A data breach response plan template runs two Indian clocks: six hours to CERT-In, in force today, and 72 hours to the Data Protection Board from May 2027
GDPR Article 30 requires controllers and processors to keep a written record of processing activities. The under-250-employee exemption rarely applies in practice