DPDP Glossary

Reasonable Security Safeguards

Measures a Data Fiduciary must take to protect personal data and prevent personal data breach, elaborated in Rule 6.

Section 8(5); Rule 6

What it means

Section 8(5) requires a Data Fiduciary to protect personal data in its possession or under its control by taking reasonable security safeguards to prevent personal data breach. Rule 6 elaborates those safeguards once applicable. “Reasonable” is contextual — not a single product checkbox — and sits beside breach intimation duties when prevention fails.

Worked example

Storing password-equivalent tokens in plaintext logs, with no access control or encryption in transit, is hard to defend as reasonable safeguarding for login credentials. A layered programme — access control, encryption, logging, vendor assurance — maps more closely to the duty’s intent.

In practice

Assign security ownership against Rule 6 items as they commence. Connect safeguards to breach playbooks (Rule 7). See the Rule 6 page for dedicated framing.

Rule 6: Security safeguards →

Source

Section 8(5); Rule 6 · Official text (PDF)

Educational summary based on the Digital Personal Data Protection Act, 2023 and Rules, 2025. Not legal advice.

Further reading

← Back to glossary