Data Retention Policy Under DPDP Act 2023
How long can you keep personal data under DPDP? Understanding data retention requirements, storage l. Get expert help today.
Discuss this page with an LLM
DPDP Action Sheet
Use this before your next workflow goes live. It keeps the useful parts visible and turns DPDP into checks your team can actually answer.
For Data Retention Policy Under DPDP Act 2023, the DPDP question is how personal data enters the workflow, where it is stored, which tools touch it, what purpose was explained, and how deletion or withdrawal will work.
1. Lead Forms
Check:
- What data are you collecting?
- Is the purpose clear at the point of collection?
- Is marketing consent separate from service communication?
- Can the user withdraw consent later?
Common mistake: one checkbox that silently covers newsletters, sales calls, partner sharing and remarketing.
2. Email and WhatsApp
Check:
- Who is on the list?
- Where did consent come from?
- Is the list imported from a vendor, event, webinar, scrape or old CRM?
- Can you prove the source of consent?
Common mistake: treating every lead as permanently marketable.
3. Ads and Retargeting
Check:
- Are pixels or ad platforms receiving identifiable user behavior?
- Are audiences built from customer lists?
- Are lookalike or remarketing audiences using personal data?
Common mistake: assuming "the ad platform handles it" means your company has no DPDP responsibility.
4. Website Analytics
Check:
- Which tools run on the site?
- Are IP address, device identifiers, session IDs or form fields being captured?
- Is analytics used only for measurement, or also for profiling and targeting?
Common mistake: installing tools first and asking privacy questions later.
5. Vendor List
Make a quick list:
- CRM
- Email platform
- WhatsApp provider
- Analytics
- Ad pixels
- Form tool
- Landing page builder
- Webinar tool
For each vendor, answer: what data goes there, why, who can access it and how deletion works.
6. This Week's Action
Map one campaign from first click to final follow-up. Mark every place personal data is collected, enriched, shared, uploaded or used for targeting.
If your team cannot answer where the data came from and where it goes next, start with a data flow map before rewriting policy copy.
Book a DPDP clarity callWant all of this handled, end to end? Sanctum is the all-in-one DPDP compliance programme behind this site: legal position, data map, gap analysis, implementation, tooling, training, readiness opinion, and breach cover under one accountable owner. How all-in-one DPDP compliance works or see the Sanctum programme.
Balancing Statutory Retention with DPDP Deletion
Section 12 of the DPDP Act requires you to delete personal data as soon as the specific purpose for collecting it is gone. However, Indian businesses often face a “retention trap” where the Income Tax Act or Companies Act requires keeping records for eight years. You must map every data field to a specific law that justifies its storage beyond the active customer relationship.
Managing Data After Consent Withdrawal
When a user withdraws consent or closes their account, you cannot keep their data for “potential future marketing.” You must strip away all identifiers like phone numbers and email addresses unless a secondary legal obligation, such as an active dispute or a tax audit requirement, applies to that specific record.
Retention Risks by Workflow
| Workflow | Personal Data Involved | DPDP Retention Risk |
|---|---|---|
| Customer Onboarding | Aadhaar/PAN scans, address proof | Keeping ID copies after the KYC verification is finalized and recorded. |
| Failed Lead Conversion | Name, phone number, email | Storing contact details of “dead” leads for years without a follow-up consent trigger. |
| Employee Offboarding | Bank details, family health history | Retaining sensitive medical or financial data of former staff beyond the 5-year limit. |
| Technical Support | Screen recordings, IP addresses | Holding onto troubleshooting logs that contain PII after the ticket is closed. |
This week
Identify one folder on your cloud storage or local server labeled “Old” or “Archive” from before 2022. Delete any files containing customer names or phone numbers that are not required for your current tax filings or active contracts.
Now think about your work. Where does personal data enter your workflows? Where does it sit? Who else touches it?
Frequently asked questions
Does the DPDP Act allow us to keep data for 10 years if our internal policy says so?
No, internal policies do not override the Act. You can only keep data if the original purpose still exists or if another Indian law specifically mandates a long-term retention period.
What happens to user data stored in our offline disaster recovery backups?
You must have a process to ensure that if a backup is restored, any data previously deleted under a "right to erase" request is not accidentally put back into your live systems.
Can we keep anonymized transaction data for business intelligence?
Yes, if the data is truly anonymized and cannot be linked back to an individual, it no longer qualifies as personal data under the DPDP Act and can be kept indefinitely.