Two clocks. Tracked together.
CERT-In's 6-hour intimation and the DPDPA's 72-hour report to the Data Protection Board start the moment an incident is logged. ConsentArc runs both, and drafts the notices for you.
INC-0142 · Unauthorised database access
logged 14 Mar 2026, 09:12 IST · both clocks started
CERT-In intimation
CERT-In Directions, 2022
06:00:00
Data Protection Board report
DPDP Act S8(6) · Rule 7
72:00:00
Blast radius
Affected systems
Exposed data categories
People affected
up to ~48,000
Upper bound from linked systems, deliberately not a false precise count
Notification artefacts
- CERT-In intimation
- Board intimation · Rule 7
- Detailed report for the Board
- Data-principal notice template
- Board notification PDF
Generated automatically from the incident record, instead of being drafted under pressure.
Built for the worst afternoon of the year.
When an incident lands, the work is already laid out: who to tell, by when, and with which document.
Dual clock tracking
CERT-In's 6-hour intimation and the DPDPA's 72-hour Board report, side by side.
Rule 7 artefacts
Board intimation, detailed report and a data-principal notice template, generated for you.
Severity classifier
Each incident is classified for severity at the point it's logged.
Breach blast radius
Affected systems and exposed data categories, with a caveated upper bound on people affected.
Board notification PDF
The notification document is produced automatically from the incident record.
Tabletop Drill Mode
Rehearse a full breach response without touching live records or scores.
Separate deadlines, never confused.
The 6-hour and 72-hour obligations are different legal duties with different recipients. Both start together and run side by side, so neither is missed while attention is on the other.
- Both clocks start when the incident is logged
- Live countdowns for each recipient
An honest estimate, not a false precise count.
Link the affected systems and the data categories they hold. ConsentArc shows a clearly caveated upper bound on the people affected, which is what you can actually stand behind early on.
- Linked systems and exposed data categories
- Upper bound on people affected, clearly caveated
Blast radius · INC-0142
-db
People affected
up to ~48,000
Upper bound from linked systems, not a precise count
Rehearse before it's real.
Tabletop Drill Mode runs a full simulated breach, with clocks and artefacts, without affecting real compliance scores or records. Your team learns the steps on a quiet day.
- Available on Growth, Business and Enterprise
- Nothing in a drill touches live data
Mapped to the clauses that apply.
Every workflow in this module traces back to a specific obligation, so you can show an auditor why each step exists.
- DPDP Act S8(6)A personal data breach must be reported to the Data Protection Board and to each affected data principal.
- DPDP Rules, Rule 7Intimate the Board without delay, then send a detailed report within 72 hours.
- CERT-In Directions, 2022Report cyber security incidents to CERT-In within 6 hours of noticing them.
Ready to move forward?
Confirm your tier and we'll provision your tenant and walk you through setup.
hello@consentarc.com+91-9532453200Data stored in India