Skip to main content

Endpoint

Authentication

Requires a developer API key in the Authorization header.

What this does and does not do

Under the Digital Personal Data Protection Act, 2023, s.8(6) and the DPDP Rules, 2025, r.7, a Data Fiduciary that becomes aware of a personal data breach informs each affected Data Principal without delay, informs the Data Protection Board without delay, and sends the Board a detailed report within 72 hours of becoming aware (extendable on written request). There is no risk threshold. These obligations apply from 13 May 2027 (Rules r.1). This endpoint keeps the fiduciary’s register and computes the deadlines. Grantex does not notify Data Principals and does not file anything with the Board. It records what the fiduciary tells it it sent, and emits webhook events the fiduciary can act on.

Request Body

Example Request

Response — 201 Created

Events and audit

The breach is recorded on the audit chain as grantex.dpdp.breach_recorded, and two webhook events are emitted: dpdp.breach.recorded (breachId, status, awareAt, affectedCount, boardDetailedReportDueAt) and dpdp.breach.principal_intimation_due (breachId, awareAt, affectedCount, due: "without_delay"). Neither carries principal ids or the breach text. With DPDP_BREACH_DEADLINE_ALERTS_ENABLED=true, a worker emits dpdp.breach.board_report_due before and after the 72-hour deadline (see Self-hosting).

Error Responses

List Breaches, Get Breach, Update Breach, Record Principal Intimation.

Ownership

Grantex is owned by Orchestrum Technologies LLP. Inventor and owner: Sanjeev Kumar. Ownership contact: sanjeev@orchestrum.in or mishra.sanjeev@gmail.com.
Last modified on September 30, 2026