What SEBI asks, verbatim
Does the entity have a framework / policy on cyber security and risks related to data privacy? (Yes/No) If available, provide a web-link of the policy
Disclose existence of cyber security and data privacy framework/policy and provide web-link.
Quoted from the SEBI BRSR Format as amended March 2025, with measurement guidance from the ICAI Background Material on BRSR, Revised Edition 2024, page 152.
In plain English
The disclosure asks whether the company has a written policy or framework that covers cyber security and data privacy. If it does, the company must say “Yes” and give the URL where the policy can be found. The information is usually taken from the company’s website or its internal policy documents.
What a complete, assurance-ready answer contains
A complete, assurance‑ready answer confirms the policy’s existence, states the policy’s scope (e.g., all data processing, third‑party vendors, cloud services), and supplies a permanent, publicly accessible web‑link that is not behind authentication. Assurers look for a clear reference to the policy’s version, effective date, and the responsible governance body (e.g., board or IT security committee). A common gap is omitting the policy’s version or providing a link that redirects to a generic homepage rather than the specific policy document.
Describes the completeness and granularity an assurer expects. No company figures are named.
Where the data comes from
Usually found in complaints and product records. Forward to your Customer service or Legal team.
Much of what BRSR asks for already exists in filings the company makes elsewhere, such as Pollution Control Board consents, PAT returns, hazardous-waste manifests and EPR registrations. The free gap analysis cross-references those filings against all 108 fields and shows which are already covered.
Frequently asked questions
What does BRSR P9-E5 ask for?
The disclosure asks whether the company has a written policy or framework that covers cyber security and data privacy. If it does, the company must say “Yes” and give the URL where the policy can be found. The information is usually taken from the company’s website or its internal policy documents.
Is BRSR P9-E5 an Essential or a Leadership indicator?
P9-E5 is an Essential indicator, so it is mandatory for every BRSR filer. It sits under Principle 9, Consumer Responsibility.
Who inside the company holds the data for P9-E5?
Customer service / Legal. Usually found in complaints and product records. Forward to your Customer service or Legal team.
What unit does P9-E5 use?
Yes/No + web-link. Reporting in the wrong unit, or switching the denominator of an intensity ratio between years, is one of the more common reasons a figure has to be restated.
What does a complete answer to P9-E5 look like?
A complete, assurance‑ready answer confirms the policy’s existence, states the policy’s scope (e.g., all data processing, third‑party vendors, cloud services), and supplies a permanent, publicly accessible web‑link that is not behind authentication. Assurers look for a clear reference to the policy’s version, effective date, and the responsible governance body (e.g., board or IT security committee). A common gap is omitting the policy’s version or providing a link that redirects to a generic homepage rather than the specific policy document.
Other disclosures under Principle 9
How you receive and respond to consumer complaints and feedback (mechanism)
% of turnover from products carrying info on environmental / social parameters and safe use
Consumer complaints by type (data privacy, advertising, cyber-security, quality, etc.)
Product recalls on safety grounds (number and reasons)
Corrective actions on advertising, cyber-security / privacy, recalls, or regulator penalties
Data breaches this year (number, % involving personal data, impact)
See P9-E5 against a real client
Describe a client in six fields and get all 108 BRSR disclosures classified as ready to pull, needs verification, or collect fresh, with the calculators built in. Free, no login, and nothing leaves your browser.