securion.ai
  • Solutions
  • Cyber & Cloud Security
  • Frameworks
  • Resources
  • Contact Us
SolutionsCyber & Cloud SecurityFrameworksResourcesContact Us
securion.ai

Advanced AI agents for cybersecurity automation and threat detection.

Resources

  • Resources
  • Contact Us

Legal

  • Privacy Policy
  • Terms of Service

© 2026 Securion.ai. All rights reserved.

Back to Resources
Compliance & Frameworks 8 min read

DPDP Rule 6 Explained: The Security Safeguards You Actually Need

A deep-dive into the DPDP Act's Rule 6, explaining the mandatory security safeguards like encryption, access control, and logging, and how to prove compliance using ISO 27001 or SOC 2.

DPDP Rule 6 Explained: The Security Safeguards You Actually Need
In This Article
  • Overview
  • From Vague Principle to Concrete Mandate
  • The Core Security Safeguards of DPDP Rule 6
  • The Critical Link: Rule 6 (Safeguards) and Rule 7 (Breach Reporting)
  • From Checklist to Continuous Proof: How to Prove Compliance
  • Common Gaps to Avoid
  • Recap: your Rule 6 checklist
  • Official Reference

Overview

India's Digital Personal Data Protection (DPDP) Act, 2023, introduced the principle of 'reasonable security safeguards'. It's a foundational idea: if you collect and process personal data, you are obligated to protect it. But for a long time, 'reasonable' was a grey area, leaving businesses guessing.

The draft DPDP Rules of 2025 change the game. Specifically, Rule 6 transforms this principle into a concrete, actionable set of minimum requirements. It’s no longer about interpretation; it’s about implementation.

In our previous guides, we covered the fundamentals of the DPDPA and the nuances of consent. Now, we're diving deep into the technical and organisational measures that Rule 6 mandates. This is the ‘how-to’ for every Data Fiduciary.

From Vague Principle to Concrete Mandate

The DPDP Act itself requires Data Fiduciaries to implement “reasonable security safeguards to prevent personal data breach.” This is a standard principle in global data protection laws. However, without a clear definition, proving what is 'reasonable' can be challenging during an audit or after a breach.

Rule 6 of the draft DPDP Rules provides that definition. It outlines a baseline of security measures that are considered the minimum standard. Failing to implement these isn't just poor practice; it's a direct violation of the rules, carrying significant penalties. These rules apply to every Data Fiduciary, regardless of size, from a small startup to a large enterprise.

The Core Security Safeguards of DPDP Rule 6

Rule 6 lists specific technical and organisational measures. Think of this not as a mere checklist, but as the foundation of a robust data protection programme. Let’s break down each component.

1. Encryption and De-identification

This is about making data unusable to unauthorised parties. Rule 6 is specific: * Encryption: All personal data must be encrypted, both 'at rest' (when stored on servers or databases) and 'in transit' (when moving across networks). * De-identification: Techniques like masking, tokenisation, or pseudonymisation should be used where appropriate. For example, you should mask Aadhaar numbers and tokenise PAN card numbers, ensuring the full sensitive information is not stored or displayed unnecessarily.

2. Access Control

Not everyone in your organisation needs access to all personal data. Rule 6 mandates strict access controls based on: * Principle of Least Privilege: Employees should only have access to the minimum data necessary to perform their job function. * Multi-Factor Authentication (MFA): Implement MFA for all users, especially those with access to sensitive data systems. * Role-Based Access Control (RBAC): Define roles and permissions clearly, ensuring access is granted based on job responsibility and revoked promptly when a person changes roles or leaves the company.

3. Logging and Monitoring

If you can't see who is accessing data, you can't protect it. Rule 6 requires systems to log and monitor access to personal data. This means having an audit trail that answers: Who accessed what data? When did they access it? From where? This is critical for detecting suspicious activity and for forensic analysis after an incident.

4. Log Retention

The logs you collect are only useful if you keep them. The draft rules propose a mandatory log retention period of at least one year. This ensures that in the event of an investigation, there is a sufficient historical record to analyse.

5. Data Backup, Recovery, and Business Continuity

You must be able to continue processing personal data securely and restore it in the event of a physical or technical incident. This isn't just about having backups; it's about having tested backups. You must regularly test your restore procedures to ensure they work when you need them most.

6. Breach Detection and Response

This involves having a clear, documented plan to detect, manage, and respond to a data breach. This plan should include procedures for internal reporting, investigation, containment, and notifying the Data Protection Board of India and affected individuals.

7. Contractual Safeguards for Data Processors

As a Data Fiduciary, you are ultimately accountable for what happens to your data, even when it’s handled by a third-party vendor (a Data Processor). Rule 6 requires you to have a legally binding contract—a Data Processing Agreement (DPA)—with every processor. This DPA must obligate the processor to adhere to the same security safeguards you do.

The Critical Link: Rule 6 (Safeguards) and Rule 7 (Breach Reporting)

The DPDP Act, through Rule 7, mandates that data breaches must be reported to the Data Protection Board within 72 hours. This tight deadline is only achievable if the safeguards from Rule 6 are already in place.

Without comprehensive logging (Rule 6.3), you won't have the information to investigate. Without a breach detection and response plan (Rule 6.6), your team won't know what to do. The 72-hour clock starts ticking the moment you become aware of a breach, and robust safeguards are what give you the visibility and process to meet that deadline.

From Checklist to Continuous Proof: How to Prove Compliance

Complying with Rule 6 isn't a one-time project. It requires continuous monitoring and, most importantly, evidence. The best way to manage and prove your compliance is to map Rule 6's requirements onto a recognised international security framework.

Frameworks like ISO 27001, SOC 2, or the NIST Cybersecurity Framework provide a structured way to implement and manage controls. Here's how it works:

  1. Map: Take each requirement from Rule 6 and map it to a specific control in your chosen framework (e.g., DPDP's access control rule maps to ISO 27001's A.9.4 or SOC 2's CC6 series).
  2. Score: Assess your implementation of each control. Are you fully compliant, partially compliant, or not started? This gives you a clear picture of your security posture.
  3. Assign: Assign ownership for each control to a specific person or team.
  4. Evidence: Continuously collect and store evidence that the control is working. For example, screenshots of your cloud firewall rules, reports from your MFA system, or records of your backup tests.

This is precisely the gap we built Securion.ai to close. Our platform automates the process of mapping your cloud infrastructure to these frameworks, giving you a live, control-by-control view of your compliance status and keeping the evidence audit-ready.

And here's the real time-saver: you do the work once. Because these frameworks overlap so heavily, the controls and evidence you enter for one — say, ISO 27001 — are automatically mapped and reused for DPDP Rule 6 and SOC 2. Implement a control such as access management or encryption a single time, and Securion.ai applies it across every framework it satisfies. No re-entering the same control for each standard, no duplicated effort — one implementation, many obligations covered.

For example, enable multi-factor authentication once, and that single control satisfies ISO 27001's secure-authentication requirement (A.8.5), the DPDP Rule 6 access-control safeguard, and SOC 2's logical-access criterion (CC6.1) — all at the same time.

Enable MFA once and it satisfies ISO 27001 (A.8.5), DPDP Rule 6 (access control) and SOC 2 (CC6.1) together

Common Gaps to Avoid

Many organisations stumble on the same few points. Be sure to avoid these common pitfalls:

  • Untested Backups: Having backups is not enough. If you've never tried to restore them, you don't have a recovery plan.
  • No Log Retention Policy: Forgetting to configure log retention is a simple mistake that can lead to a direct violation of the one-year rule.
  • Aadhaar Stored in Clear Text: Storing sensitive data like Aadhaar or PAN without masking or tokenisation is a major risk.
  • Missing Processor DPAs: Using a vendor without a DPA in place makes you liable for their security failures.

By focusing on these core safeguards, you move beyond just complying with the law—you build a resilient and trustworthy organisation.

Recap: your Rule 6 checklist

Turn Rule 6 into action with these six moves:

  1. Encrypt & de-identify — encrypt data at rest and in transit; mask Aadhaar, tokenise PAN.
  2. Lock down access — least-privilege plus multi-factor authentication.
  3. Log it, keep it — monitor who accesses personal data; retain logs for at least one year.
  4. Back up & test restores — a backup you've never restored is not a recovery plan.
  5. Detect & be ready — breach detection plus a response plan, so you can hit the 72-hour clock.
  6. Bind processors & prove it — DPAs with every vendor; map to ISO 27001 / SOC 2, score, and keep live evidence.

Frequently Asked Questions

1. Do these rules apply to my small startup?

Yes. The DPDP Act and its rules apply to all Data Fiduciaries processing personal data within India, regardless of size. The only exemptions are for specific use cases like personal or domestic purposes.

2. Is following ISO 27001 the same as being DPDP compliant?

Not automatically, but it's a huge step. ISO 27001 provides a comprehensive framework that covers most, if not all, of the technical and organisational measures required by Rule 6. By getting certified, you create the structure and evidence needed to demonstrate your compliance to the Data Protection Board.

3. What is the biggest challenge in implementing Rule 6?

The most significant challenge is moving from a project-based mindset to one of continuous compliance. It's not about passing an audit once a year; it's about maintaining and proving your security posture every day. This requires automation for evidence collection and continuous monitoring, which is where many manual approaches fall short.


Building a robust security programme based on Rule 6 is fundamental to earning and keeping customer trust in the digital age. It's not just a legal obligation; it's a business imperative.

Stay informed and ahead of the curve. Subscribe to our newsletter for more practical guides on cybersecurity and compliance.

If you're looking to map, measure, and prove your security posture automatically, let's have a conversation.

New to the DPDP Act? Start with our pillar guide, DPDPA Explained, and the deep-dive on DPDP Consent.

Official Reference

This guide is a practical explainer. For the authoritative text, read the official government documents:

  • The Digital Personal Data Protection Act, 2023 (PDF) — the Act as passed by Parliament.
  • The DPDP Rules, 2025 (PDF) — the operative Rules, including Rule 6 (reasonable security safeguards) and Rule 7 (breach reporting).

Why Securion?

  • AI-driven threat detection across cloud and SaaS
  • Continuous compliance for SOC 2, ISO 27001, and more
  • Hundreds of security agents — no extra headcount
  • Live audit trail your auditors can self-serve
Try Securion Free
Article Info
Author
Saravanakumar Malaichami, Founder, Securion.ai
Published
18 September 2026
Read time
8 min read
Tags
dpdp actdata protectionindiarule 6security safeguardscompliance
securion.ai
  • Solutions
  • Cyber & Cloud Security
  • Frameworks
  • Resources
  • Contact Us
Login
SolutionsCyber & Cloud SecurityFrameworksResourcesContact Us
Login