Startups & D2C · Compliance

DPDP Rule 6: what it requires of your mobile app.

DPDP Rule 6 and Section 8(5) require reasonable security safeguards to prevent a personal data breach. From a mobile app's perspective, that reduces to four points — not the whole Act. It happens to be the clause with ₹250 crore attached.

Who This Binds

Data Fiduciaries, and the Processors They Use.

Rule 6 binds every Data Fiduciary processing personal data through a mobile app, and the Data Processors — like a security SDK vendor — they engage on a contract requiring equivalent safeguards.

What We Cover

§8(5) and Rule 6 — Reasonable Security Safeguards

✓
Access control rooted in hardwareA key in the secure element, not a claim the app makes about itself.
✓
Encryption, plus proof of originPinning and a signed payload — integrity as well as confidentiality.
✓
Access and processing logs, one yearRule 6 asks 365 days; CERT-In asks 180. One setting satisfies both.
✓
The breach class servers cannot seeOverlay, screen capture, keylogging, clipboard, cloned apps — personal data taken before it ever reaches you.
What We Do Not Cover

Your Privacy Programme Stays Yours

—Consent capture, notice and consent-manager registration
—Data principal rights — access, correction, erasure
—Purpose limitation and retention across your other systems
—Cross-border transfer governance
—Grievance redressal and Board correspondence

We are a Data Processor to you. Rule 6 requires a contract mandating equivalent safeguards — ours is ready to sign.

Four Points, From the App

What Satisfies Each One in NonaShield.

PointWhat It Means in the AppWhat Satisfies It in NonaShield
1. Hardware-rooted access control A password or app-level flag isn't access control — it's a claim the app makes about itself, on a device it doesn't control. A key generated and held in the device's secure element (Android StrongBox/TEE, iOS Secure Enclave), never exportable.
2. Encryption with proof of origin Encryption alone proves confidentiality, not that the request actually came from your genuine app on the genuine device. Certificate pinning plus a signed payload on every request — integrity and origin, not just confidentiality.
3. One year of access & processing logs Rule 6 asks for 365 days of logs; CERT-In's 2022 directions separately ask for 180. Two clocks, easy to under-serve one. One signed, exportable log retained for a year — the longer of the two requirements, satisfying both at once.
4. The breach class servers cannot see Overlay attacks, screen capture, keylogging, clipboard scraping and cloned apps take personal data off the device before your servers ever see the request. On-device RASP detection for exactly this class of attack, at the point of capture — not after the data has already left.

Instrument: DPDP Act 2023, Section 8(5), and DPDP Rules 2025, Rule 6, Schedule 1. Not legal advice; confirm current requirements with your compliance counsel.

What It Costs to Get Wrong

₹250 Crore for the Failure. ₹200 Crore for Not Reporting It.

₹250 cr

maximum penalty for failing to implement reasonable security safeguards under Section 8(5), per instance, decided by the Data Protection Board of India

₹200 cr

maximum penalty for failing to notify the Board and affected data principals of a personal data breach

Both penalties need the same underlying thing to defend against: telemetry the attacker could not have written. A log you can't prove wasn't edited after the fact doesn't help you at the Data Protection Board.

12 May 2027

The compliance date for endpoint data-protection safeguards under DPDP Rule 6. Dates are compliance dates, not issue dates, as published by MeitY.

Common Mistake

HTTPS Isn't "Reasonable Security Safeguards."

What teams treat as "done"

  • TLS/HTTPS on the API, treated as the whole safeguard.
  • Server-side logs only — nothing about what happened on the device.
  • A privacy policy, mistaken for a technical control.

What Rule 6 is actually asking for

  • Proof the request came from the genuine app, not just an encrypted channel.
  • Detection of the attack classes that happen before encryption is even relevant — overlay, keylogging, clipboard, screen capture.
  • A signed record retained for a year, not a rotating server log.

TLS protects data in transit between a genuine app and your server. It says nothing about whether the app itself has been overlaid, screen-captured, or cloned before that request was ever sent — which is exactly the breach class Rule 6's endpoint safeguards target. See how this fits the rest of NonaShield's compliance mapping.

The Full Picture

One Platform, Twelve Controls, Every Sector.

DPDP Rule 6 is one of seven compliance instruments NonaShield maps to on day one — alongside the RBI Digital Payment Security Controls, RBI Authentication Directions, RBI Digital Lending Directions, NPCI's UPI MASF, SEBI CSCRF and CERT-In's retention rules. See the full compliance mapping →

Questions People Ask

DPDP Rule 6, Answered.

What does DPDP Rule 6 require of a mobile app?

DPDP Rule 6 and Section 8(5) require Data Fiduciaries to take reasonable security safeguards to prevent a personal data breach. From a mobile app's perspective, that reduces to four points: hardware-rooted access control, encryption with proof of origin, one year of access and processing logs, and protection against the breach class a server can't see — overlay, screen capture, keylogging, clipboard and cloned apps.

What is the penalty for failing DPDP Rule 6?

Up to ₹250 crore for failing to implement reasonable security safeguards under Section 8(5), and up to ₹200 crore for failing to report a breach, decided per instance by the Data Protection Board of India.

Does NonaShield cover all of DPDP compliance?

No. NonaShield covers the Section 8(5) and Rule 6 security-safeguards clause only — not consent capture, data principal rights, purpose limitation, cross-border transfer governance, or grievance redressal. Those remain the data fiduciary's own privacy programme.

How does NonaShield map to DPDP Rule 6?

A key in the secure element for access control, pinning and a signed payload for encryption with proof of origin, one year of signed access logs, and on-device detection of overlay, screen capture, keylogging, clipboard and cloned-app attacks — control-mapped on day one, not a roadmap.

Ask Us for the Coverage Report.

Four points, mapped to DPDP Rule 6, for your app.