Glossary · Security Safeguards
What Are Security Safeguards Under DPDPA?
Security safeguards under the Digital Personal Data Protection Act, 2023 are a Data Fiduciary duty, not a tool logo. Section 8(5) requires reasonable safeguards to prevent a personal data breach. Rule 6 lists the control classes. Remaining duties phase in on 13 May 2027. The Schedule ceiling for an 8(5) failure is ₹250 crore.
Last reviewed: 17 September 2026
Definition
Section 8(5) of the Digital Personal Data Protection Act, 2023 requires the Data Fiduciary to protect personal data in its possession or under its control by taking reasonable security safeguards to prevent a personal data breach. Rule 6 spells out the classes: encryption, obfuscation, masking or virtual tokens; access control over computer resources; logs, monitoring and review; backups and continuity; retention of logs and personal data for one year unless another law requires otherwise; security terms in processor contracts; and technical and organisational measures that make the rest effective. Processor copies remain personal data. A logo on a vendor slide is not the safeguard.
How this matters in practice
Map each Rule 6 class to a named owner and a log you can export. Rehearse the dual clock: CERT-In within 6 hours where the incident is covered, and Rule 7 to Principals and the Board — detailed Board report within 72 hours. Put the same hours-based SLA in every Section 8(2) contract. Software is not your Section 10(2)(b) auditor and does not cap the ₹250 crore Schedule slab.
Frequently asked questions
Does buying a vault discharge Section 8(5)?
No. You still implement Rule 6 classes, write processor security terms, and keep one-year logs unless another law says otherwise. The Board looks at what failed, not the brand on the invoice. Processor copies stay personal data.
Is the ₹250 crore figure an automatic fine?
No. It is the Schedule ceiling for failure to take reasonable security safeguards under Section 8(5). The Board sets quantum on the facts. A separate head can apply for failure to give the required breach intimation under Section 8(6).
Do only Significant Data Fiduciaries owe Rule 6?
No. Reasonable security safeguards apply to Data Fiduciaries. Rule 13 annual DPIA and independent audit start only after a Section 10 SDF notice. Do not wait for that notice to encrypt, log, or contract processors.
Map Rule 6 to owners this month
Book 30 minutes to line encryption, logs, backups and processor clauses against Section 8(5) before the 13 May 2027 duties bite.
Book a demo
Free Gap Analysis
Disclaimer: Privigo is not a law firm. This page provides operational compliance guidance only. For institution-specific obligations, work with qualified Indian legal counsel.