Ch IPreliminary
S.1 Short title and commencementS.2 DefinitionsS.3 Application and scopeCh IIObligations of Data Fiduciary
S.4 Grounds for processingS.5 NoticeS.6 ConsentS.7 Certain legitimate usesS.8 Data Fiduciary obligationsS.9 Children’s dataS.10 Significant Data FiduciaryCh IIIRights and duties of Data Principal
S.11 Right to accessS.12 Correction and erasureS.13 Grievance redressalS.14 Right to nominateS.15 Duties of the Data PrincipalCh IVSpecial provisions
S.16 Transfer outside IndiaS.17 ExemptionsCh VData Protection Board of India
S.18 Establishment of the BoardS.19 Composition of the BoardS.20 Salary and term of officeS.21 DisqualificationsS.22 Resignation and vacanciesS.23 Proceedings of the BoardS.24 Officers and employeesS.25 Members as public servantsS.26 Powers of the ChairpersonCh VIBoard powers and procedure
S.27 Powers and functions of the BoardS.28 Procedure followed by the BoardCh VIIAppeal and dispute resolution
S.29 Appeal to the Appellate TribunalS.30 Tribunal orders as a decreeS.31 Alternate dispute resolutionS.32 Voluntary undertakingCh VIIIPenalties
S.33 Penalties and the ScheduleS.34 Penalties to Consolidated FundCh IXMiscellaneous
S.35 Good-faith protectionS.36 Power to call for informationS.37 Blocking of accessS.38 Consistency with other lawsS.39 Bar of jurisdictionS.40 Power to make rulesS.41 Laying of rules before ParliamentS.42 Power to amend the ScheduleS.43 Power to remove difficultiesS.44 Amendments to other ActsObligation
Reasonable security safeguards are the technical and organisational measures a Data Fiduciary must take to protect personal data and prevent breaches.
TL;DR
Reasonable security safeguards (Section 8(5)) are the technical and organisational measures a Data Fiduciary must take to protect personal data and prevent a breach, including data handled by its processors. The DPDP Rules give more detail on what safeguards are expected.
A Data Fiduciary shall protect personal data in its possession or under its control, including in respect of any processing undertaken by it or on its behalf by a Data Processor, by taking reasonable security safeguards to prevent personal data breach.
Security is a standing duty, not an afterthought. The fiduciary must protect data it holds or controls, including data handled by its processors.
The measures must be reasonable and aimed at preventing a personal data breach. The Rules give more detail on what safeguards are expected.
Encrypting stored customer data, controlling access, and monitoring for intrusions are the kind of safeguards Section 8(5) expects.
What penalty applies for weak security?
A breach of the security duty may attract a penalty that may extend to two hundred and fifty crore rupees, the highest on the Schedule.
Does the duty cover my vendors?
Yes. It extends to processing done on your behalf by a Data Processor.
Consultant-led and partner-backed.