This is where the DPDPA differs from ISO 27001. ISO hands you a catalogue of 93 named controls to work through. The DPDPA instead asks for "reasonable security safeguards" — a principle, not a checklist. That sounds vaguer, but Rule 6 of the DPDP Rules, 2025 pins it down to a concrete, minimum set of measures every Data Fiduciary (and its processors) must have. These are your controls — and each one is measurable.
| Rule 6 safeguard |
What it means in practice |
How to measure / evidence it |
| Encryption & masking |
Encrypt personal data at rest and in transit; mask, obfuscate, or tokenise it where you can |
% of data stores encrypted, key-management policy, tokenisation coverage |
| Access controls |
Least-privilege access to every system holding personal data; multi-factor authentication |
access-review reports, MFA coverage, joiner–mover–leaver records |
| Logging & monitoring |
Log and review who accesses personal data, to detect unauthorised access, investigate, and remediate |
log coverage, alerting rules, review cadence |
| Log retention (1 year) |
Keep those access logs for at least one year |
retention configuration, log-store audit |
| Backups & resilience |
Be able to keep processing if data is destroyed or compromised |
backup success rate, tested restore (RTO / RPO) |
| Breach detection & response |
Detect, investigate, and remediate breaches quickly |
detection tooling, an incident runbook, drill records |
| Processor safeguards |
Contractually bind every vendor to the same measures — you stay accountable |
signed data-processing agreements, vendor security reviews |
The breach clock (Rule 7). If a breach does happen, the timing is strict: notify affected individuals without delay (in clear language — what happened, the likely impact, what you're doing, and what they should do), and file a detailed report to the Data Protection Board within 72 hours of becoming aware. You can only hit that clock if your logging and detection (the controls above) are already working.
So how do you measure compliance? Because "reasonable" isn't a number, you prove it by adopting a recognised control framework and keeping live evidence against it. In practice, that means mapping the Rule 6 safeguards onto a control set you already understand — ISO 27001, SOC 2, or NIST — then scoring every control as implemented, partial, or not started, assigning an owner, and keeping the evidence current for the day the Board asks. That control-by-control, evidence-backed view is exactly how you turn a principle into something you can measure.