Skip to main content

The 3rd and main DPDP commencement date is computed as 13 May 2027, which is interpretation until officially confirmed.

Sources last verified on 23 September 2026. Methodology

DPDP Rule 6 security safeguards, explained control by control

Security

By · Primary sources verified by dpdprules.orgPublished · Last reviewed 8 min read

What security safeguards does DPDP Rule 6 require?

The short answer

Once Rule 6 is in force, it requires reasonable security safeguards to prevent a personal data breach, and it names the minimums: data security measures such as encryption, obfuscation, masking or virtual tokens; access control on computer resources; visibility over access through logs, monitoring and review; measures for continued processing such as backups; retention of such logs and personal data for 1 year for detection and investigation, unless compliance with any law for the time being in force requires otherwise; safeguard provisions in processor contracts; and technical and organisational measures for effective observance. The duty covers processing done on your behalf by a Data Processor. Rule 6 is not in force yet: it sits in the group commencing 18 months after publication, computed as 13 May 2027, which is interpretation until officially confirmed.

More answered questions →

Diagram: Rule 6(1): 7 named minimums, and what clause (e) actually says. The same diagram appears further down this article, where it is described in full.

Most security regulation speaks in generalities. Rule 6 names its minimums, which makes it unusually easy to turn into an engineering checklist.

The scope sentence matters

DPDP Rules 2025, r. 6 · Reasonable security safeguards · verbatim

"A Data Fiduciary shall protect personal data in its possession or under its control, including in respect of any processing undertaken by it or on its behalf by a Data Processor, by taking reasonable security safeguards to prevent personal data breach"

2 scoping choices stand out: the duty covers data under your control even when a processor holds it, and the safeguards listed after this sentence are a floor, introduced with at the minimum.

The 7 named minimums

Rule 6(1)(a), data security measures. Securing personal data through encryption, obfuscation, masking or virtual tokens mapped to the data. Pick the technique per data store; the rule offers alternatives rather than mandating one.

Rule 6(1)(b), access control. Appropriate measures to control access to the computer resources used by you or your processor, wherever applicable.

Rule 6(1)(c), visibility. "Visibility on the accessing of such personal data, through appropriate logs, monitoring and review, for enabling detection of unauthorised access, its investigation and remediation to prevent recurrence." This is the only clause in Rule 6 that requires logs, which matters for reading clause (e).

Rule 6(1)(d), continuity. Reasonable measures, such as backups, for continued processing if confidentiality, integrity or availability is compromised.

Rule 6(1)(e), 1 year of logs and data. For detection, investigation and continuity, retain the logs and the personal data for 1 year, unless compliance with any law in force requires otherwise. This is 1 of 2 separate 1 year minimum floors in the Rules, and the other, Rule 8(3), reaches wider material for different reasons; both floors are set out side by side with the erasure duties. This is also the clause most often summarised wrongly, so it is quoted in full and read word by word below.

Rule 6(1)(f), processor contracts. Appropriate provisions in your contract with any Data Processor for taking reasonable security safeguards, wherever applicable.

Rule 6(1)(g), organisational measures. Technical and organisational measures to ensure the safeguards are actually observed, which is the difference between having controls and running them.

Diagram headed "Rule 6(1): 7 named minimums, and what clause (e) actually says", with a subtitle recording that the duty covers processing a Data Processor does on your behalf. A band across the top prints clause (e) in full from Gazette issue No. 760 at page 26, and notes underneath it that the list the clause belongs to is introduced by Rule 6(1) with the words "which shall include, at the minimum". The left panel lists the 7 minimums as the Gazette letters them: (a) data security, such as encryption, obfuscation, masking or virtual tokens; (b) access control on the computer resources, wherever applicable; (c) visibility on access, through appropriate logs, monitoring and review; (d) continued processing after a compromise, such as backups; (e) retain such logs and personal data for 1 year, the clause quoted above; (f) safeguard provisions in the processor contract, wherever applicable; and (g) technical and organisational measures, effectively observed. The right panel is headed as what a summary drops and as this site’s reading, and it carries 3 items. And, not or: the object of retain is the phrase such logs and personal data, so the clause reaches both and not whichever is cheaper to keep. Unless, not where required: the year applies of itself and yields only where another law in force requires otherwise, and it never waits to be required. Floor, not ceiling: because the list is a minimum we read the year as a floor, and Rule 6 sets no maximum, so where one binds it is section 8(7) of the Act or Rule 8(1) of the Rules. A band across the foot records that Rule 6 sits in the group commencing 18 months after publication, computed at 13 May 2027 and interpretation until officially confirmed, and that section 8(7) and Rule 8(1) commence with it. The footer records that the draft Rules of 3 January 2025 carried clause (e) on draft Gazette page 30 in the same words, that 4 of the 7 minimums were re worded before notification while (c), (e) and (g) were not, and that the corrigenda of 10 December 2025 correct pages 24, 29, 32, 34 and 38 while Rule 6 is on page 26.

What clause (e) actually says, word by word

DPDP Rules 2025, r. 6, (1)(e) · Reasonable security safeguards · verbatim

"for enabling the detection of unauthorised access, its investigation, remediation to prevent recurrence and continued processing in the event of such a compromise, retain such logs and personal data for a period of one year, unless compliance with any law for the time being in force requires otherwise"

2 small words in that sentence carry most of its weight, and a summary that drops either one states a different rule.

And, not or. The object of retain is the phrase "such logs and personal data", so the clause reaches both the logs and the personal data, not whichever of the 2 is cheaper to keep. A summary that offers logs or data, which is not what the clause says, leaves a reader free to keep the access logs, erase the records those logs point at, and believe clause (e) is satisfied. Which logs and which data is a question the clause answers only by reference: this site reads "such logs" as the logs clause (c) requires and "personal data" as the data sub rule (1) obliges a Data Fiduciary to protect, because those are the only referents either phrase has in the rule, and that reading is ours rather than something the clause states.

Unless, not where required. The retention is stated flat and then given 1 exit: compliance with any law for the time being in force requiring otherwise. It is not a duty that waits for some other requirement to switch it on. Read the other way round, as retain for 1 year where required, the clause would collapse into nothing: it would oblige a Data Fiduciary to do only what some other law already obliges it to do, which is not a safeguard the Rules would need to prescribe. Which way the exit runs is open on the words. "Requires otherwise" is wide enough to accommodate a law requiring a shorter hold as well as a longer one, which is the reading the retention article already records, and it is a real question rather than a pedantic one, because section 8(7) of the Act requires erasure once the specified purpose is no longer being served, and the 2 provisions commence together in the same 18 month group.

What the clause does not fix. It sets no start point. Rule 8(3), the other 1 year floor, dates its year "for a minimum period of one year from the date of such processing"; clause (e) names no date to count from at all, so when the year starts is a judgement about the material rather than something the Rules answer. It also sets no ceiling of its own. The list is introduced with the words "which shall include, at the minimum", so this site reads the year in clause (e) as a floor under log retention rather than a period to be observed exactly. That reading is ours, and the drafting argument against it is worth printing: Rule 8(3) fixes its year expressly as "a minimum period of one year" where clause (e) says only "a period of one year", so somebody could read clause (e) as a fixed hold. What Rule 6 certainly does not do is authorise erasure. A maximum, where there is one, comes from elsewhere: from section 8(7) of the Act and from Rule 8(1) with the Third Schedule, both in the same 18 month group as Rule 6, and the retention article sets those erasure duties against both floors.

The draft asked for the same year in the same words

Rule 6 was consulted on before it was notified, and the comparison is short enough to check. Comparing the draft Rules of 3 January 2025 with the notified Rules of 13 November 2025 clause by clause: (a), (b), (d) and (f) were re worded, and (c), (e) and (g) are identical, word for word.

The re wordings are worth knowing, and 2 of them this site reads as qualifying the duty. Clauses (b) and (f) each gained the words "wherever applicable", which the draft did not carry. On our reading those words qualify the duty, because access control and the contract provision are now expressly conditioned on something; a fair competing reading is that they only address whether a Data Processor is engaged at all, in which case nothing is qualified, and neither reading is settled by anything in the instrument. Clauses (a) and (d) moved from "including" to "such as", which reads as an example rather than an inclusion, and clause (a) also lost the word "its" before encryption and gained a comma so that masking joins the list rather than the alternative. Like (c) and (g), clause (e) went through consultation untouched.

Nor has it been corrected since. The corrigenda of 10 December 2025 reach Gazette pages 24, 29, 32, 34 and 38 of issue No. 760, and Rule 6 is printed on page 26, so every word quoted above is the text as first published.

When this bites

Rule 6 sits in the 18 month commencement group; the computed date is 13 May 2027 and is interpretation until officially confirmed. It is computed from 13 November 2025, and why this site counts from 13 November and not 14 November sets out the records on both sides. Almost everything on the list is cheaper to build into a young system than to retrofit.

What to do

Map each named minimum to a control you can point at, and put the gaps into your company plan. The official text with sources lives at Rule 6. If the engineering side of this is yours to own, the DPDP compliance checklist for CTOs sequences the same controls by team.

Rule 6, official text →The security team guide →

Rule 6Security safeguards

Share this: