
The Digital Personal Data Protection Act, 2023 (“DPDP Act”) establishes a framework for the protection of digital personal data and imposes specific obligations on organisations that determine the purpose and means of processing personal data (“Data Fiduciaries”).
Reasonable Security Measures under the DPDP Act and Rules
What Organisations Need to Know
The Digital Personal Data Protection Act, 2023 (“DPDP Act”) establishes a framework for the protection of digital personal data and imposes specific obligations on organisations that determine the purpose and means of processing personal data (“Data Fiduciaries”).
One of the key obligations of a Data Fiduciary is to protect personal data in its possession or under its control by implementing reasonable security safeguards to prevent personal data breaches. This obligation also extends to personal data processed on behalf of the Data Fiduciary by its Data Processors.
The Digital Personal Data Protection Rules, 2025 (“DPDP Rules”) prescribe the minimum security safeguards that organisations should address as part of their data-protection framework.
Significant Financial Exposure for Non-Compliance
DPDP compliance is not merely a matter of good corporate practice. Failure to implement reasonable security safeguards can expose an organisation to significant financial penalties.
Under the DPDP Act, a breach of the obligation of a Data Fiduciary to take reasonable security safeguards to prevent a personal data breach may attract a penalty of up to ₹250 crore. Other contraventions under the DPDP Act may also attract substantial penalties, depending on the nature of the breach.
The potential financial exposure makes it important for organisations to proactively assess their data-security practices and ensure that appropriate technical, organisational and contractual safeguards are implemented and documented.
Organisations should assess their existing information-security framework against the following key requirements.
Organisations should implement appropriate technical measures to protect personal data, including encryption, masking, obfuscation, and tokenisation, as appropriate. These measures should be considered for personal data stored in databases, applications, cloud environments, backups, and other systems, particularly where unauthorised access could create risk forindividuals.
Access to systems and personal data should be appropriately restricted. Organisations should implement suitable access-control and authentication mechanisms, including role-based access and least-privilege principles, and periodically review whether employees and other authorised users continue to require access.
Access should be promptly revoked when an employee leaves the organisation or no longer requires access.
Organisations should maintain appropriate logging and monitoring mechanisms to provide visibility into access to personal data.
These mechanisms should enable the organisation to:
Maintaining logs without appropriate monitoring and review may not be sufficient to achieve these objectives.
Organisations should have reasonable measures to ensure continued processing where the confidentiality, integrity, or availability of personal data is compromised. This should include appropriate data backups, recovery mechanisms, and business-continuity arrangements. Backups should be appropriately secured and periodically tested to ensure that data can be restored when required.
The DPDP Rules require relevant logs and personal data to be retained for one year, where necessary for detecting unauthorised access, investigating incidents, undertaking remediation, preventing recurrence, and ensuring continued processing following a compromise, unless another applicable law requires otherwise.
Organisations should therefore establish appropriate procedures governing the retention, protection, and deletion of logs and personal data. This should not, however, be interpreted as a blanket requirement to retain all personal data for one year. Retention should be assessed in the context of the purpose of processing and other applicable legal requirements.
Organisations frequently rely on third-party service providers to process personal data, including cloud service providers, HR and payroll platforms, CRM systems, technology providers, and other SaaS platforms.
Contracts with such Data Processors should contain appropriate provisions requiring the implementation of reasonable security safeguards and addressing matters such as confidentiality, access controls, security incidents, breach reporting, data retention, and deletion.
The use of a third-party Data Processor does not eliminate the need for the Data Fiduciary to exercise appropriate oversight over the security of personal data.
Data security is not merely an IT function. Organisations should establish appropriate technical and organisational measures to ensure that security safeguards are effectively implemented.
This may include:
A practical DPDP compliance and security assessment should examine whether the organisation has:
A privacy policy by itself does not establish effective DPDP compliance. Organisations should be able to demonstrate that appropriate technical, organisational, and contractual safeguards are actually implemented and periodically reviewed.
A security assessment can help identify gaps between an organisation’s existing practices and the requirements of the DPDP framework and provide a structured basis for corrective action.
The appropriate safeguards will depend on the organisation’s nature of business, volume and nature of personal data processed, technology environment, processing activities, and associated risks.
Brands & Bonds assists organisations in establishing and strengthening their DPDP compliance framework, including:
To assess your organisation’s readiness under the DPDP framework, consider undertaking a focused DPDP security assessment to identify gaps, prioritise remediation, and strengthen your compliance posture.