You can write the cleanest consent notice in India, but if you cannot tell when someone inside or outside the organisation has touched personal data they should not have, none of that notice actually protects anyone. This is a practical playbook for building that detection capability, aimed at the people who have to make it work: security engineers, DPOs and whoever owns the breach-response decision.

Logging as a legal requirement

Rule 6 sets a floor for security safeguards: encryption, access control, masking or tokenisation, and a minimum retention period for logs. Rule 8(3) extends that retention requirement to at least one year for all processing, not only for incidents already flagged as breaches. If you do not have access logs reaching back twelve months, you cannot reconstruct unauthorised use even after someone raises a concern about it.

Signals of unauthorised use

Detection is not just about external hacks. Most unauthorised use is an internal permissions issue or a compromised credential. You need to monitor the right signals.

  • Bulk exports of customer databases or financial records to external drives or personal emails.
  • Off-hours access to sensitive HR or payroll systems that fall outside a role's normal scope.
  • API keys or service accounts querying personal data at volumes that exceed normal application behaviour.
  • A sudden spike in Data Principal grievances under Section 13 regarding data they never shared with you.

Building the 72-hour workflow

Rule 7 does not allow a risk-based threshold before notification kicks in. Every personal data breach has to be reported to the Board within 72 hours. Ambiguity about who decides is the single most common reason organisations miss that deadline.

  • Name one specific individual who can authorise a Board notification without waiting for a committee to convene.
  • Treat every Data Processor contract as a real control point, ensuring audit rights and breach-notification clauses have teeth.
  • Run periodic access reviews against least privilege to revoke permissions nobody remembered to remove.
  • Document every investigation, even the false alarms, as a documented conclusion of no breach is a far stronger position than no investigation at all.

Detection is the underlying muscle that makes every other DPDP obligation, from the 72-hour breach clock to grievance redressal, actually achievable on time.