NewTabletop Drill Mode
Module 03 · Breach Incident Management

Two clocks. Tracked together.

CERT-In's 6-hour intimation and the DPDPA's 72-hour report to the Data Protection Board start the moment an incident is logged. ConsentArc runs both, and drafts the notices for you.

INC-0142 · Unauthorised database access

logged 14 Mar 2026, 09:12 IST · both clocks started

Classifying severity

CERT-In intimation

CERT-In Directions, 2022

06:00:00

Data Protection Board report

DPDP Act S8(6) · Rule 7

72:00:00

Blast radius

Affected systems

payments-dbcrm-prod

Exposed data categories

FinancialContactIdentifiers

People affected

up to ~48,000

Upper bound from linked systems, deliberately not a false precise count

Notification artefacts

  • CERT-In intimation
  • Board intimation · Rule 7
  • Detailed report for the Board
  • Data-principal notice template
  • Board notification PDF

Generated automatically from the incident record, instead of being drafted under pressure.

What's included

Built for the worst afternoon of the year.

When an incident lands, the work is already laid out: who to tell, by when, and with which document.

Dual clock tracking

CERT-In's 6-hour intimation and the DPDPA's 72-hour Board report, side by side.

Rule 7 artefacts

Board intimation, detailed report and a data-principal notice template, generated for you.

Severity classifier

Each incident is classified for severity at the point it's logged.

Breach blast radius

Affected systems and exposed data categories, with a caveated upper bound on people affected.

Board notification PDF

The notification document is produced automatically from the incident record.

Growth+

Tabletop Drill Mode

Rehearse a full breach response without touching live records or scores.

Two clocks

Separate deadlines, never confused.

The 6-hour and 72-hour obligations are different legal duties with different recipients. Both start together and run side by side, so neither is missed while attention is on the other.

  • Both clocks start when the incident is logged
  • Live countdowns for each recipient
06:00
CERT-In 6-hour intimation
parallel
72:00
DPDPA Board 72-hour report
Blast radius

An honest estimate, not a false precise count.

Link the affected systems and the data categories they hold. ConsentArc shows a clearly caveated upper bound on the people affected, which is what you can actually stand behind early on.

  • Linked systems and exposed data categories
  • Upper bound on people affected, clearly caveated

Blast radius · INC-0142

payments
-db
FinancialContactIdentifiers

People affected

up to ~48,000

Upper bound from linked systems, not a precise count

Drill mode

Rehearse before it's real.

Tabletop Drill Mode runs a full simulated breach, with clocks and artefacts, without affecting real compliance scores or records. Your team learns the steps on a quiet day.

  • Available on Growth, Business and Enterprise
  • Nothing in a drill touches live data
Live workspace
live records untouchedcompliance score unchanged
Built on the law

Mapped to the clauses that apply.

Every workflow in this module traces back to a specific obligation, so you can show an auditor why each step exists.

  • DPDP Act S8(6)A personal data breach must be reported to the Data Protection Board and to each affected data principal.
  • DPDP Rules, Rule 7Intimate the Board without delay, then send a detailed report within 72 hours.
  • CERT-In Directions, 2022Report cyber security incidents to CERT-In within 6 hours of noticing them.

Ready to move forward?

Confirm your tier and we'll provision your tenant and walk you through setup.

hello@consentarc.com+91-9532453200Data stored in India