CERT-In + DPDP Breach Rules 2026: WhatsApp Business Playbook
When customer data leaks out of a WhatsApp stack, two clocks start at once: CERT-In's 6-hour incident-reporting direction and the DPDP Act's duty to notify the Data Protection Board and every affected user. This playbook for founders and the person who is de-facto CISO puts both regimes side by side — CERT-In 2022 directions (6-hour reporting, 180-day in-India log retention, covered-incident annexure) vs DPDP Section 8(6) breach duties (Board + affected-principal notice, penalty schedule up to ₹250 crore — verify current rules) — explains why WhatsApp-first businesses are exposed (phone numbers, chat history and opt-in records are all personal data; the vectors are leaked API tokens, wandering CSV exports, compromised team logins and BSP-side incidents), translates the reportable-incident annexure into WhatsApp scenarios, lays out a rehearsable 6-hour runbook from detect-and-timestamp through contain (rotate tokens, revoke sessions), scope, CERT-In report, DPDP intimation and customer comms — including an honest utility-template breach notice sent on WhatsApp itself — solves the one-incident-three-documents convergence problem with a master incident-doc template, gives a prevention checklist (token hygiene, 2FA, role-based access, audit logs, data minimisation, retention windows), and lists the breach-SLA questions to put to any BSP before signing. Not legal advice; verify current directions and rules.