How long must you retain personal data under DPDP — data retention guide
DPDP requires you to delete personal data when it is no longer needed. Here is a practical guide to building a DPDP-compliant data retention schedule.
What is the DPDP retention principle?
The retention principle: retain personal data only as long as is necessary for the processing purpose or as required by law. This creates a two-step test: (1) Is there a statutory minimum retention requirement? If yes, retain until that period expires. (2) After any statutory minimum, is there still a legitimate business purpose for retaining the data? If no, delete. Most organisations fail on step 2 — they comply with statutory minimums but then retain data indefinitely without re-evaluating the ongoing business purpose. DPDP ends this default to indefinite retention.
What are the key statutory retention periods in India?
Common Indian statutory retention minimums for personal data: Income Tax records — 8 years from the end of the relevant assessment year (Income Tax Act); EPF records — 5 years after the last contribution (EPF Act); ESIC records — 5 years; Gratuity records — until the gratuity liability is discharged (Payment of Gratuity Act); Companies Act records (registers, minutes) — the Companies Act prescribes varying periods, generally 8–10 years; PMLA customer records (KYC, transaction records) — 5 years after the end of the customer relationship or the transaction. These minimums define the floor, not the ceiling — DPDP requires deletion once the minimum period and business purpose have both expired.
How do you build a data retention schedule?
Structure: list every category of personal data your organisation holds; for each category, identify the processing purpose; identify applicable statutory retention requirements; determine the business purpose retention period (the period needed beyond statutory requirements); set the total retention period (the greater of statutory minimum and business purpose period); and specify the deletion method (anonymise, delete, shred). Review the schedule annually. Automate deletion where possible — build retention period triggers into your databases and CRM. Manual deletion processes are unreliable at scale.
What are best practice retention periods for common data types?
Suggested retention periods (business purpose based): customer contact data (inactive customers) — 3 years from last interaction or account closure; marketing consent records — 5 years from the date consent was given (evidence of consent); employee records — 7 years from employment termination (covers most statutory minimums); job applicant data (unsuccessful candidates) — 90 days from the role being filled; vendor contact data — 3 years from last business transaction; website analytics data — 12 months; CCTV footage — 30 days (unless an incident requires extended retention).
What is the DPDP deletion standard?
DPDP does not specify a technical deletion standard, but the intent is genuine deletion — not merely archiving data to an inaccessible location. Best practice: hard deletion from production systems; deletion from backups within the next backup cycle (or ensuring the data is overwritten by routine backup processes); deletion from cloud storage; notification to Data Processors (vendors) to delete their copies. Document the deletion event — a deletion log stating what was deleted, when, and by whom is valuable evidence of compliance. For highly sensitive data (biometric, health, financial), use certified data destruction or cryptographic erasure.
How do you handle personal data that spans multiple retention periods?
A single customer record may contain data with different retention requirements: transaction records (PMLA — 5 years); tax records (Income Tax Act — 8 years); marketing consent records (best practice — 5 years); contact details (business purpose — 3 years after account closure). The record cannot be deleted in one block — delete individual fields as their retention periods expire while retaining others. In practice, this requires field-level retention controls in your database schema, or a periodic data review process that deletes specific fields while retaining others. This is one of the more technically complex aspects of DPDP compliance for organisations with large legacy databases.
Frequently asked questions
Can we retain personal data in an anonymised form after the retention period expires?
Yes. Once data is genuinely anonymised — where it is impossible to identify the individual from the data, even with other available information — it is no longer personal data and falls outside the DPDP Act's scope. Anonymised data can be retained indefinitely for statistical, research, or analytical purposes without DPDP compliance obligations. The critical requirement: the anonymisation must be genuine. Pseudonymised data (replaced with a code that could be re-linked to the individual) is still personal data and cannot be retained indefinitely under DPDP.
What happens if we cannot technically delete data from a backup?
Backups present a practical challenge: you cannot typically delete individual records from a backup tape or snapshot without restoring and rebuilding the entire backup. Standard practice: ensure that data in backups is overwritten in the routine backup cycle; document your backup retention policy (most backups are retained for 30–90 days before being overwritten); and if a backup must be retained beyond the data's retention period, segregate it with restricted access and delete it at the next available backup rotation. Note in your retention schedule that backup data may persist for up to your backup retention period after the active data is deleted.
Must we inform data principals when their data is deleted?
The DPDP Act does not require proactive notification of data deletion — you do not need to email customers to tell them their data was deleted at the end of the retention period. However, if a data principal has requested erasure, you should confirm that the deletion has been carried out. For data principals who ask whether their data has been deleted (as part of an access request or follow-up), you should be able to confirm deletion and the date on which it occurred from your deletion log.
Build your DPDP data retention schedule
Niti Bharat's Data Retention Schedule tool generates a customised retention schedule for your industry — covering all data categories, statutory minimums, business purpose periods, and deletion triggers.
Build Your Retention Schedule