What Organisations Need to Know


The Digital Personal Data Protection Act, 2023 (“DPDP Act”) establishes a framework for the protection of digital personal data and imposes specific obligations on organisations that determine the purpose and means of processing personal data (“Data Fiduciaries”).

Reasonable Security Measures under the DPDP Act and Rules 

What Organisations Need to Know

The Digital Personal Data Protection Act, 2023 (“DPDP Act”) establishes a framework for the protection of digital personal data and imposes specific obligations on organisations that determine the purpose and means of processing personal data (“Data Fiduciaries”).

One of the key obligations of a Data Fiduciary is to protect personal data in its possession or under its control by implementing reasonable security safeguards to prevent personal data breaches. This obligation also extends to personal data processed on behalf of the Data Fiduciary by its Data Processors.

The Digital Personal Data Protection Rules, 2025 (“DPDP Rules”) prescribe the minimum security safeguards that organisations should address as part of their data-protection framework.

Significant Financial Exposure for Non-Compliance

DPDP compliance is not merely a matter of good corporate practice. Failure to implement reasonable security safeguards can expose an organisation to significant financial penalties.

Under the DPDP Act, a breach of the obligation of a Data Fiduciary to take reasonable security safeguards to prevent a personal data breach may attract a penalty of up to ₹250 crore. Other contraventions under the DPDP Act may also attract substantial penalties, depending on the nature of the breach.

The potential financial exposure makes it important for organisations to proactively assess their data-security practices and ensure that appropriate technical, organisational and contractual safeguards are implemented and documented.

What Are the Reasonable Security Safeguards?

Organisations should assess their existing information-security framework against the following key requirements.

1. Encryption and Other Data Security Measures

Organisations should implement appropriate technical measures to protect personal data, including encryption, masking, obfuscation, and tokenisation, as appropriate. These measures should be considered for personal data stored in databases, applications, cloud environments, backups, and other systems, particularly where unauthorised access could create risk forindividuals.

2. Access Controls

Access to systems and personal data should be appropriately restricted. Organisations should implement suitable access-control and authentication mechanisms, including role-based access and least-privilege principles, and periodically review whether employees and other authorised users continue to require access.

Access should be promptly revoked when an employee leaves the organisation or no longer requires access.

3. Logging, Monitoring, and Review

Organisations should maintain appropriate logging and monitoring mechanisms to provide visibility into access to personal data.

These mechanisms should enable the organisation to:

  • Detect unauthorised access;
  • Investigate security incidents;
  • Identify the cause of a breach;
  • Undertake remediation; and
  • Prevent recurrence.

Maintaining logs without appropriate monitoring and review may not be sufficient to achieve these objectives.

4. Backups and Business Continuity

Organisations should have reasonable measures to ensure continued processing where the confidentiality, integrity, or availability of personal data is compromised. This should include appropriate data backups, recovery mechanisms, and business-continuity arrangements. Backups should be appropriately secured and periodically tested to ensure that data can be restored when required.

5. Retention of Logs and Personal Data

The DPDP Rules require relevant logs and personal data to be retained for one year, where necessary for detecting unauthorised access, investigating incidents, undertaking remediation, preventing recurrence, and ensuring continued processing following a compromise, unless another applicable law requires otherwise.

Organisations should therefore establish appropriate procedures governing the retention, protection, and deletion of logs and personal data. This should not, however, be interpreted as a blanket requirement to retain all personal data for one year. Retention should be assessed in the context of the purpose of processing and other applicable legal requirements.

6. Security Obligations for Data Processors

Organisations frequently rely on third-party service providers to process personal data, including cloud service providers, HR and payroll platforms, CRM systems, technology providers, and other SaaS platforms.

Contracts with such Data Processors should contain appropriate provisions requiring the implementation of reasonable security safeguards and addressing matters such as confidentiality, access controls, security incidents, breach reporting, data retention, and deletion.

The use of a third-party Data Processor does not eliminate the need for the Data Fiduciary to exercise appropriate oversight over the security of personal data.

7. Technical and Organisational Measures

Data security is not merely an IT function. Organisations should establish appropriate technical and organisational measures to ensure that security safeguards are effectively implemented.

This may include:

  • Information-security and privacy policies;
  • Employee confidentiality obligations;
  • Data-protection and security training;
  • Incident-response procedures;
  • Vendor due diligence;
  • Access-management procedures;
  • Data retention and deletion procedures; and
  • Periodic security assessments and reviews.

What Should Organisations Do?

A practical DPDP compliance and security assessment should examine whether the organisation has:

  • Identified and mapped the personal data it processes;
  • Implemented appropriate encryption and other security safeguards;
  • Established effective access controls;
  • Implemented logging and monitoring mechanisms;
  • Maintained secure and tested backups;
  • Established a personal data breach response mechanism;
  • Incorporated appropriate security obligations into Data Processor contracts;
  • Implemented relevant privacy and information-security policies;
  • Conducted employee awareness and security training; and
  • Periodically reviewed and tested its security safeguards.

Why a DPDP Security Assessment Matters

A privacy policy by itself does not establish effective DPDP compliance. Organisations should be able to demonstrate that appropriate technical, organisational, and contractual safeguards are actually implemented and periodically reviewed.

A security assessment can help identify gaps between an organisation’s existing practices and the requirements of the DPDP framework and provide a structured basis for corrective action.

The appropriate safeguards will depend on the organisation’s nature of business, volume and nature of personal data processed, technology environment, processing activities, and associated risks.

How We Can Assist

Brands & Bonds  assists organisations in establishing and strengthening their DPDP compliance framework, including:

  • DPDP compliance audits;
  • Gap assessments;
  • Privacy policies and documentation;
  • Data processor agreements;
  • Privacy notices;
  • Employee advisory support;
  • Data breach response; and
  • Ongoing compliance support.

To assess your organisation’s readiness under the DPDP framework, consider undertaking a focused DPDP security assessment to identify gaps, prioritise remediation, and strengthen your compliance posture.