DPDP Wiki Talk to us

/The Rules · 2025

Rule 6: Reasonable security safeguards

DPDP Rules, 2025, G.S.R. 846(E) dated 13 November 2025. Comes into force on 13 May 2027.

UpcomingOfficial textComes into force on 13 May 2027 (phase 3) · rule 1(4)
Provision
Rule 6 of The Digital Personal Data Protection Rules, 2025
Status
Comes into force on 13 May 2027 (phase 3)
Made under
s. 8 General obligations of Data Fiduciary
Source
Ministry of Electronics and Information Technology · G.S.R. 846(E) · 13 November 2025 · Official PDF

Rule 6. Reasonable security safeguards

Verbatim from the Gazette of India
(1)

A Data Fiduciary shall protect personal data in its possession or under its control, including in respect of any processing undertaken by it or on its behalf by a Data Processor, by taking reasonable security safeguards to prevent personal data breach, which shall include, at the minimum, —

(a)

appropriate data security measures, such as securing of personal data through encryption, obfuscation, masking or the use of virtual tokens mapped to that personal data;

(b)

appropriate measures to control access to the computer resources used by such Data Fiduciary or such a Data Processor, wherever applicable;

(c)

visibility on the accessing of such personal data, through appropriate logs, monitoring and review, for enabling detection of unauthorised access, its investigation and remediation to prevent recurrence;

(d)

reasonable measures for continued processing in the event of confidentiality, integrity or availability of such personal data being compromised as a result of destruction or loss of access to personal data or otherwise, such as by way of data-backups;

(e)

for enabling the detection of unauthorised access, its investigation, remediation to prevent recurrence and continued processing in the event of such a compromise, retain such logs and personal data for a period of one year, unless compliance with any law for the time being in force requires otherwise;

(f)

appropriate provision in the contract entered into between such Data Fiduciary and such a Data Processor, wherever applicable, for taking reasonable security safeguards; and

(g)

appropriate technical and organisational measures to ensure effective observance of security safeguards.

(2)

In this rule, the expression “computer resource” shall have the same meaning as is assigned to it in Information Technology Act, 2000 (21 of 2000).

Interpretation in plain English

Interpretation · not legal advice
Interpretation, not legal advice. This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation.
Data FiduciaryData Processor

A Data Fiduciary (the person or entity deciding how and why data is processed) must protect the personal data it possesses or controls. This obligation applies even when the data is processed on its behalf by a Data Processor (an entity processing data for the Data Fiduciary). To prevent a personal data breach, the Data Fiduciary must put in place reasonable security safeguards.

The rules list minimum security measures that a Data Fiduciary must implement. These include securing data through methods like encryption, masking, obfuscation, or using virtual tokens. The Data Fiduciary must also control access to the computer resources used by itself or its Data Processor. Furthermore, the Data Fiduciary must maintain visibility over who accesses the data by using logs, monitoring, and reviews to detect, investigate, and fix unauthorized access.

To ensure processing can continue if data is lost, destroyed, or compromised, the Data Fiduciary must have measures in place, such as data backups. It must keep access logs and personal data for exactly one year to help detect and fix unauthorized access, unless another law requires a different time period.

Finally, the Data Fiduciary must include specific security requirements in its contracts with any Data Processors. It must also use appropriate technical and organizational measures to make sure these security safeguards are effectively followed.

Key points

  • A Data Fiduciary must implement reasonable security safeguards to protect personal data from breaches, including when a Data Processor handles the data. [(1)]
  • Minimum safeguards include data encryption, masking, and controlling access to computer resources. [(1)(a), (1)(b)]
  • The Data Fiduciary must monitor data access and keep logs and personal data for one year to detect and investigate unauthorized access, unless another law requires otherwise. [(1)(c), (1)(e)]
  • Measures like data backups must be used to ensure processing can continue if data is lost or compromised. [(1)(d)]
  • Contracts between a Data Fiduciary and a Data Processor must include provisions for taking reasonable security safeguards. [(1)(f)]

Common misreadings

  • A Data Fiduciary might think it is not responsible for security if a Data Processor handles the data, but the rule explicitly makes the Data Fiduciary responsible for data processed on its behalf.
  • One might assume access logs can be deleted immediately, but the rule requires retaining these logs and personal data for one year unless another law dictates otherwise.

Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.

/MYND · DPDP practice

Putting this into practice?

MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.

How we use these details: only to respond to you. Withdraw any time by writing to sales@myndsol.com. This form is protected against automated submissions.