Data Retention Under DPDP Act: Rules, Requirements, Timelines and Best Practices
- Loading...
Data is one of the most valuable assets for modern businesses. Customer information, employee records, transaction details, account information, communication records and online identifiers are routinely collected and stored across websites, applications, CRM systems, cloud platforms and other digital infrastructure.
Get a callback
But an important question often gets overlooked:
How long can a business retain personal data?
The Digital Personal Data Protection Act, 2023 (DPDP Act) introduces a framework that requires organisations to think carefully about the lifecycle of digital personal data—from collection and processing to retention and erasure.
The DPDP Rules, 2025 provide additional requirements concerning when certain classes of Data Fiduciaries must erase personal data after a specified period of inactivity, as well as a separate minimum one-year retention requirement for certain personal data, traffic data and processing logs.
This makes data retention under the DPDP Act an important compliance issue for organisations operating in India.
However, one point needs to be made clear at the beginning:
The DPDP Act does not prescribe one universal retention period for all personal data.
The appropriate retention period depends on the purpose of processing, applicable legal requirements, the specific provisions of the DPDP framework and the circumstances of the organisation.
What Is Data Retention?
Data retention refers to the period for which an organisation keeps personal data after collecting or processing it.
For example, a business may collect a customer’s:
- Name
- Mobile number
- Email address
- Address
- Purchase history
- Account information
- Support communications
The organisation may need some of this information while providing its service.
But what happens when:
- The customer closes the account?
- The transaction is completed?
- The service is discontinued?
- The customer withdraws consent?
- The purpose for which the information was collected is no longer relevant?
This is where a data retention policy becomes important.
A retention policy establishes:
What data is retained → Why it is retained → For how long → Where it is stored → When it should be deleted → What legal exception may permit further retention
Why Is Data Retention Important Under the DPDP Act?
The DPDP framework is based on the idea that personal data should be processed for legitimate and specified purposes rather than being stored indefinitely without a continuing reason.
Section 8 of the DPDP Act places obligations on Data Fiduciaries concerning the accuracy, security and erasure of personal data. The Act also provides for erasure when the purpose for which the personal data was processed is no longer being served, unless retention is necessary for a legal purpose.
The practical implication is significant:
A business should be able to explain why it still needs personal data that it continues to retain.
Keeping information forever simply because storage is inexpensive is not a sound privacy-governance approach.
Does the DPDP Act Specify a Fixed Data Retention Period?
No.
This is one of the most important points businesses need to understand.
There is no single rule under the DPDP Act saying:
“All personal data must be deleted after X years.”
Instead, retention depends on several factors, including:
- The purpose for which data was collected
- Whether that purpose is still being served
- Whether another law requires retention
- Whether specific DPDP Rules apply to the organisation
- Whether the information is required for legal claims or compliance
- Whether the organisation has an ongoing legitimate operational requirement under the applicable DPDP framework
The DPDP Rules, 2025 do, however, introduce specific deemed-end-of-purpose periods for certain classes of Data Fiduciaries and corresponding purposes listed in the Third Schedule.
Therefore, organisations should avoid creating a blanket retention period for all personal data.
Data Retention vs Data Erasure Under DPDP
These concepts are closely related but not identical.
Data retention
Keeping personal data for a defined reason and period.
Data erasure
Deleting personal data once the applicable retention period or purpose has ended, unless further retention is legally required or otherwise permitted.
The overall lifecycle can therefore be represented as:
Collection
↓
Processing
↓
Retention
↓
Purpose fulfilled / retention period expires
↓
Erasure
This lifecycle should be reflected in an organisation’s internal data governance processes.
The Purpose Limitation Principle and Data Retention
One of the most important concepts behind DPDP data retention is purpose limitation.
A business should know why it is processing personal data.
For example:
A customer provides a mobile number to receive an OTP.
The organisation should not automatically assume that it can retain and use that number indefinitely for unrelated marketing activities.
Similarly, if a user creates an account, the organisation should understand:
- Why the account data is needed
- Which information is necessary
- What happens when the account becomes inactive
- What information needs to be retained for legal or operational reasons
- What information should eventually be erased
This makes data retention part of the broader data lifecycle management process.
What Do the DPDP Rules 2025 Say About Data Retention?
The Digital Personal Data Protection Rules, 2025, notified by MeitY in November 2025, provide more specific operational requirements.
Rule 8 deals with the situation where the specified purpose is deemed to no longer be served for certain classes of Data Fiduciaries and corresponding purposes listed in the Third Schedule.
The rule provides that the Data Fiduciary must erase the personal data unless:
- retention is necessary for compliance with a law, or
- the applicable retention period specified in the Third Schedule has not expired.
The rule also requires advance notice to the Data Principal before erasure in the specified circumstances.
This is an important development because it translates the broader data-lifecycle principle into more specific operational requirements for certain covered entities.
48-Hour Notice Before Certain Erasures
One particularly important requirement under Rule 8 concerns advance notification.
At least 48 hours before the relevant erasure period expires, the Data Fiduciary must inform the Data Principal that the personal data will be erased.
The Data Principal can then take action—for example, log into their account, contact the Data Fiduciary regarding the specified purpose or exercise applicable rights.
This creates a practical workflow:
Inactivity period approaches
↓
Business identifies upcoming erasure
↓
48-hour notification sent
↓
User logs in / initiates contact / exercises rights
↓
Data may continue to be retained where the applicable rule permits
OR
↓
No action
↓
Data is erased, subject to applicable legal retention requirements
This means organisations covered by the relevant Rule 8 requirements need systems capable of identifying upcoming deletion events and triggering the appropriate communication.
One-Year Retention of Certain Data and Processing Logs
A common misconception is that DPDP always requires businesses to delete data as soon as the original purpose ends.
That is not correct.
Rule 8(3) introduces an important exception/requirement for specified purposes under the Seventh Schedule.
A Data Fiduciary must retain, for at least one year from the date of processing, the relevant personal data, associated traffic data and other logs of processing undertaken by it or on its behalf by a Data Processor, for the purposes specified in that Schedule.
After that period, the Data Fiduciary must cause the data and logs to be erased unless another law requires further retention or the Government has notified otherwise.
This creates an important distinction:
“Delete data when the purpose ends” does not necessarily mean “delete immediately in every situation.”
Specific statutory retention requirements can override ordinary deletion workflows.
Example: E-Commerce Transaction
The 2025 Rules provide an illustration involving an e-book platform.
Suppose:
Customer purchases an e-book
The platform processes:
- Customer information
- Order details
- Payment information/events
- Delivery information
- Processing logs
Once the e-book is delivered, the specified purpose may be considered served.
However, for the purposes covered by the relevant Seventh Schedule requirement, the platform must retain specified personal data and associated logs for at least one year from the transaction before erasure, unless another law requires longer retention.
This illustrates why businesses should not build a deletion system based solely on:
“User deleted account = immediately delete everything.”
The organisation must first determine whether any legal retention obligation applies.
Example: Cloud Service Provider
The Rules also provide an example involving a company using a cloud service provider.
If the company is the Data Fiduciary and the cloud provider is acting as its Data Processor, the Data Fiduciary has responsibility for ensuring that the applicable retention requirement is followed by the processor as well.
The Rule’s illustration specifically addresses retention of data and associated processing logs for the prescribed minimum period.
This highlights a major practical issue:
Data retention compliance does not stop at your own servers.
Businesses must understand where their data is being stored and processed by third-party vendors.
What Happens When a User Deletes an Account?
Account deletion is one of the most common data-retention scenarios.
Suppose a customer clicks:
“Delete My Account.”
A business should not simply assume that every record can immediately be deleted.
It should evaluate:
1. What data exists?
For example:
- Profile information
- Login information
- Transaction records
- Support tickets
- Marketing preferences
- Consent records
- Security logs
2. Why is each category retained?
Some information may no longer be necessary.
Other information may need to be retained because another law requires it.
3. What can be deleted immediately?
The business should identify data for which there is no continuing reason to retain it.
4. What must be retained?
Certain records may need to be preserved because of statutory, regulatory, accounting, tax, legal or other applicable requirements.
5. What happens to backups?
The organisation should have a documented approach for backup systems rather than ignoring them.
Withdrawal of Consent Mean All Data Must Be Deleted Immediately?
Not necessarily.
The DPDP Act provides a right to withdraw consent where consent is the basis for processing, but withdrawal does not automatically mean that every piece of personal data must instantly disappear from every system in every circumstance.
The organisation needs to determine:
- What processing was based on consent?
- Is there another lawful basis or legitimate use applicable?
- Is retention required by another law?
- Is the data still necessary for another specified purpose?
- Are there applicable obligations concerning erasure?
The correct approach is therefore:
Consent withdrawal → identify affected processing → stop/modify processing where required → assess retention → erase data where required
rather than:
Consent withdrawal → immediately delete every record.
Data Retention and Legal Obligations
The DPDP framework recognises that other laws can require personal data to be retained.
Rule 8 expressly provides an exception where retention is necessary for compliance with a law in force.
This means a company’s retention policy should not be created by looking at the DPDP Act alone.
A business may also need to consider applicable requirements relating to:
- Tax records
- Accounting
- Employment
- Financial transactions
- Regulatory reporting
- Litigation
- Fraud investigations
- Sector-specific regulations
- Contractual obligations
Therefore, an effective retention schedule should distinguish between:
DPDP retention requirement
and
Other legal retention requirement
Data Retention Policy Under DPDP: What Should It Include?
A business should consider creating a formal Data Retention and Deletion Policy.
The policy should ideally cover:
1. Data category
What type of personal data is involved?
2. Processing purpose
Why is the organisation processing the data?
3. Collection source
Where was the information obtained?
4. Applicable retention period
How long should it be retained?
5. Legal basis for retention
Why is the organisation allowed or required to retain it?
6. Deletion trigger
What event starts the deletion process?
Examples:
- Account closure
- Purpose completion
- Contract termination
- Expiry of retention period
- User inactivity
7. Deletion method
How will the data be erased from:
- Production systems
- Databases
- Applications
- Cloud storage
- Third-party processors
- Other relevant systems?
8. Exceptions
When can data be retained beyond the standard period?
9. Responsibility
Which department or system owner is responsible?
Data Retention Schedule Example
A business can maintain a retention matrix such as:
| Data Category | Purpose | Retention Trigger | Retention Period | Action |
|---|---|---|---|---|
| Account data | Account management | Account closure/inactivity | Based on applicable requirement | Review and erase |
| Marketing data | Marketing communication | Withdrawal/end of purpose | Based on applicable requirement | Suppress/erase |
| Transaction data | Order processing | Transaction completion | As required by applicable law | Retain |
| Support data | Customer support | Resolution/end of purpose | Defined by policy and applicable law | Review |
| Consent records | Demonstrating consent | Consent lifecycle | As required by applicable framework | Retain securely |
| Processing logs | Security/compliance | Date of processing | At least one year where Rule 8(3) applies | Erase after applicable period |
Important: The table above is an implementation example, not a universal legal retention schedule. Actual periods must be determined based on the organisation’s activities, applicable laws and the specific DPDP requirements that apply.
Data Retention Under DPDP and Consent Management
Consent management and data retention are closely connected.
Consider a user who provides consent for:
“Receive promotional communications.”
The organisation should be able to determine:
- When consent was given
- What purpose it covered
- What notice was presented
- Whether consent was withdrawn
- When withdrawal occurred
- Which systems received the preference
- What happened after withdrawal
A consent management platform can help create an auditable record of these events.
However, consent records themselves should also be governed by a documented retention policy.
This is particularly important because:
Deleting all consent evidence immediately after consent withdrawal may make it difficult for an organisation to demonstrate the historical consent lifecycle when required.
Retention and deletion must therefore be balanced rather than treated as opposing concepts.
Role of Data Processors in Data Retention
Modern businesses depend heavily on third-party processors.
Examples include:
- Cloud providers
- CRM platforms
- Email platforms
- Analytics services
- Payment providers
- Customer-support platforms
- HR software
- Marketing automation platforms
If a Data Processor stores or processes personal data on behalf of a Data Fiduciary, the Data Fiduciary should ensure that its contracts and operational controls address applicable retention and deletion requirements.
The organisation should know:
Where is the data?
Who has it?
How long is it retained?
How is it deleted?
What happens to backups?
What happens when the business relationship ends?
A vendor that keeps customer information indefinitely after the business has instructed it to delete the information can create significant governance concerns.
Backup Data and DPDP Retention
Backups are often forgotten during deletion exercises.
Imagine a company deletes a customer’s information from its live database.
However, copies remain in:
- Daily backups
- Disaster-recovery systems
- Archived databases
- Cloud snapshots
- Log repositories
The organisation therefore needs a documented backup lifecycle.
A practical policy may distinguish between:
Active production data
and
Backup/DR data
The organisation should define how deletion requests and retention periods interact with backup cycles.
This does not necessarily mean that every backup must be individually modified immediately in every circumstance. The organisation should establish a defensible process consistent with applicable legal requirements, security practices and its backup architecture.
Data Minimisation and Retention
Data minimisation and retention are closely related.
The less unnecessary personal data an organisation collects, the less data it eventually needs to retain, protect and delete.
For example, if a business does not actually need a customer’s date of birth for a particular service, collecting it creates an additional data-governance obligation.
A useful principle is:
Do not collect data without a defined purpose, and do not retain data without a continuing reason.
This can reduce:
- Privacy risk
- Security risk
- Storage complexity
- Compliance burden
- Data-breach impact
What Businesses Should Do to Become DPDP-Ready for Data Retention
A practical implementation process can be divided into eight steps.
Step 1: Map Personal Data
Identify every major source of personal data.
Include:
- Websites
- Mobile apps
- CRM
- ERP
- HR systems
- Marketing systems
- Customer support
- Cloud storage
- Databases
- Third-party platforms
Step 2: Categorise Data
Group data into meaningful categories.
For example:
- Customer data
- Employee data
- Prospect data
- Transaction data
- Consent data
- Support data
- Security logs
Step 3: Identify the Purpose
For each category, document:
Why are we processing this information?
If the organisation cannot clearly answer this question, the data should receive additional scrutiny.
Step 4: Identify Applicable Legal Retention Requirements
Check whether another law requires the organisation to retain the data for a particular period.
Do not create a retention policy based only on the DPDP Act.
Step 5: Define Retention Periods
Create a retention schedule for each category.
Avoid using:
“Retain forever.”
unless there is a clearly documented legal or operational justification.
Step 6: Automate Deletion
Where practical, use automated lifecycle rules.
For example:
Purpose ends
↓
Retention timer starts
↓
Exception check
↓
Deletion approval / trigger
↓
Data erased
↓
Deletion logged
Automation reduces the possibility of human error.
Step 7: Manage Third-Party Processors
Review vendor agreements and verify:
- Retention periods
- Deletion procedures
- Data-return processes
- Sub-processors
- Backup handling
- Security safeguards
Step 8: Maintain Evidence
The organisation should be able to demonstrate:
- What data it retains
- Why it retains it
- How long it retains it
- Which legal requirement applies
- When deletion occurred
- Who/what system performed deletion
This makes retention a governance process rather than merely a database operation.
Common Data Retention Mistakes Under DPDP
Mistake 1: Keeping all data forever
Storage is inexpensive, but indefinite retention can create unnecessary privacy and security risks.
Mistake 2: Assuming DPDP gives one fixed retention period
The Act does not establish one universal retention period for every category of personal data.
Mistake 3: Deleting everything immediately
Businesses may have statutory obligations requiring certain records to be retained.
Mistake 4: Ignoring third-party systems
Deleting data from the CRM while leaving it in a marketing platform or cloud service creates an incomplete deletion process.
Mistake 5: Ignoring backups
Deletion policies should address backup and disaster-recovery environments appropriately.
Mistake 6: No data inventory
If a business does not know where personal data exists, it cannot reliably manage its retention.
Mistake 7: No automated deletion process
Manual deletion across thousands of records and multiple systems is difficult to manage consistently.
Data Retention Under DPDP: Compliance Checklist
-
Identify all personal data collected and processed
-
Map where personal data is stored
-
the purpose for each category
-
Identify applicable legal retention obligations
-
Create a data retention schedule
-
Define deletion triggers
-
Establish erasure procedures
-
Review inactive accounts
-
Establish processes for user deletion requests
-
Review consent withdrawal workflows
-
Include third-party processors in the retention framework
-
Address backups and disaster-recovery systems
-
Automate deletion where practical
-
Maintain deletion logs and evidence
-
Periodically review retention periods
-
Monitor changes to DPDP requirements and applicable sectoral laws
Frequently Asked Questions About Data Retention Under DPDP Act
Is there a fixed data retention period under the DPDP Act?
No. The DPDP Act does not establish one universal retention period for all personal data. Specific requirements can apply depending on the purpose, the Data Fiduciary, the DPDP Rules and other applicable laws.
When should personal data be deleted under DPDP?
Personal data should be erased when the purpose for which it was processed is no longer being served, subject to applicable legal requirements and specific provisions of the DPDP framework. Rule 8 of the 2025 Rules specifies deemed end-of-purpose periods for certain classes of Data Fiduciaries and purposes.
Does DPDP require companies to delete data after a user closes their account?
Not necessarily immediately or in every case. The organisation needs to determine whether the purpose has ended and whether any other law or applicable DPDP requirement requires continued retention.
Is one-year data retention mandatory under DPDP?
A one-year minimum retention requirement applies under Rule 8(3) to personal data, associated traffic data and processing logs for the specified purposes listed in the Seventh Schedule. It is not a blanket one-year retention rule for every type of personal data processed by every organisation.
Does withdrawal of consent require immediate deletion?
Not automatically. Withdrawal affects processing based on consent, but the organisation must assess applicable retention obligations and whether another lawful basis or legal requirement permits or requires continued retention.
How long should consent records be retained?
There is no single universal retention period that can safely be applied to every consent record solely based on the DPDP Act. Organisations should consider their evidentiary, regulatory, contractual and operational requirements and applicable Rules. A registered Consent Manager has specific record-retention obligations under the DPDP Rules.
Can a business retain personal data because it may be useful in the future?
Businesses should avoid retaining personal data indefinitely merely because it might be useful someday. Retention should be connected to a defined purpose or applicable legal requirement.
Data Retention Under DPDP Act: Key Takeaways
The DPDP framework changes how organisations should think about personal data.
The question is no longer simply:
“Where do we store customer data?”
Businesses should also be asking:
“Why are we storing it, how long do we need it, when should it be erased, and can we demonstrate that our retention practices are controlled?”
The key principles are:
- There is no single universal DPDP retention period.
- Purpose matters.
- Legal retention obligations can require data to be retained longer.
- Certain Data Fiduciaries are subject to specific deemed-end-of-purpose periods under Rule 8.
- Certain specified processing activities have a minimum one-year retention requirement for relevant personal data and logs.
- Third-party Data Processors must be included in the retention strategy.
- Account deletion and consent withdrawal require careful lifecycle management.
- Deletion should include appropriate systems, processors and backup considerations.
- Retention policies should be documented and periodically reviewed.
- Automation can make retention and erasure more reliable at scale.
Conclusion
Data retention under the DPDP Act is not about choosing one number of years and applying it to every piece of personal data.
It is about creating a controlled data lifecycle.
An organisation should know:
What data it has → Why it has it → Where it is stored → How long it should be retained → What legal requirement applies → When it should be erased → How erasure is verified.
The DPDP Rules, 2025 make this issue even more operational by establishing specific requirements for certain Data Fiduciaries, including advance notice before certain erasures and a minimum one-year retention period for specified personal data and processing logs.
For businesses, the best approach is to build a data retention and deletion framework that combines privacy requirements with legal, regulatory, security and operational needs.
A mature DPDP compliance programme should therefore treat data discovery, purpose limitation, retention, deletion, consent management and auditability as interconnected processes rather than separate compliance tasks.
Official references
- MeitY – Digital Personal Data Protection Rules, 2025
- MeitY – Gazette Notification containing DPDP Rules, 2025
- MeitY – Explanatory Note to DPDP Rules, 2025
This article is intended for educational and SEO purposes and should not be treated as legal advice. Organisations should assess their specific retention obligations against the DPDP Act, DPDP Rules, applicable sectoral regulations and other laws.
I can also create a DPDP Acts–style FAQ section, schema-ready FAQ markup, and internal-linking plan for this article.