DPDP Rule 6 security safeguards, explained control by control
By Abhijeet Singh · Primary sources verified by dpdprules.orgPublished · Last reviewed 8 min read
What security safeguards does DPDP Rule 6 require?
The short answer
Once Rule 6 is in force, it requires reasonable security safeguards to prevent a personal data breach, and it names the minimums: data security measures such as encryption, obfuscation, masking or virtual tokens; access control on computer resources; visibility over access through logs, monitoring and review; measures for continued processing such as backups; retention of such logs and personal data for 1 year for detection and investigation, unless compliance with any law for the time being in force requires otherwise; safeguard provisions in processor contracts; and technical and organisational measures for effective observance. The duty covers processing done on your behalf by a Data Processor. Rule 6 is not in force yet: it sits in the group commencing 18 months after publication, computed as 13 May 2027, which is interpretation until officially confirmed.

Most security regulation speaks in generalities. Rule 6 names its minimums, which makes it unusually easy to turn into an engineering checklist.
The scope sentence matters
"A Data Fiduciary shall protect personal data in its possession or under its control, including in respect of any processing undertaken by it or on its behalf by a Data Processor, by taking reasonable security safeguards to prevent personal data breach"
2 scoping choices stand out: the duty covers data under your control even when a processor holds it, and the safeguards listed after this sentence are a floor, introduced with at the minimum.
The 7 named minimums
Rule 6(1)(a), data security measures. Securing personal data through encryption, obfuscation, masking or virtual tokens mapped to the data. Pick the technique per data store; the rule offers alternatives rather than mandating one.
Rule 6(1)(b), access control. Appropriate measures to control access to the computer resources used by you or your processor, wherever applicable.
Rule 6(1)(c), visibility. "Visibility on the accessing of such personal data, through appropriate logs, monitoring and review, for enabling detection of unauthorised access, its investigation and remediation to prevent recurrence." This is the only clause in Rule 6 that requires logs, which matters for reading clause (e).
Rule 6(1)(d), continuity. Reasonable measures, such as backups, for continued processing if confidentiality, integrity or availability is compromised.
Rule 6(1)(e), 1 year of logs and data. For detection, investigation and continuity, retain the logs and the personal data for 1 year, unless compliance with any law in force requires otherwise. This is 1 of 2 separate 1 year minimum floors in the Rules, and the other, Rule 8(3), reaches wider material for different reasons; both floors are set out side by side with the erasure duties. This is also the clause most often summarised wrongly, so it is quoted in full and read word by word below.
Rule 6(1)(f), processor contracts. Appropriate provisions in your contract with any Data Processor for taking reasonable security safeguards, wherever applicable.
Rule 6(1)(g), organisational measures. Technical and organisational measures to ensure the safeguards are actually observed, which is the difference between having controls and running them.
What clause (e) actually says, word by word
"for enabling the detection of unauthorised access, its investigation, remediation to prevent recurrence and continued processing in the event of such a compromise, retain such logs and personal data for a period of one year, unless compliance with any law for the time being in force requires otherwise"
2 small words in that sentence carry most of its weight, and a summary that drops either one states a different rule.
And, not or. The object of retain is the phrase "such logs and personal data", so the clause reaches both the logs and the personal data, not whichever of the 2 is cheaper to keep. A summary that offers logs or data, which is not what the clause says, leaves a reader free to keep the access logs, erase the records those logs point at, and believe clause (e) is satisfied. Which logs and which data is a question the clause answers only by reference: this site reads "such logs" as the logs clause (c) requires and "personal data" as the data sub rule (1) obliges a Data Fiduciary to protect, because those are the only referents either phrase has in the rule, and that reading is ours rather than something the clause states.
Unless, not where required. The retention is stated flat and then given 1 exit: compliance with any law for the time being in force requiring otherwise. It is not a duty that waits for some other requirement to switch it on. Read the other way round, as retain for 1 year where required, the clause would collapse into nothing: it would oblige a Data Fiduciary to do only what some other law already obliges it to do, which is not a safeguard the Rules would need to prescribe. Which way the exit runs is open on the words. "Requires otherwise" is wide enough to accommodate a law requiring a shorter hold as well as a longer one, which is the reading the retention article already records, and it is a real question rather than a pedantic one, because section 8(7) of the Act requires erasure once the specified purpose is no longer being served, and the 2 provisions commence together in the same 18 month group.
What the clause does not fix. It sets no start point. Rule 8(3), the other 1 year floor, dates its year "for a minimum period of one year from the date of such processing"; clause (e) names no date to count from at all, so when the year starts is a judgement about the material rather than something the Rules answer. It also sets no ceiling of its own. The list is introduced with the words "which shall include, at the minimum", so this site reads the year in clause (e) as a floor under log retention rather than a period to be observed exactly. That reading is ours, and the drafting argument against it is worth printing: Rule 8(3) fixes its year expressly as "a minimum period of one year" where clause (e) says only "a period of one year", so somebody could read clause (e) as a fixed hold. What Rule 6 certainly does not do is authorise erasure. A maximum, where there is one, comes from elsewhere: from section 8(7) of the Act and from Rule 8(1) with the Third Schedule, both in the same 18 month group as Rule 6, and the retention article sets those erasure duties against both floors.
The draft asked for the same year in the same words
Rule 6 was consulted on before it was notified, and the comparison is short enough to check. Comparing the draft Rules of 3 January 2025 with the notified Rules of 13 November 2025 clause by clause: (a), (b), (d) and (f) were re worded, and (c), (e) and (g) are identical, word for word.
The re wordings are worth knowing, and 2 of them this site reads as qualifying the duty. Clauses (b) and (f) each gained the words "wherever applicable", which the draft did not carry. On our reading those words qualify the duty, because access control and the contract provision are now expressly conditioned on something; a fair competing reading is that they only address whether a Data Processor is engaged at all, in which case nothing is qualified, and neither reading is settled by anything in the instrument. Clauses (a) and (d) moved from "including" to "such as", which reads as an example rather than an inclusion, and clause (a) also lost the word "its" before encryption and gained a comma so that masking joins the list rather than the alternative. Like (c) and (g), clause (e) went through consultation untouched.
Nor has it been corrected since. The corrigenda of 10 December 2025 reach Gazette pages 24, 29, 32, 34 and 38 of issue No. 760, and Rule 6 is printed on page 26, so every word quoted above is the text as first published.
When this bites
Rule 6 sits in the 18 month commencement group; the computed date is 13 May 2027 and is interpretation until officially confirmed. It is computed from 13 November 2025, and why this site counts from 13 November and not 14 November sets out the records on both sides. Almost everything on the list is cheaper to build into a young system than to retrofit.
What to do
Map each named minimum to a control you can point at, and put the gaps into your company plan. The official text with sources lives at Rule 6. If the engineering side of this is yours to own, the DPDP compliance checklist for CTOs sequences the same controls by team.
Related tool
Compliance Plan
Generate 1 company level action plan and see the work for your role first.
Open
Related tool
Data Breach Response Playbook
Rule 7 is not in force yet, so plan its breach steps now, including the 72 hour submission to the Board, against the exact requirements.
Open