DPDP Rule 6 • 7 min read
Rule 6(1)(d) Security Deep Dive: Data Backups and Continued Processing
A definitive guide for enterprise compliance leaders on operationalising Rule 6(1)(d) of the DPDP Rules, 2025, focusing on data availability, verifiable backups, and establishing regulatory evidence trails for continued processing.
Last updated:
Rule 6(1)(d) Continued Processing and Enterprise Backups
Enterprise continuity under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 goes far beyond merely stopping unauthorised external access to servers. Under Section 4(1) of the Act, personal data may only be processed for a lawful purpose for which the Data Principal has given her consent or for certain legitimate uses. Section 4(2) clarifies that a 'lawful purpose' means any purpose not expressly forbidden by law. Regardless of the specific lawful basis relied upon, safeguarding personal data to ensure it remains available for its intended purpose is a non-negotiable statutory obligation. Crucially, Rule 6(1)(d) of the DPDP Rules, 2025 specifically mandates 'reasonable measures for continued processing when confidentiality, integrity or availability is compromised (e.g., destruction or loss of access), including data backups.' For a Head of Compliance or Chief Information Security Officer managing records for Data Principals in India, this translates directly into a strict operational mandate for maintaining secure, heavily tested, and verifiable data backups.
Statutory Anchors for Unshakeable Data Availability
The fundamental obligation to ensure data availability under Rule 6(1)(d) stems from the primary accountability framework established in Section 8 of the DPDP Act. Section 8(1) unambiguously states that a Data Fiduciary shall be responsible for complying with the provisions of the Act and the rules made thereunder 'irrespective of any agreement to the contrary or failure of a Data Principal to carry out the duties provided under this Act.' This strict liability applies to any processing undertaken by the Fiduciary itself or on its behalf by a Data Processor. This explicit statutory mandate, enforced practically via the DPDP Rules, 2025, demands the implementation of reasonable measures to ensure continued processing when data is compromised. For an enterprise compliance team, this definitively removes any lingering ambiguity: robust backup infrastructures are no longer merely best-practice IT operations; they fall directly under mandatory data protection compliance.
Defining Minimum Versus Reasonable Backup Measures
The explicit inclusion of data backups within Rule 6(1)(d) of the DPDP Rules, 2025 establishes a minimum baseline floor for compliance. However, the legal standard of 'reasonable measures' dictates how these backups must be architected, managed, tested, and secured against modern threats. For a large-scale enterprise, a reasonable measure strongly implies the utilisation of immutable backups that are physically or logically isolated from the primary network. If data suffers destruction or a sudden loss of access due to ransomware, the Fiduciary must have a resilient mechanism to guarantee continued processing. Furthermore, reasonableness dictates that personal data within these backup repositories can be distinctly managed. If a Data Principal successfully exercises their right to erasure, restoring a month-old backup cannot be allowed to accidentally resurrect data that the Fiduciary was legally obligated to purge.
Scope of Binding Obligations and Processor Oversight
Accountability for data availability and continued processing cannot be outsourced away through vendor agreements. As established under Section 8(1), the Data Fiduciary remains entirely legally responsible for compliance. When engaging external vendors, cloud providers, or third-party IT managed services, Section 8(2) strictly requires that a Data Fiduciary may engage, appoint, use or otherwise involve a Data Processor to process personal data on its behalf for any activity related to the offering of goods or services only under a valid contract. If a Data Processor suffers a catastrophic system failure that results in the destruction of personal data or a sustained loss of access, it is the Data Fiduciary who faces the immediate regulatory exposure for violating Rule 6(1)(d). Compliance leaders must therefore ensure that all Section 8(2) processor contracts explicitly outline guaranteed backup frequencies, strict data restoration timelines, and comprehensive audit rights.
Cross-Border Backup Strategies and Legal Context
Enterprises often utilise global cloud infrastructure, which inevitably leads to questions regarding the offshore storage of data backups. Under Section 16(1) of the DPDP Act, the Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary for processing to such country or territory outside India as may be so notified. Unless and until the Central Government explicitly notifies a restriction against a specific country, transferring personal data offshore for backup purposes is generally permitted. However, compliance leaders must pay close attention to Section 16(2), which clarifies that the DPDP Act does not restrict the applicability of any other law for the time being in force in India that provides for a higher degree of protection for, or restriction on, the transfer of personal data outside India. Sector-specific regulations requiring backups to remain within Indian borders must still be adhered to alongside DPDP Rules compliance.
Addressing Common Enterprise Security Misconceptions
A highly frequent misconception is the belief that existing, generic IT disaster recovery (DR) plans automatically satisfy the requirements of Rule 6(1)(d). While helpful for general business resilience, standard disaster recovery often lacks the specific data-level granularity required by the DPDP Rules, 2025. Another dangerous myth is that relying on the default availability guarantees provided by major hyperscale cloud providers effectively transfers the compliance burden. This is legally false under Section 8(1). Additionally, Section 8(3) indicates that where personal data processed by a Data Fiduciary is likely to be used to make a decision that affects the Data Principal, the Fiduciary shall ensure its completeness, accuracy, and consistency. If an organisation restores an outdated, corrupted backup and subsequently uses that flawed data to make decisions affecting Data Principals, it violates Section 8(3).
Evidence to Keep for Regulator Readiness
Building a comprehensive evidence pack requires documentation mapped to specific internal control owners to prove adherence to Rule 6(1)(d). First, maintain an updated data backup and restoration policy detailing exact backup frequency, testing intervals, and encryption standards. Second, keep a logged audit trail of all Section 8(2) Data Processor contracts that explicitly include binding clauses for data availability guarantees. Third, retain detailed quarterly attestation reports demonstrating the successful completion of documented data restoration drills, proving that the backups actively support continued processing. Fourth, maintain a continuously updated Record of Processing Activities (RoPA) that explicitly includes the geographical location and retention periods of all backup repositories holding personal data.
Intersecting Obligations and Critical Breach Exposure
Failing to maintain accessible, functional backups triggers severe, cascading compliance failures across multiple provisions of the Act and Rules. If the malicious destruction of data occurs, or if access is permanently lost because a backup is corrupted and cannot be restored, it compromises the statutory standard of continued processing under Rule 6(1)(d) of the DPDP Rules, 2025. Such availability compromises can definitively constitute a personal data breach under the Act, immediately triggering mandatory obligations to notify the Data Protection Board of India. Poor vendor oversight under Section 8(2) exponentially compounds this regulatory risk.
Next Steps for Enterprise Compliance Leaders
With the DPDP Rules, 2025 cementing specific security safeguards, large enterprises must urgently transition from theoretical policy drafting to practical, operational evidence gathering. Compliance leaders should immediately audit their primary data repositories against Rule 6(1)(d) requirements, ensuring that routine backup mechanisms for continued processing are actively tested, properly documented, and contractually binding across all third-party Data Processors.
Sources
Frequently asked questions
What does Rule 6(1)(d) of the DPDP Rules, 2025 require regarding data backups?
Rule 6(1)(d) mandates that Data Fiduciaries implement reasonable measures for continued processing when confidentiality, integrity, or availability is compromised. This explicitly includes utilizing data backups to recover from incidents like the destruction or loss of access to personal data.
Can a Data Fiduciary rely entirely on a Data Processor to maintain compliance with backup rules?
No. While Section 8(2) allows a Data Fiduciary to engage a Data Processor under a valid contract, Section 8(1) unequivocally states that the Data Fiduciary remains responsible for complying with the Act and Rules, irrespective of delegating the processing activity.
Are offshore data backups permitted under the DPDP Act?
Yes, generally. Under Section 16(1), the Central Government may notify specific countries where transfers are restricted. Until such restrictions are notified, offshore backups are permitted, provided they do not violate any other Indian laws that impose stricter transfer conditions as per Section 16(2).
ComplyDP