Skip to main content
Compliance · DPDP

DPDP section 8(5) is a duty about the safeguards themselves

Section 8(5) requires a Data Fiduciary to protect personal data in its possession or under its control by taking reasonable security safeguards to prevent personal data breach. Rule 6(1) of the 2025 Rules names seven things those safeguards must include at a minimum. An engagement produces evidence about the state of those safeguards in the systems that hold the personal data — which is what the mapping below sets out, limb by limb.

The distinction

What an engagement evidences here

Section 8(5) is written as an outcome: protect personal data, by taking reasonable security safeguards, to prevent personal data breach. Rule 6(1) then sets the minimum content of those safeguards. What is owed is a state of affairs inside the systems that process personal data — so a Data Fiduciary asked to account for it has to be able to say how it knows the safeguards hold, and that is the question a test answers. An engagement exercises access control on the surfaces that reach personal data, exercises whether the logging and monitoring named in Rule 6(1)(c) would in fact surface an unauthorised access, and leaves a reproducible artefact everywhere it got further than it should have. That is evidence about the safeguards. It is a narrower thing than compliance with the Act, and deliberately so: notice, consent, purpose limitation, retention, erasure, Data Principal rights and grievance redress are the larger part of what DPDP asks of a Data Fiduciary, and they are answered by work of an entirely different kind. This page is about the part that can be measured.

Limb by limb

The seven minimum safeguards in Rule 6(1), and what is put on record against each

Rule 6(1) requires reasonable security safeguards “which shall include, at the minimum” the seven limbs below. Quoted from G.S.R. 846(E), read at source on 14 September 2026; the Rule commences eighteen months after publication of the Gazette notification, around mid-May 2027. The right-hand column is what a B-52 engagement can put on record about each, including where that is thin.

Rule 6(1)What an engagement puts on record
(a) Data security measures Where a tested surface returns personal data in a response or carries it in transit, the engagement records what actually came back. A value arriving in a form the design intended to be tokenised or masked is reported as a finding with the exchange attached to it.
Verbatim: “appropriate data security measures, such as securing of personal data through encryption, obfuscation, masking or the use of virtual tokens mapped to that personal data”.
(b) Access control The limb testing speaks to most directly. Authorisation across roles and tenants, privilege escalation paths, and reach to personal data by a principal that should have none — each carrying the request and the response that established it.
Verbatim: “appropriate measures to control access to the computer resources used by such Data Fiduciary or such a Data Processor, wherever applicable”.
(c) Visibility on access An engagement is a known set of actions at known times against known targets. Setting what your monitoring raised beside that timeline measures this limb rather than describing it, which is the difference between a safeguards file that asserts visibility and one that shows it.
Verbatim: “visibility on the accessing of such personal data, through appropriate logs, monitoring and review”.
(d) Continued processing after loss of access Backup and restore is an operational control rather than a tested surface, and the recoverability question sits outside an engagement. What does fall inside it is exposure of the backup estate an in-scope target reaches — an unauthenticated export route, a store open to a principal that should not hold it.
Rule 6(1)(d), on measures for continued processing in the event of loss of access to personal data or otherwise, such as by way of data-backups.
(e) Retention of logs and personal data A retention period is a configuration and a policy decision. What an engagement supplies is the other half of the limb — the detection, investigation and remediation those retained records exist to support, exercised against real activity with a written account of what was done and when.
Verbatim: “for enabling the detection of unauthorised access, its investigation, remediation to prevent recurrence and continued processing in the event of such a compromise, retain such logs and personal data for a period of one year, unless compliance with any law for the time being in force requires otherwise”.
(f) Processor contract terms Drafting sits with your counsel. Where a processor-operated surface is inside the agreed scope, the engagement tests it on the same terms as your own systems and reports findings against it under the same severity scheme, so the contractual term and the measured state can be read together.
Verbatim: “appropriate provision in the contract entered into between such Data Fiduciary and such a Data Processor, wherever applicable, for taking reasonable security safeguards”.
(g) Technical and organisational measures Effective observance is a claim about whether the measures work. A finding that has moved open, fixed, retested and closed — and that was marked closed only because a retest could not reproduce it — is the form evidence for this limb takes.
Verbatim: “appropriate technical and organisational measures to ensure effective observance of security safeguards”.

(a) Data security measures

What an engagement puts on record
Where a tested surface returns personal data in a response or carries it in transit, the engagement records what actually came back. A value arriving in a form the design intended to be tokenised or masked is reported as a finding with the exchange attached to it.

Verbatim: “appropriate data security measures, such as securing of personal data through encryption, obfuscation, masking or the use of virtual tokens mapped to that personal data”.

(b) Access control

What an engagement puts on record
The limb testing speaks to most directly. Authorisation across roles and tenants, privilege escalation paths, and reach to personal data by a principal that should have none — each carrying the request and the response that established it.

Verbatim: “appropriate measures to control access to the computer resources used by such Data Fiduciary or such a Data Processor, wherever applicable”.

(c) Visibility on access

What an engagement puts on record
An engagement is a known set of actions at known times against known targets. Setting what your monitoring raised beside that timeline measures this limb rather than describing it, which is the difference between a safeguards file that asserts visibility and one that shows it.

Verbatim: “visibility on the accessing of such personal data, through appropriate logs, monitoring and review”.

(d) Continued processing after loss of access

What an engagement puts on record
Backup and restore is an operational control rather than a tested surface, and the recoverability question sits outside an engagement. What does fall inside it is exposure of the backup estate an in-scope target reaches — an unauthenticated export route, a store open to a principal that should not hold it.

Rule 6(1)(d), on measures for continued processing in the event of loss of access to personal data or otherwise, such as by way of data-backups.

(e) Retention of logs and personal data

What an engagement puts on record
A retention period is a configuration and a policy decision. What an engagement supplies is the other half of the limb — the detection, investigation and remediation those retained records exist to support, exercised against real activity with a written account of what was done and when.

Verbatim: “for enabling the detection of unauthorised access, its investigation, remediation to prevent recurrence and continued processing in the event of such a compromise, retain such logs and personal data for a period of one year, unless compliance with any law for the time being in force requires otherwise”.

(f) Processor contract terms

What an engagement puts on record
Drafting sits with your counsel. Where a processor-operated surface is inside the agreed scope, the engagement tests it on the same terms as your own systems and reports findings against it under the same severity scheme, so the contractual term and the measured state can be read together.

Verbatim: “appropriate provision in the contract entered into between such Data Fiduciary and such a Data Processor, wherever applicable, for taking reasonable security safeguards”.

(g) Technical and organisational measures

What an engagement puts on record
Effective observance is a claim about whether the measures work. A finding that has moved open, fixed, retested and closed — and that was marked closed only because a retest could not reproduce it — is the form evidence for this limb takes.

Verbatim: “appropriate technical and organisational measures to ensure effective observance of security safeguards”.

Commencement

Which parts of the Rules are operative, and from when

Rule 1 commences the Rules in three tranches, each measured from the date of publication of the Gazette notification. Read at source on 14 September 2026.

Which parts of the Rules are operative, and from when
StateWhat it meansWhat follows
Rules 1, 2 and 17 to 21 Short title and commencement, definitions, and the appointment, terms and operations of the Data Protection Board of India. Rule 1(2) commences these on the date of publication in the Official Gazette. Operative since November 2025.
Rule 4 — Consent Manager registration Registration and obligations of a Consent Manager. Rule 1(3) commences it one year after the date of publication of the Gazette. Around mid-November 2026.
Rules 3, 5 to 16, 22 and 23 Terminal Notice, consent, the Rule 6 security safeguards, the Rule 7 breach intimations, retention and erasure, Data Principal rights, grievance redress, and the Rule 13 duties of a Significant Data Fiduciary. Rule 1(4) commences these eighteen months after the date of publication of the Gazette. Around mid-May 2027.
Key
  • Commenced on publication
  • Commences one year after publication
  • Commences eighteen months after publication
  • TerminalNo state follows this one

The provisions

What the Act and the Rules say, in their own words

The Act is Act No. 22 of 2023, assented 11 August 2023. The Rules are G.S.R. 846(E), made under section 40. Every fragment in quotation marks below was read in the Gazette text on 14 September 2026; a row that summarises rather than quotes says so.

ProvisionWhat it carries
Act, section 8(5) “A Data Fiduciary shall protect personal data in its possession or under its control, including in respect of any processing undertaken by it or on its behalf by a Data Processor, by taking reasonable security safeguards to prevent personal data breach.”
Quoted in full. The duty is framed as an outcome — protect, in order to prevent — and Rule 6(1) supplies its minimum content. Read 2026-09-14.
Act, section 8(6), with Rule 7 Section 8(6): “In the event of a personal data breach, the Data Fiduciary shall give the Board and each affected Data Principal, intimation of such breach in such form and manner as may be prescribed.” Rule 7 prescribes three intimations. Rule 7(1): to each affected Data Principal, “without delay”, with five enumerated items including likely consequences and the mitigation implemented. Rule 7(2)(a): to the Board, “without delay”, a description including “its nature, extent, timing and location of occurrence and the likely impact”. Rule 7(2)(b): to the Board, “within seventy-two hours of becoming aware of the breach, or within such longer period as the Board may allow on a request made in writing in this behalf”, the updated and detailed information and the broad facts.
The Board is owed two intimations rather than one, and the seventy-two hours attaches to the second and is extensible on written request. Read 2026-09-14.
Act, section 10(1) and 10(2) Summarised. Significant Data Fiduciary status arises where the Central Government notifies a Data Fiduciary or class of Data Fiduciaries as such, on an assessment of factors it determines, including the volume and sensitivity of personal data processed, risk to the rights of Data Principals, and the impact on the sovereignty and integrity of India. A notified entity appoints a Data Protection Officer based in India; appoints “an independent data auditor to carry out data audit, who shall evaluate the compliance of the Significant Data Fiduciary in accordance with the provisions of this Act”; and undertakes periodic Data Protection Impact Assessment and periodic audit.
The person named in section 10(2)(b) is a data auditor evaluating compliance with the Act. Read 2026-09-14.
Rules, Rule 13 “A Significant Data Fiduciary shall, once in every period of twelve months from the date on which it is notified as such or is included in the class of Data Fiduciaries notified as such, undertake a Data Protection Impact Assessment and an audit to ensure effective observance of the provisions of this Act and the rules made thereunder.” Rule 13(2) requires a report of significant observations to the Board. Rule 13(3) adds a due-diligence duty to verify that technical measures including algorithmic software adopted for processing personal data are not likely to pose a risk to the rights of Data Principals.
The twelve months run from the date of notification as a Significant Data Fiduciary, not from a calendar year end. Read 2026-09-14.
Act, THE SCHEDULE [see section 33(1)] Entry 1 attaches to “Breach in observing the obligation of Data Fiduciary to take reasonable security safeguards to prevent personal data breach under sub-section (5) of section 8”, and reads “May extend to two hundred and fifty crore rupees”. Entry 2, failure of intimation under section 8(6), “May extend to two hundred crore rupees”. Entry 4, the additional obligations of a Significant Data Fiduciary under section 10, “May extend to one hundred and fifty crore rupees”.
Read column by column from the Gazette table on 2026-09-14 and corroborated against the PIB backgrounder of 17 November 2025. Penalties under section 33 follow an inquiry by the Board into a breach of a statutory obligation.
Act, section 44(2)(a) “The Information Technology Act, 2000 shall be amended in the following manner, namely:— (a) section 43A shall be omitted”.
Section 44(2) is notified to come into force with effect from 13 May 2027, so section 43A and the Rules made under it stand omitted from that date rather than today — which matters, because section 43A is the provision the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 were made under, and a security programme built against that regime is the common starting point. Read 2026-09-14.

Act, section 8(5)

What it carries
“A Data Fiduciary shall protect personal data in its possession or under its control, including in respect of any processing undertaken by it or on its behalf by a Data Processor, by taking reasonable security safeguards to prevent personal data breach.”

Quoted in full. The duty is framed as an outcome — protect, in order to prevent — and Rule 6(1) supplies its minimum content. Read 2026-09-14.

Act, section 8(6), with Rule 7

What it carries
Section 8(6): “In the event of a personal data breach, the Data Fiduciary shall give the Board and each affected Data Principal, intimation of such breach in such form and manner as may be prescribed.” Rule 7 prescribes three intimations. Rule 7(1): to each affected Data Principal, “without delay”, with five enumerated items including likely consequences and the mitigation implemented. Rule 7(2)(a): to the Board, “without delay”, a description including “its nature, extent, timing and location of occurrence and the likely impact”. Rule 7(2)(b): to the Board, “within seventy-two hours of becoming aware of the breach, or within such longer period as the Board may allow on a request made in writing in this behalf”, the updated and detailed information and the broad facts.

The Board is owed two intimations rather than one, and the seventy-two hours attaches to the second and is extensible on written request. Read 2026-09-14.

Act, section 10(1) and 10(2)

What it carries
Summarised. Significant Data Fiduciary status arises where the Central Government notifies a Data Fiduciary or class of Data Fiduciaries as such, on an assessment of factors it determines, including the volume and sensitivity of personal data processed, risk to the rights of Data Principals, and the impact on the sovereignty and integrity of India. A notified entity appoints a Data Protection Officer based in India; appoints “an independent data auditor to carry out data audit, who shall evaluate the compliance of the Significant Data Fiduciary in accordance with the provisions of this Act”; and undertakes periodic Data Protection Impact Assessment and periodic audit.

The person named in section 10(2)(b) is a data auditor evaluating compliance with the Act. Read 2026-09-14.

Rules, Rule 13

What it carries
“A Significant Data Fiduciary shall, once in every period of twelve months from the date on which it is notified as such or is included in the class of Data Fiduciaries notified as such, undertake a Data Protection Impact Assessment and an audit to ensure effective observance of the provisions of this Act and the rules made thereunder.” Rule 13(2) requires a report of significant observations to the Board. Rule 13(3) adds a due-diligence duty to verify that technical measures including algorithmic software adopted for processing personal data are not likely to pose a risk to the rights of Data Principals.

The twelve months run from the date of notification as a Significant Data Fiduciary, not from a calendar year end. Read 2026-09-14.

Act, THE SCHEDULE [see section 33(1)]

What it carries
Entry 1 attaches to “Breach in observing the obligation of Data Fiduciary to take reasonable security safeguards to prevent personal data breach under sub-section (5) of section 8”, and reads “May extend to two hundred and fifty crore rupees”. Entry 2, failure of intimation under section 8(6), “May extend to two hundred crore rupees”. Entry 4, the additional obligations of a Significant Data Fiduciary under section 10, “May extend to one hundred and fifty crore rupees”.

Read column by column from the Gazette table on 2026-09-14 and corroborated against the PIB backgrounder of 17 November 2025. Penalties under section 33 follow an inquiry by the Board into a breach of a statutory obligation.

Act, section 44(2)(a)

What it carries
“The Information Technology Act, 2000 shall be amended in the following manner, namely:— (a) section 43A shall be omitted”.

Section 44(2) is notified to come into force with effect from 13 May 2027, so section 43A and the Rules made under it stand omitted from that date rather than today — which matters, because section 43A is the provision the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 were made under, and a security programme built against that regime is the common starting point. Read 2026-09-14.

How this page was sourced

What was read, when, and what could not be pinned

Sources behind every clause reference on this page As of 2026-09-14
  • The Digital Personal Data Protection Act, 2023 — Act No. 22 of 2023, assented 11 August 2023, Gazette of India Extraordinary Part II Section 1. Sections 8(5), 8(6), 10(1) and 10(2), 44(2)(a) and the Schedule to section 33(1) were read in the Gazette text.
  • The Digital Personal Data Protection Rules, 2025 — G.S.R. 846(E), Gazette of India Extraordinary Part II Section 3(i), made under section 40. Rules 1, 6, 7 and 13 were read in the notified text.
  • The Press Information Bureau backgrounder of 17 November 2025 was used to corroborate the notification date, the eighteen-month phasing and the penalty heads in the Schedule.
  • Every clause number and every quoted fragment on this page was taken from those texts on 14 September 2026. Where a row summarises instead of quoting, the row says so in its own words.

Deliberately excluded

  • Two publication dates are in circulation and both come from government sources: the notification carries 13 November 2025, and the PIB backgrounder states the Rules were notified on 14 November 2025. Rule 1 runs its clocks from the date of publication of the Gazette, so this page writes “around mid-November 2026” and “around mid-May 2027” and asserts no single day.
  • Separate notifications of November 2025 are reported to have commenced provisions of the Act and constituted the Data Protection Board of India. Their instrument numbers could not be retrieved from a primary source, so none is cited here. Where the Board matters, this page relies on Rule 1(2), which commences Rules 17 to 21 on publication and was read at source.
  • Which provisions bear on your organisation, and whether it has been notified under section 10(1), are determinations for you and your advisers. What is stated here is what the instruments say and what an engagement produces.

Which model

Choose by who ends up reading the report

All three models cover the same eleven classes and produce the same evidence against each finding. The decision is about the destination: whether the report stays inside your organisation, or reaches somebody who will ask who stood behind it.

Beside the Rule 13 audit

Where an engagement sits next to a Significant Data Fiduciary audit

Rule 13(1) puts a Data Protection Impact Assessment and an audit on a twelve-month cycle for an entity the Central Government has notified under section 10(1), running from the date of that notification, with a report of significant observations going to the Board under Rule 13(2). That is a data-protection compliance exercise, and the person carrying it out is the independent data auditor section 10(2)(b) names. A security engagement is a different exhibit in the same file: it is what an assessment or an audit has to draw on when it reaches the safeguards limb, because it is the part of the picture that was measured rather than described. Where your engagement is going to be read alongside that work, take the expert-verified model. An unverified report arriving in an audit file is a document somebody else then has to stand behind, and that somebody is usually the person who commissioned it.

What the report carries

One finding on a surface holding personal data, in three registers

The same finding, written for the three people who will each open the report for a different reason.

01 Reproduce

The engineer who has to fix it

The exchange
The request that went out and the response that came back, with the portion that establishes the defect marked.
The steps
Written so that your own engineer reproduces it without having to ask us a question first.
The classification
A CVSS v4.0 score published with its vector string, so your team can recompute it, together with the CWE.
02 Locate

The privacy owner who has to account for it

What it reached
Which personal data the defect put within reach, and under whose authorisation the run was permitted to go that far.
The limb it bears on
Which of the seven minimum safeguards in Rule 6(1) the finding speaks to — most often access control under (b) or visibility under (c).
Where a gate held
An approval gate that stopped a run is on the record beside the finding, so the account of the engagement includes what it was refused.
03 Close

The auditor or customer reading the file

The lifecycle
Open, fixed, retested, closed — and nothing is marked closed until a retest has failed to reproduce it.
Scope and dates
What was in scope, who authorised it, and the window in which the testing actually ran.
Whose signature
Where the engagement ran under the expert-verified or the human-led model, Security Brigade signs the report — CERT-In empanelled since 2008, ISO 27001 certified.

Against the visibility limb

The measurement an inspection cannot produce

Rule 6(1)(c) asks for visibility on the accessing of personal data through appropriate logs, monitoring and review, and Rule 6(1)(e) ties retention of those records to detection, investigation and remediation. An engagement generates known activity at known times, which is what makes a comparison possible at all.

The input

A timeline of what was actually done

The engagement produces a record of the actions taken against each target and the time each one ran. That is the input side of a detection comparison, and it is generated whether or not anybody asks for it.

The comparison

What your monitoring raised beside it

Set your alerts and logs against that timeline and the visibility limb has been measured rather than described. The comparison is yours to run inside your own estate; the timeline is what makes it runnable.

The gap

Where nothing was raised at all

A run that passes unremarked through a surface holding personal data is itself a finding about the monitoring, and it is reported as one rather than left in a footnote.

The cadence

Coverage between the deep engagements

One scan of one application or target starts at $500, which is what makes a run after each release cheap enough to actually happen. A twelve-month cycle has to look back over something, and a release-by-release record is the something.

The boundary

Where this page holds its scope

A statute this new attracts confident copy. These five lines are the ones this page declines to overstate.

The position
What an engagement evidences Evidence about the state of the safeguards around personal data at the time the engagement ran, mapped to the limbs of Rule 6(1) it bears on. The obligation in section 8(5) is discharged by the safeguards; notice, consent, purpose limitation, retention, erasure, Data Principal rights and grievance redress are answered by work of a different kind, and a report is one exhibit in that file.
Mapping, not issuing Findings are mapped to the clauses named on this page. Certification and attestation come from bodies appointed to issue them, and that is a different engagement from this one.
Significant Data Fiduciary status Section 10(2) and Rule 13 bind an entity the Central Government has notified under section 10(1), and the twelve-month cycle runs from the date of that notification. Whether your organisation is one is settled by that notification.
The dates The Rules commence in three tranches measured from the date of publication of the Gazette notification. Government sources carry both 13 and 14 November 2025 as that date, so the one-year and eighteen-month marks appear here as around mid-November 2026 and around mid-May 2027.
Whose instruments these are Security Brigade has been CERT-In empanelled since 2008 and is ISO 27001 certified. Those are the two instruments this site claims. The B-52 platform holds none of its own, and the empanelment belongs to the firm delivering the engagement rather than to the software.

What an engagement evidences

The position
Evidence about the state of the safeguards around personal data at the time the engagement ran, mapped to the limbs of Rule 6(1) it bears on. The obligation in section 8(5) is discharged by the safeguards; notice, consent, purpose limitation, retention, erasure, Data Principal rights and grievance redress are answered by work of a different kind, and a report is one exhibit in that file.

Mapping, not issuing

The position
Findings are mapped to the clauses named on this page. Certification and attestation come from bodies appointed to issue them, and that is a different engagement from this one.

Significant Data Fiduciary status

The position
Section 10(2) and Rule 13 bind an entity the Central Government has notified under section 10(1), and the twelve-month cycle runs from the date of that notification. Whether your organisation is one is settled by that notification.

The dates

The position
The Rules commence in three tranches measured from the date of publication of the Gazette notification. Government sources carry both 13 and 14 November 2025 as that date, so the one-year and eighteen-month marks appear here as around mid-November 2026 and around mid-May 2027.

Whose instruments these are

The position
Security Brigade has been CERT-In empanelled since 2008 and is ISO 27001 certified. Those are the two instruments this site claims. The B-52 platform holds none of its own, and the empanelment belongs to the firm delivering the engagement rather than to the software.

Adjacent obligations

What sits next to this on the same desk

Intimation under Rule 7 runs to the Data Protection Board and to each affected Data Principal, and the Board is owed two of them rather than one. A report to CERT-In, where another instrument calls for it, is a separate duty to a separate recipient running on a clock of its own. A testing cadence under SEBI CSCRF or under the RBI Directions comes from those instruments and is stated there in paragraph numbers of their own. What carries across all of them is the evidence itself — one finding, one reproducible artefact, one severity vector with its CWE, one closure record — however many files it ends up in, and whichever of them is open on the desk that week.

Scope it against the safeguards you will have to account for

A scoping call settles which systems hold personal data, which of them the engagement can reach, and which delivery model the report has to come out of. Entry is $500 for one scan of one application or target.