Description
Respond to a personal data breach in five recorded stages and meet the 72 hour reporting rule, shown through a software company.
A support team finds customer records exposed on a misconfigured server. The DPDP Act requires the organisation to inform the Data Protection Board and every affected person, and the DPDP Rules add a detailed report to the Board within 72 hours.
TrustOS runs the response in five stages: detected, assessed, notified, remediated and evidence. It records the incident and likely impact, identifies affected people, tracks communications and control updates, and retains the full evidence package. Penalties for failing to report a breach go up to 200 crore rupees.
In this video
- Who must be informed
- The 72 hour detailed report
- Five stage response
- Evidence package and penalties