Security

    What level of data security is expected from us under DPDP, and how do we ensure we are compliant?

    Short Answer

    DPDP requires encryption, access controls, monitoring, and secure storage to protect personal data from unauthorized access and breaches.

    Answer

    DPDP requires businesses to implement reasonable security safeguards to protect personal data from unauthorized access, breaches, or misuse. This includes encryption, access controls, monitoring systems, and secure storage practices.

    From a business perspective, security is not just an IT function — it must be embedded across systems, vendors, and workflows. You should also regularly review and upgrade your security posture as systems evolve.

    Law Reference

    Section 8(5) – Security Safeguards

    "A Data Fiduciary shall implement appropriate technical and organisational measures…"

    Business Impact

    Security must be embedded across all systems and vendors, not just IT. Regular reviews and upgrades are essential as technology evolves.

    Real-World Example

    A retail chain must encrypt customer data in its CRM, implement role-based access for store managers, and monitor its POS systems for unauthorized data access.

    Was this answer helpful?

    Still have questions?

    Our team is here to help you with any questions about DPDP compliance.