Accountability and accuracy
The Fiduciary is responsible for everything processed by it or for it, whatever a contract says. It must put appropriate technical and organisational measures in place. Where data will be used for a decision about the person, or shared with another Fiduciary, it must be complete, accurate and consistent.
Sources: Act s.8(1)Act s.8(3)Act s.8(4)
Security safeguards (Rule 6)
Section 8(5) requires reasonable security safeguards to prevent a personal data breach, including over Processors. Rule 6 sets the minimum: encryption, obfuscation, masking or virtual tokens; access control; and logs, monitoring and review to detect and investigate unauthorised access. It also requires measures such as backups so processing can continue after a compromise.
Logs and personal data needed to detect, investigate and recover from a compromise must be kept for one year, unless another law requires otherwise. Processor contracts must provide for security safeguards. Failing to take reasonable security safeguards carries the Act's highest penalty: up to Rs 250 crore.
Sources: Act s.8(5)Rules r.6Act Schedule item 1
Breach notice (Rule 7)
A personal data breach is any unauthorised processing, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access, that compromises confidentiality, integrity or availability. On becoming aware of any breach, the Fiduciary must tell each affected person without delay, through her user account or registered contact details.
The message must be concise, clear and plain. It covers what happened and when, the likely consequences for her, mitigation measures, steps she can take to protect herself, and a business contact who can answer her questions.
The Board must be told without delay, with the nature, extent, timing, location and likely impact. Within 72 hours of becoming aware, or longer if the Board allows on a written request, a detailed report follows. It covers facts and causes, mitigation, findings on who caused it, remedial steps and the notices sent to people.
Failing to give the Board or affected people notice of a breach can attract a penalty of up to Rs 200 crore.
Sources: Act s.2(u)Act s.8(6)Rules r.7Act Schedule item 2
Erasure and retention (Rule 8)
Unless a law requires retention, the Fiduciary must erase personal data at the earlier of two points. One is when consent is withdrawn; the other is as soon as it is reasonable to assume the purpose is no longer served. It must make its Processors erase it too. The Act's example: a bank keeps identity records ten years after closure because banking law requires it.
The Third Schedule fixes when the purpose is treated as no longer served for three classes. They are e-commerce entities with at least 2 crore registered users in India, online gaming intermediaries with at least 50 lakh, and social media intermediaries with at least 2 crore. The period is three years without contact or use of rights.
Access to the user account, and to stored virtual tokens that can be used for money, goods or services, are carved out. At least 48 hours before erasure under Rule 8, the person must be told her data will be erased unless she logs in, makes contact or exercises her rights.
Separately, every Fiduciary must keep personal data, traffic data and processing logs for at least one year from the processing, for the Seventh Schedule purposes. After that it must erase them unless another law needs them. The Rules' example: an e-book shop keeps order and delivery logs for a year even if the buyer deletes her account.
Sources: Act s.8(7)Act s.8(8)Rules r.8Rules Third Schedule
A published contact and a grievance channel
Every Fiduciary must prominently publish, on its website or app, the business contact of its DPO if it has one. If not, it publishes the contact of a person who can answer questions about its processing. It must mention this contact in every reply to a rights request. It must also set up an effective grievance redressal mechanism.
Sources: Act s.8(9)Act s.8(10)Rules r.9
Key points
- Rule 6 sets minimum safeguards, including encryption, access control and logs.
- Tell people and the Board without delay; full report within 72 hours.
- Erase when the purpose ends or consent goes, unless law requires keeping.
- Keep processing logs for at least one year.
- Publish a contact person and run a grievance channel.
In practice
A checklist for your organisation.
- Encrypt or mask personal data at rest and control who can reach it.
- Keep access logs for at least one year and review them.
- Rehearse a breach runbook with a 72-hour Board report template.
- Set retention rules per purpose, with a stated legal reason for holds.
- Publish your DPO or contact person on the website and in every reply.
Check what you learned
5 questions. Choose an answer to see why it is right.
0 of 5 answered
Question 1 of 5
Within what time must the detailed breach report reach the Board, unless the Board allows longer?
Show the answer
C. 72 hours
Rule 7(2)(b) requires the detailed report within seventy-two hours of becoming aware of the breach, or a longer period the Board allows in writing.
Rules r.7(2)(b)Rule 7(2)(b) requires the detailed report within seventy-two hours of becoming aware of the breach, or a longer period the Board allows in writing.
Rules r.7(2)(b)Question 2 of 5
When must each affected Data Principal be told about a breach?
Show the answer
A. Without delay
Rule 7(1) requires intimation to each affected Data Principal without delay, on becoming aware of any personal data breach.
Rules r.7(1)Rule 7(1) requires intimation to each affected Data Principal without delay, on becoming aware of any personal data breach.
Rules r.7(1)Question 3 of 5
What is the maximum penalty for failing to take reasonable security safeguards?
Show the answer
D. Rs 250 crore
Item 1 of the Schedule to the Act: breach of the section 8(5) security obligation may attract up to two hundred and fifty crore rupees.
Act Schedule item 1Item 1 of the Schedule to the Act: breach of the section 8(5) security obligation may attract up to two hundred and fifty crore rupees.
Act Schedule item 1Question 4 of 5
Under Rule 8(2), how much warning must a large platform give before erasing an inactive user's data?
Show the answer
C. At least 48 hours
Rule 8(2) requires the Data Principal to be informed at least forty-eight hours before the erasure period ends.
Rules r.8(2)Rule 8(2) requires the Data Principal to be informed at least forty-eight hours before the erasure period ends.
Rules r.8(2)Question 5 of 5
For how long, at minimum, must processing logs be kept under Rule 8(3)?
Show the answer
D. One year
Rule 8(3) requires personal data, traffic data and processing logs to be kept for a minimum period of one year from the date of processing.
Rules r.8(3)Rule 8(3) requires personal data, traffic data and processing logs to be kept for a minimum period of one year from the date of processing.
Rules r.8(3)
Official sources for this lesson
- The Digital Personal Data Protection Act, 2023 (No. 22 of 2023), Gazette of India, Extraordinary, Part II, Section 1, 11 August 2023
- Digital Personal Data Protection Rules, 2025, G.S.R. 846(E), MeitY, 13 November 2025 (with Schedules)
- G.S.R. 843(E), 13 November 2025: dates on which provisions of the DPDP Act come into force
A plain-English summary of the DPDP Act 2023 and DPDP Rules 2025, checked on 28 September 2026. It is not legal advice. Words in this lesson are explained in the DPDP dictionary.