Regulators & Obligations

Authorities and reporting timelines that apply to your engagements

Regulators covered

DPB
Data Protection Board of India

DPDP Act enforcement, breach notifications, penalties.

MeitY
Ministry of Electronics & IT

DPDP Rules, notified countries, exemptions.

CERT-In
Indian Computer Emergency Response Team

Cyber incident reporting (6-hour rule).

RBI
Reserve Bank of India

BFSI data localisation, IT directions, payments.

SEBI
Securities and Exchange Board of India

CSCRF, market intermediary cybersecurity.

IRDAI
Insurance Regulatory & Development Authority

Insurer information security guidelines.

TRAI
Telecom Regulatory Authority

Subscriber data, UCC, telecom privacy.

NHA
National Health Authority

ABDM, health data management policy.

Reporting obligations

IDObligationTriggerSLARegulator
OB-01Personal data breach notificationOn detection of breachWithout delay; per RulesDPB
OB-02Cyber incident reportOn detection of incident6 hoursCERT-In
OB-03DSAR fulfilmentVerified principal requestWithin prescribed periodDPB
OB-04Grievance redressalGrievance raisedReasonable periodDPB
OB-05Annual DPIA / audit (SDF)SDF designationAnnualDPB
OB-06Cross-border transfer attestationTransfer to non-notified countryOn transferMeitY / DPB
OB-07BFSI breach reportingMaterial cyber incident2-6 hours per circularRBI