How long can we retain personal data under the DPDP Act?

Personal data should not be kept beyond the point at which the purpose it was collected for is served, unless retention is required for compliance with a law. Once the purpose is exhausted and no legal retention duty applies, the data — and copies held by processors — should be erased.

Dinkar Singh

That makes retention a per-purpose question rather than a single company-wide period. A retention schedule tied to purposes in your RoPA is what makes deletion defensible; a blanket "seven years" policy usually cannot be justified against every category it covers.

Erasure also has to be real. Data surviving in a reporting replica, a backup outside its stated window or a processor's environment has not been deleted.

General information about the DPDP Act, not legal advice. Obligations depend on your circumstances.

Dinkar SinghDinkar covers privacy engineering at ProtectComply — discovery, consent propagation and the evidence trail behind them.

Where do you stand under DPDP?

Take the free readiness check and find out in 10 minutes.

Start free readiness check →