ConsenPro Logo
Breach & Incident Management · DPDP Rules 2025, Rule 7

A Breach Is Not the Risk. Missing the Deadline Is.

ConsenPro Breach & Incident Management gives your organisation automated detection, structured response, and a complete audit trail to meet the DPDP Act's 72-hour notification obligation and prove you did.

72 Hrs
DPB notification deadline
₹200 Cr
Penalty for notification failure
4 Stages
Detect · Assess · Notify · Remediate
100%
Audit trail from detection to closure
ConsenPro: Breach Response CentreLIVE INCIDENT

Time remaining to DPB notification

71HRS
:
59MIN
:
59SEC

DPDP Rules 2025 · Rule 7 · Breach ID: BRE-2025-0041

Breach Detected

SIEM alert · 142k records

09:14:32 today

DPB Notification

Draft in progress · DPO review

Stage 3 of 4

DP Comms

Sent · 1,42,318 principals

Confirmed

2025-06-14 09:14:32 [ALERT] Anomalous DB access: users table, 142k rows

2025-06-14 09:14:33 [INFO] SIEM event forwarded to ConsenPro breach monitor

2025-06-14 09:14:34 [ALERT] Bulk export detected, source IP: 10.24.1.87

72 Hours Sounds Like Enough Time. It Isn't.

A personal data breach does not announce itself cleanly. It surfaces as an anomaly in a SIEM log, an unexpected database access event, or a vendor report. By the time your security team confirms the breach, your legal team understands the DPDP implications, your DPO has scoped the affected Data Principals, and your compliance team has drafted a Rule 7 notification the clock has been running for hours.

Without a structured, automated response workflow, the 72-hour window is not a deadline your team can reliably meet. ConsenPro changes that.

Manual Response
Hour 0Breach detected by security team
Hour 8Email chain: Security, Legal, DPO
Hour 24DPO confirmed, scope still unclear
Hour 48Draft notification in Word, review in progress
Hour 72Deadline missed, notification incomplete

72-hour deadline missed. DPB penalty exposure.

ConsenPro Automated
Hour 0SIEM event triggers detection record automatically
Hour 1DPO notified, scope assessed by the platform
Hour 6Rule 7 notification draft generated
Hour 12DPO reviews and submits to DPB portal
Hour 18Data Principals notified 1.4L confirmed

DPB notified at Hour 12 60 hours ahead of deadline.

Detection That Doesn't Wait for a Human.

The first step in meeting the 72-hour deadline is knowing about the breach as early as possible. ConsenPro integrates with your existing SIEM infrastructure and database scanning tools to surface anomalous access events the moment they occur not hours later when someone reviews a log file.

Monitor Configurations

Define data sources, SIEM providers, anomaly thresholds, and alert routing. Every configuration change is logged.

Breach Detection Events

When a breach fires, ConsenPro creates a structured detection record capturing source, anomaly type, data categories, and the exact timestamp the 72-hour clock begins.

Detection Rows: Field-Level Flagging

Individual data records flagged at field level enabling precise scoping of affected Data Principals, exposed categories, and the harm assessment required by Rule 7.

SIEM and Database Integration

Connects to CloudWatch, QRadar, Splunk, and more via standard API. Database-level detection surfaces bulk exports and unusual query volumes.

Data Sources

Database Scan

PostgreSQL · MySQL · Oracle

SIEM Integration

CloudWatch · QRadar · Splunk

ConsenPro
Breach Monitor

Detection Rules
Threshold Config
Auto-Classification

Triggered Events

EVT-001HIGH

Bulk export, users table, 142k rows

CloudWatch / SIEM · 09:14:32

From Detection to DPB Notification. Structured.

Once a breach is detected, ConsenPro activates a time-tracked response workflow guiding your team through every required step with deadlines, accountability assignments, and evidence capture built in. Nothing falls through the gaps.

72-Hour Response Window
01
02
03
04
01

Detect & Classify

Breach event received from SIEM or database scan. Automatically classified by source, data category, and preliminary severity. DPO notified immediately. 72-hour clock starts.

ConsenPro Platform + DPO
SIEM or DB scan event ingested
Source and severity auto-classified
DPO notified instantly
72-hour timer started
02

Assess & Scope

Structured impact assessment covering Data Principals affected, personal data categories exposed, likely harm, third-party involvement, and cross-border transfer implications.

DPO + Legal Team
Data Principals count scoped
Exposed categories identified
Harm level assessed
Detection Rows pulled for precision
03

Notify DPB & Data Principals

Rule 7-compliant DPB notification drafted with all mandatory fields pre-populated. DPO reviews and submits. Mass notifications dispatched to affected Data Principals.

DPO + ConsenPro Platform
Rule 7 notification auto-drafted
Mandatory fields pre-populated
DPO reviews and submits to DPB
Data Principals notified at scale
04

Remediate & Close

Corrective actions assigned to owners with deadlines. Every action is logged as a signed audit entry. Incident closed only when all actions are verified and evidenced.

Security + CISO + DPO
Actions assigned with deadlines
Every action logged and signed
DPO sign-off required to close
Full timeline archived in ledger

Every Action. Every Actor. Permanently Recorded.

Remediation is not the end of a breach it is the beginning of the evidence record you will need if the Data Protection Board initiates a formal inquiry. ConsenPro captures every corrective action automatically, without any additional effort from your team.

Remediation Audit Entries

Every corrective action (a system patch, access revocation, vendor notification, or configuration change) is logged as a signed audit entry the moment it is recorded.

Evidence-Gated Closure

A breach incident cannot be marked closed until all assigned remediation actions are completed and evidenced. DPO sign-off is required. This prevents premature closure that could expose you to a DPB finding.

Full Incident Timeline and Post-Incident Report

Every event on a single exportable timeline. Auto-generated post-incident report summarising breach nature, response timeline, actions taken, and lessons identified.

Tamper-Proof Audit Ledger

Merkle-tree anchored · Cryptographically verified

Every breach detection event, assessment record, DPB notification, Data Principal communication, and remediation action is anchored in ConsenPro's Merkle ledger. The record cannot be altered after the fact. If the DPB asks what your organisation did you can show them exactly, with cryptographic proof that nothing was edited.

// Merkle root BRE-2025-0041

hash: a3f7c2d1e8b94f6a...

prev: 9b21a0f5c3d8e7b2...

signed: DPO · 2025-06-14T09:14:32Z

status: VERIFIED ✓

Incident Timeline · BRE-2025-0041

Detection to Closure · 61 Hours

DetectionHour 0
ConsenPro Monitor

Breach detected via SIEM alert, bulk export of 142k records

AssessmentHour 1
DPO: Priya Sharma

Impact scope confirmed: 1,42,318 Data Principals, categories: Name, Phone, Email, PAN

NotificationHour 6
ConsenPro Platform

Rule 7 DPB notification draft generated, all mandatory fields populated

DPB SubmissionHour 12
DPO: Priya Sharma

Notification submitted to the Data Protection Board · Ref: DPB/2025/BRN-4419

DP CommsHour 14
ConsenPro Platform

Mass notification dispatched to 1,42,318 Data Principals via SMS and email

Corrective ActionHour 18
Security: Arjun Mehta

Compromised credentials revoked. Source IP 10.24.1.87 blocked at firewall.

VerificationHour 36
CISO: Deepak Rao

All corrective actions verified and evidenced

ClosureHour 61
DPO: Priya Sharma

Incident closed. Post-incident report generated. Audit ledger sealed.

Is Your Organisation Ready for a 72-Hour Response?

Most organisations discover they are not ready during an actual breach when it is too late to prepare. ConsenPro's team will assess your current incident response capability against the DPDP Rules 2025 requirements and identify exactly where your gaps are.

What you receive from the assessment

Incident Response Readiness Assessment

Your current capability mapped against Rule 7 requirements detection, scoping, notification, and remediation.

SIEM Integration Review

Assessment of whether your existing security stack can feed breach events into a DPDP-compliant response workflow.

72-Hour Simulation

A tabletop walkthrough of a breach scenario showing how ConsenPro handles detection to DPB notification in your environment.

Gap Register

Specific gaps in your current response process with prioritised remediation steps.

ConsenPro Breach & Incident Management · A Product of CAMS (Computer Age Management Services)

DPDP Act 2023DPDP Rules 2025, Rule 7ISO 27001:2022SOC 2 Type II