What are the reasonable security safeguards required under the DPDP Rules, 2025?
Answer:
Every Data Fiduciary must protect personal data through measures such as encryption, obfuscation or masking, virtual tokens, access controls, monitoring and logging to detect unauthorised access, retention of logs for at least one year, secure backups for recovery, and appropriate contractual safeguards with Data Processors. These obligations apply regardless of any contract with a processor.
reasonable security safeguards rule 6 encryption logs access control
Related Questions:
- By when do organizations need to technically integrate with Board-registered Consent Managers?
- Is the consent notice required to give contact details?
- What makes consent valid under Section 6 of the DPDP Act?
- Must a Data Fiduciary maintain data accuracy?
- What is the right to correction and erasure?
- How are DPDP penalties determined by the Board?