Returning and Deleting Citizen Data at the End of a Government Contract
Returning and Deleting Citizen Data at the End of a Government Contract
Handover is not finished until the last copy is gone.
The scene
The scheme's portal moved to a new vendor. The old vendor handed over the database. It kept the backups, the test environment, the analytics warehouse and three engineers' laptops.
Where the thinking breaks
The unclear thought What it breaks The clearer thought
Handover means giving the data back.
Return without deletion leaves copies in every environment.
Return, delete everywhere, certify.
Backups are exempt from deletion.
Backups hold the same data and the same risk.
Include backups in exit, with a schedule.
Exit plans on day one
Write the exit plan at contract start: what returns, what deletes, where, by when, and who certifies.
Monday morning
01 For each contract, list every environment holding data.
02 Draft the exit and deletion plan.
03 Agree certification with the department.
Questions, answered plainly
What happens to personal data when a government IT contract ends? +
As a processor, the vendor should return data to the department and delete remaining copies, including backups and test environments, unless law requires retention. Contracts should specify this.
Should vendors certify deletion? +
Yes. A written certificate of deletion, covering all environments and backups, is good practice and evidences compliance.
Sector · Government vendors The State's exemption is not your exemption. Read →
Government vendors · Deep dive The State's exemption is not your exemption. Read →
Government vendors · Deep dive Real citizens in test data. Read →
Tell us where your data sits. We'll show you where the exposure is.
A partner replies within one working day, with a first view on your penalty exposure.
Speak to a partner →
Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).