At a glanceThe DPDP Act sets no single universal retention limit. The rule is purpose-driven: you must erase personal data once the purpose it was collected for is served, or the person withdraws consent — whichever comes first — unless a law requires you to keep it. On top of that, the DPDP Rules set a hard three-year deletion clock for a few classes of large platforms (big e-commerce, social media and online gaming), with a 48-hour advance notice before that deletion.
Educational resource only. This explains how retention and erasure work under India’s Digital Personal Data Protection Act, 2023 (DPDP Act), and its Rules; it is not formal legal advice.
Does DPDP set a fixed retention period?
No — and that surprises people expecting a number like “keep records for 7 years.” The DPDP Act does not fix a single retention period for personal data. Instead it ties retention to purpose: you may hold data for as long as the purpose you collected it for is genuinely being served, and no longer.
This is a shift from “keep everything, just in case.” Under DPDP, holding onto a customer’s Aadhaar copy, phone number or documents after you’ve finished the job they were collected for is not neutral — it’s data you’re no longer entitled to keep, and every extra month is extra breach exposure with no lawful basis behind it.
The core rule: erase when the purpose is served
Section 8(7) is the heart of it: erase personal data once consent is withdrawn or the purpose is done, whichever is earlier — unless a law requires retention. The Act’s own words require a Data Fiduciary to “erase personal data, upon the Data Principal withdrawing her consent or as soon as it is reasonable to assume that the specified purpose is no longer being served, whichever is earlier,” and to have its Data Processor erase it too.
Two triggers, then, each starting the clock:
- Consent withdrawn — the person takes back the consent the processing relied on.
- Purpose served — it becomes reasonable to assume the specified purpose is no longer being served (the loan is closed, the delivery is complete, the candidate wasn’t hired).
The standard is “as soon as it is reasonable to assume” — a reasonableness test, not a same-day deadline, but not an open-ended licence either. A business should be able to say, for each category of data it holds, what purpose keeps it and when that purpose ends.
The exception: when a law requires you to keep data
You can — and sometimes must — keep data past its purpose when another law demands it. The erasure rule applies “unless retention is necessary for compliance with any law for the time being in force.” So statutory retention obligations override the erase-when-done rule: income-tax record-keeping, KYC retention under RBI norms, company-law registers, and similar.
The load-bearing caveat is that this exception is specific, not a blanket excuse. A legal duty to retain a KYC record doesn’t entitle you to keep it for marketing, or to hold unrelated data alongside it. Retain only what the law names, only for as long as it names, and erase the rest.
The three-year rule for large platforms
For a few classes of large platforms, the DPDP Rules turn the purpose test into a hard three-year clock. The Third Schedule to the Rules names specific classes and a fixed period: if a Data Principal hasn’t approached the platform for the specified purpose for three years, the data must be erased (unless a law requires keeping it). The named classes are:
- E-commerce entities with at least 2 crore registered users in India.
- Social media intermediaries with at least 2 crore registered users in India.
- Online gaming intermediaries with at least 50 lakh registered users in India.
Crucially, this three-year rule is scoped to those large classes — it is not a universal “delete inactive accounts after three years” rule that applies to every business. If you’re a clinic, an agency or a small SaaS, your obligation is the purpose-based rule above, not the Third Schedule clock. The narrow exceptions the Rules preserve even for the named platforms are things like continued access to the user’s own account and to virtual tokens used to obtain money, goods or services.
The 48-hour pre-deletion notice
Before that three-year deletion, the platform must warn the person — at least 48 hours ahead. The Rules require the Data Fiduciary to notify the Data Principal at least forty-eight hours before the retention period ends, so the person has a chance to re-engage and preserve their data (for example, by logging in or confirming they still want the account).
This pairs with the three-year rule and, like it, applies to the named large classes — not as a general obligation on every small business.
What “erasure” has to reach
Deleting the data on your own server isn’t enough — erasure has to reach every copy you put out. The erasure duty explicitly extends to your Data Processors: when erasure is due, you must cause any processor you handed the data to (a verification vendor, a cloud tool, an outsourced back-office) to erase it as well.
A related point for tech teams: the Rules require certain security logs — traffic and processing logs kept to detect and investigate unauthorised access — to be retained for a minimum of one year. That’s a distinct obligation from personal-data retention: the logs help you prove and investigate a breach, while the underlying personal data still has to go once its purpose is served. Don’t confuse the two clocks.
This is where insecure intake bites hardest. If a customer’s documents were collected over WhatsApp and email and copied into three people’s phones and a shared drive, “erase it” becomes almost impossible to actually do — and impossible to prove you did. Collecting through a system that tracks where data went, and can delete it on schedule, is what makes the erasure obligation deliverable rather than aspirational.
FAQ
How long can I keep customer data under the DPDP Act?
As long as the purpose you collected it for is genuinely being served — there’s no fixed universal limit. Once the purpose is done or consent is withdrawn, you must erase it, unless a law requires you to keep it.
Does the three-year deletion rule apply to my small business?
No. The three-year rule applies only to the large classes named in the Third Schedule (big e-commerce, social media and online gaming platforms above the user thresholds). Smaller businesses follow the purpose-based erasure rule described above.
Can I keep KYC or tax records even after the purpose is over?
Yes — where another law (RBI KYC norms, income-tax rules, company law) requires retention, that overrides the erase-when-done rule. But keep only what the law names, for only as long as it names.
Do I have to delete data held by my vendors too?
Yes. The erasure rule requires you to cause your Data Processors to erase the personal data you gave them, not just delete your own copy.