Security, Audits and Incident Response

Use this hub to move from security readiness to a defensible incident response. The four linked guides cover the operating sequence: assess the evidence an auditor will expect, design reasonable safeguards, rehearse the breach-response clock, and preserve records that show what the organisation knew and did.

Current status — checked 29 August 2026: most substantive DPDP safeguard, personal-data-breach, and related evidence duties are notified but scheduled to commence on 13 May 2027. Use the lead time to test controls and response workflows now, while continuing to meet cyber-security, contractual, and sector-specific duties that already apply.

Start with the guide that matches your goal:

  • Audit readiness: use the 2026 DPDP Audit Checklist to assign owners and locate missing artefacts.
  • Preventive controls: use the Reasonable Security Safeguards guide to map technical and organisational measures.
  • Incident operations: use the DPDP Data Breach Response Plan to separate immediate escalation from the detailed 72-hour Board update and CERT-In’s separate clock.
  • Defensible evidence: use the consent-evidence guide to connect notices, consent records, access logs, decisions, and remediation.

Treat this page as a navigation aid and implementation overview, not legal advice. Confirm the final operating model with qualified counsel and the organisation’s security, privacy, and sector-regulatory teams.

6 articles

Back to home