Digital Personal Data Protection Rules, 2025
Show AI Summary
Personal data protection requires informed consent, security safeguards, breach reporting, retention controls, and additional duties for significant data fiduciaries.
Data Fiduciaries must protect personal data through encryption or comparable controls, access restrictions, logs, monitoring, backups, processor-contract obligations, and technical and organisational safeguards. They must retain relevant personal data and logs for at least one year, subject to applicable law. On becoming aware of a personal data breach, they must promptly give affected Data Principals clear information on the breach, likely consequences, mitigation, protective steps, and contact details, and notify the Board without delay, followed by detailed information within seventy-two hours unless the Board allows more time.