Readiness assessment

Obligation

Data Retention

Data retention rules require a Data Fiduciary to erase personal data once consent is withdrawn or the specified purpose is no longer served, unless a law requires keeping it.

Defined inSection 8(7) to 8(8)
CategoryData Lifecycle & Security
Applies toEvery Data Fiduciary

What the Act says

DPDP Act 2023, Section 8(7)

A Data Fiduciary shall, unless retention is necessary for compliance with any law, erase personal data upon the Data Principal withdrawing her consent or as soon as it is reasonable to assume that the specified purpose is no longer being served, whichever is earlier, and cause its Data Processor to erase such data.

In plain language

The default is deletion, not indefinite storage. Once the purpose is done or consent is withdrawn, the fiduciary must erase the data and make its processors do the same.

The purpose is deemed no longer served if the person neither approaches the fiduciary for it nor exercises any rights for a prescribed period, which the Rules set for different classes of fiduciaries.

Example

After a used-car listing sells and the sale concludes, the marketplace should no longer retain the seller's data, unless a law requires it.

Related terms

Related sections of the Act

Related Rules

Frequently asked questions

When must data be erased?

When consent is withdrawn or the specified purpose is no longer served, whichever is earlier, unless a law requires retention.

Who sets the time periods?

The Rules prescribe them, and they can differ for different classes of fiduciaries and purposes.

Continue learning