Skip to main content
Finin2minAction Guide · source-controlled
DPDP, Privacy & DataUpdated 5 October 2026

DPDP Data Retention and Erasure: Building a Purpose-Expiry Schedule

By Ravi Sisodia · Reviewed by CA Divyanshu Sengar · Updated 5 October 2026

Rule 8 and Schedule III create specific purpose-expiry triggers for certain large digital platforms, while the Act also requires erasure when consent is withdrawn or purpose ends unless law requires retention; the core regime is scheduled for May 2027.

Finin2min 2-Minute Summary

Current status: the retention map can be built now

Create two clocks for every data set

Clock one asks how long the business purpose remains active. Clock two asks whether another law requires retention after that purpose ends. The final decision is the longer lawful requirement, not a blanket 'keep seven years' policy across all systems.

Tag legal holds separately so they can be removed when litigation/investigation ends.

Deletion has to propagate beyond the primary database

Map replicas, analytics stores, CRM, data lake, support tools, logs and processors. A user-record deletion that leaves the same personal data in marketing and vendor systems is not an effective lifecycle control.

Backups can require special handling; document how expired data becomes inaccessible and ages out under the security/backup design.

October 2026 status: build the deletion engine before Rule 8 commences

Rule 8 and the relevant section 8 erasure obligations are final but are scheduled for the May 2027 commencement of the core regime. The implementation period should be used to prove that a purpose-expiry event in the system can actually trigger deletion, anonymisation or a lawful retention exception across every connected store.

Choose several real data journeys - closed customer, rejected applicant, dormant marketplace user, former employee or completed support case - and trace copies across production, analytics, CRM, data lake, processor and archive. Record where deletion cannot yet be automated.

A legal-retention table should cite the external law that requires continued storage. 'Compliance' or 'future business use' is too vague to justify keeping personal data after purpose expiry.

Purpose-expiry schedule fields

Questions readers commonly ask

Is there a universal three-year retention period under DPDP?

No. Schedule III creates a specific three-year trigger for identified classes/purposes; other data follows its purpose and legal-retention rules.

Are Rule 8 obligations already operative in October 2026?

No. They are on the May 2027 commencement track.

Can tax/KYC records be kept after account closure?

Yes where another law requires retention; document that legal basis.

Must processor copies be addressed?

Yes. The Data Fiduciary's lifecycle control must extend to processing done on its behalf.

Official / primary sources

Disclaimer

Important: General educational and professional-reference material. Apply the current Code, Rules, insurance contract/regulatory instrument or DPDP commencement status to the exact facts before acting. Educational and professional reference only; confirm the current law, rates and the facts of your case before relying on this page.

Educational and professional reference only — not financial, tax or legal advice. Verify the current official position from the primary source before relying on any figure, rate, provision or deadline.