DPDPA Rule 6: Reasonable Security Safeguards

DPDPA Rule 6: Reasonable Security Safeguards

Ensure your business meets all requirements of the new DPDP Act. Discover actionable steps for data fiduciaries to protect user privacy and avoid penalties.

Himanshu Jotwani

Written by

Himanshu Jotwani

Date

Read time

5 min

You can outsource your infrastructure. You can outsource your processing. But under Rule 6 of the DPDPA Rules 2025, you cannot outsource your accountability.

When it comes to data protection and privacy, Rule 6 sets the baseline security obligations for any Data Fiduciary. The mandate is direct: you must prevent personal data breaches through reasonable security safeguards, and you must ensure those safeguards operate across your systems and your vendors.

This is a minimum standard. You are expected to implement at least the controls listed in the rule, and then strengthen them based on your processing environment and actual risks.

Scope and Accountability

The rule leaves no room to shift blame to a vendor. If a processor handles your data, your obligations extend to them.

A Data Fiduciary holds a shield protecting personal data, extending it over a Data Processor.
  • Applies to all personal data in a Data Fiduciary’s possession or control.
  • Covers processing carried out by the Data Fiduciary and by any Data Processor acting on its behalf.
  • The Data Fiduciary remains responsible for ensuring safeguards are in place, including through contract.

You cannot sign away your risk.

The Minimum Safeguards You Must Implement

Rule 6 requires, at a minimum, the following measures. A policy that says you do these things is not enough. You have to actually do them.

  • Protect personal data with appropriate data security measures. Examples include encryption, obfuscation, masking, or use of virtual tokens mapped to the underlying personal data.
  • Control access to computer resources used by the Data Fiduciary or the Data Processor. Limit system and data access to authorized users only.
  • Maintain visibility into personal data access. Keep appropriate logs and perform monitoring and review to detect unauthorized access, investigate incidents, and remediate with prevention of recurrence in mind.
  • Ensure continued processing if confidentiality, integrity, or availability is compromised due to destruction, loss of access, or similar events. Maintain data backups and a disaster recovery capability.
  • Retain logs and personal data for at least one year to enable detection of unauthorized access, investigation, remediation to prevent recurrence, and continuity of processing after a compromise. This applies unless another prevailing law requires a different retention period.
  • Include appropriate provisions in contracts with Data Processors that obligate them to take reasonable security safeguards.
  • Implement appropriate technical and organisational measures that ensure these safeguards are effectively observed in practice.

These items form a floor, not a ceiling. If your processing or risk is higher, plan for stronger controls.

What Counts as Computer Resources

The term “computer resource” has the same meaning as under the Information Technology Act, 2000.

In operational terms, expect this to cover your entire digital infrastructure: computers, networks, software, and storage systems involved in processing personal data. Build your controls to span the full environment. An isolated secure application does not compensate for a compromised network.

The One-Year Retention Requirement

One part of Rule 6 deserves special attention. You must retain logs and personal data for at least one year for specific security purposes.

The intent is clear. Without historical records and access to the relevant data, you cannot reliably detect, analyze, or remediate breaches, nor can you maintain continuity after an incident. You are just guessing after the fact.

A magnifying glass examining a digital log file, representing data protection and privacy compliance.

Key points for implementation:

  • Define the logging scope. Cover authentication, authorization, administrative actions, data access events, and system changes across fiduciary and processor environments.
  • Protect logs with integrity controls. Prevent tampering and ensure only authorized personnel can access them.
  • Align personal data retention with the stated security purpose. If your standard business retention is shorter, create a defensible exception that ties directly to Rule 6, or confirm if another law overrides the one-year period.
  • Document the rationale and data inventory. Be specific about which logs and which datasets fall under the one-year requirement.

Translating the Rule Into Operations

Turn the rule into concrete execution across people, process, and technology:

  • Data protection at rest and in transit. Encrypt databases, file stores, and backups. Use strong key management. Mask or tokenize sensitive fields in lower environments, analytics pipelines, and support workflows.
  • Access control. Enforce least privilege and segregation of duties. Use strong authentication for administrators. Align access approvals to role definitions and record them. Review access regularly and revoke promptly.
  • Monitoring and review. Centralize security logs. Define alert thresholds for unauthorized access attempts and anomalous data reads. Review privileged activity and data exfiltration indicators. Escalate and investigate within defined timelines.
  • Continuity and recovery. Keep regular, tested backups. Validate restore points for both data and configuration. Maintain a disaster recovery plan with defined recovery time and recovery point objectives that reflect your processing obligations. A failover plan that has not been tested is a theory, not a capability.
  • Vendor governance. Insert explicit security obligations in processor contracts. Require implementation of Rule 6 safeguards and cooperation with your detection, investigation, and remediation processes. Ensure processors support your logging and retention requirements.
  • Organisational measures. Issue clear security policies. Train staff on handling personal data, access hygiene, and incident reporting. Assign owners for key controls and require periodic evidence of performance.

Boundaries and Interpretation

Under any modern data privacy act, boundaries matter. Rule 6 is no different:

  • Minimum standard. The rule lists baseline controls. You should augment them based on your data volume, sensitivity, processing context, and exposure.
  • Retention caveat. The one-year retention applies unless another law in force requires otherwise. Track conflicts early and document which rule prevails for each dataset.
  • Fiduciary accountability. Contracting out does not dilute your duty. You must ensure processors actually implement safeguards, not just promise them.
  • Purpose limitation. Retention under Rule 6 is tied to detection, investigation, remediation, and continuity after compromise. Do not treat this as a blanket license to stockpile data indefinitely.

A Practical Checklist

  • Inventory personal data and data flows, including all processors and sub-processors. You cannot protect what you cannot see.
  • Classify datasets and map where encryption, masking, or tokenization must be applied.
  • Define and enforce access control models. Implement multi-factor authentication for high-risk access.
  • Establish a logging standard that covers fiduciary and processor systems. Centralize logs and secure them.
  • Set monitoring rules, investigation playbooks, and remediation procedures. Record evidence and outcomes.
  • Implement backups with routine restore testing. Validate your disaster recovery plan against real scenarios.
  • Update processor contracts to incorporate Rule 6 safeguards and support for your security program.
  • Create a retention schedule that satisfies the one-year requirement or documents legal overrides.
  • Train teams and run periodic control reviews. Fix gaps with deadlines and accountability.

Getting this right is about operational discipline. You need controls that work, evidence that proves they work, and contracts that extend your data act protection wherever your data goes.

Closing this gap is where many teams struggle. You are juggling retention exceptions, vendor variations, and evidence collection while stakeholders push for speed. Regodit gives you a structured way to operationalize Rule 6 across policy, controls, vendors, and proof, so you can show compliance without slowing the business.

Compliance is an outcome, not a checklist

If you want a clear path from rule to execution, explore how Regodit can help you implement and evidence these safeguards. Schedule a discussion to review your current posture and identify fast, pragmatic improvements.

Disclaimer: The views and explanations shared in this blog are based on our team's understanding of the relevant compliance frameworks. While every effort has been made to ensure accuracy, readers are encouraged to refer to the original legal provisions and official notifications for authoritative guidance. Please reach out to us at connect@solsphere.ai.

Keep reading

All blogs →