How to implement data retention and deletion under DPDP

How to implement data retention and deletion under DPDP
Retention

How to implement data retention and deletion under DPDP

Keeping data longer than necessary is a DPDP violation. Here is how to build a retention schedule and implement automated deletion.

Quick Answer: The DPDP Act requires that personal data be retained only as long as necessary for the specified purpose or for the period required by applicable law — whichever is longer. After that period, the data must be erased or anonymised. Retaining data indefinitely 'just in case' is not a lawful retention basis under the Act. Building a data retention schedule requires mapping each data category to its applicable statutory or operational retention period, implementing automated deletion workflows, and documenting the schedule so it can be produced on Board inquiry. Vendor systems that retain your data after termination must be covered by deletion obligations in your DPAs.

What is the DPDP storage limitation principle?

The Act requires that personal data not be retained beyond the period necessary for its processing purpose. Retention must be justified by either: (a) the purpose itself (customer data retained while the customer relationship is active); (b) a specific statutory requirement (income tax records for 8 years, GST records for 6 years, EPF records for the life of the fund); or (c) a legal obligation such as a court order or regulatory investigation hold. Generic justifications — 'we might need it', 'it could be useful for analytics', 'our backup system keeps it indefinitely' — are not lawful retention bases.

How do you build a data retention schedule?

A retention schedule maps each data category to its applicable retention period. For each category, identify: the purpose for which the data is held; the applicable statutory retention period (Income Tax Act, Companies Act, GST Act, Labour laws, SEBI, RBI rules — all specify different periods); the operational retention need (how long does the business need the data after the relationship ends); and the deletion method (secure deletion, anonymisation, or archival). Apply the longer of the statutory period and the operational need, and document the justification.

What statutory retention periods apply to Indian businesses?

Key statutory periods: Income Tax records — 8 years from end of relevant year. GST records — 72 months (6 years). Company books of account — 8 years (private companies), indefinite for public companies under certain circumstances. EPF records — life of the fund or 5 years after claim settlement. SEBI investor records — 5 years from transaction date. Contracts and agreements — 3–12 years depending on cause of action limitation period. Bank account statements — 10 years under PMLA. Medical records — 3–5 years depending on context. Map each data category against the applicable law.

How do you implement automated deletion workflows?

Manual deletion does not scale. Implement automated deletion: set a deletion date for each record or data category in your database when the record is created or the relationship ends; build a scheduled job that runs periodically (weekly or monthly) to identify and delete records past their retention date; log all deletions in an audit trail; and test the deletion workflow in a staging environment before deploying to production. For archived data (cold storage, backup tapes), include a backup purge schedule aligned to your retention policy.

How do you handle deletion requests vs statutory retention obligations?

When a data principal requests erasure under DPDP, you must delete data that is no longer needed for any lawful purpose. But statutory obligations create an exception: you cannot delete data you are legally required to retain (GST invoice, employment record, bank transaction). The correct response to an erasure request is: delete the data not covered by statutory retention, and explain to the data principal what data must be retained and for how long. Do not use 'statutory retention' as a blanket refusal — only the specific records required by specific laws can be retained.

How do you manage retention for backup and archival systems?

Backup and archival systems are often excluded from data deletion workflows — a record deleted from the production database may persist in backups for months or years. Your retention policy must address backups: define how long backups are kept (e.g., 30 days for daily backups, 12 months for monthly archives); implement backup purge schedules; and ensure that when a data principal's data is deleted from production, you have a process to confirm when that deletion will propagate to backups. For compliance-critical deletion requests (court order, severe harm risk), consider accelerated purge of backup data.

Frequently asked questions

Can we anonymise data instead of deleting it?

Yes. Anonymisation — genuinely removing all identifying information so that the individual can no longer be re-identified even indirectly — satisfies the deletion obligation under DPDP. Anonymised data is no longer personal data and is outside the Act's scope. The key is that anonymisation must be genuine, not pseudonymisation (where a code replaces the name but the key is retained). Common anonymisation techniques: k-anonymity, data masking, aggregation. Pseudonymised data is still personal data — deleting the key makes it anonymous.

What counts as a lawful basis for retaining customer data after the relationship ends?

After a customer relationship ends (account closure, subscription cancellation, purchase completion), the lawful basis for retaining data shifts: statutory obligations (tax records, consumer protection claims periods) justify retention for specific data for specific periods. Beyond that, you may retain data for a short period for post-relationship purposes — dispute resolution, product return windows — but must delete after that window closes. Retaining the full customer profile indefinitely for 'win-back marketing' without renewed consent is not a lawful basis.

How do we handle retention for data held by vendors (Data Processors)?

Your DPA with each vendor must specify the retention period for data they process on your behalf — and the obligation to delete on your instruction or on contract termination. Conduct an annual vendor DPA review to verify that vendors are actually deleting data within the specified period. Request deletion certificates from critical vendors at contract end. Remember that a vendor's backup systems may retain data beyond the nominal deletion date — your DPA should address backup purge timelines.

Build your DPDP data retention schedule

Niti Bharat's Data Retention Schedule template provides pre-mapped statutory periods for Indian businesses — Income Tax, GST, EPF, SEBI, and more — with an automated deletion workflow guide.

Get the Retention Schedule Template
Previous Post Next Post

Get Free DPDP Checklist