Compliance hub
DPDP Act compliance: how IAM and identity governance deliver the safeguards
The Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 turn access control from good practice into statutory obligation. Rule 6 names the minimum safeguards every Data Fiduciary must implement — and several of them are, quite literally, identity and access management controls. IamLogic implements them as product features with evidence built in.
Context
What the framework expects
The DPDP Rules were notified on 13 November 2025 (G.S.R. 846(E)). The substantive obligations — including Rule 6's security safeguards — take effect in phases, with the main tranche approximately 18 months after publication (around May 2027). The Consent Manager framework under Rule 4 arrives earlier, around November 2026.
Rule 6 requires minimum safeguards including access control measures, encryption/masking/tokenization, and — critically for IAM — 'visibility on the accessing of such personal data, through appropriate logs, monitoring and review', with access logs retained for at least one year.
The penalty schedule is severe: up to ₹250 crore per contravention for failing to implement reasonable security safeguards — the highest penalty in the Act — and ₹200 crore for failure to notify a breach.
Identity obligations
The requirements that touch IAM
- Implement access control measures for systems processing personal data
- Maintain logs of access to personal data, with monitoring and review
- Retain access logs for a minimum of one year
- Apply reasonable security safeguards proportionate to the data held (Act, Section 8(5))
- Detect, respond to and report personal data breaches
Timelines: Key dates: Rules notified 13 November 2025 · Consent Manager provisions ≈ November 2026 · main safeguard obligations (incl. Rule 6) ≈ May 2027. Organisations that treat May 2027 as a start date will be implementing under penalty risk; identity programmes typically take 6–12 months to mature.
Control mapping
Requirement → IamLogic control
The table your compliance team and your auditor both want: each identity-relevant requirement, the product control that implements it, and which product it lives in.
| Requirement | IamLogic control | Product |
|---|---|---|
| Rule 6: access control measures for personal data systems | SSO with RBAC, adaptive MFA and context-based authentication as the enforced front door to data-bearing applications | Access Manager |
| Rule 6(1)(c): visibility on accessing of personal data through logs, monitoring and review | Centralised authentication and access logs across all connected applications, including legacy apps via browser plugin | Access Manager |
| Rule 6: retention of access logs for at least one year | Audit trails of every access decision, provisioning action and review sign-off, retained per policy | Both products |
| 'Review' of access (Rule 6(1)(c)) and least privilege as a reasonable safeguard | Scheduled access certification campaigns with enforced revocation and sign-off evidence | IamLogic IGA |
| Preventing access by persons with no continuing need (leavers, role changes) | Automated joiner–mover–leaver lifecycle with immediate deprovisioning | IamLogic IGA |
| Data minimisation of internal exposure | Role management, role mining and SoD rules limiting who can combine which entitlements | IamLogic IGA |
This page is provided for general information and maps regulatory expectations to IamLogic product capabilities. It is not legal advice. Regulatory obligations and timelines evolve — confirm your organisation's specific requirements with your compliance counsel.
FAQ
Common questions
Is IAM legally required by the DPDP Act?
The Act requires 'reasonable security safeguards' and the Rules specify minimum safeguards that include access control, access logging and review. IAM/IGA platforms are the standard mechanism for implementing exactly those controls at scale — and for proving it.
We already have Active Directory. Isn't that enough?
AD authenticates users to Windows resources. It doesn't give you per-application access logs across your estate, certification campaigns, SoD enforcement or lifecycle-driven deprovisioning — the capabilities Rule 6's language points at. IamLogic builds on top of your existing AD.
Can IamLogic run on-premises so personal data stays in our environment?
Yes — full on-premises deployment is a first-class option, keeping identity data, credentials and logs entirely within your infrastructure in India.
Map DPDP Act 2023 to your environment
A working session with our engineers: your systems, this framework's requirements, and a concrete gap list you keep either way.