Preservation and Retention of information by intermediaries – Sec.67C

July 14, 2017

Under Section 67C Information Technology Act, every digital intermediary operating in India must preserve and retain specified electronic records for mandated durations and formats prescribed by the Central Government. Intentional failure to comply constitutes a cognizable cyber offense punishable by imprisonment for up to three years along with substantial monetary fines.

Statutory Framework and Text of Section 67C

Section 67C was inserted into the Information Technology Act 2000 through the Information Technology Amendment Act 2008 to address critical gaps in cyber investigation and electronic evidence preservation. The statutory provision establishes clear legal obligations for all categories of intermediaries, including telecom service providers, network service providers, internet service providers, web-hosting platforms, search engines, online payment portals, and social media platforms.

Section 67C. Preservation and Retention of information by intermediaries: (1) Intermediary shall preserve and retain such information as may be specified for such duration and in such manner and format as the Central Government may prescribe. (2) Any intermediary who intentionally or knowingly contravenes the provisions of sub section (1) shall be punished with an imprisonment for a term which may extend to three years and shall also be liable to fine.

The legislative mandate ensures that law enforcement agencies and cyber forensic investigators have access to verifiable digital logs and traffic metadata during the investigation of cyber crimes, security incidents, and financial fraud.

Mandatory Preservation and Retention of Information by Intermediaries

The preservation and retention of information by intermediaries serves as the backbone of electronic trail verification. When cyber security incidents occur, digital artifacts such as server access logs, IP address allocations, user login timestamps, routing records, and subscriber identity records are often the only reliable proof connecting a threat actor to an illegal action. Without statutory retention rules, ephemeral network logs are frequently overwritten or discarded during routine system maintenance, creating insurmountable obstacles for criminal prosecutions.

Intermediaries must therefore maintain secure, tamper-evident archiving mechanisms that prevent unauthorized deletion, alteration, or corruption of retained logs. These storage systems must adhere to strict cryptographic standards and access controls to maintain evidentiary integrity under Indian evidence law.

Scope of Data and Information Formats Prescribed for Retention

Under regulatory guidelines issued under the Information Technology Act, the scope of retained electronic information encompasses diverse categories of system and user data. The primary classifications include:

  • System and Access Logs: Detailed records of user log-ins, session start and end times, assigned IP addresses, port numbers, device identifiers, and MAC addresses.
  • Transaction and Financial Records: Authentication logs, payment gateway session IDs, virtual account identifiers, and API request-response records for electronic transactions.
  • Subscriber Information: Full registration particulars, verified contact numbers, email addresses, KYC documentation, and dates of account activation or termination.
  • Communication Metadata: Message transmission timestamps, source and destination network addresses, email headers, and routing protocols without encroaching upon encrypted content bodies.

These records must be maintained in structured formats that allow prompt extraction and submission to authorized investigation agencies upon receipt of lawful notices.

CERT-In Directives and Intermediary Data Retention Compliance

The operational requirements for intermediary data retention compliance have been significantly reinforced by directives issued by the Indian Computer Emergency Response Team (CERT-In) under Section 70B of the Information Technology Act. In April 2022, CERT-In issued mandatory cybersecurity directions requiring virtual private network (VPN) providers, cloud service vendors, and data centers to maintain verified customer registration data and connection logs for a minimum duration of five years.

Furthermore, all corporate entities and service providers must synchronize their system clocks with the National Physical Laboratory (NPL) or International Bureau of Weights and Measures (BIPM) time servers. Clock synchronization ensures consistent, immutable time-stamping across distributed network infrastructure, resolving timing discrepancies during cyber forensic timelines. Legal scholars and students studying technology law can examine foundational concepts in Jurisprudence of Cyber Space to understand how time-stamping and digital evidence standards evolved under Indian cyber jurisprudence.

Penalties, Enforcement, and Cyber Law Intermediary Liability

Non-compliance with Section 67C triggers severe legal repercussions for intermediaries and their designated officers. Sub-section (2) explicitly penalizes intentional or knowing failure to preserve mandated information with imprisonment for up to three years, in addition to fines. This criminal liability operates alongside potential forfeiture of intermediary safe harbour protection under Section 79 of the Information Technology Act.

When an intermediary fails to preserve logs or refuses to cooperate with investigating officers, it risks losing immunity against third-party content and actions hosted on its network. The statutory scheme establishes that cyber law intermediary liability extends beyond passive hosting to include active regulatory compliance with data preservation orders. Parallel compliance obligations governing intellectual property infringement on electronic platforms are explored in Intellectual Property Rights Class Notes, highlighting how statutory duties intersect across modern digital platforms.

Technical Standards and Legal Best Practices for Intermediaries

To maintain rigorous compliance and insulate corporate officers from penal action, digital intermediaries must implement structured governance protocols:

  1. Automated Log Archiving: Deploy write-once-read-many (WORM) storage or cryptographic hash-chaining to guarantee that log archives cannot be modified post-creation.
  2. Secure Clock Synchronization: Configure Network Time Protocol (NTP) daemons across all servers to maintain sub-second accuracy with official Indian Standard Time servers.
  3. Law Enforcement Request Cell: Establish a dedicated legal compliance cell capable of verifying statutory notices under Section 91 of the Code of Criminal Procedure and providing certified log extracts with Section 65B Indian Evidence Act certificates.
  4. Periodic Compliance Audits: Conduct regular internal and third-party cybersecurity audits to identify logging failures, storage capacity bottlenecks, or unmonitored server endpoints.
  5. Data Minimization and Privacy Safeguards: Ensure that retention protocols restrict access to authorized personnel and do not collect surplus personal data beyond regulatory mandates.

By combining technical controls with diligent legal oversight, intermediaries satisfy statutory obligations under Section 67C while supporting lawful investigative processes and safeguarding digital infrastructure.

Found this helpful?

Share this page with others