Privra/Document

Breach notification

Version 1

Back to trust center

Please note: This document provides template drafts for breach notifications. It is not a government certification, legal opinion, or a substitute for qualified legal counsel. Privra recommends consulting with legal professionals to ensure full compliance with the Digital Personal Data Protection Act, 2023, and the DPDP Rules, 2025, as well as any other applicable laws and regulations.

---

## Data Breach Notification Drafts (Section 8(6) DPDP Act, 2023)

### 1. To: Data Protection Board of India

**Subject: Data Breach Notification – Privra – [Date of Incident Discovery]**

**Date:** [Date of this Notification]

**To:** The Data Protection Board of India [Address of DPBI, if known, or general salutation]

Dear Sir/Madam,

This notification is submitted by Privra, a Data Fiduciary, in compliance with Section 8(6) of the Digital Personal Data Protection Act, 2023, and the Digital Personal Data Protection Rules, 2025, regarding a personal data breach. We are providing the following summary of the incident and will submit any further details and prescribed forms as required by the applicable Rules within the stipulated timelines.

**Incident Summary:**

* **Organization Notifying:** Privra * **Contact Person for Incident:** John Doe, Data Protection Officer (DPO) * **Email:** DPO@company.com * **Phone:** [DPO's Phone Number, if applicable] * **Incident Period/Date:** `[To be completed when facts are known]` * **Date of Discovery:** `[To be completed when facts are known]` * **Nature of Breach:** `[To be completed when facts are known]` (e.g., Unauthorised access, data exfiltration, accidental disclosure, system compromise, ransomware attack) * **Data Categories Affected:** `[To be completed when facts are known]` (e.g., Names, email addresses, phone numbers, account IDs, payment information, demographic data, IP addresses) * **Approximate Scale of Affected Data Principals/Records:** `[To be completed when facts are known]` (e.g., Approximately [NUMBER] user accounts, [NUMBER] records) * **Likely Consequences for Data Principals:** `[To be completed when facts are known]` (e.g., Risk of identity theft, phishing attacks, unauthorised access to other services, financial fraud, reputational harm) * **Measures Taken/Proposed by Privra:** * `[To be completed when facts are known]` (e.g., Immediately isolated affected systems, engaged forensic experts, implemented enhanced security protocols, notified affected Data Principals, reset passwords, offered credit monitoring services) * Ongoing investigation to determine the full scope and root cause. * Reviewing and strengthening internal security policies and procedures. * **Steps for Data Principals to Mitigate Harm:** * `[To be completed when facts are known]` (e.g., Advised to change passwords, monitor accounts for suspicious activity, be vigilant against phishing attempts) * **Further Information:** Privra is committed to providing all necessary information and cooperation to the Data Protection Board of India as required by the Act and Rules. We will update the Board as our investigation progresses and more details become available.

We appreciate your understanding and guidance in this matter.

Sincerely,

John Doe Data Protection Officer Privra

---

### 2. To: Affected Data Principals

**Subject: Important Information Regarding a Data Security Incident at Privra**

**Date:** [Date of this Notification]

**Dear [Data Principal Name, if known, or "Dear Valued User"],**

We are writing to inform you about a data security incident that may have involved some of your personal data. At Privra, protecting your data is our top priority, and we sincerely regret any concern or inconvenience this may cause.

**What Happened?**

On `[Date of Discovery]`, we identified `[Nature of Breach, e.g., unauthorised access to a portion of our systems / an accidental disclosure of data]`. Our security team immediately took action to `[Measures taken, e.g., secure our systems and prevent further unauthorised access / contain the incident]`.

**What Data Was Involved?**

Based on our current investigation, the incident may have affected the following types of your personal data: * `[Data Categories Affected, e.g., Your name]` * `[Data Categories Affected, e.g., Your email address]` * `[Data Categories Affected, e.g., Your phone number]` * `[Data Categories Affected, e.g., Your account ID]` * `[Data Categories Affected, e.g., (If applicable) Limited payment information (e.g., last four digits of card number, but NOT full card numbers or CVVs)]` * `[Data Categories Affected, e.g., (If applicable) Other specific data points relevant to the incident]`

Please be assured that `[State what was NOT compromised, e.g., your passwords were encrypted and not directly exposed / full payment card details were not affected]`.

**What is the Likely Impact?**

The likely consequences of this incident could include `[Likely Consequences, e.g., an increased risk of phishing attempts, spam, or other unsolicited communications. In some cases, there might be a risk of identity theft or unauthorised access to other online accounts if you reuse passwords]`. We have no indication that your data has been misused at this time, but we are providing this notification out of an abundance of caution and in compliance with Section 8(6) of the Digital Personal Data Protection Act, 2023.

**What We Are Doing:**

1. **Securing Our Systems:** We have taken immediate steps to `[Measures taken, e.g., patch vulnerabilities, enhance monitoring, and strengthen our security infrastructure]`. 2. **Investigation:** We have engaged `[If applicable, e.g., leading cybersecurity experts]` to conduct a thorough forensic investigation to understand the full scope and root cause of the incident. 3. **Notifying Authorities:** We have notified the Data Protection Board of India, as required by law. 4. **Continuous Improvement:** We are reviewing and enhancing our security policies and procedures to prevent similar incidents in the future.

**What You Can Do:**

We recommend you take the following precautions to protect yourself: 1. **Change Passwords:** As a best practice, we strongly advise you to change your password for your Privra account immediately. If you use the same password for other online services, we recommend changing those too. 2. **Monitor Your Accounts:** Remain vigilant and review your bank statements, credit card statements, and other online accounts for any suspicious activity. Report any unusual transactions to your financial institution immediately. 3. **Beware of Phishing:** Be cautious of any unsolicited emails, messages, or calls that ask for your personal information. Privra will never ask for your password or sensitive personal data via email. 4. **Consider Credit Monitoring:** `[Optional: If relevant and offered, e.g., We are providing complimentary [NUMBER] months of credit monitoring services through [Service Provider]. Please visit [Link] to enrol using code [Code].]`

We understand you may have questions. Our dedicated team is here to help.

**Contact Us:**

For any questions or concerns regarding this incident, please contact our Data Protection Officer, John Doe, at: * **Email:** DPO@company.com * **Phone:** [DPO's Phone Number, if applicable] * **Our Website:** [Link to a dedicated incident information page, if available]

We sincerely apologise for this incident and appreciate your understanding and trust as we work to resolve this matter thoroughly.

Sincerely,

The Privra Team

---

### 3. Optional FAQ

**Q1: What is a data breach?** A: A data breach occurs when personal data is accessed, disclosed, altered, or destroyed in an unauthorised or unlawful manner. In this case, `[briefly reiterate nature of breach, e.g., an unauthorised party gained access to a portion of our systems]`.

**Q2: What specific data of mine was impacted?** A: While we cannot provide individual specifics in this general notification, the types of data potentially affected include `[list general categories again, e.g., your name, email address, and account ID]`. We do not believe `[state what was NOT affected, e.g., your passwords were compromised in plain text or full financial details were exposed]`.

**Q3: What should I do now?** A: We strongly recommend changing your Privra password and any other passwords you might have reused across different services. Please also monitor your financial accounts for any suspicious activity and be wary of unsolicited communications asking for personal information.

**Q4: Is my data safe with Privra now?** A: We have taken immediate and comprehensive steps to secure our systems and contain the incident. Our team, along with external cybersecurity experts, is continuously working to enhance our security measures and prevent future occurrences. We are committed to the ongoing protection of your data.

**Q5: How can I get more information or report suspicious activity related to this incident?** A: You can reach out to our Data Protection Officer, John Doe, directly at DPO@company.com or [DPO's Phone Number]. Please provide details of any suspicious activity you encounter so we can investigate further.

---

### 4. Checklist (Internal Items to Complete Before Sending)

**Before sending the Data Protection Board of India Notification:**

* [ ] Confirm all incident details (dates, nature, scope, categories, scale) are accurate and complete. * [ ] Ensure `[NUMBER]` of affected Data Principals/records is estimated. * [ ] Finalise "Measures Taken/Proposed" section with concrete actions. * [ ] Identify and confirm the official contact details for the Data Protection Board of India. * [ ] Complete any prescribed forms as required by the DPDP Rules, 2025. * [ ] Obtain internal legal review and approval for the notification. * [ ] Prepare for potential follow-up questions from the DPBI.

**Before sending the Affected Data Principals Notification:**

* [ ] Finalise the exact wording for "What Happened," "What Data Was Involved," and "Likely Impact." * [ ] Ensure the language is empathetic, clear, and easy to understand for a general audience. * [ ] Confirm all "What We Are Doing" and "What You Can Do" recommendations are actionable and accurate. * [ ] Verify the contact details (John Doe, DPO@company.com, phone number) are correct and operational. * [ ] If offering credit monitoring or other services, ensure all details (provider, link, code) are correct and ready. * [ ] Determine the method of communication (email, postal mail, in-app notification) and prepare the distribution list. * [ ] Prepare a dedicated landing page on the website with FAQ and contact information, if applicable. * [ ] Train customer support/DPO team on how to handle queries related to the incident. * [ ] Obtain internal legal and communications review and approval. * [ ] Plan for potential media inquiries, if applicable.

Transparency page powered by Privra. This page reflects disclosures chosen by the organization; it is not legal advice or a government certification.

Privra