Rule 6Security Safeguards & Breach Intimation
Reasonable security safeguards
What the Rule sets out
Fleshes out Section 8(5) with a baseline: appropriate encryption or masking of personal data, access controls with logging, continuous monitoring for unauthorised access, contractual security obligations flowing down to Data Processors, and retention of relevant logs for at least one year for detection and investigation of breaches.
What this means in practice
- A one-year log retention floor means your logging/SIEM retention policy needs to be checked against this explicitly, not just against your general IT policy.
- Processor contracts need security clauses that mirror your own obligations, not generic confidentiality language.
Summarised for practical use from the publicly notified DPDP Rules, 2025. Confirm exact clause text against the official Gazette notification before relying on it for compliance decisions.