How to Build a Data Retention and Erasure Schedule Under the DPDP Rules 2025

A data retention and erasure schedule is the document that decides, for every category of personal data a business holds, when the obligation to erase bites and what displaces it. Under the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 that question has three distinct answers, and conflating them is where most schedules go wrong.
Step 1: Establish What Is in Force and What Is Not
By G.S.R. 843(E) dated November 13, 2025, issued under section 1(2) of the Act, sections 3 to 5, most of section 6, and sections 7 to 17 come into force eighteen months after publication. Section 8 and section 12 are both in that group. Rule 8 of the Rules, notified by G.S.R. 846(E) of the same date, sits in the matching eighteen month tranche with rules 3, 5 to 16, 22 and 23.
What commences at the one year point is narrower: section 6(9) and section 27(1)(d) of the Act, and rule 4 of the Rules, which together carry the consent manager framework. A retention schedule is therefore being built against obligations that commence in May 2027, not against the November 2026 date, and the difference should be stated plainly in whatever paper accompanies the schedule.
Step 2: Separate the Three Erasure Triggers
The first trigger is in section 8(7)(a). Unless retention is necessary for compliance with any law in force, the data fiduciary must erase personal data upon the data principal withdrawing her consent, or as soon as it is reasonable to assume that the specified purpose is no longer being served, whichever is earlier. This runs on its own, without any request.
The second is in section 12(3). The data principal may request erasure, and on receipt the fiduciary must erase unless retention is necessary for the specified purpose or for compliance with any law in force. The carve out is wider here than under section 8(7), because the specified purpose itself can justify retention.
The third is the deemed expiry of the specified purpose under rule 8, which applies only to the classes of fiduciary listed in the Third Schedule. A schedule that collapses these three into a single retention period will either over retain against section 8(7) or under retain against a statutory obligation elsewhere.
Step 3: Work Out Whether You Are in the Third Schedule
Rule 8(1) provides that a data fiduciary who is of a class, and is processing personal data for the corresponding purposes, specified in the Third Schedule shall erase that personal data once the time period specified there has elapsed, unless its retention is necessary for compliance with any law in force.
The Third Schedule specifies three classes: an e-commerce entity with not less than two crore registered users in India, an online gaming intermediary with not less than fifty lakh registered users in India, and a social media intermediary with not less than two crore registered users in India. For each, the period is three years from the date on which the data principal last approached the fiduciary for the performance of the specified purpose, or the date of commencement of the Rules, whichever is later. The purposes covered exclude data processed to enable the data principal to access her user account or any virtual token she has stored.
Two points follow. The clock runs from the last approach, not from account creation or last purchase. And the account access carve out means the identifiers a user needs in order to log back in are not swept up by the three year rule.
Step 4: Build the Forty Eight Hour Intimation
Rule 8(2) requires that at least forty eight hours before the completion of the period, the data fiduciary inform the data principal that the personal data will be erased unless she logs into her user account or otherwise initiates contact for the performance of the specified purpose, or exercises her rights.
Design the intimation as a re-engagement event rather than a notice. It has to reach a channel the user still monitors, it has to state what will be erased, and a response has to reset the three year period rather than merely log a reply. Build the reset into the same system that calculates the period, because a notice that cannot be acted on is worse than none.
Step 5: Reconcile the Erasure Duty With the One Year Floor
Rule 8(3) requires a data fiduciary to retain the personal data, the associated traffic data and other logs of the processing for a minimum period of one year, for the purposes the Rules specify, after which erasure is required unless some other law in force requires longer retention.
A floor and a ceiling in the same rule means the schedule has to hold both. Record against each data category the earliest date on which erasure is permitted and the latest date on which it is required, and treat any category where the two invert as a legal question rather than a configuration problem.
Step 6: Map the Compliance With Law Carve Out to Real Statutes
Both section 8(7) and section 12(3) preserve retention that is necessary for compliance with any law for the time being in force. That is a reference to identified obligations, not a general licence, and it is the limb most often asserted without support.
So the schedule should name the statute, the provision and the period for every category where the carve out is relied on, and should record where no such provision exists. The entries that cannot be sourced are the ones to fix before commencement, because they are the entries an auditor or the Board will test first.
Step 7: Push the Schedule Through to Processors and Backups
Section 8(1) keeps the data fiduciary responsible for compliance in respect of processing undertaken on its behalf by a data processor, and section 6(6) requires it, on withdrawal of consent, to cease and to cause its processors to cease processing. The schedule is therefore a contractual instrument as much as an internal one.
Carry the periods into the processing agreement, require deletion certificates on the same cycle, and deal expressly with backups, archives and analytics copies. An erasure that leaves the record in a warehouse table is not an erasure.
Common Pitfalls to Avoid
Reading three years as a general retention period: Rule 8 and the Third Schedule apply to three named classes above stated user thresholds. Everyone else is governed by section 8(7), which has no fixed period at all.
Counting from the wrong date: The period runs from the date the data principal last approached the fiduciary for the specified purpose, or commencement of the Rules, whichever is later.
Erasing the keys to the account: The Third Schedule purposes exclude data processed to enable access to the user account or to a stored virtual token.
Sending the intimation into a dead channel: Rule 8(2) is only useful if it reaches the user. An address last confirmed three years ago is the likeliest point of failure.
Asserting compliance with law without a provision: The carve out in section 8(7) and section 12(3) is tied to an actual legal obligation. Name it or drop the entry.
Treating an erasure request as absolute: Under section 12(3) retention may be justified by the specified purpose as well as by law, which is a wider carve out than the one in section 8(7).
Stopping at the production database: Section 8(1) and section 6(6) reach processing done on the fiduciary's behalf. Backups, archives and processor copies are in scope.
Key Statutory Provisions
Section 6 of the Digital Personal Data Protection Act, 2023: Sub-section (6) requires the data fiduciary, on withdrawal of consent, to cease and to cause its data processors to cease processing, unless retention is required by law.
Section 8 of the Act: Sub-section (1) keeps the fiduciary responsible for processing done on its behalf, and sub-section (7)(a) requires erasure on withdrawal of consent or when it is reasonable to assume the specified purpose is no longer served, whichever is earlier, unless retention is necessary for compliance with law.
Section 12 of the Act: Sub-section (3) entitles the data principal to request erasure, on which the fiduciary must erase unless retention is necessary for the specified purpose or for compliance with any law in force.
Rule 8 of the Digital Personal Data Protection Rules, 2025: Deemed expiry of the specified purpose for the classes in the Third Schedule, the forty eight hour intimation before erasure, and the one year minimum retention of personal data, associated traffic data and other logs of the processing.
Third Schedule to the Rules: E-commerce entities and social media intermediaries with not less than two crore registered users in India, and online gaming intermediaries with not less than fifty lakh, with a three year period measured from the data principal's last approach.
Sources and References
Digital Personal Data Protection Act, 2023, bare text on India Code
Rule 8 of the Digital Personal Data Protection Rules, 2025, full text
Commencement notification G.S.R. 843(E) dated November 13, 2025
Digital Personal Data Protection Rules, 2025, G.S.R. 846(E) dated November 13, 2025
Disclaimer: This article is for informational purposes only and does not constitute legal advice. Readers should consult a qualified legal professional for advice specific to their circumstances.

Comments