Section 28(2)(v) in The Credit Information Companies Rules, 2006
(v)ensure that the system adopted for the purpose is sufficiently adequate to protect against any unauthorised modification or deletion of the data, information or credit information maintained by them;