How do I write a DPDP data retention policy?
Turn the retention principle into a document you can enforce.
Build it from your inventory
Start with a data inventory so the policy reflects reality. For each category — customer records, marketing contacts, employee files, logs — record why you hold it, how long, the legal basis for any extended retention, and what triggers deletion.
Make periods defensible
Justify each period against a purpose or a law. 'Indefinite' is rarely defensible. Where a regulator mandates a minimum, cite it; where it's your own choice, tie it to the time the data remains useful for its purpose.
Operationalise and review
Assign an owner, automate deletion where you can, and review the schedule at least annually and whenever practices change. Keep deletion logs as evidence of compliance.
Frequently asked questions
What should a retention policy contain?
Data categories, purposes, retention periods, the basis for any extended retention, deletion triggers, ownership, and how backups and processor copies are handled.
How do I set the right period?
Tie it to the purpose or a statutory requirement. If neither justifies keeping the data, delete it.
How often should I review it?
At least annually and whenever your data practices, vendors or legal obligations change.
Generate a retention policy
Use the Data Retention Policy Generator to produce a category-by-category schedule you can enforce.
Retention Policy Generator