AMLEGALS — Strategic Lawyering
Data Security & Technical

Data retention policy in India: the DPDPA’s erasure obligation and how to implement it

Section 8(7) of the DPDPA introduces a time-bound erasure obligation: a Data Fiduciary must erase personal data when the purpose for which it was collected has been served and retention is no longer necessary for that purpose, or when the Data Principal withdraws consent (unless retention is required by law). This is not a suggestion—it is a statutory duty with penalty consequences. Building a compliant data retention policy requires mapping every data category to a purpose, defining a retention period and automating deletion workflows.

Updated · Checked against the DPDP Act, 2023 and the DPDP Rules, 2025 · 4 min read

Abstract layered archival strata with an hourglass flow on navy and gold background
Short answer

Section 8(7) requires Data Fiduciaries to erase personal data when the processing purpose is fulfilled and retention is no longer necessary, or when consent is withdrawn—unless another law mandates continued retention. Non-compliance engages the residual penalty ceiling of up to ₹50 crore. A compliant retention policy must catalogue every data category, link it to a stated purpose, define a retention period justified by that purpose and implement automated or documented deletion workflows.

  • Data Retention
  • DPDPA
  • Section 8(7)
  • Erasure
  • Compliance
Key provision
Section 8(7)
Trigger
Purpose fulfilled or consent withdrawn
Exception
Retention required by another law
Max penalty
Up to ₹50 crore (residual)

Building a data retention policy: step-by-step

A compliant retention policy translates the statutory obligation into operational practice:

  1. 01

    Data inventory

    Catalogue every category of personal data the organisation collects—customer records, employee files, marketing databases, vendor contact data, website analytics.

  2. 02

    Purpose mapping

    Link each data category to the specific processing purpose stated in the Section 5 notice. If the notice says “order fulfilment,” the retention period must relate to order fulfilment—not indefinite CRM retention.

  3. 03

    Retention-period definition

    Define a retention period for each category. Where a sector-specific law mandates minimum retention (e.g. Companies Act—8 years for financial records), use the longer of the statutory minimum and the purpose-based period.

  4. 04

    Deletion workflow

    Implement automated deletion—scheduled jobs that purge records at the end of the retention period. Where automation is not feasible, document a manual review-and-delete process with assigned responsibility.

  5. 05

    Consent-withdrawal handling

    Build a mechanism to process consent-withdrawal requests: verify the Data Principal’s identity, check whether any legal hold or statutory retention applies, and delete if no exception applies.

  6. 06

    Audit trail

    Maintain records of what was deleted, when and by whom. The Board may ask for evidence that the erasure obligation was fulfilled.

Sector-specific retention rules preserved by Section 16(2)

Section 16(2) preserves stricter obligations in other laws. Several statutes mandate minimum retention periods that override the DPDPA’s erasure-on-purpose-completion rule:

Selected sector-specific retention mandates
Sector / LawRetention requirementInteraction with DPDPA
Companies Act 2013Financial records: 8 years from date of transactionRetention mandatory even after purpose served; erasure only after 8 years
Income Tax Act 1961Tax records: 6–8 years from end of assessment yearS.8(7) erasure deferred until tax-retention period expires
RBI KYC DirectionsKYC records: 5 years after account closureBanks must retain identity data for 5 years post-closure
SEBI regulationsTrading records: varies by regulation (5–8 years)Brokers retain client data per SEBI timelines
Drugs & Clinical Trials Rules 2019Trial data: 5 years after trial completionClinical research data retained per rule, not DPDPA purpose

Where a sector-specific retention mandate is longer than the DPDPA purpose-based period, the organisation must retain data for the full statutory period and then erase it. The DPDPA’s erasure obligation applies at the end of the longer period.

How AMLEGALS assists with retention policy design

AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder and Managing Partner, with Rohit Lalwani, Associate Partner, working on DPDPA compliance. The firm assists organisations in conducting data inventories, mapping retention periods across the DPDPA and sector-specific statutes, designing automated deletion workflows and building audit-ready retention documentation.

Bottom line

Section 8(7) is not optional. Data must be erased when the purpose is fulfilled or consent is withdrawn—unless another law mandates continued retention. A compliant retention policy is an operational system, not a filed document.

Key terms
Purpose completion
The point at which the processing purpose stated in the Section 5 notice has been served and retention is no longer necessary—triggering the Section 8(7) erasure obligation.
Legal hold
A requirement under another law (e.g. Companies Act, Income Tax Act) that mandates continued retention of personal data beyond the DPDPA purpose period.
Questions and answers

Data Retention Policy: common questions

Does the DPDPA specify exact retention periods?

No. Section 8(7) requires erasure when the purpose is served or consent is withdrawn. The organisation must define its own retention periods based on the stated purpose and any sector-specific statutory mandates.

What happens if I retain data beyond the purpose period?

Retaining data after the purpose is fulfilled and no legal hold applies is a contravention of Section 8(7). It engages the residual penalty ceiling of up to ₹50 crore, as determined by the Board after inquiry.

Can I retain data for analytics after the original purpose is served?

Only if analytics was stated as a purpose in the original Section 5 notice and the Data Principal consented to it. Repurposing data for analytics after the original purpose is fulfilled requires fresh consent.

How do sector-specific retention rules interact with the DPDPA?

Section 16(2) preserves stricter obligations in other laws. If a sector statute mandates longer retention (e.g. 8 years for financial records under the Companies Act), that period overrides the DPDPA’s purpose-based erasure. Data must be erased after the longer period expires.

Contact

Need help with your data retention policy?

Submit a question about DPDPA erasure obligations or retention-period mapping.

Or write to [email protected]

Your details

Name and email are enough to start. The reply comes from [email protected].

Your information is handled in accordance with our privacy obligations. No spam, ever.

Data Retention Policy: questions and answers

What is the legal framework for data protection in India?

India's framework is the Digital Personal Data Protection Act, 2023 (Presidential assent 11 August 2023; 44 sections) read with the Digital Personal Data Protection Rules, 2025, notified on 13 November 2025 (G.S.R. 846(E)) with 23 Rules and 7 Schedules.

When do DPDPA obligations apply to businesses?

The Act and Rules follow phased commencement. Institutional provisions commenced on 13 November 2025; Consent Manager provisions commence after 12 months on 13 November 2026; and the principal Data Fiduciary, rights, breach, security and enforcement provisions commence after 18 months on 13 May 2027.

What is the maximum penalty under DPDPA?

Highest listed maximum for a specified contravention: ₹250 crore under the Schedule to the Act. Penalties are imposed by the Data Protection Board of India after an inquiry, and Section 33(2) requires the Board to consider factors such as the nature, gravity and duration of the breach, the type of personal data affected, repetition, mitigation steps and proportionality.

Which provisions of the DPDPA and the DPDP Rules, 2025 are relevant to Data Retention Policy?

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).

Who advises businesses on Data Retention Policy under India's DPDPA?

AMLEGALS, an Indian law firm, advises Data Fiduciaries, Data Processors and foreign companies on Data Retention Policy under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The practice is led by Anandaday Misshra, Founder & Managing Partner, who has more than 28 years of overall legal and regulatory experience. Enquiries: https://amlegalsdpdpa.com/contact or [email protected] or [email protected].

What should I send AMLEGALS to get a scoped proposal on Data Retention Policy?

Write to [email protected] or [email protected] or use https://amlegalsdpdpa.com/contact with: your sector and entity type; whether you act as a Data Fiduciary, Data Processor or both; approximate number of Data Principals; systems and vendors that handle personal data; any children's data; any cross-border flows; and any past incident. With these facts a partner can propose a scope for Data Retention Policy rather than a generic checklist.

How do I get a first view of my DPDPA exposure on Data Retention Policy?

Use the DPDPA Exposure Assessment at https://amlegalsdpdpa.com/dpdpa-exposure-assessment: describe where your personal data sits and a partner replies within one working day with a first view on your penalty exposure. Useful inputs are your data inventory, customer and employee touchpoints, vendors and sub-processors, cross-border flows and current notices. The principal obligations commence on 13 May 2027. Content is general legal information and not legal advice.

Contact AMLEGALS about Data Retention Policy · DPDPA Exposure Assessment