DPDP Rules status: compliance window active. Read the update

Skip to content
Data Privacy · DPDP Act 2023

Retention & erasure — how long you may keep personal data

Rule 8 and the Third Schedule set concrete retention and erasure timelines for large e-commerce, online gaming, and social media platforms. Section 8(6)–(8) sets the broader duties: breach intimation, erasure on withdrawal, and the deemed-expiry rule.

Educational only · not legal adviceReviewed by Sandesh Kokate, Editor

In plain English

If you are a Data Fiduciary, you must erase personal data once its purpose is over or consent is withdrawn. The exception is when another law requires you to keep it. Rule 8 also sets two extra timelines:

  • A one-year minimum retention for all processing logs and traffic data.
  • A three-year rule for very large e-commerce, online gaming, and social media platforms.

For those large platforms: if a user has not logged in or exercised her rights for three years, the platform must erase her data. But first, it must warn her at least 48 hours before deletion. The one-year retention floor still applies. This is true even if the user deletes her account or the original purpose is finished.

Think of it like

Think of a self-storage locker company. It must let you remove your belongings when you cancel the contract. But tax law may force it to keep a copy of the invoice for several years. A very large warehouse chain has extra duties too. It must keep security-camera logs for a fixed period. It must warn you before destroying inactive boxes. And it cannot keep your stuff forever just because you stopped visiting.

Key takeaways

  • Erasure is the default when consent is withdrawn or the purpose is no longer served. The exception: another law requires retention.
  • Every Data Fiduciary must keep personal data, traffic data, and processing logs. The minimum is one year from the date of processing.
  • Large e-commerce, online gaming, and social media platforms must treat most data as expired after three years.
  • Account access and virtual-token access are carved out of the three-year rule.
  • Before erasing data under Rule 8(1), the platform must warn the user. It must give at least 48 hours' notice.
  • The Data Fiduciary must also cause its Data Processor to erase the data it shared for processing.

What this means for you

Founders

Build your retention schedule now. Keep logs for at least one year. Erase data right away when consent is withdrawn or the purpose ends. Add a 48-hour warning step if your user numbers cross the Third Schedule limits.

Freelancers

If you host or process client data, your contract must say who handles the one-year retention. It must also say who erases data when consent is withdrawn.

Creators

Audience data and platform analytics must be erased when the purpose ends. If you use a large third-party platform, check whether the Third Schedule three-year rule applies to it. It may not apply to you.

Status

EnforceableCore obligations enforceable 13 May 2027. The Act has been on the statute book since 13 November 2025. The Data Protection Board is not yet hearing complaints.

Primary sources

Official text

Official text — Rule 8, DPDP Rules, 2025
RULE 8 — Time period for specified purpose to be deemed as no longer being served (DPDP Rules, 2025) 8. (1) A Data Fiduciary, who is of such class and is processing personal data for such corresponding purposes as are specified in Third Schedule, shall erase such personal data, unless its retention is necessary for compliance with any law for the time being in force, or, for the corresponding time period specified in the Third Schedule, if the Data Principal neither approaches such Data Fiduciary for the performance of the specified purpose nor exercises her rights in relation to such processing. (2) At least forty-eight hours before completion of the time period for erasure of personal data under this rule, the Data Fiduciary shall inform the Data Principal that such personal data shall be erased upon completion of such period, unless she logs into her user account or otherwise initiates contact with the Data Fiduciary for the performance of the specified purpose or exercises her rights in relation to the processing of such personal data. (3) Without prejudice to sub-rules (1) and (2), a Data Fiduciary shall retain, in respect of any processing of personal data undertaken by it or on its behalf by a Data Processor, such personal data, associated traffic data and other logs of the processing for a minimum period of one year from the date of such processing, for the purposes as specified in the Seventh Schedule, after which the Data Fiduciary shall cause such personal data and logs to be erased, unless further retention is required for compliance with any other law for the time being in force or notified by the Government. Illustration. Case 1: X, a Data Principal purchases an e-book on an e-book platform Y. Once delivery is completed, the specified purpose of processing is served. The platform Y must retain the order details, personal data, and logs of the processing (such as order confirmation, payment, and delivery events) for at least one year from the date of the transaction, even if X deletes her account. Case 2: X, a company engages a cloud service provider C as its Data Processor to host customer records. X as the Data Fiduciary, is required to ensure that the C also retains the data and associated logs for at least one year before erasure, unless any other applicable law requires a longer period.
Official text — Third Schedule, DPDP Rules, 2025
THIRD SCHEDULE [See rule 8(1)] — Retention time periods (DPDP Rules, 2025) Class of Data Fiduciary 1: A Data Fiduciary who is an e-commerce entity having not less than two crore registered users in India. Class of Data Fiduciary 2: A Data Fiduciary who is an online gaming intermediary having not less than fifty lakh registered users in India. Class of Data Fiduciary 3: A Data Fiduciary who is a social media intermediary having not less than two crore registered users in India. Purposes (all three classes): For all purposes, except for the following: (a) Enabling the Data Principal to access her user account; and (b) Enabling the Data Principal to access any virtual token that is issued by or on behalf of the Data Fiduciary, is stored on the digital facility or platform of such Data Fiduciary, and may be used to get money, goods or services. Time period (all three classes): Three years from the date on which the Data Principal last approached the Data Fiduciary for the performance of the specified purpose or exercise of her rights, or the commencement of the Digital Personal Data Protection Rules, 2025, whichever is latest. Note: "e-commerce entity", "online gaming intermediary", "social media intermediary" and "user" carry the meanings assigned in the Note to the Third Schedule (referencing the Consumer Protection Act, 2019 and the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021).
Official text — Section 8(6)–(8), DPDP Act, 2023
SECTION 8(6)–(8) — General obligations of Data Fiduciary, breach + erasure sub-sections (DPDP Act, 2023) (6) In the event of a personal data breach, the Data Fiduciary shall give the Board and each affected Data Principal, intimation of such breach in such form and manner as may be prescribed. (7) A Data Fiduciary shall, unless retention is necessary for compliance with any law for the time being in force,— (a) erase personal data, upon the Data Principal withdrawing her consent or as soon as it is reasonable to assume that the specified purpose is no longer being served, whichever is earlier; and (b) cause its Data Processor to erase any personal data that was made available by the Data Fiduciary for processing to such Data Processor. (8) The purpose referred to in clause (a) of sub-section (7) shall be deemed to no longer be served, if the Data Principal does not approach the Data Fiduciary for the performance of the specified purpose and does not exercise any of her rights in relation to such processing, for such time period as may be prescribed.
Quick self-check

Am I a Data Fiduciary?

Run the 3-minute self-check to see whether these retention and erasure duties apply to your product.

Run it now

Citation

Kokate, S. (2026). Retention & erasure — how long you may keep personal data. India AI Rulebook. Retrieved from https://indiaairulebook.com/learn/data-privacy/retention-erasure. Educational content, not legal advice.

The Rules are dated 13 November 2025 and were published in the Gazette on 14 November 2025. Some sources therefore give 14 May 2027. We use 13 May 2027; see Methodology.