Section 8(2) (
Data Processor): While the DPDPA largely channels obligations through the Data Fiduciary, Section 8(5) (Security Safeguards) creates a direct legal standard that processors must meet. Under the 2025 Rules, processors are also explicitly named in the context of security audits and log maintenance. IT companies must therefore ensure both their contractual frameworks and their direct security posture align with the Act, as Data Fiduciaries will demand compliance commitments.
Section 8(5) (Security Safeguards): IT companies must implement reasonable security safeguards whether acting as Fiduciary or Processor.
Rule 6 mandates encryption, masking, tokenisation, access controls, and 1-year log retention - requirements directly relevant to IT infrastructure management.
Section 16 (
Cross-Border Transfer): IT companies with global delivery models must comply with cross-border transfer restrictions. Under the negative-list approach in section 16, transfers are permitted unless the Central Government notifies a country or territory as restricted. No such notification has been issued as of the current date. IT companies designated as Significant Data Fiduciaries should note separately that Rule 13(4) can require specified categories of personal data to be kept within India, and that sectoral localisation requirements continue to apply under section 16(2).
Section 8(6) (Breach Notification - Dual Clock): IT companies discovering breaches in client data must navigate two parallel timelines. Rule 7 of the DPDP Rules requires notification to the Board and affected individuals "without undue delay," with a detailed report within 72 hours. The 2022 CERT-In Directions (which remain in force) require cybersecurity incidents to be reported within 6 hours. An IT company may satisfy the DPDPA's 72-hour window but still be in violation of the IT Act / CERT-In's 6-hour window for the same incident, so processes must be designed to the shorter clock.