Reasonable Security Safeguards Under Rule 6: The Minimum List
This is the most useful rule in the whole framework, because it is a checklist rather than a standard. It also carries the largest penalty head in the Act.
The seven minimum requirements
Rule 6(1) obliges a Data Fiduciary to protect personal data in its possession or control, including processing carried out on its behalf by a Data Processor, by taking safeguards that include at minimum:
- (a) appropriate data security measures, such as securing personal data through encryption, obfuscation, masking, or virtual tokens mapped to that data;
- (b) appropriate measures to control access to the computer resources used by the Data Fiduciary or its Data Processor;
- (c) visibility on access to personal data through appropriate logs, monitoring and review, to enable detection of unauthorised access, its investigation, and remediation to prevent recurrence;
- (d) reasonable measures for continued processing if confidentiality, integrity or availability is compromised, such as data backups;
- (e) retention of those logs and the personal data for one year, unless another law requires otherwise;
- (f) appropriate provision in the contract with a Data Processor for taking reasonable security safeguards;
- (g) appropriate technical and organisational measures to ensure the safeguards are effectively observed.
The one year retention is the expensive line
Rule 6(1)(e) requires logs and personal data to be retained for one year specifically to support detection, investigation and remediation. It is the item most often left out of budgets, because log storage scales with traffic and has to be provisioned before an incident, not after.
It also interacts awkwardly with erasure. Rule 8 requires personal data to be erased once the specified purpose is no longer served, while Rule 6(1)(e) requires retention for a year to support investigation. Resolving that tension deliberately, and writing down the reasoning, is better than discovering the conflict during an audit.
Encryption is not the only option
Rule 6(1)(a) lists encryption, obfuscation, masking or virtual tokens mapped to the personal data. Tokenisation is an accepted route, which matters for systems where field-level encryption would break functionality.
Your processors are your problem
Rule 6(1) explicitly extends to processing undertaken on your behalf, and 6(1)(f) requires the contractual provision. Appointing a vendor does not move the obligation; it adds a contract you now have to get right.
Rule 6 rewards the organisation that treats it as an engineering backlog rather than a policy document. Every clause maps to something you either have deployed or do not.
Infosek Team
A practical assessment order
- Start with (c) and (e). Logging with a year of retention takes the longest to provision and unblocks breach reporting.
- Then (b). Access control is usually where the widest gap sits, particularly in CRMs, support tools and data warehouses.
- Then (a). Decide encryption or tokenisation per data set rather than globally.
- Then (f). Get the clause into processor contracts early, since renegotiating live agreements is slow.
- (d) and (g) are usually partly in place already through existing continuity and governance work.
Common questions
What are reasonable security safeguards under the DPDP Rules?
Rule 6(1) requires, at minimum: appropriate data security measures such as encryption, obfuscation, masking or virtual tokens; access control on computer resources; logs, monitoring and review giving visibility on access to personal data; measures for continued processing such as backups; retention of logs and personal data for one year; contractual provisions requiring safeguards from Data Processors; and appropriate technical and organisational measures to ensure the safeguards are observed.
How long must logs be retained under the DPDP Rules?
One year. Rule 6(1)(e) requires the Data Fiduciary to retain logs and personal data for a period of one year, to enable detection of unauthorised access, its investigation and remediation, unless another law in force requires otherwise.
Want a gap assessment against Rule 6?
Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.
Book Free 30-Min Assessment