Breach response · DPDP s.8(6), Rule 7

Seventy-two hours, counted.

Record an incident and the clock starts. Each step is taken once, in order, with a timestamp; the Board report is drafted from the incident's own fields; affected people are found from the systems involved and notified in two languages.

s.8(6) IntimationRule 7 Contents & 72 hoursBilingual notices
A breach in the console: the 72-hour clock, the ordered steps and the drafted Board report
The challenge

A breach is the worst day to design a process.

Rule 7 asks for intimation without delay, a full report within 72 hours, and notice to every affected person. Teams that have not rehearsed it lose the first day finding out who owns it.

Rule 7(2)
The report has required contents
Nature, extent, timing, likely impact, mitigation, remedial measures and findings about the person responsible. A free-text email to the Board will be sent back.
Who was affected?
Finding the people
Which systems were involved, which purposes those systems serve, which people gave consent for those purposes. Without an inventory, this is guesswork under pressure.
Evidence
Proving you were on time
Later, the question will be when you knew and when you told. The record has to be written as it happens, not reconstructed.
What Nyvika does

The sequence, enforced.

Nyvika does not let a breach be closed before the report is filed and the people are told, and it will not let steps be taken out of order.

The register

Severity, detection time, affected systems from the inventory, categories of data, description and containment.

  • Clock starts at the recorded detection time
  • Hour-of-72 on the incident and the overview
  • Register report says whether each incident met it

Ordered steps

Contain, intimate the Board, report within 72 hours, notify people, resolve, close. Each once, in order, timestamped.

  • Closing requires the report and the notices
  • Every step is an audit event
  • Timeline appended under a lock

Drafted Board report

The report is assembled from the incident's fields with gaps shown in brackets until filled.

  • Rule 7(2) contents in order
  • Edit, then record as filed
  • Kept with the incident

Notices to people

Recipients derived from the affected systems' purposes, plus a pasted list; sent by email and SMS or WhatsApp in two languages.

  • Bilingual templates
  • Recorded on the timeline and the notifications log
  • Contact addresses from the encrypted vault
Rehearsal

Practise on a drill.

A test incident runs the whole sequence with notices to your own team, so the first real one is not the first time anyone has seen the screen.

  • Same screens

    A drill is an ordinary incident flagged as a test; it is excluded from the register report.

  • Same clock

    See what 72 hours feels like when the report still has brackets in it.

  • Same evidence

    The audit log shows the drill happened, which is itself a reasonable safeguard to show.

The bilingual breach notice as a person receives it
One ledger

How it connects.

Every module writes to the same registers and the same hash-chained evidence, so nothing is re-keyed and nothing is lost between teams.

Questions

Asked about breach response.

Does Nyvika file the report with the Board?

It drafts the report in the form Rule 7 requires and records when you filed it. Filing itself happens through the Board's own channel, which the Act leaves to the fiduciary.

What counts as detection time?

The time your team records as when the breach became known. The clock runs from there. Recording it honestly is in your interest: the audit log shows when the incident was created either way.

Can we notify people before the report is filed?

Yes. Intimation to people and to the Board can happen as soon as containment is recorded; only closing the incident waits for the report.

Still have a question? Write to us.

Run a drill before you need one.

In the demo we open a test incident on your data categories and walk the 72 hours in ten minutes.