Buyer Questions • 5 min read
How long can we keep customer data under DPDP?
Learn how the DPDP Act and Rules 2025 define data retention limits, purpose exhaustion under Section 8, and how CFOs can automate deletion to remain headcount-neutral.
Last updated:
How Long Can We Keep Customer Data Under DPDP
Under the Digital Personal Data Protection Act, 2023, you can keep customer data only as long as necessary to fulfill the specific purpose for which it was collected, or until the data principal withdraws their consent. Indefinite data retention is now strictly illegal. Section 8 of the Act mandates that data fiduciaries must erase personal data when the purpose for processing is exhausted, unless another applicable law requires you to keep it longer.
This means there is no single universal time limit like thirty days or five years written into the DPDP Act for all data. Instead, the legal clock is tied entirely to the lifecycle of your customer relationship and the specific transaction. Once the transaction concludes and no other legal floor exists, the data must be purged from your systems.
The Legal Mechanics Of Section 8 And Purpose Exhaustion
Section 8 provides specific illustrations of how purpose exhaustion works in practice. If an e-commerce platform processes a customer's data to help them sell a used car, the platform must delete that personal data as soon as the sale is concluded. The purpose is fulfilled, and retaining the data for future marketing without fresh consent violates the Act.
The Act also outlines when a purpose is deemed to be no longer served. If a data principal does not approach you for the performance of the specified purpose and stops exercising their rights over a continuous period, you cannot hold their data indefinitely in a dormant state. You must actively prune inactive accounts to maintain compliance.
Managing Erasure Requests Under Section 12
Section 12 grants the data principal the explicit right to erasure. When a customer submits a deletion request, your organization must erase their personal data across all systems. Consent is the primary basis for processing, except where Section 7 legitimate uses apply. If the data relies on consent and the customer revokes it by requesting erasure, you must comply promptly.
However, the Act includes a critical exception for compliance with other laws. If a banking law requires a financial institution to maintain KYC records for ten years after an account closes, the bank must retain that data for the full ten years. Sectoral retention floors always override the immediate deletion requirements of the DPDP Act.
What This Means For The Mid-Market CFO
For a CFO managing lean budgets, data retention under the DPDP Act is fundamentally an opex line issue. You might wonder if you can manage these deletion requirements with a lawyer and a few spreadsheets. While technically possible in a company with only a dozen customers, manual tracking scales poorly and directly increases your monthly burn by requiring constant human intervention.
Building a compliant data retention schedule requires identifying every sectoral law that applies to your business, mapping those against the DPDP Act, and tracking purpose exhaustion across thousands of records. Trying to do this manually means adding full-time compliance headcount, which defeats the goal of a headcount-neutral compliance strategy.
Every gigabyte of stale customer data sitting in your cloud environment is not just an unnecessary storage cost, it is an unfunded liability. The effort to manually sift through unstructured repositories during a Section 12 erasure request takes hours of engineering time away from product development. By deploying automated data mapping, you eliminate this wasted engineering burn and reduce your overall infrastructure expenses.
Furthermore, over-retaining data creates massive financial risks. If you hold onto stale data and suffer a security incident, the DPDP Rules, 2025 require intimation to affected Data Principals without delay plus a detailed report to the Data Protection Board within 72 hours. Keeping data past its purpose artificially expands your breach blast radius and exposes you to Section 8 non-compliance penalties, which carry a ceiling of up to 250 crore rupees.
Evaluating automated data lifecycle platforms usually reveals a highly favorable payback period. A phased spend on software that automatically tags data by purpose, applies sectoral retention floors, and executes scheduled deletions is vastly cheaper than hiring dedicated personnel. You can do more with less by turning complex legal retention policies into automated code.
The Operational Reality Of The DPDP Rules 2025
The DPDP Rules, 2025 introduce operational specifics that make informal deletion practices obsolete. It is no longer enough to simply drop a table in a database and assume you are compliant. You must maintain verifiable audit trails that prove the data was securely erased when the purpose was exhausted or when the Section 12 erasure request was processed.
If the Data Protection Board audits your organization, they will ask for evidence of your retention schedules and proof that deletions actually occurred across your primary databases, CRM platforms, and third-party vendors. The Rules demand a systemic approach to data lifecycle management, especially for companies acting as Significant Data Fiduciaries.
Please note that the territorial scope of the Act covers digital personal data processed within India, and processing outside India connected to offering goods or services to Data Principals in India. Any cross-border data transfers to your offshore servers are generally permitted unless the Central Government restricts transfer to notified countries or territories. Whether stored locally or abroad, your retention limits and deletion obligations remain identical.
What To Do Next
With 275 days remaining until the DPDP hard compliance deadline of 13 May 2027, CFOs must act now to implement defensible schedules before the regulatory window closes and financial penalties apply.
1. Map your existing data inventory to identify the specific purpose for each dataset and cross-reference it with sectoral retention laws to establish minimum storage limits.
2. Replace spreadsheet-based tracking with automated retention workflows that integrate directly with your core databases, ensuring your compliance program remains headcount-neutral.
3. Establish a secure audit trail for all data deletions to satisfy the strict evidentiary requirements of the DPDP Rules, 2025 during regulatory inquiries.
Evaluate your current data storage risks and uncover hidden liabilities before they impact your balance sheet. Run a free discovery audit at freescan.complydp.com to map your data footprint and build a cost-effective, automated compliance plan.
Sources
Frequently asked questions
Does the DPDP Act specify an exact number of days to keep data?
No, the DPDP Act does not prescribe a universal time limit like thirty or sixty days. Section 8 requires data to be erased when the specific purpose for collection is exhausted, unless another applicable law mandates a longer retention period.
Can we keep customer data indefinitely if they never ask us to delete it?
No. The Act explicitly states that if a data principal stops approaching you for the service over a continuous period, the purpose is deemed to be no longer served. You must proactively delete dormant data rather than waiting for an erasure request.
How do sectoral laws like tax or banking regulations interact with DPDP deletion rules?
Sectoral retention floors always override the immediate deletion requirements of the DPDP Act. If a financial law requires you to keep KYC data for ten years, you must retain it for that duration to comply with the law, even if the customer requests erasure under Section 12.
Is it cost-effective to handle data deletion requests manually with spreadsheets?
Managing Section 12 erasure requests and tracking purpose exhaustion manually quickly increases your opex line through engineering and legal burn. Automating these workflows provides a much faster payback period and allows you to maintain a headcount-neutral compliance posture.
What happens if we fail to delete data after the purpose is exhausted?
Over-retaining data violates Section 8 of the Act, which carries penalties of up to 250 crore rupees. It also artificially expands your risk profile, meaning a cyber attack will trigger mandatory 72-hour breach reporting to the Board under the Rules 2025 for a much larger volume of data.
ComplyDP