A DPDP data-deletion request, start to finish
A data-deletion request, start to finish
When someone asks you to delete their data, five things have to happen — in order, and on the record. Here is the whole path.
Request received
Via the rights channel
Identity verified
Confirm who’s asking
Acknowledged
Within a 90-day window
Delete everywhere
All systems & backups
Confirmed
Only legal retention
A reachable deletion channel
There is a real, published way to ask for deletion — the rights channel or the Grievance Officer — not a dead end.
Verify before you delete
Confirm the requester is who they say before acting, so you don’t erase or expose data on an unverified request.
Act within the window
Acknowledge the request and complete it inside your published timeline — at most 90 days.
Deleted across systems
Remove the data from live systems and processors, and schedule backups for deletion — not just the primary copy.
Confirm, keep only what’s required
Tell the requester it’s done, and retain only the residue the law specifically requires you to keep.
This is an illustration of the process, not legal advice.
Related Articles
Collecting personal data from your own customers?
These are the rights your business has to honour. See where you stand with a two-minute self-check — no sign-up, no data stored.
Run the compliance self-check →