Rule 6 lists specific technical and organisational measures. Think of this not as a mere checklist, but as the foundation of a robust data protection programme. Let’s break down each component.
1. Encryption and De-identification
This is about making data unusable to unauthorised parties. Rule 6 is specific:
* Encryption: All personal data must be encrypted, both 'at rest' (when stored on servers or databases) and 'in transit' (when moving across networks).
* De-identification: Techniques like masking, tokenisation, or pseudonymisation should be used where appropriate. For example, you should mask Aadhaar numbers and tokenise PAN card numbers, ensuring the full sensitive information is not stored or displayed unnecessarily.
2. Access Control
Not everyone in your organisation needs access to all personal data. Rule 6 mandates strict access controls based on:
* Principle of Least Privilege: Employees should only have access to the minimum data necessary to perform their job function.
* Multi-Factor Authentication (MFA): Implement MFA for all users, especially those with access to sensitive data systems.
* Role-Based Access Control (RBAC): Define roles and permissions clearly, ensuring access is granted based on job responsibility and revoked promptly when a person changes roles or leaves the company.
3. Logging and Monitoring
If you can't see who is accessing data, you can't protect it. Rule 6 requires systems to log and monitor access to personal data. This means having an audit trail that answers: Who accessed what data? When did they access it? From where? This is critical for detecting suspicious activity and for forensic analysis after an incident.
4. Log Retention
The logs you collect are only useful if you keep them. The draft rules propose a mandatory log retention period of at least one year. This ensures that in the event of an investigation, there is a sufficient historical record to analyse.
5. Data Backup, Recovery, and Business Continuity
You must be able to continue processing personal data securely and restore it in the event of a physical or technical incident. This isn't just about having backups; it's about having tested backups. You must regularly test your restore procedures to ensure they work when you need them most.
6. Breach Detection and Response
This involves having a clear, documented plan to detect, manage, and respond to a data breach. This plan should include procedures for internal reporting, investigation, containment, and notifying the Data Protection Board of India and affected individuals.
7. Contractual Safeguards for Data Processors
As a Data Fiduciary, you are ultimately accountable for what happens to your data, even when it’s handled by a third-party vendor (a Data Processor). Rule 6 requires you to have a legally binding contract—a Data Processing Agreement (DPA)—with every processor. This DPA must obligate the processor to adhere to the same security safeguards you do.