5 min read

How Long Are Banks Permitted to Store Customer Personal Data Under the DPDP Act?

A detailed analysis of data retention limits for banks under the DPDP Act 2023. This guide covers Section 8 purpose limitation, exceptions for RBI statutory requirements, and what General Counsels evaluate to establish defensible compliance.

Written byVipul Abhishek· Former Advocate, Supreme Court of India

Last updated:

Under the Digital Personal Data Protection Act, 2023, banks are permitted to store customer personal data only as long as necessary to fulfill the stated purpose or as required by other applicable laws. The text does not mandate a flat one-year or ten-year limit for all accounts. Section 8 requires Data Fiduciaries to erase data when the specified purpose is no longer served. Section 4(1) dictates that processing occurs only for a lawful purpose based on consent or certain legitimate uses. Section 4(2) defines a lawful purpose as any purpose not expressly forbidden by law. Processing for a loan application relies on consent. Responding to a medical emergency is a legitimate use. If a sector regulator like the Reserve Bank of India mandates a longer retention period for anti-money laundering or KYC records, the DPDP Act permits the bank to keep the data for that exact statutory duration. Compliance requires mapping the data category to the specific regulatory mandate.

Statutory Retention Limits Under Section 8

Section 8(7) establishes the core retention rule for Data Fiduciaries. It states that data is erased when the purpose for processing is met or when the Data Principal withdraws consent. The Act accommodates overlapping regulatory obligations directly. An illustration within Section 8 clarifies this mechanism for financial institutions. It describes a scenario where an individual closes a savings account. Banking laws require the bank to maintain client identity records for ten years beyond account closure. Since retention is necessary for compliance with applicable law, the bank retains the personal data for that period. The DPDP Act yields to the specific statutory retention mandate. A bank relies on the specific RBI Master Direction on KYC or the Prevention of Money Laundering Act rather than the DPDP Act to justify the extended hold. Fiduciaries cannot cite general convenience. The law requires citing the exact section of the competing statute.

Applying The Rules To Legacy Systems

Consent is the primary basis for processing under Section 4, except where Section 7 legitimate uses apply. The DPDP Rules 2025 operationalise how this translates to customer interactions. Banks issue itemised notices before or at the time of requesting consent. These notices specify the purpose of data collection. General Counsels verify that the purposes listed in these notices match the actual retention schedules executed by core banking systems. If a bank collects data for a loan application that is subsequently rejected, the data cannot sit in a legacy database indefinitely. The bank deletes the record unless a specific legal mandate requires preservation. Legal teams review existing data lakes. They map current storage durations against the original notices provided to customers during onboarding.

Processor Contracts And Liability Allocation

Data retention extends beyond internal servers. Banking institutions rely on third-party vendors for credit underwriting, customer support, and cloud hosting. Section 8(1) holds the bank responsible for compliance regardless of any agreement to the contrary or processor failures. Section 8(2) restricts the engagement of Data Processors to a valid contract. Legal heads evaluating indemnities update vendor agreements to enforce specific data destruction protocols. When the retention period expires at the bank level, the processor also deletes the records. A compliance program provides an evidence trail showing that data destruction commands cascade to all relevant vendors. The contract specifies the technical methods the processor uses to purge the files and return confirmation to the bank.

Purpose Expiration Under Section 8(8)

A frequent error is assuming that initial consent permits indefinite storage. Section 8(8) states that the purpose is deemed no longer served if the Data Principal does not approach the Data Fiduciary for the performance of the specified purpose and does not exercise any rights. The timeline for this inactivity is determined by prescribed rules. If a customer opens a trading account but performs no trades for the prescribed period, the fiduciary evaluates if the purpose is exhausted. Another mistake is applying maximum retention periods universally across the institution. KYC records require a ten-year hold based on banking regulations. Secondary marketing data or website analytics do not inherit that exemption. Legal teams build granular retention schedules to segregate data types. Fulfilling an erasure request requiring manual database queries carries a high risk of missing statutory response windows. IT departments isolate data sets subject to different retention timelines.

The 218 Day Compliance Deadline

Banks typically qualify as Significant Data Fiduciaries based on the volume of financial data they process. This designation brings added duties under the Act. Section 10 mandates periodic data protection impact assessments and independent data audits for SDFs. The Data Protection Board of India oversees compliance and levies penalties for breaches. With exactly 218 days remaining until the DPDP hard compliance deadline of 13 May 2027, institutions face a short window to update their data lifecycle practices. General Counsels map data repositories to specific legal retention requirements. Outside counsel spend spikes if mapping exercises start late. Lawyers manually review thousands of unstructured data pools to determine which laws apply to which tables. Early auditing controls these costs.

Automating Deletion Workflows

Manual deletion processes scale poorly in large enterprise environments. An auditor or the Data Protection Board of India asks for verifiable logs. These records prove that data was erased upon purpose expiration or consent withdrawal. Evaluating platforms requires examining how the software integrates with existing IT architecture. An automated system tracks the consent lifecycle and triggers alerts when statutory retention limits approach. It issues specific commands directly to the core banking platform. Software orchestrates deletion across internal databases and external processor environments. This removes the manual legal review burden. The technology provides the exact audit trail required for regulator engagement. Engineers configure systems to issue automated purge commands aligned with the updated retention schedules.

Legal heads need clear visibility into their data practices before the regulatory deadline. Compare current data retention workflows against the specific mandates of the DPDP Act and Rules 2025. This comparison identifies compliance gaps. You can test your organisational readiness at https://www.complydp.com/audit-preview to see where your policies require immediate updates. The assessment generates a report of vulnerable workflows.

Sources

Frequently asked questions

How long are banks permitted to store customer personal data under the DPDP Act?

Banks are permitted to store customer personal data only as long as necessary to fulfill the stated purpose or as required by other applicable laws. The DPDP Act does not set a single arbitrary time limit. It requires data deletion once the original purpose is met.

Does the DPDP Act override RBI data retention requirements?

No. Section 8 of the DPDP Act explicitly states that if retention is necessary for compliance with another law, the Data Fiduciary may retain the personal data. Reserve Bank of India mandates for retaining KYC and transaction records dictate the timeline for those specific files.

What happens to personal data if a loan application is rejected?

If a loan application is rejected and the specified purpose for processing ends, the bank deletes the associated personal data. Retaining this data requires a separate legal basis or explicit, fresh consent from the applicant.

Who is liable if a banking software vendor fails to delete data?

Under Section 8(1) of the DPDP Act, the bank acts as the Data Fiduciary and remains fully responsible for compliance. General Counsels structure vendor contracts to enforce data deletion and allocate liability if the Data Processor fails to comply.

How should banks prepare for the 2027 DPDP deadline?

With 218 days remaining until the 13 May 2027 compliance deadline, banks map their data repositories and implement automated deletion workflows. They also issue itemised notices under the DPDP Rules 2025. Evaluating these processes early controls outside counsel spend and mitigates regulator scrutiny.