Personal data should not be kept beyond the point at which the purpose it was collected for is served, unless retention is required for compliance with a law. Once the purpose is exhausted and no legal retention duty applies, the data — and copies held by processors — should be erased.
That makes retention a per-purpose question rather than a single company-wide period. A retention schedule tied to purposes in your RoPA is what makes deletion defensible; a blanket "seven years" policy usually cannot be justified against every category it covers.
Erasure also has to be real. Data surviving in a reporting replica, a backup outside its stated window or a processor's environment has not been deleted.
General information about the DPDP Act, not legal advice. Obligations depend on your circumstances.
Dinkar Singh — Dinkar covers privacy engineering at ProtectComply — discovery, consent propagation and the evidence trail behind them.
Take the free readiness check and find out in 10 minutes.
Start free readiness check →