Regulatory 9 min read

“Reasonable Security Safeguards” Is Now a Number

The DPDP Act attaches its largest penalty to a duty it deliberately declines to define. That is not a drafting gap — it is an instruction to show your reasoning. Here is what defensible reasoning looks like.

Key takeaways

  • The Act's heaviest penalty sits on a duty stated as an outcome, not a control list — so compliance is argued, not ticked.
  • “Reasonable” is a proportionality test: the safeguards you owe scale with the exposure you carry.
  • That makes a documented exposure estimate the strongest evidence you can hold — it shows the decision was informed, not accidental.
  • The breach-notification clock starts on awareness, not on certainty. Build the decision path before you need it.
  • Most organisations already hold the inputs. What they lack is a record connecting data, exposure, control decision and sign-off.

Read India's Digital Personal Data Protection Act, 2023 looking for a control list and you will not find one. The obligation that carries its largest financial penalty — up to ₹250 crore — is expressed in a single clause: a Data Fiduciary must take reasonable security safeguards to prevent a personal data breach.

No control framework is named. No minimum standard is prescribed. Security teams used to regulations that enumerate requirements tend to read this as an unfinished sentence. It is not. It is a proportionality test, and it moves the burden somewhere uncomfortable: onto your ability to show that what you chose to do was reasonable given what you were carrying.

An outcome-shaped duty behaves differently from a control-shaped one

A control-shaped obligation — encrypt data at rest, retain logs for 180 days, run quarterly vulnerability scans — can be audited by inspection. Either the control exists or it does not. Compliance is a state you can be in.

An outcome-shaped obligation cannot be audited that way, because the standard is relative. The safeguards that are reasonable for a payroll file covering 40 employees are not the safeguards that are reasonable for an authentication database covering 40 million. Both organisations are subject to the identical clause. They owe materially different things under it.

Which means the question a regulator will eventually ask is not did you have control X. It is closer to: you held this data, at this volume, with this exposure — what did you know about that, and what did you decide to do about it?

The Act does not ask whether you were secure. It asks whether your decisions about security were reasonable in light of what you were carrying.

The penalty schedule tells you where the drafters put the weight

The Schedule to the Act sets upper limits for each category of breach. Reading them as a ranking is instructive — it shows which failures the legislature considered most serious.

FailureUpper limit
Failure to take reasonable security safeguards to prevent a personal data breach₹250 crore
Failure to notify the Board or affected Data Principals of a personal data breach₹200 crore
Breach of the additional obligations relating to children's data₹200 crore
Breach of the additional obligations of a Significant Data Fiduciary₹150 crore
Breach of any other provision of the Act or rules₹50 crore

Two things stand out. The safeguards duty outranks everything else, including notification. And the second-largest exposure attaches to a purely procedural failure — not telling anyone. An organisation can suffer a breach it could not reasonably have prevented and still face a nine-figure penalty for how it handled the aftermath.

What “reasonable” asks you to be able to show

Proportionality tests are argued, not asserted. In practice, an organisation defending its safeguards is making four connected claims, and each one needs something behind it.

1. You knew what you held

A defensible position starts with an inventory that answers the questions a regulator will ask: which systems process personal data, what categories, at what volume, retained for how long, accessible by whom, and shared with which processors. Not a data-flow diagram drawn once for a certification and never revisited — a live record with owners against each entry.

This is also the step most often skipped, because it is unglamorous and it surfaces uncomfortable answers. The dormant reporting database holding six years of customer records nobody has queried since 2021 is precisely the finding that matters, and precisely the one an inventory built for an audit tends to miss.

2. You understood the exposure that created

Holding personal data creates a quantifiable loss position: regulatory penalty, notification and remediation cost, legal defence, customer attrition, and the operational cost of responding. That position differs enormously between systems, which is exactly why the same clause imposes different duties on different fiduciaries.

An organisation that can state its exposure in financial terms — with the assumptions written down — is in a fundamentally stronger position than one relying on a colour-coded register. Not because the estimate will prove exactly right, but because it demonstrates the duty was engaged with rather than assumed away. Our note on why boards need financial framing covers the mechanics of getting there.

3. Your control decisions responded to that exposure

This is the link that most compliance programmes leave implicit, and it is the one that carries the argument. Controls should be traceable to the exposure they reduce. When the authentication database is the largest single concentration of personal data in the estate, the record should show that this is why it received the tokenisation project, the access review, and the segmentation work — rather than those controls landing there because a vendor bundle included them.

Equally important: the decisions not to act. Accepting a risk is a legitimate choice. Accepting it silently is what looks negligent in hindsight. A dated acceptance, with a named owner and a stated rationale, is evidence of a functioning risk process. Its absence is evidence of nothing at all.

4. Someone accountable signed it

Reasonableness is judged against what the organisation knew, and knowledge is attributed to people. Risk acceptances signed at a level with the authority to accept them, minuted board discussion of material exposures, and a review cadence that survives the departure of whoever built the programme — these convert individual judgement into organisational position.

The notification clock starts before you are certain

The second-largest penalty in the Schedule attaches to notification failure, and this catches capable teams out for a structural reason: the obligation triggers on becoming aware of a breach, while the instinct of every competent responder is to establish the facts first.

Those two impulses pull in opposite directions during exactly the hours when nobody is thinking clearly. The gap is not closed by a policy document that says “notify promptly.” It is closed in advance, by deciding three things while calm:

  • What constitutes awareness. Which signal, reaching which role, starts the clock — written down before an incident, not reconstructed after one.
  • Who decides. A single named role with the authority to notify, and a deputy, because incidents do not respect leave calendars.
  • What goes out at hour one. A drafted notification that says what is known, what is not yet known, and what is being done — so uncertainty does not become the reason for delay.

The organisations that handle this well are not the ones with the best forensics. They are the ones that decided, in advance, that an incomplete notification sent on time beats a complete one sent late.

Where this leaves a security team

The uncomfortable feature of an outcome-shaped duty is that you cannot finish it. There is no certificate, no attestation, no state of being compliant with a proportionality test. What there is instead is a record: of what you held, what you understood about it, what you decided, and who decided it.

That record is not primarily a compliance artefact. It is the same material that lets a security team argue for budget, prioritise between competing projects, and answer the board's questions without hedging. The DPDP Act has simply raised the cost of not having it.

Most organisations already hold the inputs — scattered across an asset register, a risk log, a set of vendor assessments and a few years of board decks. What they lack is the thread connecting them. That thread is the deliverable.

See this against your own numbers.

A 30-minute walkthrough of 4sight on TrustCore using your environment — or start with a free self-serve assessment, no sales conversation required.