DPDP Glossary
Reasonable Security Safeguards
Measures a Data Fiduciary must take to protect personal data and prevent personal data breach, elaborated in Rule 6.
Section 8(5); Rule 6
What it means
Section 8(5) requires a Data Fiduciary to protect personal data in its possession or under its control by taking reasonable security safeguards to prevent personal data breach. Rule 6 elaborates those safeguards once applicable. “Reasonable” is contextual — not a single product checkbox — and sits beside breach intimation duties when prevention fails.
Worked example
Storing password-equivalent tokens in plaintext logs, with no access control or encryption in transit, is hard to defend as reasonable safeguarding for login credentials. A layered programme — access control, encryption, logging, vendor assurance — maps more closely to the duty’s intent.
In practice
Assign security ownership against Rule 6 items as they commence. Connect safeguards to breach playbooks (Rule 7). See the Rule 6 page for dedicated framing.
Source
Section 8(5); Rule 6 · Official text (PDF)
Educational summary based on the Digital Personal Data Protection Act, 2023 and Rules, 2025. Not legal advice.