DPDP Rule 6 security safeguards, explained control by control
By dpdprules.org editorial team · Reviewed by dpdprules.org source verificationPublished · Last reviewed
The short answer
Rule 6 requires reasonable security safeguards to prevent a personal data breach, and it names the minimums: data security measures such as encryption, obfuscation, masking or virtual tokens; access control on computer resources; visibility over access through logs, monitoring and review; measures for continued processing such as backups; retention of logs and personal data for one year for detection and investigation; safeguard provisions in processor contracts; and technical and organisational measures for effective observance. The duty covers processing done on your behalf by a Data Processor.
Most security regulation speaks in generalities. Rule 6 names its minimums, which makes it unusually easy to turn into an engineering checklist.
The scope sentence matters
"A Data Fiduciary shall protect personal data in its possession or under its control, including in respect of any processing undertaken by it or on its behalf by a Data Processor, by taking reasonable security safeguards to prevent personal data breach"
Two scoping choices stand out: the duty covers data under your control even when a processor holds it, and the safeguards listed after this sentence are a floor, introduced with at the minimum.
The seven named minimums
Data security measures. Securing personal data through encryption, obfuscation, masking or virtual tokens mapped to the data. Pick the technique per data store; the rule offers alternatives rather than mandating one.
Access control. Appropriate measures to control access to the computer resources used by you or your processor.
Visibility. Logs, monitoring and review sufficient to detect unauthorised access, investigate it and prevent recurrence.
Continuity. Reasonable measures, such as backups, for continued processing if confidentiality, integrity or availability is compromised.
One year of logs and data. For detection, investigation and continuity, retain logs and personal data for one year, unless another law requires otherwise.
Processor contracts. Appropriate provisions in your contract with any Data Processor for taking reasonable security safeguards.
Organisational measures. Technical and organisational measures to ensure the safeguards are actually observed, which is the difference between having controls and running them.
When this bites
Rule 6 sits in the eighteen month commencement group; the computed date is 13 May 2027 and is interpretation until officially confirmed. Almost everything on the list is cheaper to build into a young system than to retrofit.
What to do
Map each named minimum to a control you can point at, and put the gaps into your company plan. The official text with sources lives at Rule 6.
Related tool
Compliance Plan
Generate one company level action plan and see the work for your role first.
Open
Related tool
Breach Response Assistant
Turn breach obligations into a clear response workflow with the exact Rule 7 steps.
Open
Rule 6, official text →The security team guide →
Sources cited on this page
- [1]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 6, p. 26. Published 13 November 2025. Official source ↗ · Official requirement · Verified 16 August 2026
- [2]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 1, (4), p. 24. Published 13 November 2025. Official source ↗ · Official requirement · Verified 16 August 2026Rule 6 is in the eighteen month commencement group; the computed date 13 May 2027 is interpretation until officially confirmed.