Updated Cybersecurity and Breach Notification Requirements in India

India’s Computer Emergency Response Team (“CERT”) has published new obligations for how companies manage cyber risk that are expected to take effect on 29 June. These not only create new documentation and log retention requirements for various industry sectors but also require notification of data security incidents to regulators within 6 hours of the incidents. Notification requirements are triggered where certain types of cyberattacks are detected, even if there is no suspicion of access to personal data. The regulations leave some questions unanswered, such as their territorial scope and the range of personal data potentially impacted, and provide for civil and criminal penalties for non-compliance. In this video for our Global Data Protection Review series, Scott Loughlin, Global Co-Lead of the Privacy and Cybersecurity practice discusses the new regulations with our local counsel contact in India, Stephen Mathias from Kochhar & Co.

Contacts
Scott Loughlin
Partner
Washington, D.C.

 

This website is operated by Hogan Lovells International LLP, whose registered office is at Atlantic House, Holborn Viaduct, London, EC1A 2FG. For further details of Hogan Lovells International LLP and the international legal practice that comprises Hogan Lovells International LLP, Hogan Lovells US LLP and their affiliated businesses ("Hogan Lovells"), please see our Legal Notices page. © 2024 Hogan Lovells.

Attorney advertising. Prior results do not guarantee a similar outcome.