Infosek
INFOSEK

Reasonable Security Safeguards Under Rule 6: The Minimum List

This is the most useful rule in the whole framework, because it is a checklist rather than a standard. It also carries the largest penalty head in the Act.

Reasonable Security Safeguards Under Rule 6: The Minimum List

The seven minimum requirements

Rule 6(1) obliges a Data Fiduciary to protect personal data in its possession or control, including processing carried out on its behalf by a Data Processor, by taking safeguards that include at minimum:

The one year retention is the expensive line

Rule 6(1)(e) requires logs and personal data to be retained for one year specifically to support detection, investigation and remediation. It is the item most often left out of budgets, because log storage scales with traffic and has to be provisioned before an incident, not after.

It also interacts awkwardly with erasure. Rule 8 requires personal data to be erased once the specified purpose is no longer served, while Rule 6(1)(e) requires retention for a year to support investigation. Resolving that tension deliberately, and writing down the reasoning, is better than discovering the conflict during an audit.

Encryption is not the only option

Rule 6(1)(a) lists encryption, obfuscation, masking or virtual tokens mapped to the personal data. Tokenisation is an accepted route, which matters for systems where field-level encryption would break functionality.

Your processors are your problem

Rule 6(1) explicitly extends to processing undertaken on your behalf, and 6(1)(f) requires the contractual provision. Appointing a vendor does not move the obligation; it adds a contract you now have to get right.

Rule 6 rewards the organisation that treats it as an engineering backlog rather than a policy document. Every clause maps to something you either have deployed or do not.

Infosek Team

A practical assessment order

Common questions

What are reasonable security safeguards under the DPDP Rules?

Rule 6(1) requires, at minimum: appropriate data security measures such as encryption, obfuscation, masking or virtual tokens; access control on computer resources; logs, monitoring and review giving visibility on access to personal data; measures for continued processing such as backups; retention of logs and personal data for one year; contractual provisions requiring safeguards from Data Processors; and appropriate technical and organisational measures to ensure the safeguards are observed.

How long must logs be retained under the DPDP Rules?

One year. Rule 6(1)(e) requires the Data Fiduciary to retain logs and personal data for a period of one year, to enable detection of unauthorised access, its investigation and remediation, unless another law in force requires otherwise.

Want a gap assessment against Rule 6?

Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.

Book Free 30-Min Assessment