Lilith Metaverse · Legal

Breach Notification Template — India (CERT-In + DPDP)

1.

3sections2 minread

On this page

Template id: breach-notice-certin-in.v1 owner: Security incident commander (CERT-In filing) + Lilith-Privacy lead (DPDP filing) + IN counsel

Two distinct obligations with different clocks — file both:

  1. CERT-In: reportable cyber security incidents must be reported within 6 hours of noticing (CERT-In directions of 28 April 2022). E-mail incident@cert-in.org.in using the CERT-In incident reporting format.
  2. Data Protection Board of India (DPDP Act 2023): notify the Board and each affected Data Principal of a personal data breach in the form and manner prescribed under the rules — without delay; counsel confirms the currently prescribed timeline at filing time.

The 6-hour CERT-In clock is the tightest in the wave-1 set: the draft starts in incident hour one with whatever is known; supplement later.

CERT-In report content (incident reporting format)#

  1. Reporting organisation, point of contact (name, phone, e-mail).
  2. Incident type (e.g., data breach / unauthorised access), date and time of occurrence and of detection (IST).
  3. Affected systems: which V3 systems (BFF, Postgres persistence, consent ledger, pxstream relay), their location (in residency zone, ap-south-1 and in-zone replicas), IPs/domains as applicable.
  4. Brief description and observed impact, including approximate count of India-resident users affected.
  5. Actions taken (containment, evidence preservation per the security runbook).
  6. Supplementary information to follow as scoping completes.

DPDP notification content#

  • Nature, extent, timing, and location of the breach; consequences likely to arise for Data Principals; measures taken; the Data Fiduciary contact and the published Grievance Officer (IT Rules 2021 listing, per the legal-docs publication gate).
  • Data Principal (user) notices in plain language: what happened, what data, what we did, what the user should do, grievance contact.

Internal routing#

  • CERT-In filing drafted by the security commander, reviewed by IN counsel — but the 6-hour clock outranks review availability: if counsel is unreachable at hour 5, the commander files the factual report and counsel supplements after.
  • Evidence: filed reports, acknowledgments, and timestamps in the incident evidence bucket, referenced from the Operator Console case.