InfraVeritas360DPDPiq

DPDP Insights › Questions › Which logs must we keep, for how long, and where?

Question

Which logs must we keep, for how long, and where?

Short answer: At least one year; 180 days of ICT logs in India

Keep logs that show who accessed personal data and what they did, for at least one year under the DPDP Rules. CERT-In separately asks for ICT system logs to be kept for 180 days within India. Logs must be protected so nobody can quietly change them.

What the law says

Rule 6 lists logs and monitoring as a minimum safeguard. Rule 8(3) asks for logs to be kept for at least one year. The CERT-In Directions of 2022 ask for 180 days of ICT logs kept within India.

Steps

  1. List systems holding personal data and what each logs today.
  2. Turn on access logging where it is missing.
  3. Send logs to one protected store, with at least one year of retention.
  4. Keep a copy of ICT logs in India for at least 180 days.
  5. Sync clocks and review alerts every day.

Evidence to keep

Common mistakes

How it plays out by sector

From each seat

What a good answer from management sounds like

“Every system with personal data sends access logs to a protected store kept for one year, with a copy in India.” Effort and time: Medium · 6 to 12 weeks.

Related questions

Explore our research-built assessment platformsEach one comes out of the same InfraVeritas360 Foundation Layer research. Human-led, with no AI used.