Data Protection, Cyber & IT Law

Logs and Evidence Retention: What Cyber Teams Should Preserve

Logs and Evidence Retention: What Cyber Teams Should Preserve
CA Nikhil Gupta·June 2026·3 min readDPDP & Cyber

A log-governance framework covering security purpose, CERT-In 180-day requirement, future DPDP safeguards, time synchronisation, integrity, privacy, access and legal holds.

Logs are useful only if they exist, share a reliable clock, can be searched and have not been altered by the attacker or administrator under review.

Current position

The DPDP framework is phased. The 14 November 2025 commencement notification brought specified institutional and enabling provisions into force immediately; Consent Manager-related provisions follow after one year; most operating duties and Rules follow eighteen months after Gazette publication. As of 22 June 2026, the control should distinguish current obligations from future-state DPDP readiness.

Operating issue

CERT-In’s Directions require covered entities to securely maintain ICT-system logs for 180 days within Indian jurisdiction.

Risk

The DPDP Rules include future log and evidence-related safeguard requirements when the relevant provisions commence.

Control

Logs can contain personal data, secrets and message content and therefore need access and minimisation controls.

What the organisation should understand

The five-point review

CheckWhat to examine
SourceIdentity, endpoint, network, cloud, database and application.
ContentEvent, actor, object, result and risk.
ClockTime source, zone and synchronisation.
IntegrityWrite protection, centralisation and access.
RetentionCERT-In, future DPDP, sector and incident hold.

Practical example

An application keeps login logs for seven days, while the company discovers an account takeover after a month. The root-cause evidence has expired despite cloud audit logs being available elsewhere.

How to apply the framework

Create a source-to-use map showing which incident questions each log can answer. Do not retain verbose payloads merely because storage is cheap.

Test retrieval during tabletop exercises. A contractual right to logs is not useful if a vendor takes two weeks to deliver them.

Operating workflow

Define the real process before selecting the legal label

Identify the people, data, systems, purpose, owner, processor, user journey and failure scenario. Review source, content and clock together. A policy statement or vendor assurance cannot replace evidence of how the live product behaves.

Separate current obligations from scheduled DPDP controls

Apply the 14 November 2025 commencement notification provision by provision. Continue complying with currently operative CERT-In, banking, telecom, insurance, employment, consumer, contract and criminal-law requirements. Build the scheduled DPDP workflow now, but do not describe a future provision as already enforceable.

Test and preserve evidence

Run the workflow in the live or controlled test environment. Preserve screenshots, approvals, logs, vendor responses, user communications, exceptions and remediation. Assign a named owner and completion date to every failed control so management can distinguish an operating safeguard from a policy intention.

Action checklist

Evidence to keep

Warning signs

  • Logs disabled for cost
  • Different time zones with no normalisation
  • Administrators can erase their own logs
  • Full passwords or tokens logged
  • Vendor logs unavailable during incident

Finin2min takeaway

Privacy and cyber maturity are visible in operating behaviour: what the organisation collects, who can use it, how vendors are controlled, how users exercise choices, how incidents are handled and whether evidence survives scrutiny.

Frequently Asked Questions

Does every company need 180 days of logs? â–¼
The CERT-In Directions apply to covered entities within their scope.
Must logs remain in India? â–¼
The Directions specify secure maintenance within Indian jurisdiction for covered entities.
Can logs contain personal data? â–¼
Yes.
Should logs be kept forever? â–¼
No, use defined purposes and holds.

Source and review trail

Use the current official instrument, portal or regulator publication before acting. This panel separates the category authority from page-specific references.

Primary category
Data Protection, Cyber & IT Law
Official starting point
www.meity.gov.in
Editorial review date
2026-07-19
Content status
Finin2min explanation; official source controls where facts, law, rates, forms or procedures can change.

Page source links

Home / Insights / Data Privacy & Cyber Law
More on Data Privacy & Cyber Law
Browse all Data Privacy & Cyber Law articles →
Related Articles
Phishing Simulation: Training Employees Without Blame Culture Business Email Compromise: Payment Approval Controls for CFOs Tabletop Exercise: How to Test a Data Breach Response Plan Quarterly Privacy and Cyber Board Dashboard: Metrics That Matter DPDP Act vs DPDP Rules: What Founders Must Understand First