Module Scope
- Does the organisation understand and meet the privacy and data protection responsibilities applicable to the information it handles?
- Does the organisation effectively manage cybersecurity risk and protect its information, systems, and services from cyber threats and disruption?
- Does the organisation maintain appropriate capability to respond to cyber incidents and sustain or restore critical operations?
- Does the organisation identify and meet additional privacy, cybersecurity, and digital requirements arising from its activities, regulatory status, and services?
Module Application
The INDIA - PRIVACY AND DATA PROTECTION AND CYBERSECURITY module guides organisations on meeting the privacy, personal data protection, information security, and cybersecurity responsibilities that apply to their activities in India. It addresses requirements that vary according to an organisation's activities, sector, regulatory status, services, technologies, systems, and the information it handles, together with specialised requirements that apply to particular regulated sectors, infrastructure, and digital services.
The INDIA - PRIVACY AND DATA PROTECTION AND CYBERSECURITY module provides information to organisations about how to comply with legal responsibilities when dealing with the following:
- Information security and cybersecurity governance appropriate to the organisation's activities, systems, information, and regulatory status
- Privacy and personal data governance, including collection, use, consent, disclosure, transfer, individual rights, grievance redressal, retention, and purpose limitation
- Protection of systems, information, and technology assets against cybersecurity threats and unauthorised access, use, disclosure, alteration, loss, or disruption
- Cyber incident identification, reporting, response, remediation, and recovery
- Business continuity, disaster recovery, backup, restoration, and cyber resilience
- Technology outsourcing, third-party service providers, and cloud arrangements where sector-specific requirements apply
- Additional cybersecurity, audit, reporting, data protection, and resilience responsibilities applying to regulated financial-sector organisations
- Telecommunications cybersecurity and Critical Telecommunication Infrastructure requirements
- Aadhaar authentication, information security, confidentiality, audit, and ecosystem responsibilities
- Intermediary and digital platform responsibilities, including content governance, grievance handling, information preservation, and lawful Government requests
- Information access and records requirements applying to qualifying public authorities
- Registration, user verification, record-keeping, security, and inspection requirements applying to cyber cafés
The INDIA - PRIVACY AND DATA PROTECTION AND CYBERSECURITY module also comprehensively covers requirements arising under key Indian instruments and regulatory frameworks, including:
- The Information Technology Act 2000 and associated privacy, information security, intermediary,
- Protected System, and cyber café rules
- The Digital Personal Data Protection Act 2023 and Digital Personal Data Protection Rules 2025, including their phased commencement
- CERT-In directions and related cyber incident reporting requirements
- The Telecommunications Act 2023 and associated telecommunications cybersecurity, Critical
- Telecommunication Infrastructure, and lawful interception requirements
- The Aadhaar Act and associated authentication, offline verification, and data security regulations
- The Right to Information Act 2005
- Cybersecurity, technology risk, outsourcing, cloud, resilience, audit, and reporting frameworks administered by RBI, SEBI, IFSCA, PFRDA, and other relevant financial-sector regulators
The requirements covered by the module do not apply uniformly to every organisation operating in India. Organisations, their officers, and relevant personnel are expected to understand the requirements that arise from the organisation's activities, sector, regulatory classification, services, technologies, systems, and information handled. An organisation subject to more than one regulatory regime may need to comply with each applicable framework.
The INDIA - PRIVACY AND DATA PROTECTION AND CYBERSECURITY module should be subscribed to by any organisation that:
- Operates in India and collects, receives, possesses, stores, uses, deals with, or otherwise handles personal information or sensitive personal data or information
- Is subject to general or sector-specific information security, cybersecurity, cyber incident reporting, business continuity, or cyber resilience requirements
- Is regulated within a financial sector covered by RBI, SEBI, IFSCA, PFRDA, or another applicable financial-sector cybersecurity framework
- Uses outsourced technology, information-processing, or cloud arrangements that are subject to applicable sector-specific requirements
- Participates in the Aadhaar ecosystem or carries on telecommunications activities subject to the specialised requirements covered by the module
- Qualifies as an intermediary or significant social media intermediary
- Qualifies as a public authority for the information-access requirements covered by the module
- Operates a cyber café offering internet access to members of the public in India
- Is responsible for a Protected System or is otherwise subject to requirements relating to Critical
- Information Infrastructure or notified Critical Telecommunication Infrastructure
The specific questions and answers covered by the module include:
- How to comply with applicable requirements governing personal information and sensitive personal data or information
- How to address consent, disclosure, transfer, individual rights, grievance redressal, retention, purpose limitation, and applicable data localisation requirements
- How to establish cybersecurity governance and protect systems, information, and technology assets
- How to manage access, network security, encryption, vulnerability, testing, patching, secure development, asset governance, and personnel security requirements where applicable
- How to identify, assess, report, and respond to cybersecurity incidents and satisfy applicable national and sector-specific reporting responsibilities
- How to maintain business continuity, disaster recovery, backups, restoration capability, and cyber resilience
- How to manage regulatory responsibilities arising from outsourced technology, data-processing, and cloud service arrangements
- How to identify and comply with additional cybersecurity, audit, reporting, data-storage, and resilience requirements arising from financial-sector regulation
- How to comply with specialised telecommunications cybersecurity and Critical Telecommunication Infrastructure requirements
- How to meet applicable Aadhaar authentication, privacy, security, confidentiality, record-keeping, audit, and incident-reporting requirements
- How to comply with applicable intermediary and digital platform responsibilities
- How to comply with information-access requirements as a qualifying public authority and registration and record-keeping requirements as a cyber café operator
The INDIA - PRIVACY AND DATA PROTECTION AND CYBERSECURITY module outlines an organisation's obligations across the compliance lifecycle, including governance and accountability, protection of information and systems, identification and management of cyber risk, detection and reporting of incidents, response and remediation, business continuity, and recovery. Where applicable, the module also addresses audits, testing, personnel awareness, critical assets, third-party relationships, and cloud services.
The module distinguishes general requirements from obligations that apply only to particular sectors, regulated entities, infrastructure, activities, or digital roles. It also reflects the phased commencement of the Digital Personal Data Protection framework so that requirements not yet operative are distinguished from current compliance obligations.
Non-compliance may result, depending on the applicable regime and contravention, in regulatory directions, monetary penalties or compensation, criminal penalties, restrictions or loss of regulatory permissions, additional supervisory measures, or loss of statutory protections. Certain regimes may also impose liability on responsible individuals where the applicable legal conditions are satisfied.
The INDIA - PRIVACY AND DATA PROTECTION AND CYBERSECURITY module supports organisations in identifying the privacy, information security, cybersecurity, and specialised digital requirements arising from their activities and regulatory status and in understanding how those requirements apply to the handling of information, operation of systems and services, management of cyber risk, response to incidents, and maintenance of organisational resilience.