Rule 6, reasonable security safeguards
In short
Rule 6 requires a Data Fiduciary to protect personal data in its possession or under its control, including in respect of any processing undertaken by it or on its behalf by a Data Processor, by taking reasonable security safeguards to prevent personal data breach. Seven measures are stated as a minimum rather than as a complete list.
01The seven minimum measures
| Clause | Measure |
|---|---|
| 6(1)(a) | Appropriate data security measures, such as securing personal data through encryption, obfuscation, masking or the use of virtual tokens mapped to that personal data |
| 6(1)(b) | Appropriate measures to control access to the computer resources used by the Data Fiduciary or the Data Processor, wherever applicable |
| 6(1)(c) | Visibility on the accessing of personal data through appropriate logs, monitoring and review, to enable detection of unauthorised access, its investigation and remediation to prevent recurrence |
| 6(1)(d) | Reasonable measures for continued processing where confidentiality, integrity or availability is compromised by destruction or loss of access, such as data backups |
| 6(1)(e) | Retention of those logs and personal data for a period of one year, unless compliance with any law in force requires otherwise |
| 6(1)(f) | Appropriate provision in the contract with the Data Processor, wherever applicable, for taking reasonable security safeguards |
| 6(1)(g) | Appropriate technical and organisational measures to ensure effective observance of security safeguards |
Computer resource carries the meaning assigned to it in the Information Technology Act, 2000.
02The three provisions that decide an incident
- Clause (c) and clause (e) together. Logs must exist, and they must survive for a year. Rule 7(2)(b) requires the broad facts, circumstances and reasons leading to the breach to be reported within seventy two hours. That report is written from the logs, or it is not written.
- Clause (f). The safeguards obligation reaches the Data Processor only through the contract. Where the contract is silent, the Data Fiduciary carries the exposure without the corresponding control.
- Clause (b). Access control is stated over the computer resources used by the Data Fiduciary or the Data Processor, so a processor environment is inside the scope of the obligation rather than beside it.
03Common questions
Is encryption mandatory?
Clause (a) requires appropriate data security measures and gives encryption, obfuscation, masking and virtual tokens as examples. It states a standard illustrated by methods rather than mandating one method.
How long must logs be kept?
One year, under clause (e), unless compliance with any law in force requires otherwise. Rule 8(3) separately requires personal data, associated traffic data and logs to be retained for at least one year from the date of processing for the purposes in the Seventh Schedule.
Do these obligations apply to our processor?
The obligation sits on the Data Fiduciary, and clause (f) requires appropriate contractual provision with the Data Processor for taking reasonable security safeguards.
Ask an AI assistant about this page
Each button opens the assistant with the prompt below already written.
Answers are generated by third party systems and are not published or verified by this site. Check anything load bearing against the gazette text.