← All insights

DPDP + CERT-In: what data-center operators actually have to do

India's Digital Personal Data Protection framework and the CERT-In directions reshaped what an operator is accountable for. The headline that surprises most teams: a reportable cyber incident carries a six-hour reporting window.

The obligations that bite

In-region processing expectations, tamper-evident audit trails, breach notification on a tight clock, and demonstrable data-principal rights handling. None of these are satisfied by a policy PDF — they need controls wired into how data actually moves.

How Praman handles the clock

Praman runs a two-tier breach workflow against the CERT-In six-hour clock, keeps a hash-chained audit log that is expensive to forge, and classifies PII in-region so egress is visible rather than assumed. Compliance becomes something you can show an auditor, not argue.

Building or running AI-DC capacity in India?

Talk to us →See our services