On this page
The DPDP Act says a business must protect the personal data it holds or controls, and the Rules say what that means at the least. This page sets out what the law requires, then gives a checklist for a small business. The checklist sits in a section marked Our view, which is our opinion and carries no citation. The law is cited in the Sources box.
What the law requires
A Data Fiduciary must protect personal data in its possession or under its control by taking reasonable security safeguards to prevent a personal data breach. The duty also covers processing done on its behalf by a Data Processor. The Rules then say what these safeguards must include at the minimum, so the list below is a floor.
The duty starts on 13 May 2027, eighteen months after the commencement notification and the Rules were published on 13 November 2025. For failing to take reasonable security safeguards the penalty may extend to ₹250 crore, the highest figure in the Act’s penalty schedule. That figure is a ceiling. The Board can impose a penalty only if, at the end of an inquiry, it finds a breach of the Act or the Rules significant, and only after hearing the person. It then sets the amount.
The duty has no turnover or headcount test. If the Act covers your processing as a Data Fiduciary, the duty applies to you. The government can notify some Data Fiduciaries, including startups, so that certain listed duties do not apply, and that list does not include security safeguards. Separately, within five years of the Act starting, the government can by notification declare that any provision of the Act does not apply to particular Data Fiduciaries for a set period. We have not seen such a notification in the official texts this page relies on. Does the DPDP Act apply to my business? covers who is in.
The seven minimum safeguards
| The Rules list | In plain words |
|---|---|
| 1. Data security measures | Secure the data itself. The Rules give encryption, obfuscation, masking and virtual tokens as examples. |
| 2. Access control | Where this applies, take appropriate measures to control access to the computer resources used by you and your Data Processors. The Rules take that term from the IT Act, 2000. |
| 3. Visibility | Keep logs that give visibility of access to the data, and monitor and review them, so unauthorised access can be detected, investigated and fixed so it does not recur. |
| 4. Continuity | Have reasonable measures to keep processing going if the confidentiality, integrity or availability of the data is compromised, such as by destruction or loss of access. Backups are the example given. |
| 5. Log and data retention | Keep those logs and the personal data for one year, unless compliance with any law in force requires otherwise. |
| 6. Vendor contracts | Where it applies, put an appropriate provision on security safeguards in your contract with a Data Processor. |
| 7. Technical and organisational measures | Take the technical and organisational steps that make the safeguards work in practice. |
What the law leaves open
The rule on safeguards names no product, certification or technical standard. Encryption is one of four examples the Rules give of securing data, and backups are an example of continuity, so the Rules do not say you must encrypt everything or use a particular tool. DPDP Act vs IT Act 2000 covers how the DPDP Act relates to the IT Act, including the term “computer resource” that the Rules take from it. The choice of measure is yours, but it has to be reasonable.

Logs: one year
Two rules point at the same period. The safeguards rule asks you to keep the logs and personal data for one year, unless compliance with any law in force requires otherwise, so that unauthorised access can be detected, investigated and fixed, and processing can continue after a compromise. The retention rule asks you to keep personal data, traffic data and other logs of the processing for a minimum of one year from the date of the processing, for purposes the Rules list, and then erase them unless further retention is needed to comply with another law in force or notified by the Government. Those purposes include use by the State for the security of the State, and assessment for notifying Significant Data Fiduciaries. How long can you keep customer data? covers the wider retention rules, and when a customer asks you to delete data shows how a one-year rule sits beside an erasure request.
Your vendors
You stay responsible for complying with the Act and the Rules for processing a Data Processor does on your behalf, whatever the agreement says. The safeguards duty covers that processing, and the Rules ask for a security provision in the contract with the Data Processor, wherever applicable. Processors and vendors: what goes in a data processing agreement and your software vendors as Data Processors cover the contract.
If a breach happens anyway
A personal data breach does not by itself mean a penalty. The Board can impose one only if, at the end of an inquiry, it finds that a breach of the Act or the Rules is significant, and only after hearing the person. From 13 May 2027, a personal data breach also starts a separate duty: tell each affected person and the Board without delay, then send the Board a detailed report within 72 hours of becoming aware, or a longer period the Board allows on a written request. Personal data breach: who to tell and when sets it out.
Our view: a checklist for a small business
Our view. We would turn the seven items into these steps. The law does not say these steps are enough, and your own risks may call for more. Have counsel review decisions about your business.
- Protect the data. Turn on encryption for laptops, phones and drives that hold customer data. Do not send customer spreadsheets by email.
- Control access. Give each person their own login, with two-step sign-in on email, accounting and customer tools. Keep a list of who can open what, and remove a leaver’s access the day they go.
- Switch on logs. Turn on the activity or audit log in every tool that holds customer data. Name one person who reads them each month and note that they did.
- Back up and test. Keep a copy of customer data in a second place and restore from it once, to see that it works.
- Check how long logs last. For each tool, find out how long it keeps its logs, and arrange for the period in the table above if the default is shorter.
- List your vendors. Write down every vendor that touches customer data and add a security clause to each contract. Ask each one what it does on the points in the table above, and write the answer into the contract.
- Write it down. Put the safeguards you really run into your data protection policy, with a named owner, a staff briefing and a dated record of each step.
Start with items 2 and 3, because logs show who opened the data only once each person has their own login.
Common questions
What are reasonable security safeguards under the DPDP Rules?
The Rules say they must include at the minimum: data security measures such as encryption, masking or virtual tokens; control of access to the computer resources, as the IT Act, 2000 defines them, used by you and your Data Processors, wherever applicable; logs with monitoring and review; reasonable measures to keep processing going if the confidentiality, integrity or availability of the data is compromised, such as by destruction or loss of access, for example through backups; retention of logs and personal data for one year, unless compliance with any law in force requires otherwise; a security provision in your Data Processor contracts, where applicable; and technical and organisational measures that make them work.
Do I have to encrypt all personal data?
The rule does not say so. It gives encryption, obfuscation, masking and virtual tokens as examples of appropriate data security measures, and it names no product, certification or technical standard. The measures you choose have to be reasonable.
How long must a small business keep security logs?
For one year at the minimum. This is the log and data retention item in the seven safeguards: logs and personal data are kept for one year unless compliance with any law in force requires otherwise. The retention rule asks for personal data, traffic data and other logs of the processing to be kept for a minimum of one year from the date of the processing, and then erased unless further retention is needed to comply with another law in force or notified by the Government.
Does a small business or startup have to follow these safeguards, and from when?
If the Act applies to your processing as a Data Fiduciary, size does not take you out: the Act has no turnover or headcount test. The duties the government may lift for notified businesses, including startups, do not include security safeguards. Separately, within five years of the Act starting, the government may by notification declare that any provision does not apply to particular Data Fiduciaries for a set period; we have not seen such a notification in the texts this page relies on. The duty starts on 13 May 2027, eighteen months after the commencement notification and the Rules were published on 13 November 2025.
Who is responsible if my vendor holds the data and it is breached?
Under the DPDP Act, if the vendor processes the data on your behalf as your Data Processor, you are responsible for complying with the Act and Rules for that processing, whatever the agreement says, and the safeguards duty covers it. The Rules also ask for a security provision in the contract with the Data Processor, wherever applicable.
Next steps
- Check whether the DPDP Act applies to your business, free, in a few clicks
- How-to 04: Set the rules, in the toolkit
- How-to 09b: Sign the vendor contract, in the toolkit
- How-to 11: When something goes wrong, in the toolkit
- The free duties list, every duty in plain words
In the news
- Inside India's DPDP rules: Shaping future of personal data privacy in digital era
Press explainer on the DPDP Rules.
- Digital Personal Data Protection (DPDP) Rules, 2025: Key Highlights of the Newly Notified Framework
Summary of the Rules that includes the security safeguards.
- DPDP Rules 2025: Fiduciary Duties Phase In Over 18 Months
Explains how the Rules start in stages over 18 months.
Sources
Every section, rule and date above was checked against the official text on 7 Oct 2026.
Digital Personal Data Protection Act, 2023 (No. 22 of 2023)
Official text: the Digital Personal Data Protection Act, 2023 (MeitY, PDF)
- Section 3Application of the Act: no turnover or headcount test
- Section 8(1)Responsible for complying with the Act and Rules for processing by a Data Processor, whatever the agreement says
- Section 8(2)A Data Processor engaged for offering goods or services to Data Principals only under a valid contract
- Section 8(5)Reasonable security safeguards to prevent personal data breach
- Section 8(6)Intimation of a personal data breach to the Board and affected Data Principals
- Section 17(3)Duties that notified Data Fiduciaries, including startups, may be excused from
- Section 17(5)Any provision may be disapplied to notified Data Fiduciaries, by notification within five years of commencement
- Section 33(1) and (2)Penalty only if an inquiry finds a breach of the Act or Rules significant, after a hearing; matters the Board considers
- Schedule, item 1Penalty for failing to take reasonable security safeguards may extend to two hundred and fifty crore rupees
DPDP Rules, 2025 (G.S.R. 846(E), 13 November 2025)
- Rule 1(4)Rules 3, 5 to 16, 22 and 23 in force eighteen months from publication
- Rule 6Reasonable security safeguards: the seven minimum items
- Rule 7Intimation of a personal data breach: without delay to each affected Data Principal and the Board; detailed report to the Board within 72 hours, or a longer period the Board allows on a written request
- Rule 8(3)Logs and personal data kept for a minimum of one year
- Seventh SchedulePurposes for which personal data, traffic data and logs are kept for a minimum of one year
Notifications
Official text: commencement notification G.S.R. 843(E) (MeitY, PDF)
- G.S.R. 843(E), clause (c)Sections 3 to 5, 6 (except 6(9)), 7 to 17, 27 (except 27(1)(d)), 28 to 34, 36, 37 and 44(2) in force eighteen months from 13 November 2025
A drafting aid. Get legal advice for your situation. This article explains the published text of the Act and the Rules.


