Safeware Glasswall APAC Partner Book a demo

Explore

What is CDRZero TrustThe detection gapCapabilitiesUse cases

Products

ProductsIntegrationFile support

Compliance

Compliance hub
Country guidesSingaporeAustraliaJapanSouth KoreaIndiaIndonesiaMalaysiaThailandVietnamPhilippinesTaiwanNew ZealandMongoliaAPAC overview

More

Trust & certificationsAboutDocumentation Book a demo

Regulatory landscape ยท South Asia

India: file security and audit obligations

India imposes the region's tightest incident-reporting clock and explicit log-retention mandates: CERT-In requires six-hour reporting and 180 days of logs held in India, and the DPDP Rules 2025 add a 72-hour breach report and one-year log retention.

At a glance

How India regulates file security

  • 01

    Regime

    Directions-based cyber regime plus a new data protection statute in phased rollout

  • 02

    File security

    CERT-In technical controls; DPDP reasonable security safeguards

  • 03

    Audit and evidence

    6-hour incident reporting; 180-day logs in India; DPDP 1-year processing logs

Overview

The regulatory picture

India's obligations are unusual in being specific about evidence rather than only about outcomes, which makes them directly relevant to anyone operating a file-processing pipeline.

The CERT-In Directions 2022, issued 28 April 2022 and effective 60 days later, require reporting of specified cyber incidents within six hours of noticing them, retention of security logs for 180 days within India, and synchronisation of system clocks to trusted NTP sources. They apply broadly, to service providers, intermediaries, data centres, VPN and cloud providers, bodies corporate and government organisations.

The Digital Personal Data Protection Act 2023 and the DPDP Rules 2025 add a data protection layer on a phased 12- to 18-month rollout, requiring reasonable security safeguards, immediate intimation of breaches with a detailed report within 72 hours, and retention of traffic and processing logs for at least one year to support breach detection and investigation.

The landscape

Instruments that reach file security and audit

InstrumentAuthorityStatusRelevance
CERT-In Directions 2022CERT-InIn forceDirect
Digital Personal Data Protection Act 2023 and Rules 2025MeitYPartly in forceDirect

CERT-In

CERT-In Directions 2022

Require six-hour reporting of specified cyber incidents, 180-day retention of security logs within India, and NTP clock synchronisation. Apply to service providers, intermediaries, data centres, bodies corporate and government bodies.

Why it matters for file security. A six-hour reporting clock is only achievable if you already hold structured evidence about what happened to the files involved. The 180-day in-country log retention requirement then dictates where that evidence is stored.

How Glasswall addresses it. The per-file verdict record gives a structured processing history to draw on when a six-hour report has to be filed, and exports to SIEM so it can be held under a 180-day in-country retention policy. Meteor covers deployments where data residency rules out a cloud service.

Per-file verdict recordContent Disarm and ReconstructionGlasswall Halo / Glasswall Meteor

Source: CERT-In

MeitY

Digital Personal Data Protection Act 2023 and Rules 2025

Requires reasonable security safeguards over personal data, immediate breach intimation with a detailed report within 72 hours, and retention of traffic and processing logs for at least one year. Phased 12- to 18-month rollout.

Why it matters for file security. The one-year log retention requirement is explicitly framed around breach detection and investigation, which means processing records for personal data held in files fall inside it.

How Glasswall addresses it. Find & Redact reduces the personal data carried in documents, which lowers breach exposure directly. The per-file verdict record contributes the processing log the Rules require to be retained for at least a year.

Find & RedactPer-file verdict recordStorage Monitor + SM AuditGlasswall Halo

Source: MeitY

Latest developments

What has changed in India

Most recent first.

  1. In forceHigh impact

    DPDP Rules 2025 notified with phased compliance rollout

    The Digital Personal Data Protection Rules 2025 were notified, setting a phased 12- to 18-month compliance rollout including a 72-hour detailed breach report and at least one year of traffic and processing log retention.

    Why it matters for file security. Establishes dated compliance milestones and, importantly, an explicit log retention period tied to breach investigation, a requirement that structured per-file processing records satisfy more cleanly than application logs alone.

    How Glasswall addresses it

    Organisations mapping their DPDP log-retention obligation should account for file-processing evidence, not just application and network logs. The per-file verdict record is exportable to whatever retention tier the Rules require.

    Per-file verdict recordFind & RedactGlasswall Halo

    • banking
    • telco
    • healthcare
    • education

    Source: MeitY

Scope

About this page

This page is a working reference for organisations operating in India.

It is not legal advice. Regulatory obligations depend on how an organisation is designated, which sector it operates in and how its systems are architected, take local advice before relying on any of this for a compliance decision. Where we describe how Glasswall relates to an obligation, we are describing a control, not certifying an outcome.

Planning a deployment in India?