DPDP + CERT-In: what data-center operators actually have to do
India's Digital Personal Data Protection framework and the CERT-In directions reshaped what an operator is accountable for. The headline that surprises most teams: a reportable cyber incident carries a six-hour reporting window.
The obligations that bite
In-region processing expectations, tamper-evident audit trails, breach notification on a tight clock, and demonstrable data-principal rights handling. None of these are satisfied by a policy PDF — they need controls wired into how data actually moves.
How Praman handles the clock
Praman runs a two-tier breach workflow against the CERT-In six-hour clock, keeps a hash-chained audit log that is expensive to forge, and classifies PII in-region so egress is visible rather than assumed. Compliance becomes something you can show an auditor, not argue.
Building or running AI-DC capacity in India?