5 min read
Rule 6(1)(g) Security Safeguards: Technical and Organisational Measures Explained
A precise guide for enterprise compliance leaders on implementing appropriate technical and organisational measures under Rule 6(1)(g) of the DPDP Rules, 2025.
Last updated:
Rule 6(1)(g) of the Digital Personal Data Protection Rules, 2025 mandates that Data Fiduciaries implement appropriate technical and organisational measures. This provision requires effective observance of security safeguards across the enterprise. A Head of Compliance managing a large workforce must move beyond static IT policies. You need verifiable controls that secure personal data throughout its lifecycle. This specific rule is the core envelope for the other minimum security requirements defined in the Rules. It demands continuous evidence of control effectiveness instead of a one-time policy publication. A static spreadsheet fails this legal standard. The law requires dynamic systems to prove that the enterprise actually executes its privacy rules on a daily basis.
Section 8(5) of the Digital Personal Data Protection Act, 2023 requires a Data Fiduciary to protect personal data in its possession or under its control. The Fiduciary achieves this by taking reasonable security safeguards. Rule 6(1)(g) operationalises this broad statutory duty. It explicitly names technical and organisational measures as the mechanism to prove that security safeguards operate effectively. Processing must also tie back to a lawful purpose under Section 4. A person may process the personal data of a Data Principal only for a lawful purpose based on consent or certain legitimate uses. Securing that data is an ongoing requirement regardless of which lawful basis applies. The Act establishes the mandate to prevent data breaches. The Rules specify that Fiduciaries deploy a combination of systems and workflows to satisfy regulatory scrutiny.
The Rules establish a compliance floor. They do not set a maximum ceiling. Rule 6 minima dictate baseline technical and organisational measures. What qualifies as reasonable under Section 8(5) depends entirely on your enterprise context. A control owner managing high-volume data streams faces a different standard than a department handling minimal internal records. Section 10(1) allows the Central Government to notify a Significant Data Fiduciary based on specific factors. These assessment factors include the volume of personal data processed, risk to the rights of the Data Principal, and potential impact on the sovereignty and integrity of India. Installing access control software satisfies a technical minimum. An organisational measure requires tying that software to a documented access review workflow. If the Data Protection Board investigates, they measure your controls against the volume of data processed and the exact risk profile of your enterprise.
This legal obligation falls strictly on the Data Fiduciary. Section 8(1) of the Act states that a Data Fiduciary is responsible for complying with the Act and Rules in respect of any processing undertaken by it or on its behalf by a Data Processor. The text explicitly notes this applies irrespective of any agreement to the contrary. You cannot outsource your Rule 6(1)(g) liability. Section 8(2) adds that a Data Fiduciary may engage a Data Processor only under a valid contract. When your enterprise shares systems with vendors or relies on third-party cloud infrastructure, your compliance framework must track their technical and organisational measures. The Data Protection Board holds the Fiduciary accountable when a processor fails to maintain compliant security controls. Managing this risk requires a structured audit trail of vendor security assessments.
Many large enterprises assume an existing ISO 27001 certification automatically satisfies Rule 6(1)(g). An ISO certificate provides a generic information security standard. The DPDP Rules require controls explicitly mapped to personal data lifecycles. Another common error involves encryption. Enterprises often believe encryption alone covers the legal requirement. Encryption is a technical measure. Without the organisational measure of strict key management and access audits, the control remains legally incomplete. A third misconception is that buying a new software tool solves the compliance problem. Software provides a visual dashboard for management. The legal duty requires the enterprise to enforce the workflows that the tool measures. Buying a tool without configuring the underlying process fails the Rule 6(1)(g) mandate.
Building a regulator-ready evidence pack requires specific documentation for technical and organisational measures. The Data Protection Board will ask for proof of these controls during an inquiry.
1. Data flow maps. The privacy team maintains diagrams showing where personal data enters, resides, and exits the enterprise systems.
2. Risk assessment records. Control owners document their evaluation of security risks specific to personal data processing workflows.
3. Access review logs. IT administrators retain time-stamped logs proving that user access to personal data is periodically reviewed. The enterprise revokes access when employee roles change.
4. Incident response plans. The compliance function manages tested procedures detailing how the enterprise contains and assesses security anomalies.
5. Training attestations. Human resources track records proving that employees handling personal data complete targeted DPDP compliance training.
6. Processor contract audits. The legal team retains records showing that the Data Fiduciary reviews processor security controls under the Section 8(2) valid contract requirement.
Enterprises classified under Section 10 face additional organisational requirements. A Significant Data Fiduciary must appoint a Data Protection Officer to represent them under the provisions of the Act. This individual must be based in India. They must report directly to the Board of Directors or similar governing body. The designation of a Significant Data Fiduciary changes the scope of required organisational measures. Such entities must conduct periodic Data Protection Impact Assessments. They must also appoint an Independent Data Auditor to evaluate compliance. These added layers of governance form part of the broader technical and organisational measures expected from high-risk processors. Security safeguards scale directly with the risk to electoral democracy, public order, and state security.
Failing to implement these measures directly affects your exposure under Rule 7. This rule requires intimation of personal data breaches to affected Data Principals and to the Board within 72 hours. Your processor agreements must legally bind vendors to these same technical and organisational measures. The Schedule to the Act imposes penalties up to 250 crore rupees for failing to observe the security safeguards required by Section 8(5). The penalty applies per breach. Disconnected spreadsheets and manual updates will struggle to produce a defensible audit trail during a Board inquiry. Exactly 253 days remain until the DPDP compliance deadline of 13 May 2027. Run a gap check on your technical and organisational measures at freescan.complydp.com to identify control failures before the deadline.
Sources
Frequently asked questions
Does an ISO 27001 certification prove compliance with Rule 6(1)(g)?
No. ISO 27001 provides a generic security standard. It does not automatically map to the data privacy requirements of the DPDP Act. Rule 6(1)(g) requires technical and organisational measures specifically designed to protect personal data lifecycles and uphold Data Principal rights.
Who is legally responsible for a vendor failing to secure data under the DPDP Act?
The Data Fiduciary holds primary responsibility. Section 8(1) makes the Fiduciary liable for any processing undertaken on its behalf by a Data Processor. This liability applies irrespective of contractual terms to the contrary.
What is the difference between technical and organisational measures?
Technical measures involve IT systems and software. Examples include encryption or access control systems. Organisational measures involve the workflows, policies, and personnel structures that manage those systems. These include access review procedures and incident response plans.
How soon must we report a breach if our security safeguards fail?
Under Rule 7 of the DPDP Rules, 2025, a Data Fiduciary must intimate the Data Protection Board within 72 hours of noticing a personal data breach. You must also notify the affected Data Principals in the prescribed manner.
What is the maximum penalty for failing to implement reasonable security safeguards?
The Schedule to the DPDP Act, 2023 sets a maximum penalty of 250 crore rupees for a breach of the duty to take reasonable security safeguards under Section 8(5).
ComplyDP