The Indian regulatory picture
What the DPDP Act, RBI and CERT-In expectations ask of cryptography, written conservatively, with the parts that were still moving marked as gaps
On this page — 5 sections
Theos Quantum is registered in India, most of our early engagements are with Indian institutions, and we have a direct interest in getting this page right. It is also the page on this site where we are least willing to state a detail we have not read in a current official text. What follows is written at the level we are confident about, with the gaps marked rather than filled.
Not legal advice
Nothing on this page is legal advice. We are not a law firm and we are not qualified to advise on Indian law. Statutory instruments, rules and supervisory expectations change, and several of the ones described here were still being operationalised when this page was last reviewed. Before you rely on any statement here, have Indian counsel read the current text.
The Digital Personal Data Protection Act, 2023
The DPDP Act received presidential assent in August 2023. It is a short statute by the standards of comparable regimes, and it works through a small vocabulary: a Data Principal is the individual, a Data Fiduciary is the entity deciding the purpose and means of processing, a Data Processor processes on a Fiduciary's behalf, and a Data Protection Board of India adjudicates. Some Fiduciaries are notified as Significant Data Fiduciaries and carry extra obligations, including appointing a data protection officer based in India, appointing an independent data auditor, and conducting data protection impact assessments and periodic audits.
For cryptography, one provision does most of the work. The Act requires a Data Fiduciary to protect personal data in its possession or under its control, including data processed on its behalf, by taking reasonable security safeguards to prevent a personal data breach. It does not enumerate algorithms, key lengths or protocols. It does not mention quantum computing. The obligation is a standard of care, and the Schedule to the Act attaches a maximum penalty of up to two hundred and fifty crore rupees to a failure to meet it, which is the highest figure in the Schedule.
- Breach notification. A Data Fiduciary must give intimation of a personal data breach to the Board and to each affected Data Principal. The form and timing detail sits in the rules rather than the Act.
- Processor chain. The Fiduciary remains answerable for safeguards applied by its processors. A control you do not operate is still a control you are accountable for.
- Cross-border transfer. The Act permits transfer of personal data outside India except to territories the Central Government restricts by notification, which is a permissive default rather than an adequacy regime.
- Purpose limitation and erasure. Personal data is to be erased when the purpose is no longer served, subject to legal retention requirements. That interacts with key retention: data you cannot decrypt is not automatically data you have erased.
Commencement and rules
The Act provides for commencement by notification, and draft rules were published for public consultation in January 2025. The phased commencement schedule, the transition periods for each obligation, and the operational detail on breach notification and Significant Data Fiduciary designation are set by those rules rather than by the Act. We are not going to state dates for them here. [PLACEHOLDER: current commencement status, notified rules and the transition periods applicable to each obligation]
What came before, and still matters
The Information Technology Act, 2000 remains the underlying statute. Section 43A created liability for a body corporate that fails to maintain reasonable security practices in respect of sensitive personal data, and the rules made in 2011 on reasonable security practices gave that phrase content, including by pointing at the IS/ISO/IEC 27001 standard as one acceptable route. Many Indian organisations built their cryptographic policy documentation around that reference and it is still the shape of what a reviewer expects to see.
The relationship between the older regime and the DPDP Act, including which provisions survive and which are displaced, is a question for counsel and not for us. We mention the 2011 rules because if your control documentation cites them, that documentation is the starting point for a cryptographic inventory rather than something to discard. [PLACEHOLDER: the interaction between the IT Act 2000 regime and the DPDP Act, as confirmed by counsel]
CERT-In directions
The Indian Computer Emergency Response Team issued directions under section 70B(6) of the Information Technology Act, 2000 in April 2022. These are the most operationally specific obligations on this page, and unlike most of the rest they carry hard numbers. They apply broadly to service providers, intermediaries, data centres, body corporates and government organisations.
- Incident reporting window
- Specified cyber incidents must be reported to CERT-In within six hours of noticing them or being notified about them
- Log retention
- ICT system logs must be maintained securely for a rolling period of 180 days and maintained within Indian jurisdiction
- Clock synchronisation
- ICT system clocks must be synchronised to Network Time Protocol servers of the National Informatics Centre or the National Physical Laboratory, or to servers traceable to them
- Provider records
- Data centre, virtual private server, cloud and VPN service providers, and virtual asset service providers, must register and retain specified subscriber and transaction records for five years
- Point of contact
- A designated point of contact must be nominated to CERT-In. [PLACEHOLDER: our designated point of contact and internal reporting runbook]
The cryptographic connection is indirect but real in two places. Logs that must stay in Indian jurisdiction for 180 days are themselves an asset with an encryption-at-rest question attached, and a six-hour reporting window is only achievable if you already know what a given system uses and who owns it. Working that out during an incident is how organisations miss the window.
Sectoral regulators
Sectoral supervision is where cryptographic controls are examined in practice in India. The table records what we are confident of and marks the rest, because circular numbers and paragraph references are exactly the kind of detail that goes stale and gets quoted anyway.
| Regulator | What we are confident about | What we will not state without checking |
|---|---|---|
| Reserve Bank of India | The Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices was issued in November 2023 and took effect from 1 April 2024, applying to commercial banks, larger non-banking financial companies and credit information companies. It requires documented cryptographic controls, key management, and periodic review of the strength of cryptographic implementations. | [PLACEHOLDER: the Master Direction reference number and the specific paragraphs on cryptographic controls you intend to cite] |
| Reserve Bank of India, earlier framework | The Cyber Security Framework issued to banks in 2016 introduced baseline security controls and cyber incident reporting to the Reserve Bank, and remains part of the supervisory baseline for many entities. | [PLACEHOLDER: circular reference, current applicability, and which annex controls touch cryptography] |
| Securities and Exchange Board of India | A consolidated Cybersecurity and Cyber Resilience Framework was issued in 2024, replacing a set of entity-specific circulars with graded obligations scaled to entity size and criticality. | [PLACEHOLDER: circular reference, compliance dates by entity class, and the specific cryptography and key-management clauses] |
| Insurance Regulatory and Development Authority of India | Information and cyber security guidelines apply to insurers and cover cryptographic controls among a broader control set. | [PLACEHOLDER: current version and date of the guidelines, and the relevant clauses] |
| Policy direction | The National Quantum Mission was approved by the Union Cabinet in April 2023 with an outlay of approximately six thousand crore rupees, covering quantum computing, communication, sensing and materials. It is a research and capability programme, not a compliance instrument. | [PLACEHOLDER: any national post-quantum migration roadmap or advisory issued for regulated sectors, and its status] |
How an inventory helps you answer the questions these regimes ask
None of the instruments above requires a cryptographic bill of materials. All of them ask questions that are difficult to answer without one. That is the honest framing, and it is more useful than a compliance-mapping table implying an obligation that does not exist.
- Where is personal data encrypted, and with what? The inventory answers at asset level, with the algorithm, key size, protocol version and the evidence the finding came from. See What counts as an asset.
- Can you show the safeguard was in place before the incident, not after it? Dated inventory snapshots and the entries in the Evidence Ledger establish when a state was observed. Reconstructing that from memory after the fact is not evidence.
- Which third parties hold keys or terminate encrypted sessions for you? The inventory records the boundary. Our own side of that question is in Subprocessors and data location.
- What happens when an algorithm you depend on is deprecated? The answer a supervisor wants is a mechanism, not an intention. See Designing for crypto-agility.
- How reliable is the tool that produced this? We publish measured error rather than claiming none: 95.2% classification accuracy and 0.94 macro-F1 on our labelled evaluation set, with the method in Accuracy, false positives, and how we report error.
There is one question in that list an inventory cannot help with. What you did in the six hours after noticing an incident is a matter of process, staffing and rehearsal. No artefact substitutes for having practised it.
What we do not do here
We do not advise on Indian law, we do not represent you before the Data Protection Board of India, the Reserve Bank of India, SEBI, IRDAI or CERT-In, and we do not file incident reports, breach intimations or supervisory returns on your behalf. We do not certify compliance with the DPDP Act or with any sectoral direction, and no AutoPQC output should be described as doing so. We also hold no view on whether you are a Significant Data Fiduciary; that is a designation made by notification, not by a vendor.
More in Standards & compliance