Implement reasonable security safeguards and notify breaches
Under India DPDP Act, Section 8(5) and 8(6); DPDP Rules on breach intimation
Source-linked
Open official source
What does it require?
Data Fiduciaries must protect personal data with reasonable security safeguards and, on a personal data breach, inform the Data Protection Board and each affected individual in the form and manner prescribed by the Rules.
Practical action
Extend incident response to cover AI training data and model outputs that reveal personal data.
Who does it apply to?
All Data Fiduciaries.
- Sectors
- Cross-sector / all sectors
Evidence examples
- Breach notification procedure (document)
Framework mappings
Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.
| Framework | Reference | Note | Confidence |
|---|---|---|---|
| ISO/IEC 27001:2022 | Annex A incident management controls | Original editorial mapping. | medium |
Similar obligations in other instruments
- Report serious incidents to market surveillance authorities — EU AI Act, European Union
- Report critical safety incidents to the Office of Emergency Services — California SB 53, California (United States)
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.