Saaksh
P9-E7Essential indicator

Provide the following information relating to data breaches: a. Number of…

Data breaches this year (number, % involving personal data, impact)

Code
P9-E7
Section
Section C, principle-wise performance
Principle
Principle 9, Consumer ResponsibilityBusinesses should engage with and provide value to their consumers in a responsible manner
Type
Essential, mandatory for every filer
Unit
count / percentage / narrative
Usually held by
Customer service / Legal
Source
SEBI BRSR Format, and ICAI Background Material on BRSR, Revised Edition 2024, page 153

What SEBI asks, verbatim

Provide the following information relating to data breaches: a. Number of instances of data breaches b. Percentage of data breaches involving personally identifiable information of customers c. Impact, if any, of the data breaches

Disclose number of data breach instances, percentage involving PII, and impact assessment.

Quoted from the SEBI BRSR Format as amended March 2025, with measurement guidance from the ICAI Background Material on BRSR, Revised Edition 2024, page 153.

In plain English

You must tell how many data breaches happened, what percent of those breaches exposed customers’ personal info, and what effect the breaches had. The numbers come from your internal security or IT incident reports. Use those reports to fill in the counts, percentages, and impact details.

What a complete, assurance-ready answer contains

A complete, assurance‑ready answer lists the total number of data‑breach incidents in the reporting period, the exact percentage of those incidents that involved personally identifiable information of customers, and a concise impact assessment that categorises each breach by severity (e.g., data loss, service disruption, regulatory penalty). Assurers look for granular, incident‑level evidence such as breach logs, incident reports, and risk‑assessment matrices that justify the percentage and impact figures. A common gap is omitting the source or methodology for calculating the PII percentage, leaving the figure unsupported.

Describes the completeness and granularity an assurer expects. No company figures are named.

Where the data comes from

Usually found in complaints and product records. Forward to your Customer service or Legal team.

Much of what BRSR asks for already exists in filings the company makes elsewhere, such as Pollution Control Board consents, PAT returns, hazardous-waste manifests and EPR registrations. The free gap analysis cross-references those filings against all 108 fields and shows which are already covered.

Frequently asked questions

What does BRSR P9-E7 ask for?

You must tell how many data breaches happened, what percent of those breaches exposed customers’ personal info, and what effect the breaches had. The numbers come from your internal security or IT incident reports. Use those reports to fill in the counts, percentages, and impact details.

Is BRSR P9-E7 an Essential or a Leadership indicator?

P9-E7 is an Essential indicator, so it is mandatory for every BRSR filer. It sits under Principle 9, Consumer Responsibility.

Who inside the company holds the data for P9-E7?

Customer service / Legal. Usually found in complaints and product records. Forward to your Customer service or Legal team.

What unit does P9-E7 use?

count / percentage / narrative. Reporting in the wrong unit, or switching the denominator of an intensity ratio between years, is one of the more common reasons a figure has to be restated.

What does a complete answer to P9-E7 look like?

A complete, assurance‑ready answer lists the total number of data‑breach incidents in the reporting period, the exact percentage of those incidents that involved personally identifiable information of customers, and a concise impact assessment that categorises each breach by severity (e.g., data loss, service disruption, regulatory penalty). Assurers look for granular, incident‑level evidence such as breach logs, incident reports, and risk‑assessment matrices that justify the percentage and impact figures. A common gap is omitting the source or methodology for calculating the PII percentage, leaving the figure unsupported.

Other disclosures under Principle 9

See P9-E7 against a real client

Describe a client in six fields and get all 108 BRSR disclosures classified as ready to pull, needs verification, or collect fresh, with the calculators built in. Free, no login, and nothing leaves your browser.