Version 1.0 • CURRENT
DPDP Rules 2025 Reasonable Security Safeguards & Breach Intimation
RULE 6

Reasonable security safeguards

Official Statutory Text MeitY Gazette Notified Section 40 Delegated Authority
Plain-Language Compliance Breakdown (Editorial Analysis)

What this means: This outlines the minimum cybersecurity standards companies must follow.

They cannot store data in plain text; they must use encryption, masking, or tokenization. They must also strictly control who inside the company can access the data, keep access logs for 1 year, and maintain safe data backups.

Key Practical Takeaways for Compliance Teams

  • Delegated Specificity: This rule provides concrete operational criteria that must be reflected in technical architectures and compliance records.
  • Audit Readiness: Ensure written SOPs, consent logs, and security controls correspond directly to the statutory wording of Rule 6.
  • Statutory Traceability: In any legal interpretation, the exact Gazette text above takes precedence over internal summaries.
← PREVIOUS RULE Rule 5: Processing of personal data by State and its instrumentalities NEXT RULE → Rule 7: Intimation of personal data breach
Statutory text reproduced under open access public domain principles. This reader is designed for educational and compliance decision support.