Compliance hub

DPDP Act compliance: how IAM and identity governance deliver the safeguards

The Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 turn access control from good practice into statutory obligation. Rule 6 names the minimum safeguards every Data Fiduciary must implement — and several of them are, quite literally, identity and access management controls. IamLogic implements them as product features with evidence built in.

  • ISO/IEC 27001:2022 certified
  • Made in India
  • On-premises · Cloud · Hybrid
  • SAML · OIDC · OAuth2 · RADIUS
  • 24×7 support

Context

What the framework expects

The DPDP Rules were notified on 13 November 2025 (G.S.R. 846(E)). The substantive obligations — including Rule 6's security safeguards — take effect in phases, with the main tranche approximately 18 months after publication (around May 2027). The Consent Manager framework under Rule 4 arrives earlier, around November 2026.

Rule 6 requires minimum safeguards including access control measures, encryption/masking/tokenization, and — critically for IAM — 'visibility on the accessing of such personal data, through appropriate logs, monitoring and review', with access logs retained for at least one year.

The penalty schedule is severe: up to ₹250 crore per contravention for failing to implement reasonable security safeguards — the highest penalty in the Act — and ₹200 crore for failure to notify a breach.

Identity obligations

The requirements that touch IAM

  • Implement access control measures for systems processing personal data
  • Maintain logs of access to personal data, with monitoring and review
  • Retain access logs for a minimum of one year
  • Apply reasonable security safeguards proportionate to the data held (Act, Section 8(5))
  • Detect, respond to and report personal data breaches

Timelines: Key dates: Rules notified 13 November 2025 · Consent Manager provisions ≈ November 2026 · main safeguard obligations (incl. Rule 6) ≈ May 2027. Organisations that treat May 2027 as a start date will be implementing under penalty risk; identity programmes typically take 6–12 months to mature.

Control mapping

Requirement → IamLogic control

The table your compliance team and your auditor both want: each identity-relevant requirement, the product control that implements it, and which product it lives in.

RequirementIamLogic controlProduct
Rule 6: access control measures for personal data systemsSSO with RBAC, adaptive MFA and context-based authentication as the enforced front door to data-bearing applicationsAccess Manager
Rule 6(1)(c): visibility on accessing of personal data through logs, monitoring and reviewCentralised authentication and access logs across all connected applications, including legacy apps via browser pluginAccess Manager
Rule 6: retention of access logs for at least one yearAudit trails of every access decision, provisioning action and review sign-off, retained per policyBoth products
'Review' of access (Rule 6(1)(c)) and least privilege as a reasonable safeguardScheduled access certification campaigns with enforced revocation and sign-off evidenceIamLogic IGA
Preventing access by persons with no continuing need (leavers, role changes)Automated joiner–mover–leaver lifecycle with immediate deprovisioningIamLogic IGA
Data minimisation of internal exposureRole management, role mining and SoD rules limiting who can combine which entitlementsIamLogic IGA

This page is provided for general information and maps regulatory expectations to IamLogic product capabilities. It is not legal advice. Regulatory obligations and timelines evolve — confirm your organisation's specific requirements with your compliance counsel.

FAQ

Common questions

Is IAM legally required by the DPDP Act?

The Act requires 'reasonable security safeguards' and the Rules specify minimum safeguards that include access control, access logging and review. IAM/IGA platforms are the standard mechanism for implementing exactly those controls at scale — and for proving it.

We already have Active Directory. Isn't that enough?

AD authenticates users to Windows resources. It doesn't give you per-application access logs across your estate, certification campaigns, SoD enforcement or lifecycle-driven deprovisioning — the capabilities Rule 6's language points at. IamLogic builds on top of your existing AD.

Can IamLogic run on-premises so personal data stays in our environment?

Yes — full on-premises deployment is a first-class option, keeping identity data, credentials and logs entirely within your infrastructure in India.

Map DPDP Act 2023 to your environment

A working session with our engineers: your systems, this framework's requirements, and a concrete gap list you keep either way.