Readiness assessment
The Act
The DPDP Act, explainedThe DPDP Rules 2025

Ch IPreliminary

S.1 Short title and commencementS.2 DefinitionsS.3 Application and scope

Ch IIObligations of Data Fiduciary

S.4 Grounds for processingS.5 NoticeS.6 ConsentS.7 Certain legitimate usesS.8 Data Fiduciary obligationsS.9 Children’s dataS.10 Significant Data Fiduciary

Ch IIIRights and duties of Data Principal

S.11 Right to accessS.12 Correction and erasureS.13 Grievance redressalS.14 Right to nominateS.15 Duties of the Data Principal

Ch IVSpecial provisions

S.16 Transfer outside IndiaS.17 Exemptions

Ch VData Protection Board of India

S.18 Establishment of the BoardS.19 Composition of the BoardS.20 Salary and term of officeS.21 DisqualificationsS.22 Resignation and vacanciesS.23 Proceedings of the BoardS.24 Officers and employeesS.25 Members as public servantsS.26 Powers of the Chairperson

Ch VIBoard powers and procedure

S.27 Powers and functions of the BoardS.28 Procedure followed by the Board

Ch VIIAppeal and dispute resolution

S.29 Appeal to the Appellate TribunalS.30 Tribunal orders as a decreeS.31 Alternate dispute resolutionS.32 Voluntary undertaking

Ch VIIIPenalties

S.33 Penalties and the ScheduleS.34 Penalties to Consolidated Fund

Ch IXMiscellaneous

S.35 Good-faith protectionS.36 Power to call for informationS.37 Blocking of accessS.38 Consistency with other lawsS.39 Bar of jurisdictionS.40 Power to make rulesS.41 Laying of rules before ParliamentS.42 Power to amend the ScheduleS.43 Power to remove difficultiesS.44 Amendments to other Acts
Industries
Implementation
Training
Resources
About
Readiness assessment

Obligation

Data Retention

Data retention rules require a Data Fiduciary to erase personal data once consent is withdrawn or the specified purpose is no longer served, unless a law requires keeping it.

Defined inSection 8(7) to 8(8)
CategoryData Lifecycle & Security
Applies toEvery Data Fiduciary

TL;DR

Data retention rules (Sections 8(7) to 8(8)) require a Data Fiduciary to erase personal data once consent is withdrawn or the specified purpose is no longer served, unless a law requires keeping it. The default is deletion, not indefinite storage, and processors must erase too.

What Does the DPDP Act Say About Data Retention?

DPDP Act 2023, Section 8(7)

A Data Fiduciary shall, unless retention is necessary for compliance with any law, erase personal data upon the Data Principal withdrawing her consent or as soon as it is reasonable to assume that the specified purpose is no longer being served, whichever is earlier, and cause its Data Processor to erase such data.

What is Data Retention in Simple Words?

The default is deletion, not indefinite storage. Once the purpose is done or consent is withdrawn, the fiduciary must erase the data and make its processors do the same.

The purpose is deemed no longer served if the person neither approaches the fiduciary for it nor exercises any rights for a prescribed period, which the Rules set for different classes of fiduciaries.

Data Retention: Example

After a used-car listing sells and the sale concludes, the marketplace should no longer retain the seller's data, unless a law requires it.

Related terms

Related sections of the Act

Related Rules

Data Retention: Frequently Asked Questions

When must data be erased?

When consent is withdrawn or the specified purpose is no longer served, whichever is earlier, unless a law requires retention.

Who sets the time periods?

The Rules prescribe them, and they can differ for different classes of fiduciaries and purposes.

Continue learning