Technology risk, cybersecurity and data protection
This guide addresses a different reader from the other guides here. Where the others are written for the audit committee, the CFO and the head of internal audit, the obligations here usually land on a chief information officer, a chief information security officer or a data protection lead, and they are written so this page can be read on its own. The reason it belongs among these governance guides at all is that SEBI put cyber security expressly inside the risk management committee’s mandate, so it is a board question whether or not it is a board conversation.
The obligation that binds you today
Discussion of Indian cyber obligations tends to start with data protection. For most companies that is the wrong starting point, because the directions issued by CERT-In on 28 April 2022 under section 70B(6) of the Information Technology Act are in force now, apply very broadly, and are the most immediately enforceable cyber obligation an ordinary Indian company carries.
They apply to "all service providers, intermediaries, data centres, body corporate and Government organisations". That is not a financial-sector or technology-sector rule. If you are a body corporate, it reaches you.
The three requirements that most often surprise people: specified cyber incidents must be reported to CERT-In within 6 hours of noticing them or being brought to notice; ICT system logs must be enabled and maintained securely for a rolling 180 days, within Indian jurisdiction; and ICT system clocks must be synchronised to NIC or NPL network time protocol servers. Data centres, virtual private server providers, cloud service providers and VPN service providers carry an additional obligation to retain subscriber KYC and specified records for five years or longer where the law requires.
Six hours is an operational requirement, not a policy one. It is not achievable by a process that requires legal review before notification, and the organisations that meet it have decided in advance who can authorise a report at two in the morning.
Data protection: enacted, partly in force, and the dates decide everything
The Digital Personal Data Protection Act 2023 was brought into force in stages by a MeitY notification of 13 November 2025, and the Digital Personal Data Protection Rules 2025 were notified the same day with their own phased commencement. Three tranches matter.
In force since November 2025: the provisions establishing the Data Protection Board, and the rules governing its appointment, service terms, meetings and functioning. Also in force is the amendment to section 8(1)(j) of the Right to Information Act.
One year after publication, so around November 2026: the consent manager registration regime.
Eighteen months after publication, so 14 May 2027: effectively everything a company would recognise as a data protection obligation. Notice, consent, the rights of data principals, reasonable security safeguards, breach notification, significant data fiduciary duties, cross-border transfer restrictions, and the Board’s inquiry and penalty powers.
The consequence, stated plainly: as at August 2026, the core substantive obligations of the DPDP Act are not yet in force, and the penalties are not yet enforceable. The Act’s Schedule provides for penalties of up to ₹250 crore for failing to take reasonable security safeguards and up to ₹200 crore for failing to notify a breach. Those figures are real and they are enacted. They cannot presently be levied, because the provisions conferring the power sit in the eighteen month tranche. Copy elsewhere that tells you companies "now face ₹250 crore penalties" is describing a future state.
In January 2026, MeitY reportedly consulted stakeholders on proposals to shorten parts of the eighteen month implementation period, including possible earlier commencement for certain significant data fiduciary and cross-border provisions. As at 16 August 2026, no amendment implementing those proposals had been notified. The existing commencement dates, including 14 May 2027 for most substantive obligations, therefore remain legally operative.
Commencement status last checked on 16 August 2026. Reconfirm the Gazette and MeitY notifications before relying on this timeline. A later commencement notification could change the date without any amendment of the parent Act. Separately, on the date itself: G.S.R. 846(E) is dated 13 November 2025, but MeitY and PIB record publication and notification on 14 November 2025. Because Rule 1 calculates commencement from Gazette publication, this guide uses 14 May 2027.
What the rules will require, and what to do with the runway
Nothing above is an argument for waiting. The obligations that commence are operational rather than documentary, and the organisations that struggle will be the ones that treated this as a policy exercise.
Security safeguards. Rule 6 requires encryption, obfuscation, masking or the use of virtual tokens; access control; logging and monitoring; backups; retention of logs and personal data for one year unless other law requires otherwise; and contractual flow-down of these obligations to data processors. That last point is a procurement and contracting workstream, and it is the one with the longest lead time.
Breach notification. Rule 7 requires intimation to each affected data principal without any delay, describing the nature, extent and timing of the breach, its consequences, the mitigation taken, safety measures the individual may take, and contact details. Reporting to the Data Protection Board is two stage: an initial description of the breach without delay, followed by the specified detailed information within seventy-two hours of becoming aware of the breach, or within such longer period as the Board may allow on a request made in writing in this behalf. Note the asymmetry: there is no fixed clock for telling the individual, because "without any delay" is stricter than a clock.
Significant data fiduciaries. This status is not self-assessed. The Central Government may notify a data fiduciary, or a class, as significant, on criteria including the volume and sensitivity of personal data and the risk to data principals’ rights. Where it applies, Rule 13 requires an annual data protection impact assessment and audit, due diligence that algorithmic software does not pose a risk to data principals’ rights, and restrictions on transferring specified personal data outside India. A data protection officer based in India, answerable to the board of directors, is required.
Data principal rights. Rule 14 requires the means of exercising rights to be published, and grievance redressal to respond within a period not exceeding ninety days.
Who enforces this. The Data Protection Board of India has been established in law, with its head office in the National Capital Region and a notified composition of one Chairperson and four other Members. As at 16 August 2026, however, no official notification confirming that the Chairperson or Members have been appointed could be identified. MeitY invited applications for these positions in May 2026, with applications closing on 6 July 2026. The distinction worth holding onto is that the Board exists in law but cannot be confirmed as staffed or operational in practice.
The old regime has not gone away yet
This one is usually stated backwards, so it is worth being explicit. Section 43A of the Information Technology Act 2000 and the sensitive personal data rules of 2011 remain fully operative as at August 2026. The DPDP Act does omit section 43A, but the provision doing the omitting sits in the eighteen month tranche and has not commenced.
The practical position for the next several months is therefore that companies carry the older regime in full, plus a partially commenced DPDP regime, plus the CERT-In directions. Advice that treats the older rules as repealed is advice to stop complying with something that still applies.
The audit trail obligation nobody mentions
For financial years commencing on or after 1 April 2023, the proviso to Rule 3(1) of the Companies (Accounts) Rules 2014 requires every company that uses accounting software to maintain its books of account to use software that records an audit trail of each and every transaction, creates an edit log of every change together with its date, and ensures that the audit trail cannot be disabled. Rule 11(g) of the Companies (Audit and Auditors) Rules 2014 requires the statutory auditor to report whether the required feature was used and operated throughout the year for all transactions recorded in the software, whether the audit trail was tampered with, and whether it was preserved in accordance with statutory record retention requirements.
One correction worth making because it recurs: this is not a CARO clause. CARO 2020 contains no audit trail requirement. Attributing it there sends people looking in the wrong place and, worse, suggests it is a reporting matter for the auditor alone rather than a configuration requirement on your accounting system.
Standards, and one deadline that has already passed
ISO/IEC 27001:2022 is the current information security management standard, together with Amendment 1:2024. The 2013 edition is withdrawn, and this matters more than a version number usually would: the transition period ended on 31 October 2025, at which point certifications to the 2013 edition expire or are withdrawn. If your certificate, or a supplier’s, still references the 2013 edition, it is not a dated certificate. It is not a certificate.
ISO/IEC 27701:2025, published in October 2025, is the current privacy information management standard. It has been restructured as a standalone management system standard rather than an extension to ISO/IEC 27001, which changes how it is implemented and certified.
Organisations holding accredited ISO/IEC 27701:2019 certificates should agree a transition plan with their certification body. Under the UKAS transition arrangements, transition to the 2025 edition must be completed by 31 October 2028, subject to any earlier expiry or certification cycle requirements applying to the individual certificate. Two cautions: that date is the UKAS position specifically, and it is not an unconditional extension of validity. An individual certificate may expire sooner, and the audit timetable depends on the relevant certification and accreditation body, so confirm yours with them.
If you are a SEBI regulated entity
SEBI’s Cybersecurity and Cyber Resilience Framework, issued by circular of 20 August 2024, is a substantial and prescriptive regime, and it applies only to SEBI regulated entities across nineteen listed categories including stock brokers and depository participants, mutual funds and asset management companies, portfolio managers, credit rating agencies, custodians, depositories and the market infrastructure institutions. It does not apply to companies generally, and it is sometimes cited as though it did.
Compliance dates were extended twice, most recently to 31 August 2025 for all regulated entities other than market infrastructure institutions, KYC registration agencies and qualified registrars and transfer agents. We found no further extension in 2026, so the deadlines have passed. That is not the same as saying nothing further is due: CSCRF obligations are recurring, including periodic audits and vulnerability assessment and penetration testing, and a regulated entity that met the deadline once has an ongoing programme, not a completed project.
Send an enquiry
Tell us which of these is actually live for you: a six hour incident reporting capability you are not confident in, a DPDP readiness programme that needs scoping against the real commencement dates, a certificate that needs transitioning, or a customer security questionnaire you cannot answer honestly. A partner replies within one business day.
This page is general information, not professional advice. India’s data protection and cyber regime is changing month to month, parts of it are enacted but not yet in force, and how any of this applies depends on your organisation’s specific facts. This page states its position as at 16 August 2026. Take professional advice before acting on anything on this page. We are happy to be that adviser, but we do not act on a web page, ours or anyone else’s, without one.