Troubleshooting & Common Errors

Digital Personal Data Protection Act, 2023 (DPDP) and CERT-IN Guidelines: A Complete Guide to Website Storage Compliance for Indian Businesses

By the Domain India teamPublished 9 min read
Knowledge base article
Contents (7 sections)

Two sets of Indian rules shape how a business website stores data and logs: the Digital Personal Data Protection Act, 2023 (DPDP Act) with its 2025 Rules, and the CERT-In cyber security directions of April 2022. This guide explains, in plain terms, what each one asks of a typical website owner, what it means for where you host, and where to read the official text.

Key takeaways

The DPDP Act governs how you collect and use personal data: give a clear notice, get valid consent (or rely on a permitted legitimate use), protect the data, report breaches to the Data Protection Board and the people affected, and delete data you no longer need. Most of its obligations are scheduled to apply from May 2027. The CERT-In directions are separate: report specified cyber incidents to CERT-In within 6 hours, keep ICT system logs for 180 days within Indian jurisdiction, and synchronise server clocks. The DPDP Act does not require personal data to be stored in India.

General information, not legal advice

This article summarises public law and official guidance as of September 2026. It is not legal advice, and it does not say how any particular business, including Domain India, complies. Obligations depend on your business, sector and data. Read the official texts linked below and consult a qualified lawyer for your situation.

1. Two different rulebooks

QuestionDPDP Act 2023 and DPDP Rules 2025CERT-In Directions, 28 April 2022
What it coversDigital personal data of individualsCyber security incidents and logs
Who enforces itData Protection Board of IndiaCERT-In, under the IT Act 2000 (section 70B)
Who it applies toAnyone processing digital personal data in India, and some processing outside IndiaService providers, intermediaries, data centres, body corporates and government organisations
Key deadlineBreach report to the Board with details within 72 hoursIncident report to CERT-In within 6 hours of noticing it
LogsKeep relevant logs for at least one year (Rules)Keep ICT logs for 180 days within Indian jurisdiction

2. DPDP Act: the basics

The Act received assent in August 2023, and the Digital Personal Data Protection Rules, 2025 were notified in November 2025 with staggered start dates. The provisions setting up the Board applied at once, the consent manager framework is scheduled for November 2026, and most obligations on businesses are scheduled for May 2027. The government has discussed bringing some dates forward, so check the current position on MeitY's data protection page.

Key terms:

  • Data Principal: the person the data is about. For a child (under 18) or a person with a disability, this includes the parent or lawful guardian.
  • Data Fiduciary: you, if you decide why and how the data is processed.
  • Data Processor: a service that processes data on your behalf, such as a hosting provider, email service or CRM.
  • Significant Data Fiduciary: a fiduciary the government designates because of the volume or sensitivity of its data; it has extra duties such as a Data Protection Officer and audits.

3. What a website owner has to do under the DPDP Act

  1. Have a lawful ground.
    Process personal data only with the person's consent or for a "legitimate use" listed in the Act, such as data the person voluntarily gave for a specific purpose.
  2. Give a clear notice.
    Before or when asking for consent, say what data you collect, why, how the person can withdraw consent and exercise their rights, and how to complain to the Board. The person must be able to read it in English or in any language listed in the Eighth Schedule of the Constitution.
  3. Get valid consent.
    It must be free, specific, informed, unconditional and unambiguous, given by a clear action such as ticking an empty box. Withdrawing must be as easy as giving it.
  4. Protect the data.
    Take reasonable security safeguards. The Rules list measures such as encryption or masking, access control, logs of access, backups and the ability to detect and respond to breaches, and contracts that bind your processors to the same standard.
  5. Handle breaches.
    Inform each affected person and the Board without delay, and send the Board a detailed report within 72 hours of becoming aware.
  6. Respect rights.
    People can ask for a summary of their data, correction, completion, updating or erasure, grievance redressal, and to nominate someone to act for them. Publish how to make a request; the Rules set an outer limit of 90 days for resolving grievances.
  7. Delete what you don't need.
    Erase personal data once the purpose is served or consent is withdrawn, unless another law requires you to keep it, and make your processors erase it too.
  8. Take care with children's data.
    Get verifiable consent from a parent or guardian, and don't track, behaviourally monitor or target advertising at children.

The Act's schedule of penalties goes up to ₹250 crore for failing to take reasonable security safeguards. Practical implementation (consent records, export and delete endpoints) is covered in DPDPA compliance for Indian websites.

4. CERT-In directions: incidents, logs and clocks

CERT-In's directions of 28 April 2022 (read the official PDF) apply to service providers, intermediaries, data centres, body corporates and government organisations. "Body corporate" is broad, so many companies fall within it; check with your adviser.

  • Report within 6 hours. Specified incidents, including targeted scanning, compromise of systems, website defacement, malicious code, unauthorised access, data breaches and leaks, and attacks on servers, must be reported to CERT-In within 6 hours of noticing them. The reporting details and format are on the CERT-In website; reports go to [email protected].
  • Keep logs for 180 days. Enable logs of all ICT systems and keep them securely for a rolling 180 days within Indian jurisdiction, ready to hand to CERT-In when asked. CERT-In's FAQs indicate logs may also be kept outside India provided a copy is available within India.
  • Synchronise clocks with the NTP servers of the National Informatics Centre (NIC) or the National Physical Laboratory (NPL), or with NTP servers traceable to them.
  • Name a point of contact who liaises with CERT-In.
  • Extra duties for some providers. Data centres, VPS and cloud providers, and VPN providers must keep specified subscriber records for five years. This falls on the provider, not on its customers.

5. What this means for where you host

The DPDP Act does not require personal data to be stored in India. Transfers abroad are allowed except to countries the central government restricts by notification. Sector rules can be stricter and still apply: for example, RBI rules on payment data, or rules for insurance, telecom and government work. So:

Know where your data lives
List every place personal data goes: web server, database, backups, email, analytics, CRM and payment gateway.
Keep the logs you're responsible for
If CERT-In's directions apply to you, make sure the logs of systems you control are kept for 180 days with a copy in India.
Put processors under contract
Your hosting, email and SaaS providers process data for you; the Act makes you responsible for choosing and binding them.
Check sector rules
Payments, health, finance and government work may carry their own storage or localisation rules.

6. A practical checklist for a small business website

  • Publish a privacy notice covering what you collect, why, who you share it with (hosting, email, analytics), how long you keep it, and how people can make requests or complaints.
  • Use an unticked consent box on forms, and load non-essential tracking only after consent.
  • Collect only the fields you need. Don't ask for Aadhaar, PAN or date of birth "just in case".
  • Use HTTPS, strong unique passwords with two-factor login, least-privilege access, and patched software.
  • Keep backups and test restoring them.
  • Keep access and security logs for the periods above, and set a deletion schedule for everything else.
  • Write a one-page incident plan: who decides, who reports to CERT-In within 6 hours, who informs the Board and affected people.

7. Hosting with Domain India

Domain India's live VPS page lists its VPS servers as located in Germany. For shared hosting, business email or other services, ask support where the service you use is hosted before you write your privacy notice. On a Domain India VPS you have root access and control your own logs, retention and clock settings; the security basics are in essential security and optimization tips for your VPS. If your website is hacked, this checklist covers cleanup, and your reporting duties above still apply.

Does the DPDP Act require my website data to be stored in India?

No. The Act allows personal data to be transferred outside India except to countries the central government restricts by notification. Sector-specific rules, such as RBI rules on payment data, can still require storage in India.

When do the DPDP Act's obligations apply?

The DPDP Rules, 2025 were notified in November 2025 with staggered dates. Most obligations on businesses are scheduled for May 2027, and the government has discussed bringing some forward, so check MeitY for the current dates.

How quickly must a data breach be reported under the DPDP Rules?

The Data Fiduciary must inform the Data Protection Board and each affected person without delay, and send the Board a detailed report within 72 hours of becoming aware of the breach.

How quickly must a cyber incident be reported to CERT-In?

CERT-In's April 2022 directions require specified cyber security incidents to be reported within 6 hours of noticing them. Details and the reporting format are on the CERT-In website.

How long must logs be kept?

CERT-In's directions require ICT system logs to be kept for a rolling 180 days within Indian jurisdiction. The DPDP Rules separately require Data Fiduciaries to keep relevant logs for at least one year.

Must the consent notice be in English and a regional language?

The Act requires that the person can access the notice in English or in any language listed in the Eighth Schedule of the Constitution. Offering the languages your customers use is good practice.

Ready to review your own setup? Read the official texts on the MeitY and CERT-In websites, see DPDPA compliance for Indian websites for implementation, or open a support ticket to ask where your Domain India service is hosted.

Questions about your hosting?

Ask our team where your service is hosted and what access you have to its logs and settings.

Open a support ticket

Ready when you are

Get cPanel hosting from ₹125/mo + GST

See plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app