Home / Act 2023 / Sec. 8
Sec. 8 · Chapter II · DPDP Act 2023

Data Fiduciary obligations

Section 8 is the baseline every Data Fiduciary owes, before any SDF or sector overlay applies. Ten sub-clauses covering accuracy, security, breach reporting, retention, and grievance. Fail any and the Board can invoke penalties up to Rs. 250 crore.

Verified 8 Sep 2026 DPDP Act 2023, Sec. 8 8 min read Also: Rules 6, 7, 8

01Section 8 is ten separately-enforceable obligations, not one

Most compliance conversations reduce Section 8 to "security and breach notification." The section is longer than that. Ten sub-clauses, each independently binding. The Board can find you in default on 8(7) even if your security and breach reporting are fine.

Sec. Obligation Rule
8(1)Responsibility for compliance, whether the processing is done by you or your processor.Rule 6
8(2)Personal data processed must be accurate, complete and consistent for the specified purpose.
8(3)Take reasonable steps to ensure accuracy, completeness and consistency.
8(4)Processor engagement only under a valid contract that binds them to Section 8.Rule 6
8(5)Reasonable security safeguards to prevent a personal data breach.Rule 6
8(6)Breach notification to the Board and to each affected Data Principal.Rule 7
8(7)Erase personal data when purpose is no longer served or consent is withdrawn.Rule 8
8(8)Cause the Data Processor to erase personal data on your instruction.Rule 8
8(9)Publish business contact information of the DPO or an authorised person.Rule 9
8(10)Establish an effective grievance redressal mechanism.Rule 13 Act

02Rule 6: what "reasonable security safeguards" actually means

Rule 6 turns the Section 8(5) obligation into a checklist. Six technical and organisational measures the Board expects to see.

  1. Encryption or tokenisation of personal data, at rest and in transit.
  2. Access controls on computer resources used to process personal data.
  3. Log retention of access, including detection, investigation and remediation of unauthorised access. Minimum log retention: one year.
  4. Data backups and continuity measures so processing can continue if data is compromised.
  5. Processor contracts that require Data Processors to implement equivalent safeguards.
  6. Any other technical and organisational measures to ensure effective observance of these safeguards.

Rule 6 takes effect on 14 May 2027. Sector regulators (RBI, IRDAI, SEBI, IRDAI) already publish tighter baselines. Falling below your sector baseline is easy for the Board to characterise as unreasonable.

Rule 6 DPDP Rules 2025 (effective 14 May 2027).

03Rule 7: breach notification form and timing

On becoming aware of a personal data breach, notify the Data Protection Board and every affected Data Principal without delay. File a comprehensive report to the Board within 72 hours.

The Rule 7 form requires cause of breach, extent of personal data affected, categories of Data Principals affected, remedial actions taken, and contact point for the Board. The 72-hour clock runs from awareness, not from the Board's opinion of when awareness occurred, so document the awareness moment.

Rule 7 does not displace CERT-In. The CERT-In Directions dated 28 April 2022 require most cyber incidents to be reported to CERT-In within 6 hours. That obligation is separate. Reporting to CERT-In does not satisfy Rule 7. You must do both.

Rule 7 DPDP Rules 2025 (effective 14 May 2027). CERT-In Directions dated 28 April 2022.

04Rule 8: retention and erasure

Erase personal data when the purpose is no longer served or the Data Principal has withdrawn consent, whichever is earlier.

Section 8(7) allows two exceptions. First, retention required by another Indian law (tax records, KYC records, retention orders by regulators). Second, retention necessary for compliance with any legal obligation. Retention beyond those is a breach.

Practical structure: for each category of personal data, document the specified purpose, the sectoral retention floor (RBI 10 years for KYC, GST 8 years, Companies Act 8 years), and the erasure trigger. Rule 8 will require publication of your retention schedule to Data Principals on request.

Sec. 8(7) DPDP Act. Rule 8 DPDP Rules 2025 (effective 14 May 2027). Sectoral retention: RBI Master Directions on KYC, GST Act, Companies Act.

05Which Section 8 failures attract which cap

Rs. 250 cr

Sec. 8(5) failure

Reasonable security safeguards not in place, personal data breach results. Highest cap in the Schedule.

Rs. 200 cr

Sec. 8(6) failure

Personal data breach occurred and you failed to notify the Board or affected Data Principals.

Rs. 50 cr

Other Sec. 8 failures

Accuracy, retention, DPO publication, grievance mechanism, processor contract. Catch-all cap.

Directions

Board directions

Sec. 32 direction to fix a specific control. Non-compliance triggers a further Sec. 33 penalty.

Ship the Section 8 stack. dcomply ships Breach Notifications, Retention Manager, Grievance Officer, ROPA, and DPO Console modules covering all ten Section 8 sub-clauses.