Data Fiduciary obligations
Section 8 is the baseline every Data Fiduciary owes, before any SDF or sector overlay applies. Ten sub-clauses covering accuracy, security, breach reporting, retention, and grievance. Fail any and the Board can invoke penalties up to Rs. 250 crore.
01Section 8 is ten separately-enforceable obligations, not one
Most compliance conversations reduce Section 8 to "security and breach notification." The section is longer than that. Ten sub-clauses, each independently binding. The Board can find you in default on 8(7) even if your security and breach reporting are fine.
| Sec. | Obligation | Rule |
|---|---|---|
8(1) | Responsibility for compliance, whether the processing is done by you or your processor. | Rule 6 |
8(2) | Personal data processed must be accurate, complete and consistent for the specified purpose. | — |
8(3) | Take reasonable steps to ensure accuracy, completeness and consistency. | — |
8(4) | Processor engagement only under a valid contract that binds them to Section 8. | Rule 6 |
8(5) | Reasonable security safeguards to prevent a personal data breach. | Rule 6 |
8(6) | Breach notification to the Board and to each affected Data Principal. | Rule 7 |
8(7) | Erase personal data when purpose is no longer served or consent is withdrawn. | Rule 8 |
8(8) | Cause the Data Processor to erase personal data on your instruction. | Rule 8 |
8(9) | Publish business contact information of the DPO or an authorised person. | Rule 9 |
8(10) | Establish an effective grievance redressal mechanism. | Rule 13 Act |
02Rule 6: what "reasonable security safeguards" actually means
Rule 6 turns the Section 8(5) obligation into a checklist. Six technical and organisational measures the Board expects to see.
- Encryption or tokenisation of personal data, at rest and in transit.
- Access controls on computer resources used to process personal data.
- Log retention of access, including detection, investigation and remediation of unauthorised access. Minimum log retention: one year.
- Data backups and continuity measures so processing can continue if data is compromised.
- Processor contracts that require Data Processors to implement equivalent safeguards.
- Any other technical and organisational measures to ensure effective observance of these safeguards.
Rule 6 takes effect on 14 May 2027. Sector regulators (RBI, IRDAI, SEBI, IRDAI) already publish tighter baselines. Falling below your sector baseline is easy for the Board to characterise as unreasonable.
03Rule 7: breach notification form and timing
On becoming aware of a personal data breach, notify the Data Protection Board and every affected Data Principal without delay. File a comprehensive report to the Board within 72 hours.
The Rule 7 form requires cause of breach, extent of personal data affected, categories of Data Principals affected, remedial actions taken, and contact point for the Board. The 72-hour clock runs from awareness, not from the Board's opinion of when awareness occurred, so document the awareness moment.
Rule 7 does not displace CERT-In. The CERT-In Directions dated 28 April 2022 require most cyber incidents to be reported to CERT-In within 6 hours. That obligation is separate. Reporting to CERT-In does not satisfy Rule 7. You must do both.
04Rule 8: retention and erasure
Erase personal data when the purpose is no longer served or the Data Principal has withdrawn consent, whichever is earlier.
Section 8(7) allows two exceptions. First, retention required by another Indian law (tax records, KYC records, retention orders by regulators). Second, retention necessary for compliance with any legal obligation. Retention beyond those is a breach.
Practical structure: for each category of personal data, document the specified purpose, the sectoral retention floor (RBI 10 years for KYC, GST 8 years, Companies Act 8 years), and the erasure trigger. Rule 8 will require publication of your retention schedule to Data Principals on request.
05Which Section 8 failures attract which cap
Sec. 8(5) failure
Reasonable security safeguards not in place, personal data breach results. Highest cap in the Schedule.
Sec. 8(6) failure
Personal data breach occurred and you failed to notify the Board or affected Data Principals.
Other Sec. 8 failures
Accuracy, retention, DPO publication, grievance mechanism, processor contract. Catch-all cap.
Board directions
Sec. 32 direction to fix a specific control. Non-compliance triggers a further Sec. 33 penalty.