Most organisations preparing for DPDP are building towards a single behaviour: when someone asks you to delete their data, delete it.
That behaviour is non-compliant.
The DPDP framework imposes a retention floor and an erasure ceiling simultaneously, and they overlap. Getting this wrong is not a technicality — it is the difference between a system that produces defensible evidence and one that destroys it.
This page sets out both obligations, shows where they collide, and describes what a compliant erasure actually consists of.
There are two, and they operate differently.
A Data Principal is entitled to erasure of her personal data for the processing of which she had previously given consent. On receiving the request, the Data Fiduciary must erase the personal data — unless retention is necessary for the specified purpose or for compliance with any law for the time being in force.
That exception is not narrow. Indian law is dense with retention mandates.
Independently of any request, a Data Fiduciary must erase personal data on withdrawal of consent, or as soon as it is reasonable to assume the specified purpose is no longer being served, whichever is earlier — unless retention is necessary for compliance with law. The Fiduciary must also cause its Data Processor to erase.
This is the obligation most organisations have not planned for at all, because it requires no trigger from the individual. It requires you to notice, on your own initiative, that a purpose has been served.
For specified classes, the Rules convert "purpose no longer served" into a clock.
| Class | Threshold | Erasure after |
|---|---|---|
| E-commerce entity | ≥ 2 crore registered users in India | 3 years of Data Principal inactivity |
| Online gaming intermediary | ≥ 50 lakh registered users in India | 3 years of Data Principal inactivity |
| Social media intermediary | ≥ 2 crore registered users in India | 3 years of Data Principal inactivity |
The clock runs from the later of: the date the Data Principal last approached the Fiduciary for performance of the specified purpose or to exercise her rights, or the commencement of the Rules.
Two purposes are carved out and survive the clock: enabling the Data Principal to access her user account, and enabling her to access a virtual token issued by or on behalf of the Fiduciary, stored on its platform, usable to obtain money, goods or services. Wallet balances and store credit do not evaporate at three years.
At least forty-eight hours before the erasure period completes, the Data Fiduciary must inform the Data Principal that her data will be erased on completion of the period, unless she logs into her account, otherwise initiates contact for the specified purpose, or exercises her rights.
Without prejudice to the erasure duties above, a Data Fiduciary must retain — in respect of any processing undertaken by it or on its behalf by a Data Processor — the personal data, associated traffic data and other logs of the processing, for a minimum period of one year from the date of processing, for the purposes specified in the Seventh Schedule. Only after that may it erase, and only if no other law requires longer.
The Rules illustrate this directly, and the illustration is the whole argument:
A person buys an e-book on a platform. Once delivery completes, the specified purpose is served. The platform must nonetheless retain the order details, personal data and processing logs — order confirmation, payment, delivery events — for at least one year from the transaction date, even if the customer deletes her account.
A second illustration extends it down the chain: a company using a cloud service provider as its Data Processor must ensure the provider also retains the data and associated logs for at least a year before erasure.
| Scenario | Erasure says | Retention says | Correct action |
|---|---|---|---|
| Customer deletes account 2 months after a purchase | s. 12 / s. 8(7): erase | Rule 8(3): retain 1 year minimum | Suppress from active processing; retain the transaction record and logs; document why |
| Customer requests erasure of KYC data held by a bank | s. 12: erase | Sectoral mandate: retain client identity records for the statutory period | Refuse erasure for the mandated data; explain the legal basis; erase anything outside the mandate |
| Marketing consent withdrawn | s. 6(4) / s. 8(7): cease and erase | Nothing mandates retention of marketing profile | Erase the marketing data; retain a suppression record, or you will re-contact them |
| Dormant e-commerce account, 3 years inactive, wallet balance present | Rule 8(1): erase | Third Schedule carve-out: virtual token access | Erase for other purposes; preserve the token and account-access data |
| Employee leaves | s. 8(7): purpose served | Multiple statutory employment and tax retention periods | Retain per mandate; restrict access; erase discretionary data |
The pattern across every row is the same: erasure is purpose-scoped, not record-scoped. The correct unit of erasure is "this data, for this purpose," never "this person's row."
Six steps. If your system does fewer, it is not doing erasure.
Step 4 conceals a trap worth naming separately, because it catches sophisticated teams.
If a person withdraws marketing consent and you erase their record completely, you have destroyed the only evidence that they opted out. The next time their email arrives through an import, a partner list or a re-engagement campaign, you will contact them again — and you will have no record of why you shouldn't have.
The answer is a suppression record: the minimum data needed to honour the withdrawal, retained for that purpose alone, and nothing else. It looks like retention and functions as erasure. Getting this wrong in either direction is a breach — over-retain and you have kept a marketing profile you were told to delete; under-retain and you will re-contact a person who withdrew.
DPDP does not displace these. s. 12 defers to them expressly.
| Source | Broadly requires retention of |
|---|---|
| Reserve Bank of India directions | KYC and customer identification records, transaction records |
| Prevention of Money-Laundering Act and rules | Client identity and transaction records |
| Income-tax Act and rules | Books of account and supporting records |
| Companies Act, 2013 | Books of account and statutory registers |
| IRDAI regulations | Policyholder and claims records |
| TRAI and telecom licence conditions | Subscriber verification and call detail records |
| SEBI regulations | Client and transaction records for intermediaries |
A D2C brand with 2.4 crore registered users. A customer buys in March 2027 and stops using the account.
Note what this requires: a per-customer clock, a class determination, a scheduled notification, a re-engagement listener, a retention register, and an audit record at each step. Note also that the brand's user count crossing two crore is what pulls it into this regime at all — a fact that changes as the business grows.
Five capabilities, none of which a policy document provides:
One year. Rule 8(3) requires retention of personal data, associated traffic data and processing logs for at least one year from the date of processing, for the purposes in the Seventh Schedule, unless another law requires longer.
Yes, where retention is necessary for the specified purpose or for compliance with any law. s. 12 makes the erasure right expressly subject to that. The correct response is to retain the mandated data, erase the rest, and document the basis.
Not entirely, and not immediately. The Rules illustrate this directly: a platform must retain transaction records and processing logs for at least a year even where the customer has deleted her account. Data outside any retention mandate should be erased.
Third Schedule classes: e-commerce entities and social media intermediaries with not less than two crore registered users in India, and online gaming intermediaries with not less than fifty lakh — after three years of Data Principal inactivity, excluding account access and virtual token purposes.
Rule 8(2) requires a Data Fiduciary to inform the Data Principal at least forty-eight hours before the erasure period completes that her data will be erased, unless she logs in, initiates contact for the specified purpose, or exercises her rights.
Yes, in effect. Rule 8(3) applies to processing undertaken by a Data Processor on the Fiduciary's behalf, and the Rules illustrate it with a cloud service provider hosting customer records. Your provider's deletion policy is part of your compliance position.
Retain what the mandate covers, erase what it does not, restrict the retained data to the retention purpose only, and record the mandate you relied on. Silently deleting mandated records and silently refusing the whole request are both breaches.
Consiva.ai maps every obligation above to a workflow, dashboard, or automated job — so your team focuses on decisions, not tracking.
Start Free — No Credit Card →Verified against the Gazette of India on 17 August 2026. Sources: Digital Personal Data Protection Act, 2023, ss. 8(7), 12, 33(2); Digital Personal Data Protection Rules, 2025, Rule 8 and the Third and Seventh Schedules, including the illustrations to Rule 8(3). Sectoral retention periods must be confirmed from the applicable instrument. Reference material about the law, not legal advice — see /disclaimer.