TL;DR: India’s DPDP Rules 2025 require encryption, logging, access control, breach notification, and accountability across data fiduciaries and processors, making privileged access management a core compliance control according to Arcon. The practical shift is that identity teams must treat admin access, audit trails, and forensic readiness as regulatory obligations, not optional hardening.
NHIMG editorial — based on content published by Arcon: DPDP Rules 2025 and PAM compliance mapping
By the numbers:
- Only 5.7% of organisations have full visibility into their service accounts.
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools.
- 92% of organisations expose NHIs to third parties, raising concerns about supply chain security.
Questions worth separating out
Q: How should organisations govern privileged access to personal-data systems under DPDP rules?
A: Organisations should treat privileged access as a regulated control surface, not an internal convenience.
Q: Why do standing admin accounts create compliance risk for personal-data processing?
A: Standing admin accounts create compliance risk because they expand the number of always-on paths that can reach personal data and make accountability harder to prove.
Q: What do identity teams get wrong about breach notification readiness?
A: They often focus on alerting while neglecting the evidence needed to explain the incident.
Practitioner guidance
- Map personal-data pathways to privileged identities Inventory every human admin account, service account, and automation path that can reach systems holding personal data.
- Replace standing privilege with time-bound elevation Move high-risk access to just-in-time approvals with automatic expiry, especially for production databases, cloud consoles, and application administration.
- Retain tamper-resistant session evidence for investigations Store privileged session logs, command output, and recordings in immutable archives for at least the legal retention window.
What's in the full article
Arcon's full blog post covers the operational detail this post intentionally leaves for the source:
- Rule-by-rule mapping of DPDP requirements to PAM functions, including how each control supports compliance evidence.
- Product-specific examples of session recording, credential vaulting, and just-in-time elevation in regulated environments.
- Checklist-style comparison of logging, retention, and breach reporting obligations against deployment steps.
- Implementation-oriented guidance on how privileged workflows are aligned to accountability and audit needs.
👉 Read Arcon's analysis of DPDP Rules 2025 and privileged access compliance →
DPDP Rules 2025 and PAM: what identity teams need to change?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
DPDP compliance turns privileged access into regulated evidence. The article is really about proof, not just control. If an organisation cannot demonstrate who accessed personal data, when they accessed it, and what they did, then it cannot satisfy the spirit of the rules even if policy language exists. For practitioners, PAM now sits in the same category as audit logging and incident response.
A few things that frame the scale:
- Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
- 71% of NHIs are not rotated within recommended time frames, increasing the risk of compromise over time.
A question worth separating out:
Q: Who is accountable when a third party accesses personal data outside policy?
A: The organisation remains accountable for the access model, even when processing is shared with contractors, outsourcers, or cloud providers. That is why third-party access must sit inside the same lifecycle, review, and offboarding process as internal access.
👉 Read our full editorial: DPDP Rules 2025 make privileged access a compliance control