Short Answer
DPDP requires encryption, access controls, monitoring, and secure storage to protect personal data from unauthorized access and breaches.
DPDP requires businesses to implement reasonable security safeguards to protect personal data from unauthorized access, breaches, or misuse. This includes encryption, access controls, monitoring systems, and secure storage practices.
From a business perspective, security is not just an IT function — it must be embedded across systems, vendors, and workflows. You should also regularly review and upgrade your security posture as systems evolve.
Law Reference
Section 8(5) – Security Safeguards
"A Data Fiduciary shall implement appropriate technical and organisational measures…"
Security must be embedded across all systems and vendors, not just IT. Regular reviews and upgrades are essential as technology evolves.
A retail chain must encrypt customer data in its CRM, implement role-based access for store managers, and monitor its POS systems for unauthorized data access.
Was this answer helpful?
Our team is here to help you with any questions about DPDP compliance.