Endpoint
Authentication
Requires a developer API key in the Authorization header.
What this does and does not do
Under the Digital Personal Data Protection Act, 2023, s.8(6) and the DPDP
Rules, 2025, r.7, a Data Fiduciary that becomes aware of a personal data
breach informs each affected Data Principal without delay, informs the Data
Protection Board without delay, and sends the Board a detailed report within
72 hours of becoming aware (extendable on written request). There is no risk
threshold. These obligations apply from 13 May 2027 (Rules r.1).
This endpoint keeps the fiduciary’s register and computes the deadlines.
Grantex does not notify Data Principals and does not file anything with
the Board. It records what the fiduciary tells it it sent, and emits
webhook events the fiduciary can act on.
Request Body
Example Request
Response — 201 Created
Events and audit
The breach is recorded on the audit chain as grantex.dpdp.breach_recorded,
and two webhook events are emitted: dpdp.breach.recorded (breachId,
status, awareAt, affectedCount, boardDetailedReportDueAt) and
dpdp.breach.principal_intimation_due (breachId, awareAt,
affectedCount, due: "without_delay"). Neither carries principal ids or
the breach text. With DPDP_BREACH_DEADLINE_ALERTS_ENABLED=true, a worker
emits dpdp.breach.board_report_due before and after the 72-hour deadline
(see Self-hosting).
Error Responses
List Breaches,
Get Breach,
Update Breach,
Record Principal Intimation.
Ownership
Grantex is owned by Orchestrum Technologies LLP. Inventor and owner: Sanjeev Kumar. Ownership contact: sanjeev@orchestrum.in or mishra.sanjeev@gmail.com.Last modified on September 30, 2026