What do the DPDP Rules and the CERT-In Directions require of your network logs?

Written, not yet published. This route is noindex and is absent from the guides index until it is released.

The short answer

Under the DPDP Rules notified in November 2025, logs of access to personal data must be retained for a year, with full compliance due on 13 May 2027. The CERT-In Directions already require 180 days of ICT logs held in India and a cyber incident reported within six hours. Where the two differ, the longer applies.

Updated

The two instruments, and which one binds you first

 CERT-In Directions, 28 April 2022DPDP Rules 2025
StatusAlready in forceNotified November 2025; substantive obligations enforceable from 13 May 2027
Log retentionA rolling 180 days, held within Indian jurisdictionA one-year floor for logs of access to personal data
On an incidentReported within six hours of being noticedNotification to the Data Protection Board on discovery, and to affected individuals within seventy-two hours
Also requiredClocks synchronised to NIC or NPL time servers; logs produced to CERT-In on requestEncryption and access control on personal data

Where the two differ, the longer applies. One year of logs rather than 180 days. Sectoral regulators in banking and financial services impose longer periods again, and those take precedence over both.

What that means for the network itself

A retention obligation is only met if the log identifies a person. A session authenticated on a surname and a room number produces a log that satisfies the retention period and answers no question anybody will actually ask.

So the work is upstream of the logging: onboarding that ties a session to an identity, access control across wired, wireless and VPN that survives an audit, and clocks that agree with each other. The log is the last step, not the first.

Most programmes take nine to twelve months. Counting back from 13 May 2027, that is already the current planning horizon rather than a future one.

Which provisions reach your operation

That depends on what you process, for whom, and under which sectoral regulator, and where a telecom or internet-provider obligation applies, internet protocol detail records fall within it. Whether that reaches you is a question for your counsel, not for us. We state what the obligation requires of the network and cite the instrument that creates it; what follows from breaching it is theirs to advise on.

Sources

  • DPDP Rules 2025
  • CERT-In Directions, 28 April 2022

Written and reviewed by Concept Equipments.