top of page

How to Specify Reasonable Security Safeguards Under Rule 6 of the DPDP Rules 2025

Writer: Kaustav Chowdhury
Kaustav Chowdhury
9 minutes ago
5 min read

Section 8(5) of the Digital Personal Data Protection Act, 2023 requires a data fiduciary to protect personal data by taking reasonable security safeguards to prevent a personal data breach. Rule 6 of the Digital Personal Data Protection Rules, 2025 turns that standard into a list of seven minimum measures, which is what makes it drafting work rather than an engineering aspiration.

Step 1: Note the Duty, the Reach and the Date

The duty in section 8(5) extends to personal data in the fiduciary's possession or under its control, including in respect of any processing undertaken by it or on its behalf by a data processor. Section 8(1) reinforces the point by keeping the fiduciary responsible for complying with the Act in respect of any processing undertaken by it or on its behalf by a data processor.

Both come into force with the eighteen month tranche. Under G.S.R. 843(E) dated November 13, 2025 sections 7 to 17 commence eighteen months after publication, and rule 6 sits in the matching group under G.S.R. 846(E), so the date is in May 2027. What commences a year after publication is only the consent manager machinery in section 6(9), section 27(1)(d) and rule 4.

The penalty makes this the most expensive obligation in the Act. The Schedule sets a penalty of up to Rs 250 crore for failure to take reasonable security safeguards to prevent a personal data breach, which is higher than the figure for failing to notify a breach once it has happened.

Step 2: Secure the Data Itself

Rule 6(1)(a) requires appropriate data security measures, including the securing of personal data through encryption, obfuscation or masking, or the use of virtual tokens. The rule names four techniques, so a control inventory that cannot point to at least one of them for each store is incomplete on the face of it.

Record the choice per data store rather than per system, and record why. Masking a production field and leaving the same field in clear text in an analytics copy is the common failure, and it is visible in a data flow map long before it is visible in an incident.

Step 3: Control Access to the Computer Resource

Rule 6(1)(b) requires appropriate measures for controlling access to the computer resources used by the data fiduciary or the data processor. Rule 6(2) imports the meaning of computer resource from the Information Technology Act, 2000, so the scope is wider than a database and takes in the networks and devices involved.

Write the control as a statement about who may reach which resource and on what basis, not as a list of products. The products change and the statement is what the fiduciary will be asked to stand behind.

Step 4: Build Visibility and Keep the Logs for a Year

Rule 6(1)(c) requires appropriate measures for visibility on the accessing of personal data, through logs, monitoring and review, so that unauthorised access can be detected, investigated and remediated. Rule 6(1)(e) then requires that the logs and the personal data be retained for a period of one year, unless retention for a longer period is required by law.

Read those two together before setting any log rotation. A ninety day retention policy adopted for cost reasons is a breach of the rule, and it also destroys the material needed to answer the Board. Note too that the one year floor cuts against an aggressive erasure schedule, so the retention document and the security document have to be reconciled rather than written by separate teams.

Step 5: Provide for Continuity

Rule 6(1)(d) requires reasonable measures to ensure the continued processing of personal data in the event of its confidentiality, integrity or availability being compromised, including by way of data backups. This is the limb that turns a disaster recovery arrangement into a statutory obligation.

The drafting point is that backups are named as an example rather than as the whole measure, so the document should say what continued processing looks like for each critical purpose, and should be tested. A backup nobody has restored is an assertion.

Step 6: Push the Safeguards Into the Processor Contract

Rule 6(1)(f) requires appropriate provisions in the contract entered into between the data fiduciary and a data processor for taking reasonable security safeguards. Because section 8(1) leaves the fiduciary answerable for the processor's processing, this is where the liability actually sits.

Mirror the seven measures into the contract rather than importing a generic security schedule, add an audit or evidence right, and require the one year log retention expressly, since the processor often holds the logs. A clause that commits the processor to industry standard security does not map onto rule 6 and will not help.

Step 7: Close With the Observance Measure

Rule 6(1)(g) requires appropriate technical and organisational measures to ensure effective observance of the security safeguards. It is a governance limb rather than a technical one, and it is the clause under which a paper policy with no owner fails.

So the document should name who owns each measure, how often it is reviewed, and what evidence the review produces. That record is also what demonstrates reasonableness, which is the standard section 8(5) actually sets.

Common Pitfalls to Avoid

  • Writing a policy that does not track the seven measures: Rule 6(1) lists clauses (a) to (g) as a minimum. A document that cannot be mapped clause by clause invites the finding that a measure is missing.

  • Rotating logs on a cost cycle: Rule 6(1)(e) requires logs and personal data to be retained for one year unless a longer period is required by law.

  • Securing production and forgetting the copies: The duty in section 8(5) covers personal data in the fiduciary's possession or under its control, which includes analytics and archive copies.

  • Reading computer resource narrowly: Rule 6(2) imports the meaning from the Information Technology Act, 2000, so networks and devices are in scope, not only databases.

  • Relying on an industry standard security clause: Rule 6(1)(f) requires provisions for taking reasonable security safeguards. Mirror the measures and the one year log retention into the processor contract.

  • Treating backups as the whole of continuity: Rule 6(1)(d) names backups as an example of measures for continued processing, and an untested restore is not a measure.

  • Leaving the observance limb unowned: Rule 6(1)(g) requires technical and organisational measures for effective observance, which means named owners and a review record.

Key Statutory Provisions

  • Section 8 of the Digital Personal Data Protection Act, 2023: Sub-section (1) keeps the data fiduciary responsible for processing undertaken on its behalf by a data processor, and sub-section (5) requires it to protect personal data in its possession or under its control by taking reasonable security safeguards to prevent a personal data breach.

  • The Schedule to the Act: A penalty of up to Rs 250 crore for breach of the obligation to take reasonable security safeguards under section 8(5).

  • Rule 6 of the Digital Personal Data Protection Rules, 2025: Seven minimum measures, being data security including encryption, obfuscation, masking or virtual tokens; access control over computer resources; visibility through logs, monitoring and review; continuity measures including backups; retention of logs and personal data for one year; security provisions in the processor contract; and technical and organisational measures for effective observance.

Sources and References


Disclaimer: This article is for informational purposes only and does not constitute legal advice. Readers should consult a qualified legal professional for advice specific to their circumstances.

Comments


bottom of page