Skip to main content

The 3rd and main DPDP commencement date is computed as 13 May 2027, which is interpretation until officially confirmed.

Sources last verified on 23 September 2026. Methodology

Role guide

Security teams

Security carries the safeguards and the breach clock. The duties bind the organisation, but the first hours of a breach usually live entirely inside your function.

What does the DPDP framework mean for Security teams?

The first hours of a breach live inside security, which makes detection, containment and the reporting clock your work rather than anyone else's. Reasonable safeguards and log retention come next, then vendor security terms, because an incident at a vendor is still your organisation's incident. Employee facing flows usually arrive from HR.

How to read this page. The obligations belong to your organisation, not to a role or a sector. Everything here is practical emphasis: which official duties this audience usually leads or feeds into, with links to the official text. Finishing one function's work never makes the company compliant by itself.

Work your function usually leads

  • Reasonable security safeguardsRule 6, official text →

    The listed minimums read like a security control catalogue: encryption or masking, access control, logs and monitoring, backups, 1 year log and data retention, contract terms and organisational measures.

  • Breach response executionRule 7, official text →

    Awareness, containment, the without delay intimations and the 72 hour detailed Board submission are driven by security.

Work your function usually feeds into

  • Vendor security termsRule 6, official text →

    The safeguards extend to processing done on your behalf, which makes processor contracts a security review item.

  • Log and data retentionRule 8, official text →

    The 1 year retention of logs and associated data is operated jointly with engineering.

Tools for this role

Guides written for this audience