What SEBI asks, verbatim
Provide the following information relating to data breaches: a. Number of instances of data breaches b. Percentage of data breaches involving personally identifiable information of customers c. Impact, if any, of the data breaches
Disclose number of data breach instances, percentage involving PII, and impact assessment.
Quoted from the SEBI BRSR Format as amended March 2025, with measurement guidance from the ICAI Background Material on BRSR, Revised Edition 2024, page 153.
In plain English
You must tell how many data breaches happened, what percent of those breaches exposed customers’ personal info, and what effect the breaches had. The numbers come from your internal security or IT incident reports. Use those reports to fill in the counts, percentages, and impact details.
What a complete, assurance-ready answer contains
A complete, assurance‑ready answer lists the total number of data‑breach incidents in the reporting period, the exact percentage of those incidents that involved personally identifiable information of customers, and a concise impact assessment that categorises each breach by severity (e.g., data loss, service disruption, regulatory penalty). Assurers look for granular, incident‑level evidence such as breach logs, incident reports, and risk‑assessment matrices that justify the percentage and impact figures. A common gap is omitting the source or methodology for calculating the PII percentage, leaving the figure unsupported.
Describes the completeness and granularity an assurer expects. No company figures are named.
Where the data comes from
Usually found in complaints and product records. Forward to your Customer service or Legal team.
Much of what BRSR asks for already exists in filings the company makes elsewhere, such as Pollution Control Board consents, PAT returns, hazardous-waste manifests and EPR registrations. The free gap analysis cross-references those filings against all 108 fields and shows which are already covered.
Frequently asked questions
What does BRSR P9-E7 ask for?
You must tell how many data breaches happened, what percent of those breaches exposed customers’ personal info, and what effect the breaches had. The numbers come from your internal security or IT incident reports. Use those reports to fill in the counts, percentages, and impact details.
Is BRSR P9-E7 an Essential or a Leadership indicator?
P9-E7 is an Essential indicator, so it is mandatory for every BRSR filer. It sits under Principle 9, Consumer Responsibility.
Who inside the company holds the data for P9-E7?
Customer service / Legal. Usually found in complaints and product records. Forward to your Customer service or Legal team.
What unit does P9-E7 use?
count / percentage / narrative. Reporting in the wrong unit, or switching the denominator of an intensity ratio between years, is one of the more common reasons a figure has to be restated.
What does a complete answer to P9-E7 look like?
A complete, assurance‑ready answer lists the total number of data‑breach incidents in the reporting period, the exact percentage of those incidents that involved personally identifiable information of customers, and a concise impact assessment that categorises each breach by severity (e.g., data loss, service disruption, regulatory penalty). Assurers look for granular, incident‑level evidence such as breach logs, incident reports, and risk‑assessment matrices that justify the percentage and impact figures. A common gap is omitting the source or methodology for calculating the PII percentage, leaving the figure unsupported.
Other disclosures under Principle 9
How you receive and respond to consumer complaints and feedback (mechanism)
% of turnover from products carrying info on environmental / social parameters and safe use
Consumer complaints by type (data privacy, advertising, cyber-security, quality, etc.)
Product recalls on safety grounds (number and reasons)
Do you have a cyber-security / data-privacy policy? (Yes/No + web link)
Corrective actions on advertising, cyber-security / privacy, recalls, or regulator penalties
See P9-E7 against a real client
Describe a client in six fields and get all 108 BRSR disclosures classified as ready to pull, needs verification, or collect fresh, with the calculators built in. Free, no login, and nothing leaves your browser.