# Breach Notification Template — India (CERT-In + DPDP)

Template id: `breach-notice-certin-in.v1` owner: Security incident commander
(CERT-In filing) + Lilith-Privacy lead (DPDP filing) + IN counsel

Two distinct obligations with different clocks — file both:

1. **CERT-In**: reportable cyber security incidents must be reported within
   **6 hours** of noticing (CERT-In directions of 28 April 2022). E-mail
   `incident@cert-in.org.in` using the CERT-In incident reporting format.
2. **Data Protection Board of India (DPDP Act 2023)**: notify the Board and
   each affected Data Principal of a personal data breach in the form and
   manner prescribed under the rules — without delay; counsel confirms the
   currently prescribed timeline at filing time.

The 6-hour CERT-In clock is the tightest in the wave-1 set: the draft starts
in incident hour one with whatever is known; supplement later.

## CERT-In report content (incident reporting format)

1. Reporting organisation, point of contact (name, phone, e-mail).
2. Incident type (e.g., data breach / unauthorised access), date and time of
   occurrence and of detection (IST).
3. Affected systems: which V3 systems (BFF, Postgres persistence, consent
   ledger, pxstream relay), their location (`in` residency zone, `ap-south-1`
   and in-zone replicas), IPs/domains as applicable.
4. Brief description and observed impact, including approximate count of
   India-resident users affected.
5. Actions taken (containment, evidence preservation per the security
   runbook).
6. Supplementary information to follow as scoping completes.

## DPDP notification content

- Nature, extent, timing, and location of the breach; consequences likely to
  arise for Data Principals; measures taken; the Data Fiduciary contact and
  the published Grievance Officer (IT Rules 2021 listing, per the legal-docs
  publication gate).
- Data Principal (user) notices in plain language: what happened, what data,
  what we did, what the user should do, grievance contact.

## Internal routing

- CERT-In filing drafted by the security commander, reviewed by IN counsel —
  but the 6-hour clock outranks review availability: if counsel is
  unreachable at hour 5, the commander files the factual report and counsel
  supplements after.
- Evidence: filed reports, acknowledgments, and timestamps in the incident
  evidence bucket, referenced from the Operator Console case.
