DPDP Act 2025 Is Live — And Most Indian Organizations Can't Detect the Breaches It Requires Them to Report
Riya12 min read

DPDP Act 2025 Is Live — And Most Indian Organizations Can't Detect the Breaches It Requires Them to Report

India's DPDP Rules mandate breach notification and reasonable security safeguards. With ₹250 crore penalties and 240-day dwell times, Mines close the detection gap.

Share:

On November 13, 2025, India's Digital Personal Data Protection Rules went live, turning the DPDP Act 2023 from legislative principle into enforceable reality. Organizations have until May 13, 2027 to reach full compliance. After that, there's no grace period. Penalties start on day one.

The numbers are blunt. Up to ₹250 crore for failing to implement reasonable security safeguards. Up to ₹200 crore for failing to notify the Data Protection Board of India (DPBI) and affected individuals of a breach. Up to ₹200 crore for processing without valid consent. Multiple violations compound, with each infraction carrying its own penalty.

And here's the problem almost nobody is naming: you can't notify a breach you never detected.

I track India's threat landscape closely, and the trend lines are ugly. The country's cybersecurity incident count more than doubled from 1.03 million in 2022 to 2.27 million in 2024. Malware detections surged from 5 million in 2021 to 53 million in 2024, a tenfold jump in three years. The BFSI sector alone faced an average of 4.1 million attacks monthly in the first half of 2025. IBM pegs the average cost of a data breach in India at roughly ₹220 million, before DPDP penalties get layered on top.

Yet the global average time to identify and contain a breach sits close to 240 days. In India's critical sectors — healthcare (21% of malware cases), BFSI (19%), hospitality (17%), and education (15%) — aging infrastructure and underfunded security teams often push that detection gap even wider.

The DPDP Act doesn't only ask you to protect data. It asks you to know when protection fails, and to tell the regulator right away. For most Indian organizations, that capability simply doesn't exist yet.

What the DPDP Rules actually require, and where the gaps open up

The DPDP Rules 2025 create specific, enforceable obligations around security and breach detection that reach well beyond earlier CERT-In requirements.

Reasonable security safeguards (Rule 6). Data Fiduciaries must put appropriate technical and organizational measures in place to prevent personal data breaches. The Rules explicitly name encryption, access control, authentication, event detection, logging, backups, and monitoring. This is a mandatory baseline, not a suggestion, and failure sits in the highest penalty tier of ₹250 crore.

Mandatory breach notification, with no materiality threshold. GDPR requires notification only when a breach is "likely to result in a risk to the rights and freedoms of natural persons." The DPDP Rules carry no such threshold. On a strict reading, every personal data breach must be reported to the DPBI and affected Data Principals. That's an aggressive requirement, and it means organizations need detection that catches breaches of any size.

CERT-In's six-hour reporting window still applies. India's CERT-In directive already requires reporting cybersecurity incidents within six hours of detection. BFSI entities under RBI and SEBI oversight carry additional sector-specific breach reporting obligations. The DPDP Act stacks another reporting duty to the DPBI on top. Organizations now face parallel notification requirements across multiple regulators, all of them triggered by the ability to detect a breach in the first place.

Minimum one-year log retention. The Rules require keeping security logs for at least one year to support audit trails and forensic investigation. So organizations need not just detection but a provable record of it.

Significant Data Fiduciaries face extra scrutiny. Organizations classified as Significant Data Fiduciaries (SDFs) — including e-commerce platforms with 20 million+ Indian users, online gaming platforms with 5 million+ users, and entities processing large-scale behavioral or sensitive data — face mandatory audits, Data Protection Impact Assessments, and continuous compliance monitoring. For SDFs, every detection gap gets multiplied by regulatory examination.

In India's regulated sectors, the detection problem is a compliance crisis

Let's be direct about the state of breach detection across India's most regulated industries.

BFSI is under siege. The banking sector saw 248 data breaches across scheduled commercial banks over a four-year period. Supply chain attacks through vendor portals have become the preferred entry point. The ICICI Bank incident involved credential harvesting through a compromised third-party vendor. A Nupay breach exposed 273,000 bank transfer documents through a misconfigured S3 bucket. The LIC database, allegedly holding 454 million rows of policy data, was advertised for sale on dark web forums. After geopolitical tensions flared, over 1.5 million cyberattacks targeted Indian critical infrastructure, with seven APT groups identified.

Healthcare can't protect patient data. The ICMR breach exposed data on 815 million citizens. Delhi hospitals had patient records, financial data, and administrative files accessed after a server hack. Healthcare accounted for 21% of all malware detections in India, the highest of any sector. Under the DPDP Act, every one of these incidents requires notification to the DPBI and affected individuals. The Synnovis hack and what it taught about cyber deception is a sobering parallel for any healthcare provider reading this.

The talent gap cripples detection. 68% of Indian companies admit incomplete understanding of their DPDP obligations. The cybersecurity talent shortage leaves most organizations without dedicated SOC teams capable of 24/7 monitoring. When your security team is understaffed and buried in alerts, breaches that ride valid credentials or exploit third-party access go undetected for months.

Third-party risk is the blind spot. Several major Indian breaches in 2025 started from compromised vendor portals and misconfigured cloud services, not direct attacks on the organization itself. Under the DPDP Act, the Data Fiduciary is responsible regardless of whether the breach happened at a processor or vendor. You can't delegate the penalty.

How Mines close the DPDP detection gap

This is where cyber deception, specifically Mine2's Mines, becomes a direct compliance enabler.

Mines are decoy assets planted throughout your environment: fake credentials, bogus documents, decoy services, and phantom cloud resources. No legitimate user or process should ever interact with a Mine. Any interaction is, by definition, a breach indicator, which gives you immediate, zero-false-positive detection that satisfies the DPDP Act's requirement for event detection and reasonable security safeguards.

Here's why Mines fit India's DPDP challenge so well.

Mines catch breaches that traditional tools miss

The DPDP Act requires you to detect every personal data breach, not just the ones that happen to trip your SIEM rules. When an attacker uses valid credentials harvested from a third-party vendor breach, your EDR sees a legitimate login. Your SIEM sees authorized access. No alert fires.

Mines flip that. Credential Mines planted in credential stores, config files, and documentation catch credential harvesting. Data Mines scattered across file shares and databases catch unauthorized data enumeration. MineField decoy services catch network reconnaissance. Any attacker who enters your environment, however legitimate their access looks, eventually touches a Mine during their exploration. The alert fires at once. Zero false positives. No behavioral baseline needed. For DPDP compliance, that means you can detect breaches that would otherwise go unreported, not because you chose to hide them, but because you never knew they happened. We dig into that same authorized-access problem in our piece on why honeytokens catch insiders that DLP and SIEM can't.

Mines satisfy "reasonable security safeguards"

Rule 6 calls for encryption, access control, authentication, event detection, logging, and monitoring. Mine2's platform speaks directly to the event detection and monitoring requirements with a detection layer that:

  • Generates immediate alerts on unauthorized data access (supporting CERT-In's six-hour reporting window)
  • Produces forensically rich logs showing exactly what was accessed, when, and from where (supporting the one-year log retention requirement)
  • Operates with zero false positives (so every alert is actionable, which matters enormously for understaffed Indian SOC teams)
  • Needs no behavioral baselines or tuning (deployable within hours, which matters given the May 2027 deadline)

When the DPBI investigates a breach, the first question is: what safeguards did you have in place? Mines demonstrate a proactive, beyond-minimum detection capability, exactly the kind of reasonable safeguard the Act envisions.

Mines protect what BFSI and healthcare regulators care about most

For BFSI organizations under RBI oversight, the critical assets are customer account data, transaction records, and financial credentials. Mine2 Mines planted alongside them — fake account records in databases, decoy transaction logs, honeytoken API keys for banking APIs — build a detection perimeter around the data the regulator cares about most.

For healthcare organizations, Mines planted as decoy patient records, bogus clinical trial databases, and fake administrative credentials catch unauthorized access to protected health information. When the DPBI asks how you detected a breach involving patient data, "our Mines triggered when the attacker accessed decoy records" is a far stronger answer than "we found out from a dark web monitoring service three months later."

Mines enable faster breach notification

The DPDP Act's notification requirement has teeth precisely because delay compounds harm. Every day an organization stays blind to a breach is a day stolen data is being monetized, shared, or weaponized.

Mines collapse detection time from months to minutes. The moment an attacker touches a Mine, you know:

  • That a breach is occurring (triggering notification obligations)
  • What type of data is at risk (informing the scope of notification)
  • Where the unauthorized access originated (supporting forensic investigation)
  • Which systems are compromised (enabling targeted containment)

That's exactly what the DPBI and CERT-In need in a breach notification, delivered in real time rather than after a months-long forensic slog. Our walkthrough of how Mine2 detected insider data theft at an IT services firm shows what that real-time signal looks like in practice.

Cloud Mines cover India's cloud compliance challenge

As Indian organizations move to AWS, Azure, and GCP, cloud-hosted personal data falls under DPDP jurisdiction no matter where the infrastructure physically sits. Cloud misconfigurations and IAM exploitation accounted for 62% of detections in Indian cloud environments, according to DSCI.

Mine2's Cloud Mines deploy fake resources — decoy S3 buckets, phantom IAM roles, bogus Lambda functions — across cloud environments. When a misconfigured access policy or compromised cloud credential leads to unauthorized resource enumeration, Cloud Mines catch it before real personal data is reached.

A practical playbook: Mines for DPDP compliance

Phase 1: Immediate (now through November 2026)

Deploy Credential Mines across high-value systems. Start with the systems that process the most personal data: CRM databases, HR systems, patient management platforms, banking core systems. Plant fake credentials where attackers and infostealers harvest them: browser stores, config files, environment variables, documentation wikis.

Deploy MineField on network segments hosting personal data. Place decoy services next to database servers, file shares, and application servers handling personal data. Any reconnaissance against these segments triggers immediate detection.

Integrate Mine alerts with your incident response workflow. Make sure every Mine alert kicks off your breach notification checklist, including parallel notifications to CERT-In (six hours) and DPBI preparation.

Phase 2: Implementation (March 2026 to May 2027)

Extend Mines to third-party access paths. Plant Mines on segments reachable by vendors, contractors, and cloud service providers. Third-party breaches are the dominant entry vector for Indian organizations, and Mines on vendor-accessible segments catch compromised access before it reaches production data.

Deploy Cloud Mines across your AWS/Azure/GCP footprint. Focus on IAM enumeration paths, S3/Blob discovery, and cross-account trust boundaries. Cover every cloud-hosted personal data store.

Harden with Fortify. Use Mine2's Fortify to close misconfigurations, restrict unnecessary access, and eliminate privilege escalation paths. Layer Mines on top of hardened infrastructure, so even when an attacker slips past a control, their next step trips a detection.

Build your audit trail. Mine2's alert logs, deployment records, and detection reports give you the documented evidence of reasonable security safeguards the DPBI will request during an investigation.

Phase 3: Continuous compliance (post May 2027)

Rotate and refresh Mines regularly. Update decoy credentials, refresh fake records, and reposition MineField services to keep detection effective against persistent threats.

Run Mine-triggered detection drills. Test your notification workflow end to end: Mine alert → investigation → CERT-In notification → DPBI notification → affected individual notification. Prove the process works before a real breach forces you to use it.

Fold Mine deployment into SDF audit documentation. For Significant Data Fiduciaries, Mine2 deployment demonstrates a proactive, beyond-baseline approach to breach detection, exactly what auditors and the DPBI expect to see.

Where this leaves Indian organizations

The DPDP Act 2025 has changed the game. It's no longer enough to build walls around personal data. You need to know, immediately, when those walls are breached. With penalties up to ₹250 crore and no materiality threshold for notification, the cost of not knowing is now regulatory as well as operational.

India's detection reality — 240-day dwell times, 53 million malware detections, vendor-portal attacks, understaffed SOC teams — makes the DPDP Act's notification requirements practically impossible to meet with traditional security tools alone.

Mines change that. They detect breaches at the moment of unauthorized access, with zero false positives, no behavioral baselines, and deployment timelines measured in hours. For BFSI institutions under RBI oversight, healthcare organizations protecting patient data, e-commerce platforms managing millions of records, and every Data Fiduciary racing toward May 2027, Mines aren't just a security tool. They're a DPDP compliance enabler.

The clock is ticking. The DPBI is operational. The penalties are real. The question isn't whether you'll face a breach. It's whether you'll detect it in time to meet your notification obligations.


Want to close the DPDP detection gap before the deadline? See how Mine2's Mines deliver zero-false-positive breach detection →

M2

Riya

Principal Threat Researcher, Mine2 Labs

Riya tracks active threat campaigns and APT tradecraft at Mine2 Labs, translating real-world attacker behaviour into practical detection ideas.

Share this article

Secure Your Network Today

Ready to implement advanced cyber deception in your organization? See how MINE2 can transform your threat detection capabilities.