Every breach investigation basically starts with the same two questions: What happened, and when did it start? The answers to these questions mostly live in logs. And if those logs rolled off your storage 40 days ago, the answers are lost.
That gap used to be an operational embarrassment. Under India’s data protection framework, that is becoming a compliance exposure. The Digital Personal Data Protection Rules, 2025 introduce a specific one-year retention requirement for certain logs and personal data, with Rule 6 scheduled to take effect on May 13, 2027.
Log retention under DPDPA is one of the few requirements in the Rules with a hard number in it. This guide covers what that number is, which logs it applies to, how it stacks with CERT-In and sector rules and how to build a retention setup that survives an audit.
What does log retention under DPDPA require?
Rule 6 of the DPDP Rules, 2025 lists the reasonable security safeguards every Data Fiduciary must have in place. Logging appears twice in that list. Once as monitoring and visibility, and once as retention.
The Data Security Council of India’s FAQs on reasonable security safeguards explain the requirement plainly. For the purpose of detecting, investigating and remediating unauthorised access, a Data Fiduciary must retain logs and the associated personal data for one year, unless another law in force requires a different period.
Two details in that sentence matter more than the number itself.
- The purpose is investigation: retention exists so a breach can be reconstructed, which means the logs must be usable, not just stored
- One year is a floor, not a ceiling: any other applicable law can push the period up
- The obligation follows your processors: Rule 6 requires contracts with Data Processors to carry equivalent safeguards, so a vendor’s 30-day log policy becomes your problem
The same FAQs note that failure to maintain reasonable security safeguards can attract a penalty of up to Rs. 250 crores under the Schedule to the DPDP Act. Most operational obligations under the Rules become enforceable on May 13, 2027.
Which logs actually count
The Rules do not publish a log source list, which leaves teams guessing. A workable test is simple. If a log helps you answer who touched personal data, when and whether they were allowed to, it is in scope.
- Authentication and access logs: logins, failed attempts, session details, privileged access
- Administrative activity: permission changes, role grants, configuration edits
- Application and database activity: reads, writes, exports and queries against personal data
- Consent events: consent given, refreshed or withdrawn, with timestamps
- Erasure and retention actions: deletion jobs, retention exceptions and the 48-hour pre-erasure notices
- Security tooling output: alerts, detections and case notes from your monitoring stack
Access logs are usually well covered. Proof that consent was valid at the time of processing, and that data was actually deleted when it should have been, is rarely logged with the same discipline.
How the one-year rule sits with CERT-In and sector rules
For Indian firms, DPDPA is not the only clock running. The CERT-In Directions require entities to enable logs of all their ICT systems and maintain them securely for a rolling period of 180 days, within Indian jurisdiction. RBI and SEBI expectations run longer still for critical systems, and SEBI-regulated entities carry tier-specific obligations.
Stacking these rules is where teams get into trouble. A single blanket retention setting either overspends on storage or quietly breaches one of the frameworks. The workable approach is to set retention per log category against the longest applicable requirement, then document why each period was chosen.
Five steps to build defensible log retention
Defensible means you can produce the right logs, for the right period, without a scramble.
- Inventory your log sources: Start from systems that touch personal data and work outwards. Include SaaS platforms, cloud services and processor systems, not just infrastructure you own.
- Set retention by category: Map every log type to its longest applicable clock. Rule 6’s one-year security-log requirement, Rule 8’s one-year processing-log requirement where applicable, CERT-In’s 180-day ICT-log requirement, and longer sector-specific or contractual requirements.
- Close the gaps in the timeline: A year of coverage means twelve unbroken months. Hot storage plus archive is fine. Silent gaps during a migration or a licence downgrade are not.
- Protect the logs themselves: Logs hold personal data, so encryption, access control and tamper evidence apply to them too. Retention is not a licence to keep everything forever.
- Test retrieval process: Ask for a record from month ten and time how long it takes. That is the number an auditor and an investigator both care about.
Conclusion
Rule 6 gives Indian companies something unusually clear to work with. One year, for logs and the personal data attached to them, so that a breach can be investigated properly.
The harder part is everything around that number. Coverage across processor systems, consent and deletion events captured with the same rigour as access events, and retrieval that works under pressure rather than in theory.
At CyberNX, our Digital Personal Data Protection Act consulting team helps enterprises design log retention under DPDPA that holds up across CERT-In, RBI and SEBI expectations without duplicating cost or effort.
Talk to our experts and find out where your log timeline breaks today.
Log retention under DPDPA FAQs
How long must logs be kept under the DPDP Rules, 2025?
Rule 6 requires a Data Fiduciary to retain logs and the associated personal data for one year, for the purpose of detecting, investigating and remediating unauthorised access. That period applies unless another law in force requires a different one, which makes it a minimum rather than a fixed limit.
Does the one-year rule replace the CERT-In 180-day requirement?
No. They address different requirements. The two run in parallel and serve different regulators. CERT-In requires ICT system logs to be maintained for a rolling 180 days within Indian jurisdiction, while Rule 6 sets a one-year period for logs tied to personal data. Sector-specific rules can require longer retention. For example, SEBI’s CSCRF requires user-access logs for critical systems to be maintained for at least two years.
Are logs themselves treated as personal data?
Often, yes. Access logs, session records and consent trails routinely contain identifiers, so the security safeguards under Rule 6 apply to the log store as well. Encryption, access control and clear ownership matter as much for logs as for the primary database.
What do auditors usually find missing?
Three things recur. Log coverage that stops at owned infrastructure and misses processor or SaaS systems. Timeline gaps created by tool changes or storage limits. And retrieval that has never been tested, so nobody knows how long it takes to produce a record from ten months ago.




