Choose Language
Google Translate
Skip to content
Facebook X-twitter Instagram Linkedin Youtube
  • sales@cybernx.com
  • +91 90823 52813
CyberNX Logo
  • Home
  • About
    • About Us
    • CERT-In Empanelled Cybersecurity Auditor
    • Awards & Recognition
    • Our Customers
  • Services

    Peregrine

    • Managed Detection & Response
    • AI Managed SOC Services
    • Elastic Stack Consulting
    • CrowdStrike Consulting 
    • Threat Hunting Services
    • Digital Risk Protection Services
    • Threat Intelligence Services
    • Digital Forensics Services
    • Brand Risk & Dark Web Monitoring
    • Full Stack Observability

    Pinpoint

    • Red Teaming Services
    • Vulnerability Assessment
    • Penetration Testing Services
    • Secure Code Review Services
    • Cloud Security Assessment
    • Phishing Simulation Services
    • Breach and Attack Simulation Services

    nCompass

    • Cybersecurity Audit Services
    • Virtual CISO Services
    • DPDP Act Consulting
    • ISO 27001 Consulting
    • RBI Master Direction Compliance
    • SEBI CSCRF Framework Consulting
    • SEBI Cloud Framework Consulting
    • Security Awareness Training
    • Cybersecurity Staffing Services

    NXRadar

    • SBOM Solutions
    • CBOM Solutions
    • AIBOM Solutions
  • Industries
    • Banking
    • Financial Services
    • Insurance
  • Resources
    Blogs
    Case Studies
    Downloads
    Whitepapers
    Buyer’s Guide
    Research & Guides
  • Careers
  • English (US)
    • English
Contact Us
CyberNX Logo
  • English (US)
    • English
  • Home
  • About
    • About Us
    • CERT-In Empanelled Cybersecurity Auditor
    • Awards & Recognition
    • Our Customers
  • Services

    Peregrine

    • Managed Detection & Response
    • AI Managed SOC Services
    • Elastic Stack Consulting
    • CrowdStrike Consulting
    • Threat Hunting Services
    • Digital Risk Protection Services
    • Threat Intelligence Services
    • Digital Forensics Services
    • Brand Risk & Dark Web Monitoring
    • Full Stack Observability

    Pinpoint

    • Red Teaming Services
    • Vulnerability Assessment
    • Penetration Testing Services 
    • Secure Code Review Services
    • Cloud Security Assessment
    • Phishing Simulation Services
    • Breach and Attack Simulation Services

    nCompass

    • Cybersecurity Audit Services
    • Virtual CISO Services
    • DPDP Act Consulting
    • ISO 27001 Consulting
    • RBI Master Direction Compliance
    • SEBI CSCRF Framework Consulting
    • SEBI Cloud Framework Consulting
    • Security Awareness Training
    • Cybersecurity Staffing Services

    NXRadar

    • SBOM Solutions
    • CBOM Solutions
    • AIBOM Solutions
  • Industries
    • Banking
    • Financial Services
    • Insurance
  • Resources
    Blogs
    Case Studies
    Downloads
    Whitepapers
    Buyer’s Guide
    Research & Guides
  • Careers
  • Contact

Log Retention under DPDPA: What the One-Year Rule Really Means

4 min read
8 Views
  • DPDPA

Every breach investigation basically starts with the same two questions: What happened, and when did it start? The answers to these questions mostly live in logs. And if those logs rolled off your storage 40 days ago, the answers are lost.

That gap used to be an operational embarrassment. Under India’s data protection framework, that is becoming a compliance exposure. The Digital Personal Data Protection Rules, 2025 introduce a specific one-year retention requirement for certain logs and personal data, with Rule 6 scheduled to take effect on May 13, 2027.

Log retention under DPDPA is one of the few requirements in the Rules with a hard number in it. This guide covers what that number is, which logs it applies to, how it stacks with CERT-In and sector rules and how to build a retention setup that survives an audit.

Table of Contents

What does log retention under DPDPA require?

Rule 6 of the DPDP Rules, 2025 lists the reasonable security safeguards every Data Fiduciary must have in place. Logging appears twice in that list. Once as monitoring and visibility, and once as retention.

The Data Security Council of India’s FAQs on reasonable security safeguards explain the requirement plainly. For the purpose of detecting, investigating and remediating unauthorised access, a Data Fiduciary must retain logs and the associated personal data for one year, unless another law in force requires a different period.

Two details in that sentence matter more than the number itself.

  • The purpose is investigation: retention exists so a breach can be reconstructed, which means the logs must be usable, not just stored
  • One year is a floor, not a ceiling: any other applicable law can push the period up
  • The obligation follows your processors: Rule 6 requires contracts with Data Processors to carry equivalent safeguards, so a vendor’s 30-day log policy becomes your problem

The same FAQs note that failure to maintain reasonable security safeguards can attract a penalty of up to Rs. 250 crores under the Schedule to the DPDP Act. Most operational obligations under the Rules become enforceable on May 13, 2027.

Which logs actually count

The Rules do not publish a log source list, which leaves teams guessing. A workable test is simple. If a log helps you answer who touched personal data, when and whether they were allowed to, it is in scope.

  • Authentication and access logs: logins, failed attempts, session details, privileged access
  • Administrative activity: permission changes, role grants, configuration edits
  • Application and database activity: reads, writes, exports and queries against personal data
  • Consent events: consent given, refreshed or withdrawn, with timestamps
  • Erasure and retention actions: deletion jobs, retention exceptions and the 48-hour pre-erasure notices
  • Security tooling output: alerts, detections and case notes from your monitoring stack

Access logs are usually well covered. Proof that consent was valid at the time of processing, and that data was actually deleted when it should have been, is rarely logged with the same discipline.

How the one-year rule sits with CERT-In and sector rules

For Indian firms, DPDPA is not the only clock running. The CERT-In Directions require entities to enable logs of all their ICT systems and maintain them securely for a rolling period of 180 days, within Indian jurisdiction. RBI and SEBI expectations run longer still for critical systems, and SEBI-regulated entities carry tier-specific obligations.

Stacking these rules is where teams get into trouble. A single blanket retention setting either overspends on storage or quietly breaches one of the frameworks. The workable approach is to set retention per log category against the longest applicable requirement, then document why each period was chosen.

Five steps to build defensible log retention

Defensible means you can produce the right logs, for the right period, without a scramble.

Log Retention Checklist

  • Inventory your log sources: Start from systems that touch personal data and work outwards. Include SaaS platforms, cloud services and processor systems, not just infrastructure you own.
  • Set retention by category: Map every log type to its longest applicable clock. Rule 6’s one-year security-log requirement, Rule 8’s one-year processing-log requirement where applicable, CERT-In’s 180-day ICT-log requirement, and longer sector-specific or contractual requirements.
  • Close the gaps in the timeline: A year of coverage means twelve unbroken months. Hot storage plus archive is fine. Silent gaps during a migration or a licence downgrade are not.
  • Protect the logs themselves: Logs hold personal data, so encryption, access control and tamper evidence apply to them too. Retention is not a licence to keep everything forever.
  • Test retrieval process: Ask for a record from month ten and time how long it takes. That is the number an auditor and an investigator both care about.

Conclusion

Rule 6 gives Indian companies something unusually clear to work with. One year, for logs and the personal data attached to them, so that a breach can be investigated properly.

The harder part is everything around that number. Coverage across processor systems, consent and deletion events captured with the same rigour as access events, and retrieval that works under pressure rather than in theory.

At CyberNX, our Digital Personal Data Protection Act consulting team helps enterprises design log retention under DPDPA that holds up across CERT-In, RBI and SEBI expectations without duplicating cost or effort.

Talk to our experts and find out where your log timeline breaks today.

Log retention under DPDPA FAQs

How long must logs be kept under the DPDP Rules, 2025?

Rule 6 requires a Data Fiduciary to retain logs and the associated personal data for one year, for the purpose of detecting, investigating and remediating unauthorised access. That period applies unless another law in force requires a different one, which makes it a minimum rather than a fixed limit.

Does the one-year rule replace the CERT-In 180-day requirement?

No. They address different requirements. The two run in parallel and serve different regulators. CERT-In requires ICT system logs to be maintained for a rolling 180 days within Indian jurisdiction, while Rule 6 sets a one-year period for logs tied to personal data. Sector-specific rules can require longer retention. For example, SEBI’s CSCRF requires user-access logs for critical systems to be maintained for at least two years.

Are logs themselves treated as personal data?

Often, yes. Access logs, session records and consent trails routinely contain identifiers, so the security safeguards under Rule 6 apply to the log store as well. Encryption, access control and clear ownership matter as much for logs as for the primary database.

What do auditors usually find missing?

Three things recur. Log coverage that stops at owned infrastructure and misses processor or SaaS systems. Timeline gaps created by tool changes or storage limits. And retrieval that has never been tested, so nobody knows how long it takes to produce a record from ten months ago.

Author
Krishnakant Mathuria
LinkedIn

With 12+ years in the ICT & cybersecurity ecosystem, Krishnakant has built high-performance security teams and strengthened organisational resilience by leading effective initiatives. His expertise spans regulatory and compliance frameworks, security engineering and secure software practices. Known for uniting technical depth with strategic clarity, he advises enterprises on how to modernise their security posture, align with evolving regulations, and drive measurable, long-term security outcomes.

Share on

WhatsApp
LinkedIn
Facebook
X
Pinterest

For Customized Plans Tailored to Your Needs, Get in Touch Today!

Connect with us

RESOURCES

Related Blogs

Explore our resources section for insightful blogs, articles, infographics and case studies, covering everything in Cyber Security.
DPDPA Readiness Maturity Model: Where Do You Stand Today?

DPDPA Readiness Maturity Model: Where Does Your Organisation Sit?

Ask three teams inside the same company how ready they are for India’s data protection law and you may get

Find Out Common DPDPA Compliance Mistakes to Avoid

Common DPDPA Compliance Mistakes to Avoid

Previously, we have covered Penalties under the DPDP Act which tells you what non-compliance costs. This blog looks at the

DPDPA Gap Analysis with Scoring Framework

DPDPA Gap Analysis: Practical Scoring Framework for Compliance Teams

As compliance deadline looms, a DPDPA gap analysis will do a world of good for enterprises operating in India. A

RESOURCES

Cyber Security Knowledge Hub

Explore our resources section for insightful blogs, articles, infographics and case studies, covering everything in Cyber Security.

BLOGS

Stay informed with the latest cybersecurity trends, insights, and expert tips to keep your organization protected.

CASE STUDIES

Explore real-world examples of how CyberNX has successfully defended businesses and delivered measurable security improvements.

DOWNLOADS

Learn about our wide range of cybersecurity solutions designed to safeguard your business against evolving threats.
CyberNX Footer Logo
Book a Free Call

Peregrine

  • Managed Detection & Response
  • AI Managed SOC Services
  • Elastic Stack Consulting
  • CrowdStrike Consulting
  • Threat Hunting Services
  • Digital Risk Protection Services
  • Threat Intelligence Services
  • Digital Forensics Services
  • Brand Risk & Dark Web Monitoring
  • Full Stack Observability

Pinpoint

  • Red Teaming Services
  • Vulnerability Assessment
  • Penetration Testing Services
  • Secure Code Review Services
  • Cloud Security Assessment
  • Phishing Simulation Services
  • Breach and Attack Simulation Services

nCompass

  • Cybersecurity Audit Services
  • Virtual CISO Services
  • DPDP Act Consulting
  • ISO 27001 Consulting
  • RBI Master Direction Compliance
  • SEBI CSCRF Framework Consulting
  • SEBI Cloud Framework Consulting
  • Security Awareness Training
  • Cybersecurity Staffing Services

NXRadar

  • SBOM Solutions
  • CBOM Solutions
  • AIBOM Solutions
  • About
  • CERT-In
  • Awards
  • Careers
  • Sitemap
Facebook Twitter Instagram Youtube

Copyright © 2026 CyberNX | All Rights Reserved | Terms and Conditions | Privacy Policy

  • English (US)
    • English
Copyright © 2026 CyberNX | All Rights Reserved | Terms and Conditions | Privacy Policy
Scroll to Top

WhatsApp us

Not Sure Where to Start with Cybersecurity?

We value your privacy. Your personal information is collected and used only for legitimate business purposes in accordance with our Privacy Policy.