Section 8(5) · Rule 6
Rule 6: Reasonable Security Safeguards
Data Fiduciaries must protect personal data in their possession or under their control — including processing by Data Processors — by taking reasonable security safeguards to prevent personal data breach. Rule 6 sets minimum expectations for those safeguards.
What Section 8(5) and Rule 6 say
Section 8(5) requires a Data Fiduciary to protect personal data in its possession or under its control, including in respect of processing by a Data Processor, by taking reasonable security safeguards to prevent personal data breach.
Rule 6 elaborates that those safeguards shall include, at the minimum: appropriate data security measures (examples include encryption, obfuscation, masking or virtual tokens mapped to personal data); appropriate measures to control access to computer resources used by the Data Fiduciary or Data Processor; visibility into access through appropriate logs, monitoring and review to detect unauthorised access, investigate it and remediate to prevent recurrence; reasonable measures for continued processing if confidentiality, integrity or availability is compromised (for example data backups); retention of such logs and personal data for a period of one year for those detection, investigation, remediation and continuity purposes unless another law requires otherwise; appropriate contractual provision with Data Processors for reasonable security safeguards; and appropriate technical and organisational measures to ensure effective observance of the safeguards.
“Computer resource” in Rule 6 has the meaning assigned in the Information Technology Act, 2000. Personal data breach is defined in Section 2(u); intimation duties are addressed separately under Section 8(6) and Rule 7.
What it means in practice
Treat Rule 6 as a minimum menu, not a complete security programme. Map each minimum item to owners, systems and evidence: how personal data is protected at rest and in transit; who can access which systems; how logs are produced and reviewed; how backups and recovery work; how long security-relevant logs and related personal data are kept (Rule 6’s one-year retention for the stated purposes); and how processor contracts require equivalent safeguards.
Security is shared across Fiduciary and Processor relationships. Inventory processors, ensure contracts reflect Rule 6 expectations, and align incident response with breach intimation under Rule 7. Organisational measures — policies, training, access reviews — matter alongside technical controls.
Distinguish Rule 6’s one-year log/personal-data retention for security investigation from purpose-based retention and erasure under Section 8 and Rule 8 (including Third Schedule deemed periods and Rule 8(3) processing logs for Seventh Schedule purposes). Different rules serve different objectives; do not collapse them into one generic retention policy without mapping the legal hooks.
Common mistakes
- Treating encryption alone as complete compliance with Rule 6’s multi-part minimum set.
- Ignoring processor processing and contract clauses when assessing Fiduciary safeguards.
- Confusing Rule 6 one-year security log retention with Rule 8 purpose/erasure schedules.
- Building controls only for websites while overlooking other systems holding personal data.
Official source
ConsentifyAI’s explanation is educational. Authoritative text is published by the Government of India / MeitY.
Information on this page is provided for general educational and implementation-planning purposes. It is not legal advice. Organizations should assess their specific obligations with qualified legal or privacy professionals.