Next due
11 OCTGSTR-1 · Outward supplies · Sep 2026tomorrow 15 OCTPF & ESI · Contributions · Sep 2026in 5 days 20 OCTGSTR-3B · Summary return · Sep 2026in 10 days 21 OCTTax Audit Report · Form 3CA/3CB · AY 2026-27 · extended from 30 Sepin 11 days 30 OCTAOC-4 · Financial statements · FY 2025-26in 20 days 7 NOVTDS / TCS deposit · Deducted in Oct 2026in 28 days 21 NOVITR filing · Audit cases · AY 2026-27 · extended from 31 Octin 42 days 29 NOVMGT-7 / 7A · Annual return · FY 2025-26in 50 days
All due dates

CERT-In Directions of 28 April 2022: customer records and KYC retention for data centres, VPN and virtual asset providers

Direction (v) lists seven items, (a) to (g), of "accurate information" to register and keep for a period of 5 years or longer duration as mandated by the law after any...

Published
Updated
Reading time
10 min
Views
8
Questions
7 answered
  • Expert Reviewed
  • High Complexity
  • In-Depth Guide
Topic
Cyber & Data Protection
Published
October 2, 2026
Last updated
Oct 9, 2026
Reading time
10 min
0:00
Last updated: October 2026Verified against: Government sources

Directions (v) and (vi) of the CERT-In Directions of 28 April 2022 deal with records. Direction (v) requires data centres, Virtual Private Server (VPS) providers, cloud service providers and Virtual Private Network (VPN) service providers to register and maintain stated subscriber information for 5 years or longer after cancellation or withdrawal of the registration. Direction (vi) requires virtual asset service providers, virtual asset exchange providers and custodian wallet providers to maintain KYC information and records of financial transactions for five years. This article explains the Directions as issued on 28 April 2022. Later clarifications and amendments should be checked.

Where these directions come from

The Directions are issued under sub-section (6) of section 70B of the Information Technology Act, 2000, which lets the Indian Computer Emergency Response Team call for information and give direction to service providers, intermediaries, data centres, body corporate and any other person. Our article on section 70B explains the section, and our article on cyber incident reporting and log retention covers directions (i) to (iv) and Annexures I and II. CERT-In also published FAQs in May 2022. The text explained here is the Directions themselves.

Direction (v): data centres, VPS, cloud and VPN service providers

Direction (v) says Data Centres, Virtual Private Server (VPS) providers, Cloud Service providers and Virtual Private Network Service (VPN Service) providers "shall be required to register the following accurate information which must be maintained by them for a period of 5 years or longer duration as mandated by the law after any cancellation or withdrawal of the registration as the case may be":

ItemInformation, as printed
aValidated names of subscribers/customers hiring the services
bPeriod of hire including dates
cIPs allotted to / being used by the members
dEmail address and IP address and time stamp used at the time of registration / on-boarding
ePurpose for hiring services
fValidated address and contact numbers
gOwnership pattern of the subscribers / customers hiring services

Points to note from the words:

  1. The groups covered are four: data centres, VPS providers, cloud service providers and VPN service providers.
  2. The period is "5 years or longer duration as mandated by the law", counted "after any cancellation or withdrawal of the registration".
  3. The information must be "accurate", and item (a) and item (f) say "validated". The Directions do not say how validation is to be done, and this article adds no method.
  4. The text says "the members" in item (c) where the other items speak of subscribers or customers; we flag the wording and do not correct it.

If you provide hosting, cloud or VPN services, a legal due diligence review of your customer onboarding form, what you store, and how long you keep it, is a sensible first step. Data kept for this purpose also engages data-protection law, which has its own tests; see our introduction to the Digital Personal Data Protection Act, 2023.

Direction (vi): virtual asset service providers

Direction (vi) says the virtual asset service providers, virtual asset exchange providers and custodian wallet providers (as defined by the Ministry of Finance from time to time) "shall mandatorily maintain all information obtained as part of Know Your Customer (KYC) and records of financial transactions for a period of five years so as to ensure cyber security in the area of payments and financial markets for citizens while protecting their data, fundamental rights and economic freedom in view of the growth of virtual assets."

ElementWhat the words say
WhoVirtual asset service providers, virtual asset exchange providers and custodian wallet providers (as defined by the Ministry of Finance from time to time)
WhatAll information obtained as part of KYC, and records of financial transactions
PeriodFive years
Stated purposeTo ensure cyber security in the area of payments and financial markets

The second paragraph of the direction says that, for the purpose of KYC, the Reserve Bank of India (RBI) Directions 2016, the Securities and Exchange Board of India (SEBI) circular dated April 24, 2020 and the Department of Telecom (DoT) notice September 21, 2021 "mandated procedures as amended from time to time may be referred to as per Annexure III". The third paragraph says that with respect to transaction records, "accurate information shall be maintained in such a way that individual transaction can be reconstructed along with the relevant elements comprising of, but not limited to, information relating to the identification of the relevant parties including IP addresses along with timestamps and time zones, transaction ID, the public keys (or equivalent identifiers), addresses or accounts involved (or equivalent identifiers), the nature and date of the transaction, and the amount transferred."

For general background on KYC regimes under other laws, which this article does not read into the Directions, see our posts on KYC requirements under the PMLA and on crypto business registration.

Annexure III: KYC requirements

Annexure III says that for the purpose of KYC, any of the following Officially Valid Documents (OVD) as a measure of identification procedure prescribed by the Reserve Bank of India (Know Your Customer (KYC)) Directions, 2016, the SEBI clarification on Know Your Client (KYC) process and use of technology for KYC (circular SEBI/HO/MIRSD/DOP/CIR/P/2020/73 dated April 24, 2020), or the Department of Telecom File No: 800-12/2021-AS.II dated September 21, 2021 on Self-KYC (S-KYC), "shall be used and maintained":

ItemDocument, as printed
aThe passport
bThe driving license
cProof of possession of Aadhaar number
dThe Voter's Identity Card issued by the Election Commission of India
eJob card issued by NREGA duly signed by an officer of the State Government
fLetter issued by the National Population Register containing details of name and address
gValidated phone number
hTrading account number and details, Bank account number and bank details

For KYC for business entities (B2B), "documents mentioned in the Customer Due Diligence (CDD) process prescribed in Reserve Bank of India Master Direction - Know Your Customer (KYC) Direction, 2016 as updated from time to time shall be used and maintained". The RBI, SEBI and DoT instruments are cited as printed; this article does not describe their content, and later changes to them are not covered. Check the current instruments.

Consequence, meaning of terms and effect

The closing paragraphs say that the meaning of "cyber incident", "cyber security incident", "computer resource" and other terms may be ascribed as defined in the Information Technology Act, 2000 or in the 2013 Rules on the Indian Computer Emergency Response Team, and that failure to furnish the information or non-compliance with the directions "may invite punitive action under sub-section (7) of the section 70B of the IT Act, 2000 and other laws as applicable". Section 70B(7), as printed in the consolidated copy, prints imprisonment for a term which may extend to one year or fine which may extend to one lakh rupees or both. As amended by the Jan Vishwas (Amendment of Provisions) Act, 2023, item (I), the words "one lakh" are replaced by "one crore", and the one year term is not changed. Commencement of that Act is by notification and no date is in the sources used; check whether the amendment has been brought into force.

ProvisionAs printed in the consolidated copyAs amended by the Jan Vishwas (Amendment of Provisions) Act, 2023
Section 70B(7) fine"one lakh rupees""one crore rupees"
Section 70B(7) imprisonment"one year"unchanged

The Directions end: "This direction will become effective after 60 days from the date on which it is issued." This article gives no calendar date for the effective date and says nothing about any extension. Later clarifications and amendments should be checked.

A worked example

Nimbus Private Cloud Limited, an invented cloud provider, onboards a customer. Under direction (v), the provider registers the validated name of the customer, the period of hire, the IPs allotted, the email and IP address and time stamp used at on-boarding, the purpose for hiring, the validated address and contact numbers, and the ownership pattern. When the customer cancels, the provider keeps the information for 5 years or longer duration as mandated by the law, counted from the cancellation. A virtual asset exchange (invented) onboarding a user under direction (vi) keeps the KYC and transaction records for five years, so that each individual transaction can be reconstructed.

Need help with record-keeping under the Directions?

If you run a hosting, cloud, VPN or virtual asset business and need to map the records you hold against directions (v) and (vi), our team can help. Contact us for a legal due diligence review.

Key takeaways

  • Direction (v): data centres, VPS, cloud and VPN service providers register seven items of information and keep them for 5 years or longer duration as mandated by the law after cancellation or withdrawal of the registration.
  • Direction (vi): virtual asset service providers, exchange providers and custodian wallet providers keep KYC information and records of financial transactions for five years, with transactions capable of reconstruction.
  • Annexure III lists documents for KYC, and for B2B cites the CDD documents in the RBI Master Direction as updated from time to time.
  • Non-compliance may invite action under section 70B(7); as amended by the Jan Vishwas (Amendment of Provisions) Act, 2023, the fine figure changes from "one lakh" to "one crore"; check whether it is in force.
  • The Directions are effective after 60 days from the date on which they are issued; later clarifications and amendments should be checked.

Read next

Disclaimer: Based on a consolidated copy of the Information Technology Act, 2000 as amended by the Information Technology (Amendment) Act, 2008, on the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 as originally notified on 25 February 2021 and on the CERT-In Directions of 28 April 2022, read with the amendments made to the Act by the Jan Vishwas (Amendment of Provisions) Act, 2023 and by section 44 of the Digital Personal Data Protection Act, 2023, as consulted on 2 October 2026. Commencement notifications, other amendments, rules, directions and the current position of each provision are not covered and should be checked. This article is general information, not legal advice; check the official text before acting.

Quick recapKey facts & short answers

Key Facts About CERT-In Directions of 28

  • Applies in: All states across India, under the relevant central law.
  • Mode: Mostly online via the official government portal.
  • Typical timeline: Ranges from a few days to a few weeks depending on the case.
  • Non-compliance: May attract penalties, interest or late fees.
  • Expert help: TaxClue completes the entire process end to end for you.

Who is covered by direction (v)?

Data centres, Virtual Private Server (VPS) providers, Cloud Service providers and Virtual Private Network Service (VPN Service) providers.

How long must the information be kept?

For a period of 5 years or longer duration as mandated by the law after any cancellation or withdrawal of the registration.

Ask the question before you sign — it is always cheaper than asking it afterwards.

— TaxClue Compliance Desk

CERT-In Directions of 28: a key compliance topic in Indian tax and corporate law that businesses and individuals must understand to remain compliant.

Related Services & Guides

Was this article helpful?
About the author
13,350 articles
Vikas Sharma Verified expert Tax & Compliance Expert

Experienced in company registration, GST, trademark, and compliance. Helping Indian businesses stay compliant.

Last reviewed: Live

Disclaimer: This article is for general informational purposes only and does not constitute professional tax, legal or financial advice. Laws, rates and due dates change and can vary by individual case — always verify with the relevant government source (e.g. mca.gov.in, incometax.gov.in) or consult a qualified professional before acting. TaxClue accepts no liability for decisions taken based on this content.

People also ask

Questions, answered

Short, direct answers to the 7 questions readers ask most on this topic.

Data centres, Virtual Private Server (VPS) providers, Cloud Service providers and Virtual Private Network Service (VPN Service) providers.

For a period of 5 years or longer duration as mandated by the law after any cancellation or withdrawal of the registration.

That virtual asset service providers, virtual asset exchange providers and custodian wallet providers (as defined by the Ministry of Finance from time to time) maintain all KYC information and records of financial transactions for a period of five years.

They must be kept so that each individual transaction can be reconstructed, with the elements named in the direction.

The Officially Valid Documents and other items used for KYC, and for business entities the documents in the CDD process of the RBI Master Direction as updated from time to time.

The Directions say it may invite punitive action under sub-section (7) of section 70B and other laws as applicable.

No. Later clarifications and amendments should be checked.