Plain-language legal resources for authorized security work, including rules of engagement, breach-notification templates, and CERT-In documentation.
No penetration testing begins without signed Rules of Engagement (RoE) and NDA. MTA operates strictly under IT Act 2000 with Jaipur jurisdiction.
Defines scope, boundaries, and legal authorization for penetration testing.
Includes:
Templates for personal data breach notifications under DPDP Act 2023.
Includes:
Compliance with CERT-In Directions 2022 for incident reporting.
Includes:
MTA as Processor identifies breach during testing
DetectionMTA notifies Client/Fiduciary without undue delay
24hClient notifies affected Data Principals
ImmediateClient submits detailed report to DPB
72hImportant reminder
DPDP penalties can be significant, so breach roles and timelines should be confirmed in each engagement.
| Requirement | DPDP Act 2023 | CERT-In 2022 | IT Act 2000 |
|---|---|---|---|
| Breach Notification | 24h (Processor→Fiduciary), 72h (Fiduciary→DPB) | 6 hours | N/A |
| Log Retention | Reasonable period | 180 days | As prescribed |
| Data Deletion | Within 30 days post-termination | N/A | N/A |
| Encryption | Technical safeguard recommended | Required for sensitive data | Section 43 |
All cybersecurity legal templates are available upon request. We review each request to ensure appropriate use.
Documents Available
MTA-ROE Template
Word/PDF
MTA-DPDP-BREACH Templates
Word/PDF
MTA-CERT-IN Addendum
Word/PDF