The legal basis: Section 8(7) and its scope
Section 8(7) provides that the Data Fiduciary shall erase personal data: (a) where the Data Principal has withdrawn consent, unless retention is necessary for compliance with any law; and (b) where the specified purpose is no longer being served and retention is no longer necessary for that purpose.
The obligation is dual-triggered: it applies both on consent withdrawal and on purpose completion. A Data Fiduciary cannot retain data indefinitely by arguing that it “might” be useful later—the purpose must be specified at the time of collection (Section 5 notice) and retention must be limited to that purpose.
Building a data retention policy: step-by-step
A compliant retention policy translates the statutory obligation into operational practice:
- 01
Data inventory
Catalogue every category of personal data the organisation collects—customer records, employee files, marketing databases, vendor contact data, website analytics.
- 02
Purpose mapping
Link each data category to the specific processing purpose stated in the Section 5 notice. If the notice says “order fulfilment,” the retention period must relate to order fulfilment—not indefinite CRM retention.
- 03
Retention-period definition
Define a retention period for each category. Where a sector-specific law mandates minimum retention (e.g. Companies Act—8 years for financial records), use the longer of the statutory minimum and the purpose-based period.
- 04
Deletion workflow
Implement automated deletion—scheduled jobs that purge records at the end of the retention period. Where automation is not feasible, document a manual review-and-delete process with assigned responsibility.
- 05
Consent-withdrawal handling
Build a mechanism to process consent-withdrawal requests: verify the Data Principal’s identity, check whether any legal hold or statutory retention applies, and delete if no exception applies.
- 06
Audit trail
Maintain records of what was deleted, when and by whom. The Board may ask for evidence that the erasure obligation was fulfilled.
Sector-specific retention rules preserved by Section 16(2)
Section 16(2) preserves stricter obligations in other laws. Several statutes mandate minimum retention periods that override the DPDPA’s erasure-on-purpose-completion rule:
| Sector / Law | Retention requirement | Interaction with DPDPA |
|---|---|---|
| Companies Act 2013 | Financial records: 8 years from date of transaction | Retention mandatory even after purpose served; erasure only after 8 years |
| Income Tax Act 1961 | Tax records: 6–8 years from end of assessment year | S.8(7) erasure deferred until tax-retention period expires |
| RBI KYC Directions | KYC records: 5 years after account closure | Banks must retain identity data for 5 years post-closure |
| SEBI regulations | Trading records: varies by regulation (5–8 years) | Brokers retain client data per SEBI timelines |
| Drugs & Clinical Trials Rules 2019 | Trial data: 5 years after trial completion | Clinical research data retained per rule, not DPDPA purpose |
Where a sector-specific retention mandate is longer than the DPDPA purpose-based period, the organisation must retain data for the full statutory period and then erase it. The DPDPA’s erasure obligation applies at the end of the longer period.
How AMLEGALS assists with retention policy design
AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder and Managing Partner, with Rohit Lalwani, Associate Partner, working on DPDPA compliance. The firm assists organisations in conducting data inventories, mapping retention periods across the DPDPA and sector-specific statutes, designing automated deletion workflows and building audit-ready retention documentation.

