Cybersecurity 2026

INDIA Law and Practice Contributed by: Anoop Narayanan, Priyanka Gupta and Harshita Sakarya, ANA Law Group

mented by organisations for compliance with reason - able security practices and procedures. The DoT also mandates the security testing and cer - tification for telecoms equipment sold, imported or used in India, such as IP Routers, Wi-Fi Customer Premises Equipment (CPEs), Optical Line Terminals (OLTs), etc, under the Communication Security Certi - fication Scheme (ComSec). With regards to CII organisations, the NCIIPC Guide - lines prescribe security certifications by third-party agencies (government or private agencies) to protect the assets of a CII for smooth and error-free opera - tion. The certifications must also deal with enforcing or implementing any international security standards available globally for the protection of critical assets working in the CII by respective organisations. Each CII must list the certifications needed to be imple - mented for the protection of their assets and the areas involved. In addition to the certification of the CII facility, the CII must also ensure that the personnel hold certifica - tions relevant to their responsibilities and up to date with the current standards. Accordingly, knowledge- upgrade programmes via new certifications, training, seminars, workshops, etc, should also be planned for employees based on the requirements of the CIIs. The implementation process of the security certifications should also be properly monitored by the CII man - agement, so that it does not interfere with the normal functioning of the CII. 6. Cybersecurity in Other Regulations 6.1 Cybersecurity and Data Protection The DPDPA and the associated DPDP Rules represent a structural shift in India’s data governance landscape and introduce baseline cybersecurity obligations in the context of personal data processing. The Act requires data fiduciaries to implement reasonable security safeguards to prevent personal data breaches, tak - ing into account the volume and sensitivity of personal data processed, the potential harm to data principals, and the nature of processing activities. These safe - guards are intended to operate alongside, and not in

substitution of, cybersecurity obligations under the IT Act, and sector-specific regulatory frameworks. Further, data fiduciaries are required to take informed consent from their users and anyone whose data they collect, by giving a summary of what data they are col - lecting, and how they will use it. The DPDPA also gives users the right to erase or modify data they provide to data fiduciaries or to delete it. After a specific period of inactivity, data fiduciaries are under an obligation to delete the data they have on data principals. The Act and Rules also introduce the concept of a “Con - sent Manager”, enabling individuals to manage con - sent across multiple data fiduciaries through a single interface. A personal data breach is defined broadly to include unauthorised processing, accidental disclosure, loss of access, or compromise of personal data, irrespec - tive of whether actual harm has materialised. Data fiduciaries are required to notify the DPBI within 72 hours of becoming aware of the breach. Where the breach is likely to cause harm to data principals, affected individuals must also be informed in a clear and timely manner. Notifications to the DPBI must include the nature and circumstances of the breach, the categories and approximate volume of personal data and data princi - pals affected, the likely consequences of the breach, and the remedial measures taken or proposed. At present, the SPDI Rules prescribe the protection of personal information and sensitive personal data, and reasonable security practices and procedures to be implemented for collection and the processing of personal information or sensitive personal data. The SPDI Rules require all body corporates to implement reasonable security practices and standards, as well as to document their security programmes and poli - cies. However, once the DPDPA is implemented with full effect in May 2027, it will repeal the SPDI Rules. These obligations operate in parallel with incident reporting requirements under the CERT-In Directions, resulting in multi-agency reporting for cyber incidents involving personal data. This mandates co-ordination between cybersecurity and data protection functions,

203 CHAMBERS.COM

Powered by