Rule 6 gives practical content to the obligation imposed by Section 8(5) of the Digital Personal Data Protection Act, 2023. Section 8(5) requires a Data Fiduciary to protect personal data in its possession or under its control, including personal data processed on its behalf by a Data Processor. Rule 6 then identifies the minimum components of the security framework that must support that protection.
The Rule treats security as a continuing operational responsibility. It is not satisfied merely by adopting an information-security policy, purchasing cybersecurity software, entering into a standard vendor contract or obtaining an external certification. The safeguards must be appropriate to the processing, implemented in the relevant systems, extended to Data Processors, monitored in practice and capable of supporting detection, investigation, recovery and prevention of recurrence.
Commencement position: Rule 6 and Section 8(5) are scheduled to come into force on13 May 2027. Until then, Rule 6 is a notified but prospectively operative requirement against which organisations should design and test their security programmes.