The Digital Personal Data Protection Act, 2023 spent two years as an abstraction. With the DPDP Rules notified in November 2025, it now has dates, specifics and a penalty schedule — and a surprising amount of it is about identity and access management.
Rule 6 lists the minimum 'reasonable security safeguards' every Data Fiduciary must implement. Alongside encryption and backups, it names access control measures and — in Rule 6(1)(c) — 'visibility on the accessing of such personal data, through appropriate logs, monitoring and review', with access logs retained for at least one year. Failure to implement reasonable safeguards carries the Act's highest penalty: up to ₹250 crore per contravention.
What the safeguards mean in identity terms
Strip away the legal language and Rule 6 asks four operational questions. Can you control who accesses personal data? Can you see every access? Do you review whether access is still justified? And can you prove all three to an adjudicating officer?
Answering yes at enterprise scale requires specific capabilities: a policy-enforced front door to data-bearing applications (SSO with MFA), centralised access logs that include your legacy applications, periodic certification of access rights with revocations that actually execute, and lifecycle automation so departed employees and lapsed contractors lose access immediately rather than eventually.
The readiness checklist
Score your organisation honestly against these ten items. In our experience, most Indian enterprises pass fewer than half before starting a formal identity programme.
- Every application holding personal data sits behind SSO with MFA — including legacy applications
- Access to personal-data systems is role-based, not individually accumulated
- A single log records who accessed which data-bearing application, retained ≥ 1 year
- Access rights are certified on a schedule, with sign-off evidence retained
- Revocation decisions from reviews deprovision automatically in target systems
- Joiner access is provisioned from HR data, not email requests
- Leaver deprovisioning completes same-day across every connected system
- Contractor and vendor access is time-bound and expires automatically
- Segregation-of-duties rules prevent toxic combinations on personal-data systems
- You can produce all of the above as reports without manual assembly
The timeline is shorter than it looks
The main safeguard obligations take effect roughly 18 months from the Rules' publication — around May 2027. That sounds distant until you subtract the realistic duration of an identity programme: platform selection, deployment, application onboarding, role modelling and a first certification cycle typically consume 6–12 months. Organisations starting in 2026 will be compliant with margin; organisations starting in 2027 will be implementing under penalty exposure.
The efficient path is to treat DPDP not as a paperwork exercise but as the forcing function for identity hygiene you needed anyway — the same controls satisfy RBI, SEBI CSCRF, IRDAI and ISO 27001 auditors.