Compliance · DPDP
DPDP Act and employee security awareness training what the law actually asks for
The DPDP Act and the DPDP Rules do not mention staff awareness training. They require “reasonable security safeguards” and “appropriate technical and organisational measures”.
A documented awareness programme is one organisational measure you can point to, but it is not named or required. Here is what the text says, when it applies, and what SecurityRing can and cannot add.
Last reviewed 10 October 2026 against the official texts. Not legal advice.
The short answer
DPDP in three lines
Who it applies to
Data Fiduciaries processing digital personal data in India, or outside India when offering goods or services to people in India.
What it asks on awareness training
Reasonable security safeguards (s. 8(5), Rule 6) and appropriate technical and organisational measures (s. 8(4), Rule 6(1)(g)). Training is not named.
Where phishing simulation fits
It can help you show training and resilience in your safeguards file. Nothing in the Act or the Rules mentions training or phishing simulation.
Who it applies to
Who has to follow DPDP
The Act applies to the processing of digital personal data within India, and also outside India when the processing is connected with offering goods or services to Data Principals in India (section 3). A Data Fiduciary is any person who, alone or with others, determines the purpose and means of processing (section 2(i)).
What it asks for
What DPDP asks for on awareness training
The provisions that carry the security duty are below. Read with the whole text, neither the Act nor the Rules mention staff training or awareness programmes.
DPDP Act section 8(5)Official wording
A Data Fiduciary shall protect personal data in its possession or under its control, including in respect of any processing undertaken by it or on its behalf by a Data Processor, by taking reasonable security safeguards to prevent personal data breach.
DPDP Act section 8(4)Official wording
A Data Fiduciary shall implement appropriate technical and organisational measures to ensure effective observance of the provisions of this Act and the rules made thereunder.
DPDP Rules, 2025, Rule 6(1)Our paraphrase
Reasonable security safeguards must include, at the minimum: encryption, obfuscation, masking or virtual tokens; access controls; logs, monitoring and review to detect unauthorised access; backups for continued processing; retaining those logs and the personal data for one year unless the law requires otherwise; security provisions in contracts with Data Processors; and, at (g), “appropriate technical and organisational measures to ensure effective observance of security safeguards”.
DPDP Act section 8(6) and Rule 7Our paraphrase
After a personal data breach you must intimate the Data Protection Board and each affected Data Principal. Rule 7(2) requires detailed information to the Board within seventy-two hours of becoming aware, or a longer period the Board allows.
DPDP Act, Schedule, item 1Our paraphrase
For failure to take reasonable security safeguards to prevent a personal data breach (section 8(5)), the penalty may extend to two hundred and fifty crore rupees. The Data Protection Board decides after an inquiry.
Phishing simulation
Why phishing simulation helps
Phishing simulation lets you show that people were trained and that they were tested. Four reasons it helps come first; then, so you are not misled, we say exactly what the framework text itself asks for.
Test
A realistic simulated attack
SecurityRing sends a realistic simulated attack to your employees.
Teach
A short lesson after the click
A short lesson opens straight after the click, designed to take under two minutes.
Evidence
A report a reviewer can read
Campaign report, completion records, trend report and audit trail, exported as PPT, PDF or CSV.
Campaign results
Evidence for DPDP review
- People tested
- Opened
- Clicked
- Completed the lesson
In the report
- Completion records
- Trend report
- Audit trail
Export as
- PPT
- CSV
Show training and resilience
Employees are tested with realistic attacks, not only shown a course. Your reports show who was tested, how they behaved and what followed, so you can evidence resilience as well as training.
Faster, with less chasing
A simulation reaches people in their inbox. There is no long course to schedule and no constantly chasing employees to finish it, so your time goes where it is needed.
A short lesson at the right moment
When someone clicks, a short lesson opens straight away on the exact attack they just met, designed to take under two minutes. That saves you and your employees time compared with a long course.
Reports a reviewer can read
The campaign report, per-person completion records, executive trend report and dated audit trail, exported as PPT, PDF or CSV, serve as evidence of security training and phishing awareness and of actual resilience testing. Offer them alongside your other evidence.
Our view, not the law’s: stolen credentials and phishing are common routes to a breach. An ongoing simulation programme gives you dated campaign reports, completion records for the people who clicked and a trend report, which is a documented organisational measure (s. 8(4), Rule 6(1)(g)) you can add to your safeguards file to support your position that your safeguards are reasonable.
What DPDP says
The Act and the Rules do not mention training, awareness or phishing simulation.
The security duty is outcome-based: take reasonable safeguards to prevent a personal data breach. A simulation programme is supporting evidence, not a requirement being met.
Whether your safeguards are reasonable is for the Data Protection Board to judge.
Good to know
When do the security duties apply? Not yet, on the notified dates
The Act and Rules commence in phases, counted from the Gazette of India (Extraordinary) dated 13 November 2025: G.S.R. 843(E) for the Act and G.S.R. 846(E) for the Rules. The files carry a digital-signature stamp of 14 November, so a strict reading could put the dates a day later; we count from the 13 November date printed in the Gazette.
A Removal of Difficulties Order (S.O. 5458(E), Gazette of 6 October 2026) corrects the wording of sections 9(1) and 10(2)(c)(ii) only and does not change these dates. We found no other notified change as of 10 October 2026, but check the Gazette and MeitY before you rely on them.
- 13 November 2025 (on publication): sections 1(2), 2, 18 to 26 (the Data Protection Board), 35, 38 to 43 and 44(1) and (3) of the Act, and Rules 1, 2 and 17 to 21.
- 13 November 2026 (one year): Rule 4 (Consent Managers), and in the Act section 6(9) and section 27(1)(d).
- 13 May 2027 (eighteen months): the rest of the Act, including section 8 and its security safeguards duty in section 8(5), and Rules 3, 5 to 16, 22 and 23, including Rule 6 (security safeguards) and Rule 7 (breach intimation).
Evidence from SecurityRing
Evidence for DPDP from SecurityRing
SecurityRing can add a record of an ongoing awareness programme to your safeguards file. It gives evidence for the people side of safeguards, and only that.
| What DPDP asks | Evidence from SecurityRing |
|---|---|
| Appropriate organisational measures to observe the Act (s. 8(4), Rule 6(1)(g)) | Campaign reports, per-person lesson-completion records and the executive trend report show an ongoing simulation and follow-up programme and how click results change over time. |
| Reasonable security safeguards (s. 8(5), Rule 6) | Evidence for the awareness part of your safeguards only. Encryption, access control, logging, backups and processor contracts are outside SecurityRing. |
| Showing your safeguards to the Board if asked | Dated exports (PPT, PDF, CSV) and the interaction audit trail you can add to your safeguards file. |
What SecurityRing produces
- Campaign report. For each campaign: sent, opened, clicked, video completed and training completed, time to action, results by department, location, seniority and manager cohort, repeat exposure and recommended follow-up.
- Completion records. A per-person roster for each campaign, with drill-downs, showing who was phished, who finished the lesson and when. The lesson goes to people who act on a simulation, so this is not a record of training for your whole workforce.
- Executive trend report. Across campaigns over a six-month lookback: phishing exposure score, trends by department and senior management, response speed and a 30-day action plan.
- Audit trail. A dated interaction audit trail for each campaign: what each recipient did and when.
- PPT, PDF and CSV export. Download the campaign and executive trend reports as PPT, PDF or CSV for your auditor, or present them on screen.
What it does not do
- The DPDP Act does not require awareness training, so this is supporting evidence, not a requirement being met.
- SecurityRing does not provide the technical safeguards in Rule 6, breach intimation or consent management.
- SecurityRing’s lesson goes to people who click or submit in a simulation, not to every employee. Where a requirement covers all staff, keep your baseline training programme and use SecurityRing for simulation results and follow-up.
- SecurityRing’s reports are not mapped to DPDP clause numbers. You decide which report supports which clause, and your auditor decides whether it is enough.
This page is a plain-language summary for GRC teams, not legal advice. SecurityRing gives you evidence for the awareness-training part of a framework and helps you demonstrate it. Using SecurityRing does not make you compliant, it is not a certification, and no regulator or standards body endorses it. Your auditor or regulator decides whether the evidence is enough.
Does the DPDP Act require employee security awareness training?
No. Neither the Act nor the Rules mention staff training or awareness programmes. They require reasonable security safeguards to prevent a personal data breach (section 8(5)) and appropriate technical and organisational measures (section 8(4)). An awareness programme is one organisational measure you can document, but it is not named.
When do the DPDP security safeguard obligations apply?
Section 8 and Rule 6 come into force eighteen months after the 13 November 2025 Gazette notifications, which is 13 May 2027 by our count from the date printed in the Gazette. A Removal of Difficulties Order of October 2026 corrected only the wording of sections 9(1) and 10(2)(c)(ii). Check the Gazette and MeitY for updates before you rely on that date.
How can phishing simulation help with DPDP “reasonable security safeguards”?
The law does not mention training or simulation. It sets an outcome (prevent a personal data breach) and lists minimum technical measures in Rule 6. An ongoing simulation programme with dated reports, completion records and a trend report is a documented organisational measure that supports your case, but it is not required, and the Data Protection Board decides what is reasonable.
Does SecurityRing make us DPDP compliant?
No. SecurityRing gives you evidence for the awareness part of your safeguards and helps you demonstrate an ongoing programme. It does not provide encryption, access control, logging, backups or breach intimation, no regulator endorses it, and the Data Protection Board decides what is compliant.
Sources and how we checked
Last reviewed 10 October 2026. Quoted text is from the MeitY PDFs of the Act and the Rules, which we compared with the official eGazette copy of the Rules. The commencement dates are read from Rule 1(2) to (4) and from G.S.R. 843(E), both in the Gazette of India dated 13 November 2025, and counted from that date (the eGazette files were digitally signed on 14 November, so confirm the exact day with counsel before relying on it); PIB confirms the eighteen-month phased timeline. The Removal of Difficulties Order of 6 October 2026 was read in full and changes only the wording of sections 9(1) and 10(2)(c)(ii). Words searched across the Act and Rules: “awareness” does not appear, and “training” appears only in the name of a government department.
- Digital Personal Data Protection Act, 2023 (MeitY): sections 2, 3, 8 and the Schedule
- Digital Personal Data Protection Rules, 2025, G.S.R. 846(E) (MeitY): Rules 1, 6 and 7
- Gazette of India Extraordinary, No. 757, 13 November 2025: G.S.R. 843(E), dates on which the Act’s sections come into force (eGazette)
- Gazette of India Extraordinary, No. 760, 13 November 2025: G.S.R. 846(E), the Digital Personal Data Protection Rules, 2025, Rule 1 (eGazette)
- Gazette of India Extraordinary, No. 5248, 6 October 2026: S.O. 5458(E), Digital Personal Data Protection (Removal of Difficulties) Order, 2026 (eGazette)
- PIB: Government notifies DPDP Rules (14 November 2025)
See the evidence your DPDP reviewer will read
Book a demo to see how a campaign report, completion records and the executive trend report would look for your team, and how they line up with DPDP.