A Practical Guide to DPDPA Compliance Using Picus

Umut Bayram | 17 MIN READ

| September 21, 2026

What Is DPDPA Compliance?

DPDPA compliance means meeting the requirements of India's Digital Personal Data Protection Act, 2023, also called the DPDP Act, and its applicable Rules. These requirements govern how organizations collect, use, store, and share digital personal data, including lawful processing, consent, individual rights, and data security.

The DPDPA sets the legal obligations, while the Digital Personal Data Protection Rules, 2025 explain how organizations must implement many of them. A compliance program brings together privacy processes and the security controls protecting the systems that process personal data.

For security teams, Section 8(5) of the DPDPA is a central requirement. It makes Data Fiduciaries responsible for reasonable security safeguards to prevent personal data breaches, including where a Data Processor handles the data on their behalf. Rule 6 of the DPDP Rules details those safeguards, covering access controls, monitoring, continuity, retention, and processor contracts.

Does the DPDPA Apply to My Business?

The DPDPA applies to businesses that process digital personal data in India, subject to the Act's exceptions. It also covers processing outside India when it relates to offering goods or services to people in India. A business can fall within this scope even without an Indian office.

Under Section 3 of the DPDPA, the data may be collected digitally or digitized later. For example, customer details collected through an app and paper records later entered into a computer system can both be covered.

Your responsibilities depend on your role:

  • A Data Fiduciary determines why and how personal data is processed.
  • A Data Processor processes personal data for a Data Fiduciary.
  • A Data Principal is the individual the personal data concerns.
  • A Significant Data Fiduciary is a Data Fiduciary, or class of Data Fiduciaries, designated by the Central Government under Section 10 for additional obligations.

Some exceptions apply. These include an individual using data for personal or household purposes. They also include data made public by the person it concerns or by someone legally required to publish it. Section 17 of the DPDPA lists further exemptions. Check the conditions of each exemption before relying on it.

Your organization is still responsible for personal data when a cloud provider or another supplier handles it for you. Under Section 8(1) of the DPDPA, you must ensure that this processing meets the law's requirements, including keeping the data secure.

What Is the Deadline for DPDPA Compliance?

DPDPA requirements take effect in stages. Most core duties, including security safeguards and breach notification, take effect eighteen months after the November 2025 Gazette publication. Consent Manager registration requirements take effect after one year. The first group of provisions, including those setting up the Board's legal framework, took effect on publication.

As of writing this, the main security and breach-notification duties discussed here are still in the preparation period.

When

What takes effect

On publication

Initial rules and the Board’s setup provisions.

After 1 year

Consent Manager registration and obligations.

After 18 months

Most core duties, including data security, breach reporting, and extra requirements for Significant Data Fiduciaries.

The timeline above follows Rule 1 of the DPDP Rules, 2025 and the DPDPA commencement notification.

Use the preparation period to check existing safeguards, fix weaknesses, and test the changes. Under the DPDPA's Schedule, penalties can reach ₹250 crore for failing to take reasonable security safeguards and ₹200 crore for failing to meet breach-notification duties. These are maximum amounts. The Board determines a penalty through the process set out in the Act.

What are the DPDPA Security Requirements?

The DPDPA requires reasonable security safeguards to prevent personal data breaches. Section 8(5) of the DPDPA sets this duty. Rule 6 of the DPDP Rules explains the minimum measures organizations must take.

These measures cover:

  • Data protection: use appropriate measures such as encryption, obfuscation, masking, or virtual tokens linked to personal data.
  • Access control: control who can access the computer resources used to process personal data.
  • Logging and monitoring: record and review access to personal data so teams can detect unauthorized access, investigate it, and fix the weaknesses behind it.
  • Continuity: use reasonable measures, such as backups, to keep processing data after a security incident.
  • Retention: keep the relevant logs and personal data for one year unless applicable law requires otherwise.
  • Processor safeguards: include appropriate security requirements in Data Processor contracts, where applicable.
  • Effective safeguards: put technical measures and working procedures in place so these protections work as intended.

Security teams need to check how these protections work in practice. Can monitoring detect unauthorized access to customer records? Do network restrictions still work after a change? Does an updated detection rule raise the expected alert?

Security validation supports DPDPA compliance by testing defenses and recording the results. Continuous testing can help teams find weaknesses, check fixes, and provide evidence for compliance reviews.

How Does Picus Help With DPDPA Compliance?

The Picus Platform combines Breach and Attack Simulation, Autonomous Penetration Testing, and Exposure Validation. It helps teams test the controls protecting personal data, find gaps, and check whether fixes work.

The sections below explain how Picus can support specific requirements. Its results provide evidence for a compliance review.

In the references below, Sections belong to the DPDPA and Rules belong to the DPDP Rules.

The main areas are:

  • Section 8(5) and Rule 6(1)(g): Protecting Personal Data
  • Section 8(6) and Rule 7: Reporting Breaches
  • Rule 6(1)(c) and (e): Monitoring Access and Keeping Supporting Records
  • Section 10 and Rule 13: Assessments and Audits for Significant Data Fiduciaries

Section 8(5) and Rule 6(1)(g): Protecting Personal Data

“A Data Fiduciary shall protect personal data in its possession or under its control, including in respect of any processing undertaken by it or on its behalf by a Data Processor, by taking reasonable security safeguards to prevent personal data breach.” (DPDPA, Section 8(5))

“appropriate technical and organisational measures to ensure effective observance of security safeguards. ” (DPDP Rules, Rule 6(1)(g))

Protecting personal data means securing both the data itself and the systems that handle it. Attackers may exploit vulnerabilities, gain unauthorized access, and steal data from those systems. Teams need to check whether their security controls can stop or detect these attacks, identify which weaknesses put personal data at the greatest risk, and keep those protections effective as threats and configurations change.

How Does Picus Support This Requirement?

Picus Breach and Attack Simulation tests whether your security controls prevent or detect the latest techniques attackers use to steal data from organizations. It exercises security controls such as EDRs, firewalls, IDS/IPS, email security, and web application firewalls, with results showing where each control works and where protection falls short.

Figure 1. Example Picus simulation results showing which threats were blocked, triggered alerts, were only logged, or were missed.

The Picus Threat Library, maintained by Picus Labs and refreshed daily, keeps these tests aligned with current malware, threat groups, and attack techniques. Its MITRE ATT&CK mappings help teams understand which behaviors their defenses cover and which need attention.

Figure 2. Picus Threat Library, Endpoint Attacks Module

After finding gaps, the Picus Mitigation Library supplies prevention and detection content for your specific security products, along with vendor-neutral Sigma rules, to deploy the fix with one click. After fixing the gap, you can retest the security control to see if it works correctly.

Figure 3. Picus Mitigation Library provides vendor-specific and vendor-neutral mitigation.

Figure 3. Picus Mitigation Library provides vendor-specific and vendor-neutral mitigation.

Additionally, the Data Exfiltration Attacks Module in Picus Breach and Attack Simulation simulates attempts to move data out of your systems. Using artificial test data, it checks whether data loss prevention (DLP) and network security controls would block or detect the tested transfers.

The module includes a Country Specialized Data (India) Exfiltration Campaign, along with campaigns for PDF, XLS(X), and DOC(X) files. These scenarios help teams assess protection across file formats commonly used to store and share personal data, such as customer reports and spreadsheets.

Figure 4. Picus Data Exfiltration Attacks Module showing India-specific and PDF, spreadsheet, and document campaigns.

Figure 4. Picus Data Exfiltration Attacks Module showing India-specific and PDF, spreadsheet, and document campaigns.

After the simulation, results show which simulated attempts were blocked, triggered alerts, were only logged, or went unnoticed. These findings help teams identify where data could leave without an effective response and which controls need attention.

Protecting personal data also means addressing the weaknesses an attacker could exploit to reach it in the first place. For example, an unpatched vulnerability in an internet-facing application could give an attacker access to customer records or a foothold from which to reach other systems holding personal data. As new CVEs add to the remediation backlog, teams need to identify which vulnerabilities put that data at the greatest risk.

Vulnerability prioritization helps teams make that decision. It considers whether a weakness could actually be exploited despite existing security controls and how important the affected asset is to the business. This helps teams direct remediation efforts toward the weaknesses that matter most to data protection.

Picus supports this prioritization by combining security control performance with exploitability, vulnerability severity, and business context.

Where a suitable public exploit is available for a CVE, Picus Autonomous Penetration Testing uses AI agents to run the exploit and validate attack paths within boundaries set by your team. By connecting weaknesses across systems, it reveals how an attacker could move from an initial foothold to critical assets. These validated paths show what an attacker could reach and the potential extent of a compromise.

Figure 5. Picus Autonomous Penetration Testing showing a validated attack path to an asset.

However, some CVEs have no working public exploit. Also, a system may be too critical to allow live exploitation. Picus Exposure Validation supports these cases by determining whether a CVE is exploitable in your environment without running a live exploit against the critical system.

Together, these capabilities help teams identify which CVEs matter most among the many newly disclosed vulnerabilities. By considering exploitability, control performance, and asset criticality, teams can focus remediation on exposures that pose the greatest risk to personal data. This turns each exposure into a documented decision: patch it, mitigate it, monitor it, or accept it with evidence.

As frontier AI models help attackers move faster, teams need to validate their defenses at a pace that keeps up. Picus Swarm brings autonomy to this process through five specialist AI agents coordinated by Numi AI. The agents work together across discovery, exploitation, validation, remediation, and reporting.

Numi AI continuously monitors external feeds and internal changes. With signal-driven workflows, teams define which events trigger validation, such as a new CVE, an updated detection rule, or a security-control configuration change. The agents coordinate the response, apply fixes, and revalidate the results. Teams can choose manual, supervised, or fully autonomous operation for each workflow, with an audit trail of the actions taken.

This gives the organization a record of control performance, prioritized exposures, improvements made to security controls, and retest results. These results help teams check how well their security controls protect personal data and support compliance with Section 8(5).

Section 8(6) and Rule 7: Reporting Breaches

“In the event of a personal data breach, the Data Fiduciary shall give the Board and each affected Data Principal, intimation of such breach in such form and manner as may be prescribed.” (DPDPA, Section 8(6))

“On becoming aware of any personal data breach, the Data Fiduciary shall, to the best of its knowledge, intimate to each affected Data Principal, in a concise, clear and plain manner and without delay, through her user account or any mode of communication registered by her with the Data Fiduciary, — (a) a description of the breach, including its nature, extent and the timing of its occurrence; ...” (DPDP Rules, Rule 7(1))

“On becoming aware of any personal data breach, the Data Fiduciary shall intimate to the Board, — (a) without delay, a description of the breach, including its nature, extent, timing and location of occurrence and the likely impact; (b) within seventy-two hours of becoming aware of the breach, or within such longer period as the Board may allow on a request made in writing in this behalf, — (i) updated and detailed information in respect of such description; (ii) the broad facts related to the events, circumstances and reasons leading to the breach; (iii) measures implemented or proposed, if any, to mitigate risk; ... (v) remedial measures taken to prevent recurrence of such breach; ...” (DPDP Rules, Rule 7(2)(a)–(b))

Initial notifications must be made without delay. The fuller report to the Data Protection Board of India is due within 72 hours of becoming aware of the breach, unless the Board grants more time following a written request. Rule 7 requires details about the incident, measures to reduce risk, and remedial steps taken to prevent a similar breach.

Preparing this information is easier when teams already have records of security testing and improvements. After a breach, they also need evidence of the steps taken to address the weaknesses involved.

How Does Picus Support This Requirement?

Before a breach, Picus validation reports document which security controls were tested, the gaps identified, and the results of retesting after improvements. These records help teams demonstrate the security validation work carried out to protect personal data before the incident.

If a breach occurs, teams can use these records alongside incident investigation findings when preparing the Board's 72-hour report. They provide context about previously tested safeguards and improvements to security controls. Having this evidence available helps security, privacy, and legal teams assemble a documented account of the measures taken.

Picus simulation findings also support breach-response exercises. Teams can practice how an alert is escalated, who investigates the potentially affected data, and how the information reaches the people preparing the notices.

After the incident is contained and security controls are updated, teams can use Picus Breach and Attack Simulation to test techniques associated with the threat involved. Retesting checks whether the updated controls block or detect those techniques and reveals any remaining gaps. This helps teams reduce the risk of a similar breach and provides evidence of the effectiveness of the tested improvements.

These results can support the account of remedial measures taken to prevent recurrence in the Board report under Rule 7(2)(b)(v). Together with the incident findings, they help the organization explain what it tested before the breach, what it changed afterward, and how the updated defenses performed.

Rule 6(1)(c) and (e): Monitoring Access and Keeping Supporting Records

“visibility on the accessing of such personal data, through appropriate logs, monitoring and review, for enabling detection of unauthorised access, its investigation and remediation to prevent recurrence;” (DPDP Rules, Rule 6(1)(c))

“for enabling the detection of unauthorised access, its investigation, remediation to prevent recurrence and continued processing in the event of such a compromise, retain such logs and personal data for a period of one year, unless compliance with any law for the time being in force requires otherwise;” (DPDP Rules, Rule 6(1)(e))

Monitoring is one of the safeguards that needs regular checks. Detection can fail in several ways. A system may stop sending logs. A change to a log field may stop a rule from recognizing an event. A rule may run too slowly to produce a useful alert. Teams need to know which problem they are dealing with before they can fix it.

How Does Picus Support This Requirement?

Picus Breach and Attack Simulation tests detection coverage, while the Picus Mitigation Library supplies content to address identified gaps. Teams can deploy detection fixes with one click and retest the results.

Additionally, Picus Detection Rule Validation examines the health of detection rules without running an attack simulation. It checks log sources, alerting, and performance to identify detection rules that are broken, silent, skipped, or never fire. Teams can review the findings for each rule, address the issues, and revalidate to check that the fixes work.

Figure 6. Picus Detection Rule Validation showing findings for log sources, alerting, and performance.

Figure 6. Picus Detection Rule Validation showing findings for log sources, alerting, and performance.

These findings help the SOC maintain the rules it relies on to monitor access to personal data. They help teams assess monitoring effectiveness under Rule 6(1)(c). To meet Rule 6(1)(e), the organization also needs to keep the required logs and personal data for the applicable retention period; simulation reports alone do not meet that duty.

Section 10 and Rule 13: Assessments and Audits for Significant Data Fiduciaries

“The Significant Data Fiduciary shall— (a) appoint a Data Protection Officer who shall— ... (ii) be based in India; ... (b) appoint an independent data auditor to carry out data audit, who shall evaluate the compliance of the Significant Data Fiduciary in accordance with the provisions of this Act; ...” (DPDPA, Section 10(2)(a)–(b))

“A Significant Data Fiduciary shall, once in every period of twelve months from the date on which it is notified as such or is included in the class of Data Fiduciaries notified as such, undertake a Data Protection Impact Assessment and an audit to ensure effective observance of the provisions of this Act and the rules made thereunder.” (DPDP Rules, Rule 13(1))

“A Significant Data Fiduciary shall cause the person carrying out the Data Protection Impact Assessment and audit to furnish to the Board a report containing significant observations in the Data Protection Impact Assessment and audit.” (DPDP Rules, Rule 13(2))

These extra duties apply when the Central Government officially identifies an organization as a Significant Data Fiduciary. Handling a large amount of personal data does not automatically put an organization in this category.

These organizations must carry out a Data Protection Impact Assessment (DPIA). This review asks what personal data the organization uses, how that use could harm people's privacy, and what safeguards are needed. Security test results support this assessment by showing how the tested safeguards perform and where improvements are needed.

How Does Picus Support This Requirement?

Picus provides weekly and monthly technical reports that help teams review security control performance over time. They bring simulation results into a regular record that security teams, privacy teams, and auditors can use to track gaps and improvements.

The technical report includes a security score overview, score trends, and detailed results by attack module and security device. It shows which threats were blocked or not blocked, which attacker objectives were achieved or prevented, and what was not tested. These details help reviewers see where defenses worked and where protection needs attention.

MITRE ATT&CK tactic and technique coverage shows which attack behaviors were tested and how controls performed against them. Benchmarks compare scores with Picus customer, regional, and industry averages. The report also highlights commonly simulated threats and templates, helping teams identify areas to consider for further testing.

Figure 7. Picus MITRE ATT&CK results showing blocked, logged, and alerted actions across Initial Access, Execution, Persistence, and Stealth tactics.

Teams can also create custom dashboards using widgets to focus on the security metrics that matter most to their organization. By selecting and arranging widgets, they can bring relevant results into one view, making it easier to review control performance, follow progress, and highlight areas that need attention.

Figure 8. Picus dashboard widgets showing security scores, trends, and MITRE ATT&CK coverage.

These capabilities give the organization security evidence for its DPIA and independent audit under Section 10 and Rule 13. Comparing results across weeks and months helps reviewers assess how the tested safeguards perform and whether protection improves over time.

How Can You Start Preparing for DPDPA Compliance with Picus?

Start with one business process that uses personal data, such as customer registration or account support. Identify the systems and suppliers involved and the controls protecting the data. Use Picus to test the defenses, find gaps, and apply one-click fixes. Run the tests again to confirm that the fixes close the gaps.

After these tests, Picus provides weekly or monthly reports on what was blocked, what generated an alert, what was only logged, and what was missed. These reports help privacy teams and auditors review control performance and improvements. Its signal-driven workflows automatically trigger relevant retests when they detect new threats or changes to security-control configurations, such as firewall policies or detection rules, keeping the evidence up to date.

Picus brings testing, fixes, and retesting into the same security workflow. Teams can improve their defenses and keep evidence of the results as they prepare to meet DPDPA requirements.

Book a Picus demo to see how security validation can help you prepare for DPDPA compliance and test the safeguards protecting personal data.

Table of Contents

Ready to start? Request a demo