Compliance Guides6 minutes

Defending Data Erasure Under DPDP: Backups, Logs, and Legal Posture

A guide for General Counsel on operationalising Section 12 erasure requests across active databases, immutable backups, and vendor ecosystems before the 13 May 2027 DPDP deadline.

Written byVipul Abhishek· Former Advocate, Supreme Court of India · ComplyDP Co-Founder

Last updated:

Overview

With exactly 277 days remaining until the DPDP hard compliance deadline of 13 May 2027, General Counsel and legal heads face a complex liability problem. Fulfilling a data erasure request in a primary application is technically straightforward. However, permanently removing a Data Principal from immutable backups, system logs, and downstream analytics stores presents serious defensibility challenges. The Digital Personal Data Protection Act, 2023, requires organizations to prove they have honoured these requests, forcing legal teams to define what constitutes a reasonable deletion posture to limit liability and outside counsel spend.

What The DPDP Act Says

The Act establishes clear statutory duties regarding data retention and deletion. Under Section 12(1) and 12(3), a Data Principal has the right to erasure of their personal data. Furthermore, Section 8(7) requires a Data Fiduciary to erase personal data when the specified purpose is no longer being served. Section 8(8) clarifies that the purpose is deemed no longer served if the Data Principal does not approach the Data Fiduciary for the performance of the purpose, unless retention is necessary for compliance with other laws.

Importantly, these obligations extend to external vendors. Section 8(2) mandates that a Data Fiduciary may only engage a Data Processor to process personal data on its behalf under a valid contract. For General Counsel, this means indemnity clauses and limitation of liability must be tightly drafted to ensure Processors execute erasure requests across their own logs and backups. Note that consent is the primary basis for processing, except where Section 7 legitimate uses apply.

DPDP Act Vs Rules 2025: What Changed

While the Act outlines the broad right to erasure, the DPDP Rules, 2025, notified in November 2025, operationalise the mechanics. The Rules specify the exact timelines and verifiable response mechanisms for fulfilling a Section 12 request, replacing earlier ambiguity. They also introduce strict guidelines for verifiable parental consent, itemised notices, and the audit workflows that Significant Data Fiduciaries must maintain to evidence compliance. A deletion policy based solely on the 2023 Act without aligning to the operational mandates of the 2025 Rules leaves an organization exposed to regulator action.

What Every Data Fiduciary Must Do Now

The ongoing operational burden for legal and compliance teams involves creating an evidence trail that satisfies the regulator. When an erasure request arrives, it must trigger a workflow that cascades down to analytics data lakes and external vendors. For active databases, complete deletion is required. For backups and system logs, a defensible posture involves encrypting or quarantining the data, ensuring it ages out of the retention cycle naturally, and putting technical controls in place so that if a backup is restored, the deleted data is not reintroduced into production.

Managing this manually via spreadsheets and emails to IT is technically possible for early stage companies with low request volumes. However, this in-house approach breaks at scale. Tooling becomes necessary to automate API calls to Processors, log the completion of erasure tasks securely, and generate the privileged review reports that outside counsel or an auditor would demand during an inquiry.

Breach Notification Specifics

The treatment of backups and logs becomes acutely relevant during a security incident. If a quarantined backup containing data that was supposedly erased is compromised, the legal fallout multiplies. In such events, the rules require intimation to affected Data Principals without delay plus a detailed report to the Data Protection Board within 72 hours, per the Rules, 2025. An uncoordinated erasure posture directly inflates the volume of affected individuals, increasing regulatory scrutiny and potential fines.

Common Misconceptions

A frequent misconception is that erasure requests override all corporate data retention policies. Section 8 explicitly states that data can be retained if necessary for compliance with any law, such as a ten year banking record requirement. Additionally, many mistakenly believe the law establishes a separate category for sensitive information that requires different erasure standards. The Act has no separate sensitive-data category. Instead, risk and volume dictate whether an entity is classified as a Significant Data Fiduciary with higher audit obligations.

Another misunderstanding relates to the territorial and cross-border scope of the law. The Act covers digital personal data processed within India, and processing outside India connected to offering goods or services to Data Principals in India. Cross-border transfers of this data are generally permitted unless the Central Government restricts transfer to notified countries or territories via a negative list. It is incorrect to frame this using European concepts of adequacy.

Implementation Checklist

1. Map personal data sprawl across active systems, data lakes, and immutable backup stores to understand exposure. (In-house-feasible)

2. Amend all Data Processor contracts under Section 8(2) to include explicit service level agreements for executing erasure requests. (In-house-feasible)

3. Draft a formal data retention schedule that defines exactly when a purpose is deemed no longer served under Section 8(7). (In-house-feasible)

4. Deploy automated workflows to propagate deletion requests to third-party vendor APIs without manual IT tickets. (Tooling-assisted)

5. Implement quarantine protocols for backups, ensuring restored data is cross-checked against a suppression list before re-entering production. (Tooling-assisted)

6. Generate cryptographic audit trails of all fulfilled requests to provide defensible evidence during regulatory engagement. (Tooling-assisted)

Penalties And Enforcement Risk

The Data Protection Board of India enforces these provisions, and the financial exposure for non-compliance is severe. Failure to observe the duties of a Data Fiduciary under Section 8, which includes executing erasure requests and managing Processor contracts, carries a penalty ceiling of up to Rs 250 crore. For a General Counsel, mitigating this risk requires demonstrating that the organization made reasonable, documented efforts to purge the data across all systems.

How ComplyDP Helps

Evidencing your erasure posture and vendor oversight to regulators requires specialized infrastructure. ComplyDP automates the propagation of deletion requests across your data supply chain while maintaining the secure audit trails required for legal defensibility. To evaluate your organization's readiness and identify operational gaps before the deadline, visit freescan.complydp.com for a comprehensive assessment.

Sources

Frequently asked questions

Do we have to delete personal data from immutable backups under DPDP?

Section 12 requires data erasure when requested, and Section 8 mandates it when the purpose is served. For immutable backups, a defensible legal posture involves logical deletion in active systems and quarantining backups so they age out naturally, provided they are never restored into production without re-applying the deletion.

Can we retain personal data if an individual requests erasure under Section 12?

Yes, if the retention is required by other applicable laws. Section 8 clarifies that a Data Fiduciary may retain information to comply with statutory obligations, such as maintaining banking KYC records for ten years, even if an erasure request is received.

Who is liable if a Data Processor fails to delete the data from their logs?

The Data Fiduciary holds primary liability. Under Section 8(2), Fiduciaries must engage Processors under a valid contract. If a vendor fails to execute the erasure, the Fiduciary faces regulatory action from the Data Protection Board and penalties up to Rs 250 crore, making tight indemnity clauses essential.

What is the timeline for responding to a data erasure request?

The DPDP Rules, 2025 operationalise the specific timelines for responding to Data Principal rights requests. Organizations must establish automated workflows to fulfill these requests within the prescribed days to ensure full compliance before the 13 May 2027 deadline.

Is consent required to process data in our backup and log systems?

Consent is the primary basis for processing, except where Section 7 legitimate uses apply. If the initial processing was based on consent and the individual withdraws it, the obligation to erase the data extends to all systems, requiring documented proof of removal across active and inactive stores.