Legal Register
Role-Based Pathway
Executive Role Lens

Chief Security Officer (CSO / CISO)

Reasonable security safeguards, dual-clock breach notification, tokenization, IAM and technical controls

Key Statutory Provisions

3 Enforced Provisions
Section 8(5) & Rule 6 Reasonable Security Safeguards & Technical Measures
View Act

Mandates implementation of reasonable security safeguards including end-to-end encryption, multi-factor authentication, perimeter isolation, and automated breach containment.

Section 8(6) & Rule 7 Personal Data Breach Detection & Dual-Clock Notification
View Act

Enforces strict incident management procedures with dual notification timelines: CERT-In 6-hour intimation and DPBI / affected Data Principal breach intimation under DPDP Rule 7.

Section 8(7) & Rule 8 Cryptographic Erasure & Account Inactivity Shredding
View Act

Technical execution of verifiable data erasure across primary and secondary storage, backup quarantine handling, and automated account inactivity purging.

Key Deliverables & Artifacts

4 Key Deliverables
Section 8(5) reasonable security safeguards baseline & technical blueprint (Ch. 15)
Dual-clock breach incident runbook: CERT-In (6h) & DPBI/Principals (72h) (Ch. 16)
Enterprise tokenization, masking & IAM access boundary architecture (Ch. 15, 18)
Restore quarantine & cryptographic tombstone reconciliation specification (Ch. 14, App E)