DPDP Breach Clock Calculator
Every DPDP deadline, from one timestamp.
Enter the moment your organisation became aware. The four statutory clocks compute from it, live. Nothing is stored and nothing is sent — this runs in your browser.
Incident parameters
CERT-In runs in parallel and closes first: six hours from noticing, in the prescribed format.
On awareness
The hardest question in Rule 7 is not what to file. It's when the clock started. Awareness begins when the organisation becomes aware that a breach involving personal data has occurred — not when an incident is first suspected, and not when forensics conclude. If your processor tells you on day eleven, your exposure may already be retroactive.
Read our note on Rule 7Guidance, not legal advice. Verify against the current rule text.
Breach response deadlines
Awareness: Wed 12 Aug, 2026, 09:00 IST
Sector: Lending & NBFC · Not an SDF · CERT-In reportable
| Filing | Rule | Due by |
|---|---|---|
| CERT-In initial report | Direction 20(3)/2022 · 6h | Wed 12 Aug, 2026, 15:00 IST |
| Initial intimation to the Board | Rule 7(1) · without delay | Sat 15 Aug, 2026, 09:00 IST |
| Notification to data principals | Rule 7(1)(b) · without delay | Sat 15 Aug, 2026, 09:00 IST |
| Detailed report to the Board | Rule 7(2) · 72h | Sat 15 Aug, 2026, 09:00 IST |
Awareness begins when the organisation becomes aware that a breach involving personal data has occurred — not when an incident is first suspected, and not when forensics conclude.
Generated Wed 12 Aug, 2026, 22:15 IST · riskfortis.com/tools/breach-clock · Guidance, not legal advice.