miniOrange Logo

Products

Services

Plugins

Pricing

Resources

Company

Data Retention Policy Under the DPDP Act: How Long You Can Keep Data and When to Delete It

1st September, 202612 Min Read

How long should an organization keep personal data? Under the DPDP Act, the answer is not simply one year, three years, or any other fixed period. The right retention period depends on why the data was collected, whether that purpose still exists, and whether another law requires the organization to keep it.

Data Retention Under DPDP Act

Section 8(7) places a clear responsibility on Data Fiduciaries to erase personal data when the specified purpose is no longer being served or when consent is withdrawn, unless retention is required by another law. The DPDP Rules 2025 add a specific three-year deletion requirement for certain large platforms when users remain inactive.

The Core Rule for Data Retention

There Is No One-Size-Fits-All Retention Period

The DPDP Act does not give organizations one fixed number of years for keeping every type of personal data. Instead, data retention under DPDP Act is tied to the purpose for which the data was collected and whether that purpose is still being served.

Section 8(7) requires a Data Fiduciary to erase personal data when it is reasonable to assume that the specified purpose is no longer being served or when the Data Principal withdraws consent, whichever is earlier. An exception applies where another law requires the organization to retain the data.

This reflects the principle of storage limitation. Personal data should not remain in an organization's systems simply because it can be stored. Data minimization supports the same approach by limiting personal data to what is necessary for the intended purpose.

The Rule in Simple Terms

Collect → Use → Retain while needed → Erase when the purpose ends

Every category of personal data should therefore have a clear answer to:

  • Why was it collected?

  • How long is it needed?

  • What triggers its deletion?

For example, a cab platform may need trip information to complete a ride, process payment, or resolve a dispute. Once those purposes end, it should assess whether the information still needs to be retained. If there is no continuing purpose or legal requirement, indefinite retention becomes difficult to justify.

Key takeaway: DPDP compliance does not create a blanket permission to keep personal data indefinitely.

When Does the DPDP Act Require Personal Data to Be Deleted?

Look for These Three Deletion Triggers

Deletion does not happen at one universal point in time. Organizations need to identify the event that makes continued retention unnecessary or activates a specific deletion requirement.

1. The Specified Purpose Is Complete

When the purpose for collecting personal data ends, the organization should determine whether there is still a valid reason to retain it.

This could happen when:

  • A service relationship ends

  • An order is completed

  • A customer request is closed

  • A business process is finished

If another applicable law requires particular records to remain, those records may continue to be retained.

2. Consent Is Withdrawn

Where processing is based on consent, consent withdrawal can trigger erasure.

The organization should determine whether another applicable legal requirement permits or requires continued retention. If not, the relevant personal data should be considered for deletion.

This makes consent and retention management closely connected. Stopping future processing while leaving unnecessary copies across multiple systems does not fully address the data lifecycle.

3. The Applicable Inactivity Period Is Reached

The DPDP Rules 2025 introduce a specific three-year inactivity requirement for certain large platforms.

This should not be confused with the general Section 8(7) obligation.

Important: Three years is not a universal DPDP Act data retention period.

Data Principal Requests Can Also Trigger Erasure

Then explain in 2-3 sentences that organizations also need a process for handling Data Principal erasure requests, subject to applicable retention requirements.

For most organizations, the central question remains whether the specified purpose is still being served or whether another legal requirement permits continued retention.

When Does the Three-Year Data Retention Rule Apply?

A Specific Requirement for Certain Large Platforms

The DPDP Rules 2025 introduce a three-year deletion requirement for certain large platforms where users remain inactive. The Third Schedule identifies the categories covered by this requirement.

Platform category Registered-user threshold
E-commerce platforms 2 crore or more users in India
Online gaming intermediaries 50 lakh or more users
Social media intermediaries 2 crore or more users

For organizations within these specified categories, the three-year erasure requirement does not cover certain data needed to enable the Data Principal to access their user account or specified virtual tokens.

How the Rule Works

A covered platform needs to:

Identify inactive users → Determine the applicable three-year period → Send the required notice → Allow the response window → Delete if conditions remain satisfied

The three-year period is calculated with reference to the person's last interaction for the relevant purpose or the commencement of the Rules, as applicable under the framework.

Rule 8 of the DPDP Rules 2025 sets out the applicable time period for erasure, while the Third Schedule identifies the large platforms subject to the specific requirement.

Who Does This Rule Not Automatically Cover?

Organizations should not interpret the three-year provision as a universal retention window.

A company outside the specified categories cannot assume that it may retain personal data for three years simply because the Rules contain a three-year requirement. The general Section 8(7) obligation remains the starting point.

The distinction matters: The three-year requirement applies to specified large platforms. It is not a blanket retention period for every organization.

What Is the 48-Hour Notice Before Deletion?

Users Must Get an Opportunity Before Deletion

For deletion under the applicable three-year inactivity rule, a covered organization cannot simply identify an inactive account and immediately remove it.

The user must receive notice at least 48 hours before the deletion is due to take place.

The Deletion Flow

Inactivity threshold reached

Deletion notice sent

48-hour notice period

User interacts?
Yes: deletion does not proceed under the inactivity trigger
No: deletion can proceed

This makes the notice requirement an operational process rather than simply a statement in the data privacy policy.

What Should Organizations Track?

A covered platform should be able to determine:

  • Which users reached the inactivity threshold

  • When the notice was sent

  • Whether the user interacted afterward

  • Whether deletion proceeded

  • When deletion occurred

A large platform may have user information across account databases, applications, analytics systems, and other infrastructure. A practical data retention DPDP process therefore needs to connect activity monitoring, notifications, eligibility checks, and deletion workflows.

How Should Organizations Handle Employee Data Retention?

Leaving the Organization Does Not Mean Deleting Everything

Employee data retention requires the same purpose-based approach as other personal data.

When an employee leaves, an organization should not automatically delete every record associated with that individual. It should also not keep every record indefinitely. Instead, it needs to determine what information exists, why it is still needed, and whether another requirement requires continued retention.

Different Employee Records Can Have Different Retention Needs

Employee data category What to consider
Recruitment records Whether the hiring purpose has ended and continued retention is justified
Employment records Whether the information is still needed to administer or document employment
Payroll records Applicable financial, tax, or statutory requirements
Benefits records Continuing administrative or legal requirements
Former employee data Whether a continuing purpose or legal requirement exists
Dispute or legal records Applicable preservation or legal hold requirements

The important point is that employee data should not be treated as one category with one universal retention period.

A Practical Employee Data Retention Process

Identify the record → Define its purpose → Check applicable requirements → Assign a retention period → Review → Delete when no longer required

For example, former employee payroll records may need to remain available because of applicable legal requirements, while some recruitment information may no longer serve a continuing purpose.

Employee information may also exist across HR platforms, payroll providers, benefits systems, cloud applications, and other Data Processors. The retention process should therefore account for relevant third-party copies, not just the organization's HR database.

The goal is not to delete employee data as quickly as possible. It is to retain the right information for the right reason and remove it when that reason no longer exists.

When Can an Organization Retain Personal Data?

Not Every Record Must Be Deleted When Its Original Purpose Ends

The DPDP Act establishes an erasure obligation, but it does not require organizations to delete every record the moment its original purpose ends.

Section 8(7) allows retention where another applicable law requires the organization to keep the personal data.

This means DPDP Act 2023 data retention requirements must be considered alongside other legal and regulatory obligations.

Three Retention Situations to Consider

Another law requires retention: Which records must be kept and for how long

Processing logs must be retained: Which logs need to remain available

Legal hold applies: Which records must be preserved outside normal deletion

For purposes specified in the Seventh Schedule, Rule 8(3) requires the Data Fiduciary to retain the relevant personal data, associated traffic data, and processing logs for at least one year from the date of processing, unless longer retention is required by another law or notified by the Government.

However, a retention exception should never become a reason to keep an entire dataset indefinitely. If a law requires specific transaction records to be preserved, the organization should retain those records for the required period rather than using the requirement to justify retaining unrelated personal data.

For each exception, document:

  • What data must be retained

  • Why it must be retained

  • Which requirement applies

  • How long it must remain

  • When the exception expires

Deleting Data From Your Database Is Not Enough

Personal Data Can Exist With Your Processors Too

Organizations often share personal data with payroll providers, cloud platforms, analytics services, SaaS applications, and other Data Processors.

Deleting information from the primary database does not necessarily remove those copies.

When deletion is required, the Data Fiduciary must account for relevant personal data held by its Data Processors. At the same time, any specific retention requirement under Rule 8, including the one-year requirement for processing covered by the Seventh Schedule, must also be considered.

Follow the Data Across Its Lifecycle

A practical processor deletion process should establish:

Who has the data? Identify relevant processors and systems.

What data was shared? Map the personal data categories.

Why was it shared? Connect the information to its specified purpose.

When should it be deleted? Apply the relevant retention period and deletion trigger.

How will deletion be verified? Define appropriate evidence or confirmation.

Make Processor Responsibilities Clear

Processor agreements should address retention and deletion responsibilities before personal data is shared. These can include:

  • Applicable retention periods

  • Deletion instructions

  • Responsibilities when the processing purpose ends

  • Return or deletion of information

  • Evidence of completed deletion

This is particularly important when information moves through several connected systems. A practical data retention DPDP process needs visibility into where relevant copies exist and how deletion requests reach them.

What Should a DPDP Data Retention Policy Include?

Turn the Requirement Into a Process Teams Can Follow

A policy that simply says “delete personal data when no longer required” leaves too many operational questions unanswered.

A practical retention policy should connect each data category with its purpose, retention period, deletion trigger, owner, systems, and applicable exceptions. The source framework specifically identifies retention periods, deletion workflows, backups, processors, legal holds, logs, and audit trails as important elements.

Build a Retention Schedule

Start with:

Data category → Purpose → Retention period → Deletion trigger → Owner → System

Exception:

This makes the DPDP Act data retention period a documented decision rather than a blanket rule applied to every record.

Define Deletion Triggers

A policy should specify what starts the deletion process, such as:

  • Specified purpose is fulfilled

  • Consent withdrawal where applicable

  • Applicable inactivity period is reached

  • Legal retention period expires

  • Business process or relationship ends

Include Backups and Evidence

Deleting information from an active database does not necessarily remove it from backups or replicated environments. The policy should explain how these copies are handled.

It should also maintain an audit trail showing:

  • What was deleted

  • Why it was deleted

  • When deletion occurred

  • Which system performed the action

  • Whether a processor was involved

  • Whether an exception or legal hold applied

This makes the policy an operational control rather than a document that simply describes an intention.

Why Keeping Personal Data Too Long Creates Risk

Unnecessary Data Creates Unnecessary Exposure

Organizations often retain information because they believe they may need it later. Over time, this can create large stores of personal data with unclear ownership, outdated purposes, and no defined deletion date.

Over-retention can create several problems:

Compliance difficulty: The organization may struggle to demonstrate that personal data is being erased when its specified purpose ends.

Security exposure: Data that no longer serves a purpose can still be exposed during a security incident.

Operational complexity: The longer information remains stored, the harder it becomes to identify what should actually be deleted.

Third-party exposure: Old information may remain with processors and connected services.

Costly cleanup: Years of accumulated data can make later discovery and deletion significantly more difficult.

The source framework notes that the DPDP Act allows penalties of up to ₹250 crore for failure to take reasonable security safeguards.

Turn DPDP Data Retention Requirements Into an Operational Workflow

A Policy Only Works When the Process Runs

Understanding the rules is one thing. Applying them consistently across applications, databases, employees, customers, cloud environments, and processors is another.

The goal is to turn the DPDP Act 2023 data retention requirements into repeatable actions.

A Seven-Step Retention Lifecycle

1. Discover Identify where personal data exists across applications, databases, cloud environments, and relevant third parties.

2. Classify Group information by data type, purpose, business process, and applicable requirement.

3. Define Assign a retention period based on the specified purpose and applicable legal obligations.

4. Monitor Track events such as purpose completion, consent withdrawal, inactivity, or expiry of another retention requirement.

5. Trigger Start the appropriate deletion or review workflow when a defined condition is reached.

6. Delete Remove applicable data from relevant systems and account for processor-held copies and other environments.

7. Prove Maintain records showing what happened, why the action occurred, and when deletion was completed.

Make Retention Part of the Data Lifecycle

Retention should not become an annual cleanup exercise.

When a new application is introduced, its retention requirements should be defined. When a processor receives personal data, its deletion responsibilities should be established. When a business process ends, associated information should enter the appropriate review or deletion workflow.

This also supports data minimization and storage limitation by encouraging teams to ask not only what data they can store, but what they actually need and for how long.

The Practical Model

A strong retention process ultimately answers six questions:

  • What data do we have?

  • Why do we have it?

  • How long do we need it?

  • What triggers deletion?

  • Where else does it exist?

  • How do we prove what happened?

That is what turns data retention under DPDP Act from a policy requirement into a repeatable operational process.

Data Retention Is a Lifecycle Decision, Not a Storage Decision

The DPDP Act requires organizations to rethink how long personal data should remain in their systems. Retention should be tied to purpose, consent, applicable legal requirements, and defined deletion triggers, rather than an arbitrary timeline. The same approach applies to customer information, employee data, processor-held records, logs, and other personal data.

A practical data retention policy under DPDP Act helps organizations reduce unnecessary data, manage deletion consistently, and demonstrate responsible handling throughout the data lifecycle. Ultimately, effective retention comes down to knowing what data you hold, why you need it, how long you need it, and when it should be deleted.

FAQs

1. What is the data retention period under the DPDP Act?

The DPDP Act does not establish one universal retention period. Under Section 8(7), personal data should generally be erased when its specified purpose is no longer being served or consent is withdrawn, unless another law requires retention.

2. Does the DPDP Act require organizations to delete personal data?

Yes. Section 8(7) requires Data Fiduciaries to erase personal data when it is reasonable to assume that the specified purpose is no longer being served or when consent is withdrawn, subject to applicable legal retention requirements.

3. How does the DPDP Act apply to employee data retention?

Employee data retention should be based on the purpose for which employee information is held and any applicable legal requirements. Different records may require different retention periods, so organizations should avoid treating all employee data as having one universal timeline.

4. Do vendors and processors have to delete personal data?

Yes. Organizations need to account for personal data shared with processors when implementing deletion. Retention policies should define processor responsibilities, deletion workflows, and appropriate evidence that data has been removed from relevant third-party systems.

5. Can personal data be retained after its purpose ends?

It may be retained where another applicable law requires the organization to preserve specific records. Such exceptions should be clearly documented and limited to the data and period required, rather than becoming a reason to retain unrelated personal data indefinitely.

6. What should a DPDP data retention policy include?

A practical policy should define data categories, purposes, retention periods, deletion triggers, processor responsibilities, legal holds, backup considerations, required logs, and evidence of deletion. It should translate the DPDP Act 2023 data retention requirements into repeatable operational workflows.

About the Author


Minal Purwar

Content Writer

Minal is an experienced B2B content writer. She has written over 250 articles across industries like UI/UX, real estate, automotive, digital marketing, SaaS, AI & ML, and cybersecurity. She brings her interest in cybersecurity to life by creating clear, engaging content tailored for technical, non-technical, and creative pieces. Her aim is to simplify complex topics, highlight product value, and connect with both technical and non-technical audiences.

Leave a Comment