What do the DPDP Rules and the CERT-In Directions require of your network logs?
Written, not yet published. This route is noindex and is absent
from the guides index until it is released.
The short answer
Under the DPDP Rules notified in November 2025, logs of access to personal data must be retained for a year, with full compliance due on 13 May 2027. The CERT-In Directions already require 180 days of ICT logs held in India and a cyber incident reported within six hours. Where the two differ, the longer applies.
Updated
The two instruments, and which one binds you first
| CERT-In Directions, 28 April 2022 | DPDP Rules 2025 | |
|---|---|---|
| Status | Already in force | Notified November 2025; substantive obligations enforceable from 13 May 2027 |
| Log retention | A rolling 180 days, held within Indian jurisdiction | A one-year floor for logs of access to personal data |
| On an incident | Reported within six hours of being noticed | Notification to the Data Protection Board on discovery, and to affected individuals within seventy-two hours |
| Also required | Clocks synchronised to NIC or NPL time servers; logs produced to CERT-In on request | Encryption and access control on personal data |
Where the two differ, the longer applies. One year of logs rather than 180 days. Sectoral regulators in banking and financial services impose longer periods again, and those take precedence over both.
What that means for the network itself
A retention obligation is only met if the log identifies a person. A session authenticated on a surname and a room number produces a log that satisfies the retention period and answers no question anybody will actually ask.
So the work is upstream of the logging: onboarding that ties a session to an identity, access control across wired, wireless and VPN that survives an audit, and clocks that agree with each other. The log is the last step, not the first.
Most programmes take nine to twelve months. Counting back from 13 May 2027, that is already the current planning horizon rather than a future one.
Which provisions reach your operation
That depends on what you process, for whom, and under which sectoral regulator, and where a telecom or internet-provider obligation applies, internet protocol detail records fall within it. Whether that reaches you is a question for your counsel, not for us. We state what the obligation requires of the network and cite the instrument that creates it; what follows from breaching it is theirs to advise on.
The obligation names an organisation, not a department. Which one, in your building: who the obligation actually names.
What we did about the same framework in our own house: how we approached it.
Sources
- DPDP Rules 2025
- CERT-In Directions, 28 April 2022
Written and reviewed by Concept Equipments.