DPDP Rule 6 • 6 mins
Rule 6 Deep Dive: Proving Encryption and Masking for DPDP Compliance
Master Rule 6(1)(a) of the DPDP Rules 2025 to unblock enterprise deals. Learn how to implement and evidence encryption, masking, and tokenisation to pass strict B2B procurement audits and align with Section 8(5) security safeguards.
Last updated:
Rule 6 Encryption And Masking Requirements
For B2B SaaS vendors selling into large Indian enterprises, proving data security is no longer just a technical tick box on a spreadsheet. It is a critical revenue blocker. The Digital Personal Data Protection Act, 2023 requires stringent security measures for any digital personal data processed within India, or outside India if connected to offering goods or services to Data Principals in India. Rule 6(1)(a) of the DPDP Rules, 2025 specifically mandates the implementation of encryption, obfuscation, masking, or virtual tokens mapped to personal data. If your enterprise sales team is currently stalled in procurement with a major bank, healthcare provider, or fintech, it is highly likely because your compliance team cannot demonstrate a regulator-ready evidence pack showing these exact programmatic controls.
Statutory Anchors For Security Safeguards
The primary statutory foundation for these technical requirements lies in Section 8(5) of the Act. This pivotal section states that a Data Fiduciary must protect personal data in its possession or under its control by taking reasonable security safeguards to prevent a personal data breach. Furthermore, under Section 4(1), any processing of personal data must be for a lawful purpose, whether the Data Principal has given her consent under Section 4(1)(a), or for certain legitimate uses under Section 4(1)(b). Regardless of the lawful basis chosen, the security mandate remains absolute. The DPDP Rules, 2025 take this broad legislative mandate and operationalise it. You cannot claim compliance by simply pointing to a secure physical data centre with biometric locks; the law explicitly requires cryptographic or obfuscation techniques applied directly to the digital personal data elements.
Deciphering The Technical Controls: Encryption, Masking, And Tokens
Rule 6(1)(a) specifically identifies four mechanisms: encryption, obfuscation, masking, and virtual tokens. To satisfy enterprise auditors, vendors must understand the technical distinctions between these safeguards. Encryption involves transforming personal data into an unreadable format using cryptographic algorithms, rendering it useless to anyone without the decryption key. Masking and obfuscation involve obscuring specific data elements - for example, a dynamic masking rule that ensures a customer support agent only sees the last four digits of a user's phone number, while the rest is replaced with asterisks. Virtual tokens (tokenisation) replace highly identifiable data with randomly generated non-sensitive placeholders. This allows B2B analytics platforms to process vast datasets for trending and business intelligence without exposing the underlying identities of the Data Principals to internal staff.
Minimum Baselines Versus Reasonable Controls
The literal text of Rule 6(1)(a) establishes a baseline minimum standard. Implementing basic encryption at rest and in transit is merely the floor, not the ceiling. What ultimately qualifies as "reasonable" under Section 8(5) depends entirely on the context, volume, and inherent risk of the data processing activities. While DPDP 2023 evaluates all digital personal data under a uniform regulatory framework without establishing distinct tiers of regulation for higher-risk data, the practical reality of enterprise auditing means higher volumes or complex processing profiles demand significantly tighter controls. When an enterprise auditor reviews your software architecture, they will look past basic database-level encryption to verify if application-level controls - like dynamic masking and tokenisation - are actively restricting internal user access.
Who It Binds In The Supply Chain And Cross-Border Transfers
While Section 8(5) places the ultimate security obligation on the Data Fiduciary, B2B SaaS providers typically act as Data Processors. Under Section 8(2) of the Act, a fiduciary can only engage a processor under a valid contract. Consequently, large enterprises will aggressively pass every Rule 6 obligation down your supply chain through stringent Data Processing Agreements. Furthermore, these technical safeguards apply even if your servers are located offshore. Under Section 16(1), the Central Government may notify restrictions on cross-border data transfers to specific countries. Unless restricted by such a notification, transfers are permitted, but the Section 8(5) and Rule 6 obligations travel with the data. Additionally, Section 16(2) ensures that any higher-protection laws (such as RBI localisation mandates) remain fully enforceable alongside these DPDP requirements.
Common Misconceptions About Rule 6 Compliance
Many B2B compliance heads incorrectly assume that possessing a valid ISO 27001 or SOC 2 Type II certification automatically satisfies Rule 6. This is a dangerous falsehood. ISO provides an excellent governance framework, but Rule 6 requires specific, demonstrable mapping of obfuscation controls to digital personal data assets. Another widespread misconception is that simply encrypting the AWS or Azure storage volume is sufficient. Rule 6 explicitly mentions masking and obfuscation, meaning programmatic, application-level controls are necessary to prevent unauthorised internal access. Finally, many vendors falsely believe that as processors, they carry zero regulatory risk. While the Data Protection Board directly penalises the fiduciary, that same fiduciary will rigorously enforce indemnity clauses against the processor if a vendor security failure causes a statutory breach.
Evidence To Keep For Enterprise Procurement Audits
To successfully survive an enterprise procurement audit and close large contracts, you must maintain a structured, highly detailed evidence pack demonstrating robust Rule 6 compliance. Firstly, maintain a granular Record of Processing Activities (RoPA) that specifically tags which specific data fields are encrypted, masked, or tokenised across your application lifecycle. The compliance lead should act as the control owner for this living document. Secondly, document a comprehensive cryptographic key management policy alongside architecture diagrams showing exactly where obfuscation occurs in the data flow. Your Chief Information Security Officer (CISO) must formally sign off on this artifact. Finally, keep immutable, automated access logs demonstrating that decryption or unmasking operations are strictly restricted to authorised personnel on a least-privilege basis. These logs serve as primary defence evidence during a regulatory inquiry or rigorous client audit.
Cross References, Breach Intimations, And Penalties
Failing to implement the appropriate Rule 6 safeguards directly triggers catastrophic commercial and regulatory risks under interconnected sections of the law. If inadequate encryption or poor masking leads to an unauthorised data leak, Rule 7 requires breach intimation to affected Data Principals without delay, alongside a detailed incident report to the Data Protection Board within 72 hours. Furthermore, the Schedule to the Act outlines severe financial penalty ceilings of up to 250 crore rupees for failing to observe reasonable security safeguards under Section 8(5). The enterprise Data Fiduciary holds the brunt of this extreme financial risk, which is exactly why your Section 8(2) processor contracts will demand ironclad, audited proof of technical compliance before moving to signature.
Next Steps For B2B SaaS Vendors
Under Section 1(2) of the Act, the Central Government holds the power to appoint different commencement dates for different provisions by official notification. Regardless of how these phased dates are ultimately rolled out, enterprise procurement cycles routinely take six to nine months. If you are targeting a theoretical 13 May 2027 hard compliance deadline, relying on manual spreadsheets to track encryption controls is a failing strategy. Consent is the primary basis for processing, except where Section 7 legitimate uses apply, meaning you must cryptographically secure the datasets your clients lawfully collect. To unblock your enterprise deals, standardise your Rule 6 evidence pack immediately. Run a comprehensive security safeguards gap check today using freescan.complydp.com to see exactly what a tier-one enterprise auditor will flag during their technical review.
Sources
Frequently asked questions
Does our ISO 27001 certification cover the Rule 6 security safeguards?
No, ISO 27001 is a general security framework, while Rule 6 of the DPDP Rules 2025 requires specific mapping of encryption, masking, or tokens directly to personal data assets. Enterprise clients will demand a distinct, tailored audit trail showing how you programmatically apply these controls to their specific data sets.
We are a B2B SaaS acting as a processor, do we need to worry about Section 8(5)?
Yes. While Section 8(5) directly obligates the Data Fiduciary, they are legally required to enforce these rules upon you via Section 8(2) processor contracts. If you lack the required encryption and masking evidence, large enterprises will simply refuse to sign the vendor agreement to protect themselves from liability.
What happens if we fail to implement appropriate masking and suffer a data leak?
A security failure resulting in a leak triggers immediate obligations under Rule 7, requiring breach intimation to Data Principals without delay and to the Board within 72 hours. Failing to maintain reasonable security safeguards also carries a regulatory penalty ceiling of up to 250 crore rupees under the Act's Schedule.
How do we prove to our enterprise prospects that our encryption is appropriate?
You must build a regulator-ready evidence pack that includes a highly detailed Record of Processing Activities outlining which specific fields are encrypted, masked, or tokenised. You must also provide documented control owner attestations, architecture diagrams, and access logs proving that unmasking operations are strictly restricted.
When do these security safeguard rules become strictly enforceable?
Section 1 of the Act allows the Central Government to notify enforcement dates. While a hard compliance deadline like 13 May 2027 is often cited by enterprises as an ultimate threshold, B2B procurement cycles take months. Fiduciaries are demanding this compliance evidence immediately in all new vendor contracts.
ComplyDP