DPDP Rule 67 minutes

Rule 6 Security: How Data Fiduciaries Own Vendor Risk Under the DPDP Act

A definitive guide for compliance leaders on managing Data Processor security accountability under Rule 6 and Section 8(5) of the DPDP Act, 2023.

Written byVipul Abhishek· Former Advocate, Supreme Court of India · ComplyDP Co-Founder

Last updated:

The Digital Personal Data Protection (DPDP) Act, 2023 fundamentally shifts how large enterprises manage third-party risk and information security. For a Head of Compliance or Chief Information Security Officer (CISO) at a major organization, the ultimate statutory burden of data security rests squarely on the Data Fiduciary. When an enterprise outsources data processing to a cloud storage vendor, managed payroll provider, customer relationship management tool, or analytics platform, the fiduciary remains fully accountable for the security safeguards applied to that data. Compliance teams cannot simply pass the regulatory risk to third parties through aggressive legal contracts or standard indemnification clauses. Under the DPDP Rules, 2025, ensuring that every single Data Processor in the corporate supply chain meets the required minimum security floor is a strict, inescapable regulatory requirement. The legal ecosystem now demands proactive oversight rather than reactive incident response, making vendor security a critical boardroom agenda item.

Statutory Anchors In The Act And Rules

The legal foundation for this strict vendor accountability is built upon Section 8 of the DPDP Act. Section 8(5) establishes the core operational obligation: it requires a Data Fiduciary to protect personal data in its possession or under its control by taking reasonable security safeguards. Crucially, this provision explicitly includes any processing undertaken by a Data Processor on the fiduciary’s behalf. To reinforce this non-delegable duty, Section 8(1) states unambiguously that the Data Fiduciary is responsible for complying with the Act irrespective of any agreement to the contrary or any failure by the Data Principal to carry out their duties. Furthermore, Section 8(2) mandates that a Data Fiduciary may only engage a Data Processor to process personal data on its behalf under a valid contract. To operationalize these statutory mandates, Rule 6 of the DPDP Rules, 2025 translates this broad duty into a mandatory floor of seven specific security measures. These administrative and technical measures must be actively implemented, tested, and continuously monitored across the entire vendor supply chain to avoid severe regulatory consequences.

Processing Foundations and Lawful Purpose

Before evaluating vendor security, enterprises must establish the lawful foundation for the underlying processing. Section 4(1) of the Act dictates that personal data of a Data Principal may only be processed for a lawful purpose - meaning any purpose not expressly forbidden by law. This processing must be based either on valid consent provided by the Data Principal or for certain legitimate uses as outlined in Section 7 of the Act. This foundational requirement extends directly to how data is shared with external vendors. When a Data Fiduciary transfers personal data to a Data Processor, that downstream processing must remain strictly within the bounds of the original consent or the applicable legitimate use. If a vendor processes the data for their own secondary purposes outside this authorized scope, the Data Fiduciary faces immediate compliance violations under Section 8(1), as they are ultimately responsible for the processor’s activities.

Minimum Floor Versus Reasonable Safeguards

The seven measures outlined in Rule 6 dictate the absolute minimum baseline for organizational security. However, what qualifies as a reasonable safeguard under Section 8(5) scales dynamically with the specific context of the processing operations. A Head of Compliance must ensure that both internal enterprise systems and external vendor environments apply technical controls commensurate with the risk to Data Principals in India. Meeting a baseline policy requirement on paper is completely insufficient without demonstrable technical enforcement mechanisms. Regulators and the Data Protection Board will expect to see a comprehensive audit trail proving that security measures dynamically adapt to the volume and nature of the data being processed. If a processor handles massive datasets used to make decisions that affect Data Principals, the fiduciary must demand enhanced encryption, strict access controls, and continuous vulnerability scanning well beyond the standard Rule 6 floor.

Scope Of Accountability And Shared Systems

This security obligation binds the Data Fiduciary entirely, regardless of complex corporate structures or the opacity of modern cloud environments. While a Data Fiduciary may legally engage a Data Processor under a valid contract per Section 8(2), the fiduciary must continuously oversee the processor's security posture. If a primary vendor operates shared software systems, relies on multi-tenant cloud architectures, or sub-contracts data storage to other downstream entities, the primary enterprise control owner must retain absolute visibility. You need comprehensive governance over those downstream data flows to ensure Rule 6 compliance is maintained end-to-end. The DPDP Act does not recognize a chain of processors as a shield for the fiduciary; the primary enterprise remains the sole entity on the hook for protecting the personal data under its control.

Common Misconceptions About Vendor Security

Many decision-makers mistakenly believe that obtaining an ISO 27001 certificate or a SOC 2 Type II report from a vendor automatically satisfies Rule 6. While industry certifications are valuable indicators of a mature security program, the DPDP Rules require specific, mapped alignment between the vendor's technical controls and the actual personal data governed by the Act. Another dangerous myth is that a strong indemnification clause or limitation of liability in a vendor master service agreement shields the enterprise from regulatory action. Section 8(1) explicitly nullifies this defense. The Data Protection Board will hold the fiduciary fully accountable for the processor's security failure, regardless of who ultimately writes the check for commercial damages in a civil dispute.

Building A Regulator Ready Evidence Pack

To survive regulatory scrutiny, organizations must proactively build a verifiable evidence pack. First, maintain a dynamic Record of Processing Activities (RoPA) that maps exactly which personal data flows to which processor, owned and governed by the privacy office. This mapping must verify that consent is the primary basis for processing, except where Section 7 legitimate uses apply, and track exactly where that data resides geographically. Second, execute valid processor contracts under Section 8(2) that legally bind vendors to implement the specific seven measures of Rule 6. This step is managed by legal counsel but must be strictly verifiable by the compliance team during an audit. Third, collect regular technical attestations, security questionnaires, and Data Protection Impact Assessment (DPIA) outputs from critical vendors. These artefacts prove to the regulator that vendor security controls remain effective, are actively monitored by the internal control owner, and adequately protect Data Principals.

Navigating Breaches And Penalty Exposure

If a processor suffers a security incident, the resulting regulatory obligations fall heavily on the fiduciary. Under Rule 7, the fiduciary must submit a breach intimation to affected Data Principals without delay and file a detailed report to the Data Protection Board within 72 hours. Failure to maintain Rule 6 safeguards triggers severe penalty exposure under the Schedule of the Act. During an inquiry, Section 33 empowers the Board to impose significant monetary penalties. When determining the fine amount, the Board will consider several critical factors under Section 33(2): the nature, gravity, and duration of the breach; the type and nature of the personal data affected; the repetitive nature of the breach; whether the fiduciary realized a gain or avoided a loss; and the timeliness and effectiveness of the mitigation efforts taken. A documented failure to monitor a vendor's Rule 6 compliance will severely compound these penalties.

Next Steps For Enterprise Readiness

Enterprises have exactly 270 days remaining until the 13 May 2027 enforcement deadline. Updating hundreds of vendor contracts to meet Section 8(2) requirements and verifying external security architectures is a massive operational undertaking that requires immediate cross-team coordination between Legal, IT, and Procurement. Legacy GRC tools often lack the specific mapping required to tie processor security controls directly to DPDP consent artefacts, lawful purposes under Section 4, and dynamic data flows. Organizations must prioritize their high-risk processors immediately. Assess your vendor security gaps and build your regulator-ready Rule 6 evidence trail using the free evaluation at freescan.complydp.com before the regulatory window closes and exposes your organization to immense financial penalties.

Sources

Frequently asked questions

Does a vendor security breach expose the Data Fiduciary to DPDP Act penalties?

Yes. Under Section 8(1) and 8(5), the Data Fiduciary remains entirely responsible for protecting personal data processed on its behalf. If a vendor experiences a breach due to inadequate Rule 6 safeguards, the fiduciary faces immediate penalty exposure under the Schedule of the Act, which the Board determines using the factors listed in Section 33.

Are vendor ISO certifications enough to prove compliance with Rule 6?

No. While industry certifications demonstrate general security maturity, Rule 6 establishes a specific minimum floor of seven measures. The enterprise control owner must retain a documented evidence pack showing these specific controls are actively applied to the personal data governed by the DPDP Act, and tailored to the type and nature of the processing.

What must a fiduciary do if a vendor system gets breached?

The fiduciary must act immediately upon learning of the incident. According to Rule 7, the Data Fiduciary must send a breach intimation to the affected Data Principals without delay and submit a comprehensive, detailed report to the Data Protection Board within 72 hours of the incident.

Can we transfer regulatory liability to our processors via contract?

No. Section 8(1) explicitly states that the Data Fiduciary is responsible for compliance irrespective of any agreement to the contrary. While you can negotiate commercial indemnities to recover costs from vendors in civil court, the regulatory liability and resulting Board fines remain solely with the enterprise.

How much time is left to secure our vendor processing arrangements?

Organizations have exactly 270 days remaining until the 13 May 2027 compliance deadline. Updating Section 8(2) vendor contracts and validating external security controls requires significant cross-team coordination, making early action essential to avoid non-compliance.