“Reasonable security safeguards” is the single phrase tied to the Act’s highest penalty tier. Here’s what it means at an introductory level.
WHY THIS ONE MATTERS THE MOST
₹250 CRORE
The top penalty tier
Attached specifically to failing to implement reasonable security safeguards that leads to a breach.
STANDING DUTY
Not a one-time setup
Security safeguards have to be maintained continuously, across the full lifecycle of the data.
COVERS PROCESSORS TOO
Extends to vendors
A Fiduciary’s security duty includes data held by its processors on its behalf.
The Act deliberately doesn’t define “reasonable” as a fixed technical checklist — what counts as reasonable for a small startup and a national bank won’t look identical. What stays constant is the expectation: security has to be a genuine, maintained practice, proportionate to the risk, not a document that was accurate on the day it was written.
Security safeguards carry the Act’s single highest penalty for a reason — this is the obligation regulators expect to see taken most seriously.
SOURCES The DPDP Act, 2023 — official text, MeitY — https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf