Data Centres and Critical IT Infrastructure Policies

Data Centres and Critical IT Infrastructure Policies

India’s framework for data centres and critical IT infrastructure

India regulates digital data facilities, critical computer resources, and cyber resilience through the Information Technology Act, 2000, sectoral directives, and national infrastructure policies. Together, these frameworks set security controls, reporting timelines, operational standards, and institutional responsibilities for data centres, public networks, and essential digital systems.

The focus is on protecting critical information infrastructure, ensuring continuity of services, and building secure domestic storage and cloud capacity. The rules also cover incident response, data protection, logging obligations, and compliance checks for entities handling sensitive digital assets.

National policy push for data centres

  • Draft National Data Centre Policy: Formulated by the Ministry of Electronics and Information Technology (MeitY) to accelerate domestic data storage capacity.
  • Infrastructure status: Data centres are accorded infrastructure status, placing them at par with core sectors for long-term institutional credit.
  • Data Centre Economic Zones: The policy provides for specialized zones with dedicated power corridors and high-speed fiber connectivity.
  • Green growth measures: It encourages renewable energy use, higher energy-efficiency ratios, and green building standards in large facilities.
  • Continuity of operations: Data centres are designated under the Essential Services Maintenance Act to support uninterrupted round-the-clock functioning.

Statutory powers under the Information Technology Act, 2000

  • Section 70: Empowers the Central Government to declare any computer system, network, or database as a Protected System.
  • Unauthorized access: Any unauthorized access or attempt to access a declared Protected System is a cognizable offense.
  • Punishment: The offense is punishable with imprisonment of up to ten years.
  • Section 69: Authorizes designated central and state agencies to intercept, monitor, or decrypt digital information for public order and national security reasons.
  • Section 70A: Mandates a specialized national nodal agency for securing designated critical computer networks.
  • Section 70B: Establishes the national nodal body for cyber incident response, threat detection, and emergency containment.

Critical Information Infrastructure protection

  • Meaning of CII: Critical Information Infrastructure includes physical or virtual assets whose destruction or incapacitation can affect national security, the economy, public health, or public safety.
  • NCIIPC: The National Critical Information Infrastructure Protection Centre is a dedicated unit of the National Technical Research Organisation (NTRO), created under Section 70A of the IT Act.
  • Core sectors: NCIIPC identifies six critical sectors—Power and Energy, Banking and Finance, Telecommunications, Transport, Strategic Enterprises, and Government.
  • Guidelines: It issues standard operating procedures, threat and vulnerability assessments, and supply chain security auditing norms for critical sector entities.
  • Role in security: It supports protection, risk assessment, and standard-setting for declared Critical Information Infrastructure.

Sectoral response mechanisms and cyber resilience

  • Sectoral CERTs: These operate under administrative ministries to handle sector-specific incidents in coordination with national agencies.
  • Power-CERT: Deals with operational technology and Supervisory Control and Data Acquisition (SCADA) systems in the power grid.
  • Fin-CERT: Works under financial sector regulators to coordinate threat intelligence for digital banking and payment gateways.
  • Telecom-CERT: Coordinates incident handling across public and private telecommunication service providers.
  • CERT-In: The national emergency response agency issues technical advisories, tracks incidents, and coordinates vulnerability handling.
  • Cyber Swachhta Kendra: The Botnet Cleaning and Malware Analysis Centre functions under CERT-In to detect and neutralize botnet infections in citizen devices.
  • User support: It works with internet service providers and antivirus vendors to notify affected users and provide remediation tools.

Key compliance directions from CERT-In

  • Six-hour reporting rule: CERT-In directions under Section 70B(6) require specified cyber incidents to be reported within six hours of detection.
  • Covered entities: The directions apply to government bodies, commercial entities, and service providers.
  • Incident categories: The directions mandate reporting of twenty specific categories of cybersecurity incidents.
  • Time synchronization: Systems must sync clocks with Network Time Protocol servers of the National Physical Laboratory or NIC.
  • VPS, cloud, and VPN records: Virtual Private Server providers, cloud service providers, and VPN services must register customers and retain validated customer identification records and IP logs for five years.
  • Virtual assets: Virtual asset service providers and crypto exchanges must maintain KYC records and financial transaction logs for five years.

Data protection and allied cyber institutions

  • Digital Personal Data Protection Act, 2023: Governs the processing and safeguarding of digital personal data within India and related foreign processing.
  • Security safeguards: It requires reasonable security safeguards to prevent personal data breaches.
  • Penalty: Financial penalties can go up to ₹250 crore per instance of failure.
  • Data Protection Board of India: This body inquiries into non-compliances, directs remedial measures, and imposes penalties.
  • Significant Data Fiduciaries: They must appoint a resident Data Protection Officer, conduct periodic Data Protection Impact Assessments, and undertake independent statutory audits.
  • NCSC: The National Security Council Secretariat handles apex national cybersecurity policy coordination, strategy execution, and inter-agency integration.
  • I4C: The Indian Cybercrime Coordination Centre under the Ministry of Home Affairs coordinates law enforcement response to cybercrime and operates the 1930 fraud helpline.
  • STQC: Under MeitY, it provides quality assurance, security testing, and formal compliance certification for software and IT systems.

Key Prelims Takeaways

  • Protected System: Under Section 70 of the IT Act, unauthorized access can attract imprisonment up to ten years.
  • NCIIPC: It is the designated body for protecting Critical Information Infrastructure and functions as part of NTRO.
  • Six critical sectors: Power and Energy, Banking and Finance, Telecommunications, Transport, Strategic Enterprises, and Government.
  • CERT-In reporting: Specified cyber incidents must be reported within six hours of detection.
  • Time sync requirement: Systems must use NPL or NIC reference time servers.
  • Log retention: Cloud, VPS, and VPN providers must preserve specified records for five years.
  • Data centre policy: The draft National Data Centre Policy grants infrastructure status to the sector and supports Data Centre Economic Zones.
Originally written on June 18, 2026 and last modified on September 6, 2026.

Leave a Reply

Your email address will not be published. Required fields are marked *