At a glanceThis rule applies to a narrow set of large platforms — not every app. Under India’s DPDP Rules, big e-commerce and social media platforms (2 crore-plus users) and large online-gaming services (50 lakh-plus users) must erase a user’s data after three years of inactivity, and give at least 48 hours’ notice before doing so — unless the user logs back in or otherwise gets in touch, which resets the clock. If you’re not one of those notified classes, this specific rule isn’t yours; the general “delete when the purpose is over” duty still is.
Educational resource only. This explains the 48-hour pre-deletion notice and 3-year erasure rule under India’s Digital Personal Data Protection Act, 2023 (DPDP Act) and its Rules; it is not formal legal advice.
The situation
This is one of the most misread parts of the DPDP Rules. Headlines about “delete data after 3 years” and “48-hour warnings” get read as universal duties, and businesses panic-plan for rules that don’t apply to them. The first question isn’t how to comply — it’s whether the rule is even yours.
Does this rule even apply to you?
It applies only to specifically notified classes of large platforms — defined by type and user numbers. The 3-year erasure and 48-hour notice sit in the Rules’ Third Schedule, which names:
- E-commerce platforms with 2 crore (20 million) or more registered users in India;
- Social media platforms with 2 crore or more users; and
- Online gaming services with 50 lakh (5 million) or more users.
If your business isn’t one of these types, or is below these thresholds, this particular rule doesn’t apply to you. It’s a targeted obligation for the largest consumer platforms, not a general one.
What the rule requires
For those platforms: erase inactive-user data after three years, with a 48-hour heads-up first. The mechanics:
- The 3-year clock runs from the user’s last interaction — last login, or last transaction for e-commerce.
- After three years of inactivity, the platform is treated as no longer having a purpose to hold that user’s data, and must erase it.
- At least 48 hours before erasing, it must notify the user.
- Re-engagement resets it — if the user logs in or contacts the platform, the inactivity clock starts over and the data isn’t deleted.
The point of the advance notice is to give a dormant user a chance to keep their account if they still want it.
If you’re not a large platform
You skip this specific rule — but not the underlying principle. Everyone still has the general erasure duty: delete personal data once its purpose is served or consent is withdrawn, unless a law requires you to keep it. The difference is that the specific 3-year clock and 48-hour notice are only mandated for the notified large platforms. So a small business doesn’t need to build a 3-year-inactivity deletion engine — it needs to actually delete data when the purpose ends, on its own sensible schedule.
What in-scope platforms should build
If you are a notified-class platform, this becomes an engineering requirement, not a policy line. You’ll need to: track last-activity per user; identify accounts crossing three years of inactivity; send the 48-hour pre-erasure notice through a channel the user will see; handle re-engagement that resets the clock; and actually erase the data (and stray copies) when the window passes. Because it runs automatically at scale, it has to be built and tested, not handled case by case.
FAQ
Does every app have to delete inactive users’ data after 3 years?
No. The 3-year erasure and 48-hour notice apply only to notified large platforms — e-commerce and social media with 2 crore-plus users, and online gaming with 50 lakh-plus. Others follow the general “delete when the purpose is over” duty.
What triggers the 48-hour notice?
An in-scope platform must warn a user at least 48 hours before erasing their data due to three years of inactivity — unless the user re-engages first.
Can a user stop their data being deleted?
Yes — logging in or contacting the platform resets the inactivity clock, so the data isn’t erased.
I run a small online store — does this apply to me?
Only if you cross the notified threshold (2 crore users). Below that, you’re not bound by this specific rule, though you should still delete data when its purpose ends.