Know what triggers the workflow
The Act defines a personal data breach broadly: unauthorised processing or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access that compromises confidentiality, integrity or availability.
An incident workflow should therefore receive signals from security, reliability, support, vendors and business teams. Limiting intake to confirmed external attacks misses accidental and availability events.
Prepare two audiences and two Board stages
Rule 7 requires affected Data Principals to be informed without delay in a concise, clear and plain manner. The notice should explain the nature and likely consequences, mitigation already taken, recommended safety measures and a contact point.
The Board receives an initial description without delay. A fuller submission follows within seventy-two hours unless the Board allows more time, including findings, circumstances, mitigation, responsible persons and communications to affected individuals.
- Pre-approve individual and Board notification templates.
- Name the executive who can authorise communication.
- Track facts, decisions and timestamps from the first alert.
Make processors part of the clock
The Data Fiduciary remains accountable when processing is performed by a processor. Contracts should require prompt escalation, evidence preservation, continuing updates and cooperation with communications.
Exercise the playbook with a processor outage or delayed fact pattern. A tabletop test is useful only if it reveals whether the organisation can produce the information the Rules actually request.
Sources and editorial review
Prepared by DPDP Academy Editorial (Legal education and implementation guidance). Reviewed by DPDP Academy Source Review using the sources below on 2 August 2026. Statutory text, notified Rules and practical interpretation are kept distinct. Educational content, not legal advice.