Data Retention and Erasure Under Rule 8
This is the obligation that turns a policy document into engineering work. Retention that exists only in a PDF is not retention.
The general rule
Rule 8 requires erasure once the specified purpose is no longer being served, unless retention is necessary for compliance with a law in force. Purpose is therefore the unit of retention, not data type.
That is why the record of processing matters: if the purpose was never written down, there is no way to determine when it stopped being served.
The Third Schedule clock
For named classes, the Schedule fixes three years from the date the Data Principal last approached the Data Fiduciary for the specified purpose or exercised her rights, or from commencement of the Rules, whichever is latest. The classes are:
- e-commerce entities with not less than two crore registered users in India;
- online gaming intermediaries with not less than fifty lakh registered users in India;
- social media intermediaries with not less than two crore registered users in India.
The tension with Rule 6
Rule 6(1)(e) requires logs and personal data to be retained for one year to support detection and investigation of unauthorised access. Rule 8 requires erasure when purpose ends. These can conflict.
They are reconcilable, because Rule 8 permits retention necessary under a law and Rule 6 is itself a legal requirement. What matters is deciding deliberately and recording the reasoning, rather than discovering the conflict during an audit.
A retention policy that no system enforces is a description of what you intended, not of what you do. The auditable artefact is the deletion job, not the document.
Infosek Team
What implementation actually involves
- A retention period per data set, with the justifying law or purpose recorded.
- A definition of when the purpose ends, expressed as something a system can evaluate.
- Deletion jobs that run, are monitored, and fail loudly.
- A decision on backups and archives, which are the most commonly forgotten copies.
- Evidence that deletion happened, since the ability to demonstrate it is what an audit asks for.
Common questions
What is the data retention rule under DPDP?
Rule 8 requires a Data Fiduciary to erase personal data once the specified purpose is no longer being served, unless retention is necessary for compliance with any law in force. For classes named in the Third Schedule, including e-commerce and social media intermediaries with not less than two crore registered users and online gaming intermediaries with not less than fifty lakh, a three year period applies.
Can you keep data longer if another law requires it?
Yes. Rule 8 expressly preserves retention necessary for compliance with any law for the time being in force. The requirement is to identify which law justifies the period rather than to retain by default.
Need retention enforced rather than documented?
Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.
Book Free 30-Min Assessment