Reasonable security safeguards
6. (1) A Data Fiduciary shall protect personal data in its possession or under its control, including in respect of any processing undertaken by it or on its behalf by a Data Processor, by taking reasonable security safeguards to prevent personal data breach, which shall include, at the minimum, ΓÇö
(a) appropriate data security measures, such as securing of personal data through encryption, obfuscation, masking or the use of virtual tokens mapped to that personal data;
(b) appropriate measures to control access to the computer resources used by such Data Fiduciary or such a Data Processor, wherever applicable;
(c) visibility on the accessing of such personal data, through appropriate logs, monitoring and review...
(d) reasonable measures for continued processing in the event of confidentiality, integrity or availability of such personal data being compromised... such as by way of data-backups;
(e) ... retain such logs and personal data for a period of one year, unless compliance with any law for the time being in force requires otherwise;
What this means: This outlines the minimum cybersecurity standards companies must follow.
They cannot store data in plain text; they must use encryption, masking, or tokenization. They must also strictly control who inside the company can access the data, keep access logs for 1 year, and maintain safe data backups.
Key Practical Takeaways for Compliance Teams
-
•
Delegated Specificity: This rule provides concrete operational criteria that must be reflected in technical architectures and compliance records.
-
•
Audit Readiness: Ensure written SOPs, consent logs, and security controls correspond directly to the statutory wording of Rule 6.
-
•
Statutory Traceability: In any legal interpretation, the exact Gazette text above takes precedence over internal summaries.