DPDP Rules, 2025

What the DPDP Rules ask of your backups

From 13 May 2027, businesses that hold personal data in India must be able to keep working if that data is destroyed or lost, and the DPDP Rules name backups as one way to do it. Here is which parts of Rule 6 concern your backups, and which do not.

Key dates

The deadline that matters is 13 May 2027

  1. 11 August 2023The Digital Personal Data Protection Act becomes law.
  2. 13 November 2025The DPDP Rules, 2025 are notified. The Data Protection Board provisions start.
  3. 13 May 2027Most duties on businesses start, including the security safeguards in Rule 6.
Rule 6, clause by clause

Reasonable security safeguards

Rule 6 lists seven minimum safeguards. One names backups, three apply to your backup copies, and three are about your own systems. They are grouped that way here, so it is clear what a backup product can do for you and what it cannot.

1Names backups directly

Rule 6(1)(d)

Be able to keep working if personal data is destroyed, encrypted or lost, for example by keeping backups.

"reasonable measures for continued processing … such as by way of data-backups"
Where Satkosh helps

Scheduled backups you can restore onto the same machine or a new one, with recent copies locked so nothing can delete them for a period you choose.

What stays with you

Decide what to back up, and test a restore before you need one.

2Applies to your backup copies

Rule 6(1)(a)

Protect personal data with measures such as encryption.

Your backups hold the same personal data as the originals, so they need the same protection.

Where Satkosh helps

Backups are encrypted on your machine before they leave it, and stay encrypted where they are stored.

What stays with you

Encrypt the live data on your own machines and systems too.

Rule 6(1)(e)

Keep logs and personal data for one year, so a compromise can be investigated and work can continue.

Keeping a year of backups is a practical way to hold on to the personal data. The logs are a separate duty.

Where Satkosh helps

Retention settings keep daily, monthly and yearly copies, so a year or more of your data can be kept and restored. If your applications write logs to files, those folders can be backed up on the same schedule.

What stays with you

Set retention to at least a year, and keep the access logs from your own systems for a year.

Rule 6(1)(f)

Have a contract with each Data Processor that covers these safeguards.

A backup provider that handles personal data for you is a Data Processor.

Where Satkosh helps

We offer a Data Processing Agreement for Satkosh.

What stays with you

Sign it, and have one with each of your other processors.

3Not about backups

  • Rule 6(1)(b)Control access to the computer systems that hold personal data.
  • Rule 6(1)(c)Keep visibility of who accesses personal data, through logs, monitoring and review.
  • Rule 6(1)(g)Put technical and organisational measures in place so the safeguards are actually followed.

These are about your own systems and how you run them, so a backup product does not meet them for you. Satkosh's own console has multi-factor sign-in, Microsoft 365 sign-in and an audit trail, but those protect your backups, not the rest of your systems.

Before May 2027

A backup checklist for the DPDP Rules

  1. List the machines and folders that hold personal data: client files, HR records, customer lists.
  2. Back them up on a schedule, encrypted before the data leaves the machine.
  3. Keep at least one year of copies, and lock recent ones so ransomware cannot delete them.
  4. If your applications write logs to files, back those folders up with the same retention.
  5. Turn on multi-factor sign-in for everyone who can restore data.
  6. Restore something real, once a quarter, and write down that it worked.
  7. Sign a Data Processing Agreement with your backup provider.

This is not legal advice. It is our reading of Rule 6 as it applies to backups, last reviewed October 2026. Satkosh helps you meet the backup parts of Rule 6 described above. It does not make a business compliant with the DPDP Act on its own, because compliance covers how you collect, use and share personal data, not only how you protect it. Check your own obligations with a lawyer.

Source: the DPDP Rules, 2025, published in the Gazette of India as G.S.R. 846(E) on 13 November 2025. For a readable summary of the Rules and their commencement dates, see SCC Online's note on the notification. See also our Data Processing Agreement and security page.

Book a demo

See where your backups stand

Book 30 minutes. We will look at what you hold, show you how Satkosh covers the backup parts of Rule 6, and run a real restore while you watch.

No spam, just a reply from our team. Managed backup by Serverstock. Made in India.