identity theft, DoS and DDos attacks, etc. are required to be mandatorily reported to CERT-In. The report can be communicated to the authority by telephone, fax, email, post and/or through CERT-In’s website – www.cert-in.org.in.
-
In the case of a data breach in a banking company or a non-banking financing company (NBFC), a report must be filed to the Reserve Bank of India (RBI) in a Security Incident Reporting (SIR) form by the company within two to six hours from the time of occurrence or on noticing such data breach. The SIR form requires particulars of the incident, specifically name of bank, details of incident, chronological order of events, etc. Further, a subsequent update must be sent to the RBI in Cyber Security Incident Reporting (CSIR) outlining further details of the breach.
-
Additionally, with the enactment of The Digital Personal Data Protection Act, 2023 (DPDP Act), in case of a personal data breach, a Data Fiduciary, i.e., the person who alone or in conjunction with other persons determines the purpose and means of processing personal data, is required to intimate the Data Protection Board of India (yet to be established) and the affected person in the manner as prescribed under the Rules.
Note: Though DPDP Act has been enacted, the Rules for its implementation are yet to be notified.