Offer

Free security assessment — you only subscribe if we find a P0 or P1 vulnerability.

Claim free assessment
CyVigilant
All articles
Compliance

The DPDP Act 2023: Security Obligations You Can't Ignore

March 10, 2026·CyVigilant Security Team
ComplianceCyVigilant

The Digital Personal Data Protection Act, 2023 (DPDP Act) marks a watershed moment for data privacy in India. Enacted in August 2023 and progressively brought into force through Rules issued under it, the Act imposes binding security obligations on every organisation that processes digital personal data of Indian residents — regardless of where the processing occurs. For CISOs and security teams, the DPDP Act is not solely a legal matter; it creates direct operational requirements that must be implemented, maintained, and demonstrable.

Who is a Data Fiduciary and why it matters

The DPDP Act distinguishes between Data Fiduciaries (entities that determine the purpose and means of processing personal data) and Data Processors (entities that process data on behalf of fiduciaries). Most organisations that directly collect and use customer data are Data Fiduciaries — banks, NBFCs, fintechs, SaaS platforms, healthcare providers, e-commerce companies, and any organisation with a customer data layer. Data Processors include technology vendors, cloud providers, and sub-processors.

The security obligations under the DPDP Act fall primarily on Data Fiduciaries. However, Data Processors must implement security safeguards as required by the Fiduciary and are liable for processing beyond the Fiduciary's instructions. If you are a SaaS vendor processing data on behalf of enterprise clients, expect your clients to increasingly require contractual security commitments that align with their DPDP Act obligations.

The security safeguard obligation under Section 8

Section 8(4) of the DPDP Act imposes an explicit obligation on Data Fiduciaries to implement "reasonable security safeguards" to prevent personal data breaches. The Act does not prescribe specific technical controls — it establishes a reasonable security standard. The DPDP Rules (when published in their final form) are expected to provide further guidance, but in the interim, regulators are likely to interpret "reasonable" by reference to existing standards: ISO 27001, CERT-In guidelines, and sector-specific frameworks (RBI, SEBI, IRDAI).

What does reasonable security safeguard mean in practice? At minimum, it implies: encryption of personal data at rest and in transit, access controls limiting data access to authorised personnel, audit logging of data access and processing activities, regular security assessments including VAPT, an incident response capability, and vendor/processor security requirements. Organisations that cannot demonstrate these measures will face difficulty establishing that they met the statutory standard in the event of a breach.

Data breach notification: the 72-hour obligation

Section 8(6) requires Data Fiduciaries to notify the Data Protection Board of India of any personal data breach, in such form and manner as may be prescribed. The DPDP Rules draft indicates a 72-hour notification requirement from the time of discovery — consistent with the timeframe under the EU GDPR and stricter than the CERT-In Directions (which require incident reporting within 6 hours for certain incident types). Affected Data Principals must also be notified.

This notification obligation creates a direct dependency on your incident detection capability. An organisation that cannot detect a breach promptly cannot comply with the 72-hour notification requirement. Investment in SIEM, endpoint detection, and application security monitoring is therefore directly connected to DPDP Act compliance — not just security best practice.

Significant Data Fiduciaries: enhanced obligations

Organisations designated as Significant Data Fiduciaries (SDFs) by the Central Government — based on volume of data processed, sensitivity, and potential for harm — face additional obligations. These include conducting periodic Data Protection Impact Assessments (DPIAs), appointing a Data Protection Officer (DPO), and engaging an independent data auditor. The exact criteria for SDF designation are expected to include large-scale processors of sensitive personal data — banks, insurers, healthcare aggregators, and major consumer technology platforms are likely candidates.

Connecting DPDP Act compliance to your security programme

The most efficient approach to DPDP Act compliance for organisations already operating a security programme is to map existing controls to the Act's requirements rather than building a parallel compliance track. VAPT addresses the reasonable security safeguard obligation by identifying vulnerabilities that could lead to personal data breaches. Secure code reviews address security at the source code level for applications processing personal data. Security architecture reviews assess whether your data processing infrastructure is designed to prevent breaches, not merely detect them.

CyVigilant's VAPT and secure code review services directly support the reasonable security safeguard obligation under the DPDP Act. For organisations planning ahead of SDF designation, our security architecture review helps identify design-level risks. Talk to an expert to discuss your DPDP Act readiness.

Get started

Put this into action.

Book a 30-minute scoping call with a CERT-In empanelled security expert.

Talk to an Expert