AMLEGALS — Strategic Lawyering
Back to Documents
Policy

Data Retention Policy

Governing how long personal data is kept and when it must be deleted

Section 8(7)Rule 6

Data does not live forever. DPDPA requires that personal data be erased once the purpose for which it was collected has been fulfilled and retention is no longer necessary. This is not a suggestion. It is a statutory obligation with penalty exposure.

The Retention Principle

Section 8(7) establishes the rule: erase personal data when the purpose is fulfilled and retention is no longer necessary for that purpose or legal requirements. This means you cannot keep data indefinitely just in case it might be useful. You need a reason. When the reason ends, the data must go.

Defining Retention Periods

Your policy must specify retention periods for each data category. These periods should be tied to purpose fulfillment plus any legally mandated retention. Employment records may need to be kept for years after employment ends due to labor law requirements. Transaction records may need preservation for tax compliance. The policy must account for these overlapping requirements.

Key Points
  • Retention period for each data category
  • Legal basis for each retention period
  • Trigger events for retention period commencement
  • Review schedule for retention period appropriateness

Erasure Procedures

Stating that data will be deleted is not enough. You need procedures for how deletion occurs. Who initiates it. How it is verified. What happens to backups. Deletion must be complete, not just removal from active systems while copies persist in archives.

Interaction with Data Principal Rights

Data Principals have the right to erasure under Section 12. Your retention policy must accommodate this. When a Data Principal requests erasure, you must comply unless a legal obligation requires continued retention. The policy should clarify how erasure requests interact with retention schedules.

Essential Clauses

Retention Schedule by Data Category

Section 8(7)

Specific periods for each type of personal data

Legal Retention Obligations

Section 8(7)

Reference to laws requiring retention beyond purpose fulfillment

Erasure Trigger Events

Rule 6

What events initiate the deletion process

Deletion Verification Procedure

Rule 6

How complete deletion is confirmed

Backup and Archive Treatment

Section 8(7)

How deletion extends to backup systems

Exception Handling

Section 8(7)

Process for cases where retention beyond schedule is necessary

Implementation Steps

1

Conduct data inventory identifying all personal data repositories

2

Map each data category to its processing purpose

3

Research applicable legal retention requirements

4

Define retention period for each category with documented rationale

5

Implement automated retention monitoring where possible

6

Establish deletion workflows with verification checkpoints

7

Train relevant personnel on retention policy application

8

Schedule periodic policy reviews to reflect changing requirements

Frequently Asked Questions

Need This Document Drafted?

Understanding the requirement is the first step. Having it implemented correctly is what protects your organization. Our team drafts DPDPA-compliant documents tailored to your specific operations.

Get in Touch

DPDPA Data Retention Policy: questions and answers

What must a DPDPA privacy notice contain?

Section 5 read with Rule 3 requires a notice, understandable independently of other information, that itemises the personal data and the specified purpose, and explains how the Data Principal may withdraw consent, exercise rights and complain to the Board. A Data Principal has the right to access the notice in English or any language specified in the Eighth Schedule to the Constitution. The design of translation operations is an implementation matter.

What makes consent valid under DPDPA?

Section 6 requires consent to be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action and limited to personal data necessary for the specified purpose. Withdrawal must be as easy as giving consent.

Is a Data Fiduciary responsible for its vendors under DPDPA?

Yes. Section 8(1) makes the Data Fiduciary responsible for compliance in respect of processing undertaken by it or on its behalf by a Data Processor. Section 8(2) requires a Data Fiduciary to engage a Data Processor under a valid contract. Detailed contractual clause architecture is an implementation best practice guided by Section 8(2).

Which provisions of the DPDPA and the DPDP Rules, 2025 are relevant to DPDPA Data Retention Policy?

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).

Who advises businesses on DPDPA Data Retention Policy under India's DPDPA?

AMLEGALS, an Indian law firm, advises Data Fiduciaries, Data Processors and foreign companies on DPDPA Data Retention Policy under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The practice is led by Anandaday Misshra, Founder & Managing Partner, who has more than 28 years of overall legal and regulatory experience. Enquiries: https://amlegalsdpdpa.com/contact or [email protected] or [email protected].

What should I send AMLEGALS to get a scoped proposal on DPDPA Data Retention Policy?

Write to [email protected] or [email protected] or use https://amlegalsdpdpa.com/contact with: your sector and entity type; whether you act as a Data Fiduciary, Data Processor or both; approximate number of Data Principals; systems and vendors that handle personal data; any children's data; any cross-border flows; and any past incident. With these facts a partner can propose a scope for DPDPA Data Retention Policy rather than a generic checklist.

How do I get a first view of my DPDPA exposure on DPDPA Data Retention Policy?

Use the DPDPA Exposure Assessment at https://amlegalsdpdpa.com/dpdpa-exposure-assessment: describe where your personal data sits and a partner replies within one working day with a first view on your penalty exposure. Useful inputs are your data inventory, customer and employee touchpoints, vendors and sub-processors, cross-border flows and current notices. The principal obligations commence on 13 May 2027. Content is general legal information and not legal advice.

Contact AMLEGALS about DPDPA Data Retention Policy · DPDPA Exposure Assessment