AMLEGALS — Strategic Lawyering

The Three-Year Erasure Rule for Online Gaming Platforms

The Three-Year Erasure Rule for Online Gaming Platforms

The player logged off. The clock started.

The scene

Half the registered base had not played in three years. The CRM team scheduled a win-back campaign to all of them. Legal pointed out that for a platform of that size, the Rules had already scheduled something else.

Where the thinking breaks

The unclear thought What it breaks The clearer thought

Accounts are kept until the user deletes them.

For covered platforms the Rules require erasure after three years of inactivity, with prior notice.

Build erasure into the account lifecycle.

Purchase history must stay.

Keep what tax and law require; erase the profile.

Separate transaction records from player profiles.

The last message

Notice before erasure is required. Make it honest and simple: what goes, when, and how to keep the account.

Monday morning

01 Count accounts inactive for three years.

02 Separate records the law requires.

03 Draft the pre-erasure notice.

Questions, answered plainly

Does the three-year erasure rule apply to gaming companies? +

The DPDP Rules apply it to online gaming intermediaries above a registered-user threshold in India, requiring erasure after three years of inactivity with advance notice, unless law requires retention.

What notice must be given before erasure? +

The Rules require informing the Data Principal at least 48 hours before erasure that their data will be erased unless they log in or engage.

Sector · Gaming Your fastest-growing segment may legally be children. Read →

Gaming · Deep dive Twelve-year-olds learn to type 2001 in a week. Read →

Gaming · Deep dive Engagement is the product. For children, it is the risk. Read →

Tell us where your data sits. We'll show you where the exposure is.

A partner replies within one working day, with a first view on your penalty exposure.

Speak to a partner →

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).