Retention & erasure — how long you may keep personal data
Rule 8 and the Third Schedule set concrete retention and erasure timelines for large e-commerce, online gaming, and social media platforms. Section 8(6)–(8) sets the broader duties: breach intimation, erasure on withdrawal, and the deemed-expiry rule.
In plain English
If you are a Data Fiduciary, you must erase personal data once its purpose is over or consent is withdrawn. The exception is when another law requires you to keep it. Rule 8 also sets two extra timelines:
- A one-year minimum retention for all processing logs and traffic data.
- A three-year rule for very large e-commerce, online gaming, and social media platforms.
For those large platforms: if a user has not logged in or exercised her rights for three years, the platform must erase her data. But first, it must warn her at least 48 hours before deletion. The one-year retention floor still applies. This is true even if the user deletes her account or the original purpose is finished.
Think of it like
Think of a self-storage locker company. It must let you remove your belongings when you cancel the contract. But tax law may force it to keep a copy of the invoice for several years. A very large warehouse chain has extra duties too. It must keep security-camera logs for a fixed period. It must warn you before destroying inactive boxes. And it cannot keep your stuff forever just because you stopped visiting.
Key takeaways
- Erasure is the default when consent is withdrawn or the purpose is no longer served. The exception: another law requires retention.
- Every Data Fiduciary must keep personal data, traffic data, and processing logs. The minimum is one year from the date of processing.
- Large e-commerce, online gaming, and social media platforms must treat most data as expired after three years.
- Account access and virtual-token access are carved out of the three-year rule.
- Before erasing data under Rule 8(1), the platform must warn the user. It must give at least 48 hours' notice.
- The Data Fiduciary must also cause its Data Processor to erase the data it shared for processing.
What this means for you
Build your retention schedule now. Keep logs for at least one year. Erase data right away when consent is withdrawn or the purpose ends. Add a 48-hour warning step if your user numbers cross the Third Schedule limits.
If you host or process client data, your contract must say who handles the one-year retention. It must also say who erases data when consent is withdrawn.
Audience data and platform analytics must be erased when the purpose ends. If you use a large third-party platform, check whether the Third Schedule three-year rule applies to it. It may not apply to you.
Status
Primary sources
Official text
Official text — Rule 8, DPDP Rules, 2025
Official text — Third Schedule, DPDP Rules, 2025
Official text — Section 8(6)–(8), DPDP Act, 2023
Am I a Data Fiduciary?
Run the 3-minute self-check to see whether these retention and erasure duties apply to your product.
Run it nowCitation
Kokate, S. (2026). Retention & erasure — how long you may keep personal data. India AI Rulebook. Retrieved from https://indiaairulebook.com/learn/data-privacy/retention-erasure. Educational content, not legal advice.
The Rules are dated 13 November 2025 and were published in the Gazette on 14 November 2025. Some sources therefore give 14 May 2027. We use 13 May 2027; see Methodology.