All articles
Regulatory Update 8 min read 19 July 2026 Primitra

Data Retention Under the DPDP Act: Why 'Keep Everything' Is Now a Liability for Indian SMEs

The DPDP Rules 2025 turn old data from an asset into a risk. Here is how Indian SMEs should think about retention, erasure, and the 48-hour deletion notice.

Most Indian businesses have spent a decade being told that data is an asset. Collect it, store it, hold on to it, because you never know when it will be useful. Under the DPDP Act, that instinct is now a liability. Data retention under the DPDP Act is no longer a storage decision your IT team makes quietly. It is a compliance obligation with penalties attached, and the DPDP Rules, 2025, notified on 13 November 2025, have made the expectations concrete enough that "we keep everything, just in case" is a hard position to defend.

A recent overseas case shows why this matters in practice. On 1 July 2026, a Romanian company was penalised under the GDPR after regulators found it had taken up to 37 months to resolve some data erasure requests. The finding was not that the company lost data or suffered a breach. It was that the company held on to personal data long after it should have deleted it, and was slow to act when people asked to be removed. India's framework is heading in the same direction, and the businesses that treat deletion as an afterthought are the ones that will struggle first.

What data retention under the DPDP Act actually requires

The core principle sits in Section 8(7) of the Act, expanded by Rule 8 of the DPDP Rules. Personal data must be erased once the purpose it was collected for is no longer being served. Purpose is the anchor. If someone gave you their phone number to receive a delivery, and the delivery happened months ago, the justification for keeping that number needs to come from somewhere else, such as a tax or contractual requirement. "It might be handy for marketing later" does not count unless you have separate consent for exactly that.

This is a shift in default. Earlier, deletion was optional and retention was free. Now retention has to be justified, and the burden is on you as the Data Fiduciary to show why data is still around. For most SMEs, the honest answer is that a large share of stored personal data has no live purpose at all. It is old form submissions, abandoned sign-ups, expired leads, and duplicate records that nobody has looked at in years.

The Third Schedule and the 48-hour erasure notice

The Rules go further for certain large platforms. The Third Schedule sets fixed retention periods: e-commerce entities with two crore or more registered users, online gaming intermediaries with 50 lakh or more users, and social media intermediaries with two crore or more users must erase personal data three years after a user's last interaction, unless the user comes back or the law requires the data to be kept.

There is a specific mechanism attached. Before erasing this data, the business has to tell the person at least 48 hours in advance. That notice gives the individual a window to log back in, re-confirm the purpose, or exercise rights over their data. If they re-engage, the clock resets. If they do not, the data goes.

Two things are worth flagging for smaller companies. First, the Third Schedule thresholds are high, so most SMEs fall outside these exact numbers. Second, that is not a reason to relax. The Third Schedule is the clearest signal of what regulators consider reasonable, and Rule 8's general erasure duty applies to everyone regardless of size. A startup with 40,000 users is not exempt from deleting data it no longer needs. It simply does not have a fixed three-year figure written out for it.

Logs, backups, and the parts people forget

Retention is not only about your main customer database. The Rules also expect Data Fiduciaries to keep certain traffic data and processing logs for at least one year, which matters for tracing access if something goes wrong. Beyond a stated retention period, keeping data is permitted only where another law or a genuine contractual obligation requires it.

Backups are where good intentions fall apart. A business can delete a record from its live system and still hold five copies across nightly backups, an old CRM export sitting in someone's email, and a spreadsheet a former employee saved to a personal drive. Erasure has to reach these too, or at least be governed by a defined backup rotation that eventually overwrites the data. This is the operational detail that a proper privacy impact assessment tends to surface, and it is usually more work than teams expect.

A practical starting point

You do not need to solve everything at once. A workable sequence looks like this. Map where personal data lives, including the informal places like inboxes and shared drives. For each store, write down the purpose and a retention period tied to that purpose. Delete or anonymise what has no purpose left. Build a simple, repeatable way to handle erasure requests so you are not the company taking 37 months to respond. Then document the policy so you can show your reasoning if the Data Protection Board ever asks.

The substantive obligations under the Act, including data-principal rights and the deletion duty, are expected to take full effect around 13 May 2027, with the consent manager framework operational from roughly 13 November 2026. That sounds far off, but retention cleanup is slow, unglamorous work. Data accumulated over years does not get sorted in a week. Starting now means you are pruning a garden rather than clearing a jungle later. Non-compliance with security and related duties can attract penalties running into hundreds of crores, so the cost of ignoring this is not theoretical.

If you want a structured way in, our DPDP compliance checklist covers retention alongside the other core duties, and the team at Primitra can help you build a retention schedule that fits how your business actually runs.

This article is general guidance for Indian businesses and not legal advice. For a review of your own retention practices, start with our checklist or get in touch.

Get help implementing this

Turn this reading into a compliance plan.

Book a free 30-minute consultation. We'll map your DPDP Act exposure and give you a prioritized 90-day action list — no obligation.

Book a free 30-minute consultation