DPDP retention and erasure

DPDP data retention and erasure
under section 8(7) and Rule 8.

When personal data has to be erased under the DPDP Act, the three-year inactivity rule for large platforms, the 48-hour warning, the one-year minimum for logs, and how it fits with RBI, PMLA and CERT-In retention duties.

Section 8(7)Rule 8Third ScheduleRule 8(3)

Last updated Published by TryTrustableNot legal advice

01

When must personal data be erased under the DPDP Act?

Under section 8(7) of the DPDP Act, a Data Fiduciary must erase personal data when the Data Principal withdraws consent, or as soon as it is reasonable to assume the specified purpose is no longer served, whichever comes first, and must make its Data Processors erase what it gave them. Retention required by another law is the exception.

Section 8(7) comes with two illustrations. A person sells her used car through an online marketplace; once the sale concludes, the marketplace must no longer retain her data. A person closes a savings account; the bank keeps her identity records for the period banking law requires, because retention is necessary for compliance with law.

Three other provisions complete the picture:

  • Section 8(8) deems the purpose no longer served if the Data Principal neither approaches the Data Fiduciary for it nor exercises her rights for a prescribed period, which Rule 8 supplies for three classes
  • Section 8(11) says she has not approached you in any period in which she did not initiate contact for that purpose, in person or by electronic or physical communication. Your marketing emails do not count
  • Section 12(3) gives her a right to ask for erasure, which you must honour unless retention is necessary for the purpose or for compliance with law

Section 8(7) is an erasure duty, not a retention policy. Having a schedule that says two years is not compliance unless something actually erases on it.

02

What is the three-year erasure rule for large platforms?

Rule 8 and the Third Schedule deem the purpose over after three years of inactivity for three classes: e-commerce entities with at least two crore registered users in India, online gaming intermediaries with at least fifty lakh, and social media intermediaries with at least two crore. They must then erase, after 48 hours' warning.

Class (Third Schedule)Registered users in IndiaPeriodPurposes excluded
E-commerce entityNot less than 2 croreThree years from the later of her last approach or exercise of rights, or the Rules' commencementAccess to her user account; access to virtual tokens issued by the platform that can be used for money, goods or services
Online gaming intermediaryNot less than 50 lakhSameSame
Social media intermediaryNot less than 2 croreSameSame

From Rule 8(1) and the Third Schedule to the DPDP Rules 2025. E-commerce entity takes its meaning from the Consumer Protection Act, 2019 and excludes sellers on a marketplace; social media intermediary from the IT (Intermediary Guidelines) Rules, 2021.

Three details decide how the job is built.

The exclusions are narrow. Keeping the account itself reachable, and wallet balances, gift cards or in-game currency usable, is carved out. Everything else about the person, including order history held only for analytics, is in scope.

The clock starts no earlier than commencement. The period runs from the latest of her last approach, her last exercise of rights, or the commencement of the Rules. On any reading, no Third Schedule erasure falls due before late 2028, and if commencement means the date Rule 8 itself takes effect, 13 May 2027, the first ones fall due on 13 May 2030. Take advice on which date applies to you.

Rule 8(2) requires a warning. At least forty-eight hours before the period ends, you must tell her the data will be erased unless she logs in, otherwise contacts you for the purpose, or exercises her rights. Any of those resets the clock, so the notice job and the erasure job have to share one source of truth about last activity.

03

What is the one-year minimum retention under Rule 8(3)?

Rule 8(3) sets a floor for every Data Fiduciary: keep the personal data, associated traffic data and processing logs of every processing, including processing done for you by Data Processors, for at least one year from the processing, then erase them unless another law requires longer.

The purposes are those in the Seventh Schedule: use by the State for sovereignty, integrity or security, performance of legal functions, and the assessment of whether to notify a Significant Data Fiduciary. The Rule's illustrations are specific. An e-book platform keeps the order, payment and delivery records for a year even if the buyer deletes her account. A company using a cloud host must make sure the host also keeps the data and logs for a year before erasing.

Rule 6(1)(e) separately requires logs and personal data to be kept for a year for detecting and investigating unauthorised access, as part of reasonable security safeguards. The two floors point the same way. What they change is the order of operations: an erasure on withdrawal of consent under section 8(7) can no longer mean deleting everything at once. The live record goes; the processing record for the last year stays, restricted to those purposes, and then goes.

Reporting on MeitY's January 2026 consultation said Rule 8(3) was among the provisions proposed for early commencement. That had not been notified as of 28 September 2026; Rule 8 commences on 13 May 2027.

04

How does DPDP erasure interact with RBI, PMLA and CERT-In rules?

Other retention laws prevail over DPDP erasure for the records they cover, because section 8(7) and section 12(3) both allow retention required by law. The usual Indian examples are PMLA's five-year record keeping for regulated entities, CERT-In's log retention, and RBI's requirement that payment data be stored in India.

LawWhat it requiresEffect on DPDP erasure
PMLA section 12Reporting entities keep transaction records for five years from the transaction, and identity records for five years after the relationship ends or the account closes, whichever is later.Those records are retained for five years despite withdrawal or an erasure request. Everything else about the person is not.
CERT-In Directions, 2022Service providers keep ICT system logs for a rolling 180 days within Indian jurisdiction.Longer than nothing, shorter than Rule 8(3)'s year. Keep logs for the longer period.
RBI payment data storage, 2018Payment system data stored only in India.A location rule, not a duration. It decides where retained payment data lives.
Sector-specific record rulesTax, company, insurance and securities law set their own periods.Each is a legal exception for its own records, and only those.

Summary for orientation; the retention period that binds you depends on your sector and licence.

The discipline is to retain by record type, not by person. A withdrawn customer's KYC file stays for the PMLA period; her marketing profile, product analytics and support transcripts do not. The CERT-In and DPDP breach reporting comparison covers the other place the two regimes meet.

05

What does a DPDP retention and erasure programme need?

A DPDP retention programme needs a schedule by purpose and record type, a legal basis for every period longer than the purpose, a tracked last-activity date per person, a 48-hour notice job where the Third Schedule applies, erasure instructions to every processor, and evidence that each erasure happened when it fell due.

1. Schedule by purpose. For each purpose in your notice, when does it end, what law (if any) extends it, and what is kept for Rule 8(3)'s year. The record of processing activities template has a column for each.

2. Know where the data is. Erasure fails most often in the copy nobody listed: the analytics warehouse, the CRM export, the support tool. Data discovery finds them and tracks erasure requests on the clock.

3. Reach the processors. Section 8(7)(b) makes you cause your processors to erase. That needs a contract term, a channel and a confirmation; the DPDP data processing agreement template includes one.

4. Keep the proof. If the Board asks whether you erased a person's data when her consent was withdrawn, the answer is a dated record, not a policy. TryTrustable watches erasure: it knows when erasure fell due, for whom, and which processors hold the data, and it keeps the signed record. It does not delete data in your systems; your teams and processors do that.

A failure to erase falls under the ₹50 crore catch-all in the Schedule. See the DPDP penalty schedule.

Related guides: children's data and verifiable parental consent, cross-border data transfer, Significant Data Fiduciary duties, how the Data Protection Board works and the dated DPDP regulatory tracker. The DPDP Act and Rules 2025 guide sets out the whole timetable, and the DPDP penalty schedule what each failure can cost.

Questions

The things people ask us

How long can personal data be kept under the DPDP Act?

Until consent is withdrawn or it is reasonable to assume the purpose is no longer served, whichever is earlier, under section 8(7), unless another law requires longer. For large e-commerce, gaming and social media platforms, Rule 8 deems the purpose over after three years of inactivity. Every Data Fiduciary must also keep processing logs for at least one year.

What is the three-year erasure rule in the DPDP Rules?

Under Rule 8 and the Third Schedule, e-commerce entities and social media intermediaries with at least two crore registered users in India, and online gaming intermediaries with at least fifty lakh, must erase a person's data three years after she last engaged or exercised her rights, with 48 hours' notice first. Account access and stored-value tokens are excluded.

Must we warn users before erasing their data?

Yes, for the Third Schedule erasures. Rule 8(2) requires the Data Fiduciary to tell the Data Principal at least forty-eight hours before the period ends that her data will be erased unless she logs in, otherwise contacts the Data Fiduciary for the purpose, or exercises her rights. Any of those restarts the clock.

What is the one-year minimum retention under Rule 8(3)?

Every Data Fiduciary must keep the personal data, associated traffic data and other logs of each processing, including processing by its Data Processors, for at least one year from the processing, for the purposes in the Seventh Schedule. After that it must erase them unless another law requires longer. It applies even if the user deletes her account.

Does DPDP erasure override RBI or PMLA retention rules?

No. Section 8(7) and section 12(3) both allow retention where another law requires it. The Act's own illustration is a bank keeping identity records after an account closes. Under section 12 of the Prevention of Money-laundering Act, reporting entities keep transaction and identity records for five years, and that prevails over a DPDP erasure request for those records.

Does TryTrustable delete data from our systems?

No. TryTrustable watches erasure: it knows when erasure fell due, for whom, and which processors hold the data, and it keeps the signed record. The deletion itself happens in your systems and your processors' systems, done by your teams and theirs.

Withdrawal starts the clock

Consent withdrawn is erasure due.

Consent by TryTrustable records every choice and every withdrawal against the notice that produced it. Start with the free scan of what your site collects before anyone chooses.