Authority Guides • 7 mins
DPDP Act Authority Guide: Reconciling Erasure Rights with Sectoral Retention Mandates
General Counsel face conflicting obligations between DPDP Act erasure requests and long-term retention mandates from regulators like RBI and SEBI. Section 12 of the DPDP Act preserves these sectoral requirements, but enterprises must configure automated legal holds to prevent premature deletion. Legal heads must implement defensible data lifecycle policies aligned with the upcoming DPDP Rules, 2025.
Last updated:
Navigating conflicting data lifecycle obligations is a primary liability risk for General Counsel at large enterprises. The Digital Personal Data Protection Act, 2023, now transitioning into operational reality through the DPDP Rules, 2025, introduces strict erasure rights that often collide with retention mandates from sectoral regulators like the RBI, SEBI, or under the PMLA. Resolving this tension requires precise architectural controls to prevent accidental over-retention or unlawful premature deletion. Outside counsel spend on navigating these conflicts will escalate rapidly as organizations race to build defensible data infrastructure ahead of enforcement.
Section 3 of the Act establishes that it applies to digital personal data processed within the territory of India, whether collected in digital form or collected in non-digital form and digitized subsequently. It also covers processing outside India connected to offering goods or services to Data Principals in India. Under Section 3(c), the Act notably does not apply to personal data processed for personal or domestic purposes, nor to data made publicly available by the Data Principal or another person under a legal obligation. Furthermore, under Section 1(2), the Central Government may appoint different commencement dates for different provisions of this Act.
Under Section 12(1), a Data Principal has the right to erasure of personal data for which they previously gave consent. Section 12(2) grants Data Principals the right to correction, completion, and updating of inaccurate or misleading personal data. According to Section 12(3), a Data Principal shall make a request for erasure in such manner as prescribed by the DPDP Rules, 2025. Crucially for legal defensibility, Section 12(1) specifies this right operates in accordance with any requirement or procedure under any law for the time being in force. This creates a direct statutory shield against erasure demands when a valid sectoral law requires ongoing data retention.
While consent is the primary basis for processing, except where Section 7 legitimate uses apply, withdrawing that consent triggers an obligation to execute an erasure workflow. Enterprises must provide an accessible grievance mechanism and log precisely which data is retained under sectoral mandates even after an erasure or correction request is verified. If this retained data suffers a security incident, the Act requires intimation to affected Data Principals and the Data Protection Board in such manner as prescribed under the DPDP Rules, 2025.
The Data Protection Board of India holds the authority to investigate systemic failures in rights request fulfillment, correction workflows, and data lifecycle management. Penalties can reach up to 250 crore rupees for failing to secure retained data or failing to erase data when no legal mandate applies. General Counsel face dual enforcement risks from the DPBI for over-retention and from sectoral regulators for premature deletion. Defensibility in regulator engagement requires automated audit trails proving that retention was strictly tied to a specific, active statutory requirement.
Unlike older global privacy frameworks, the Indian legislative regime explicitly prioritizes existing statutory obligations over unconditional erasure rights. Cross-border transfers follow this localized logic; transfers are generally permitted unless the Central Government explicitly restricts transfers to notified countries or territories. This allows multinational enterprises to centralize their retention architecture and legal hold configurations across borders. However, they must guarantee they can seamlessly execute localized retention rules when a Data Principal in India exercises their rights under Section 12.
Scenario 1 involves an erasure request received for standard marketing data that holds no statutory retention mandate. The legal obligation requires immediate permanent erasure from all active and backup systems in the manner prescribed by the DPDP Rules, 2025. The owner for this action is Marketing Operations working in tandem with IT. The resulting artifact is a verified erasure certificate recorded securely in the enterprise privacy portal.
Scenario 2 covers an erasure request received for KYC data governed by specific PMLA or RBI mandates. The obligation is to suppress the data from active commercial use, ensure it is not processed for other purposes, and retain it in a secure archive for the designated statutory period. The owner managing this process is the Compliance Head. The required artifact is a specific legal hold tag mapped within the enterprise data catalog.
Scenario 3 triggers upon the legal expiry of a sectoral retention period for previously archived records. The obligation immediately shifts to automated permanent deletion of the previously retained personal data. The owner overseeing this final lifecycle stage is IT Security. The critical artifact generated is a defensible deletion log mapped directly to the expired statutory mandate.
General Counsel evaluating compliance platforms must demand specific architectural guarantees to manage conflicting legal obligations effectively. The following diligence questions help expose whether a vendor can handle complex legal holds without increasing outside counsel dependency or regulatory exposure. The answers directly influence contract negotiations, service level agreements, and limitation of liability clauses.
1. Does your platform allow granular policy mapping to pause DPDP erasure workflows when a specific sectoral law requires mandatory data retention? 2. Can you provide detailed audit logs demonstrating exactly why an erasure request was denied or delayed, suitable for defending our position to the DPBI? 3. What indemnities do you offer if your automated workflow prematurely deletes data required for regulatory compliance under RBI or SEBI guidelines?
4. How does your tool securely segregate retained data to ensure it is not processed for any other commercial purpose during the statutory hold period? 5. Does your solution guarantee data residency in compliance with both the DPDP Act and sectoral mandates without relying on external sovereign zones? 6. Can the platform seamlessly process Section 12 correction and completion requests alongside standard erasure workflows as per the DPDP Rules, 2025?
At the 30-day milestone of an implementation program, legal teams must map all sectoral retention mandates across business units to specific data attributes currently active in production. This vital step prevents operational blind spots during automated rights fulfillment. By day 60, enterprises must establish processing rules that structurally prioritize statutory retention over standard Section 12 erasure workflows.
At the 90-day mark, IT must deploy technical controls to isolate retained data from active processing systems while maintaining its availability for regulatory audits. These controls must automatically generate defensible audit logs to protect the organization during regulator inquiries. Completing these milestones ensures architectural readiness and technical compliance well ahead of the official enforcement date.
General Counsel evaluating compliance platforms must ensure their vendor can handle complex legal holds without exposing the enterprise to regulatory penalties. Review your current data architecture to ensure strict defensibility and proper limitation of liability allocations. Contact ComplyDP to discuss how our platform isolates legal hold data and generates audit-ready defense logs under the evolving DPDP rules framework.
Sources
Frequently asked questions
Does a DPDP erasure request override our obligations under sectoral laws like PMLA?
No. Section 12(1) of the DPDP Act 2023 explicitly states that the right to erasure operates in accordance with any requirement or procedure under any law for the time being in force. Enterprises must retain data if mandated by sectoral regulators like RBI, SEBI, or under PMLA, even after an erasure request is received through mechanisms prescribed by the DPDP Rules, 2025.
How should General Counsel manage conflicting retention timelines across different business units?
Legal heads must comprehensively map data flows and tag specific digital personal data records with their statutory retention periods. When an erasure request is received, automated workflows must execute a legal hold for mandated data while permanently erasing data not subject to legal retention. It is critical to segregate this retained data to prevent unauthorized active processing.
What happens if retained data suffers a security incident during the mandatory holding period?
Data fiduciaries remain fully liable for the security of retained data, even when it is archived solely to comply with sectoral laws. Any personal data breach requires intimation to affected Data Principals and a report to the Data Protection Board in the prescribed manner under the DPDP Rules, 2025, reinforcing the need for secure archival systems.
How do we prove to the DPBI that an erasure denial was lawful?
Defensibility requires granular audit trails linking the retained data asset to the specific statutory mandate preventing its deletion. Compliance systems must generate exportable logs that outside counsel can use to defend the fiduciary against DPBI inquiries, proving that retention was strictly tied to a valid sectoral requirement as permitted under Section 12(1).
ComplyDP