The DPDP Act does not prescribe a fixed list of security controls. Instead, Section 8(5) requires organizations to implement reasonable safeguards based on the risks associated with their processing activities.
In practice, this may include encryption, strong access controls, continuous monitoring, activity logging, backup and recovery, and incident response procedures. The safeguards should be proportionate to the type and sensitivity of the personal data being processed.