On this page
A customer writes: delete everything you hold about me. Part of what you hold is an invoice you may have to keep for another law. This page sets out what the DPDP Act and Rules say about that clash. The sections on the law are cited in the Sources box. The section marked Our view is our opinion and carries no citation.
What the law says about erasure
A person has the right to ask for erasure of her personal data when she gave consent for the processing. This includes details she voluntarily gave you for a purpose, where she has not told you she does not consent to that use. She makes the request in the manner the Rules prescribe. Once she does, you must erase her data unless keeping it is necessary for the specified purpose or for compliance with any law in force.
The Act also limits the duty to erase when a person withdraws consent or the purpose is no longer served: you must erase, and cause your Data Processors to erase, unless retention is necessary for compliance with any law. It also says that when a person withdraws consent you must stop processing her data unless the Act, the Rules or another law requires or authorises the processing.
The Act’s own example
A person closes her savings account. The bank is required by a law that applies to banks to keep the record of her identity for ten years after the account closes. Because retention is necessary for compliance with law, the bank keeps her personal data for that period. The Act gives this example itself, so the idea of a legal duty to keep a record overriding erasure is written into the law.
What the law does not say
The Act and Rules do not mention invoices, tax or any particular record-keeping law, and they do not give a retention period for invoices. They only say that retention is allowed when it is necessary for compliance with a law. The period, and what a record must contain, come from the other law. Those laws are not part of the official text we checked for this page. Check the law that applies to your invoices, or ask your accountant, for the period and the fields it requires.

The one-year minimum
The Rules add a separate rule. A Data Fiduciary must keep personal data, traffic data and logs of the processing for at least one year from the date of the processing, for the purposes the Seventh Schedule lists, and then erase them unless another law requires longer. The Rules’ own example is an e-book platform: it must keep order details, personal data and logs such as order confirmation, payment and delivery events for at least one year from the transaction, even if the customer deletes her account.
What stays and what goes
| Data | What the law says |
|---|---|
| Data that a law requires you to keep | Keep it for as long as that law requires. Retention is necessary for compliance with a law. |
| Data held only for a purpose the person consented to, which is now served or withdrawn | Erase it after the one-year minimum in the next row, and cause your Data Processors to erase their copies. |
| Personal data, traffic data and logs of the processing | Keep for at least one year from the processing, for the purposes the Rules list, then erase unless another law requires longer. |
Requests and complaints
A customer makes the request through the means you publish for rights requests, and must use your grievance process before going to the Board. Data Principal rights and the 90-day grievance limit. For how long you can keep data when no law applies, read how long you can keep customer data.
These duties start on 13 May 2027.
Our view: a way to handle the request
Our view. This is how we would handle the request.
- Split the customer’s record into what a law requires you to keep, which may include an invoice, and everything else, such as marketing preferences, saved addresses and chat history.
- Erase everything else, including copies at your suppliers, once nothing in the sections above requires you to keep it. Your software vendors as Data Processors.
- Keep the invoice for the period the other law sets. Do not use it for anything else, such as marketing.
- Write down which law you relied on, and the date you will delete what you kept. Delete it on that date.
- Tell the customer what you erased and what you kept, and why.
Common questions
Must I delete a customer’s data when she asks?
Yes, when she gave consent for the processing and makes the request in the manner the Rules prescribe. You must erase her personal data unless retention is necessary for the specified purpose or for compliance with any law in force.
Can I keep an invoice after she asks me to delete her data?
You may keep what a law requires you to keep. The Act says the duty to erase applies unless retention is necessary for compliance with any law, and gives the example of a bank that must keep identity records for ten years after an account closes.
How long must I keep invoices?
The Act and Rules do not say. They mention no invoice, tax or record-keeping law and give no invoice period. The period comes from the law that requires you to keep the invoice.
Do I have to keep a customer’s data for at least one year?
The Rules require personal data, traffic data and logs of the processing to be kept for at least one year from the processing, for the purposes the Seventh Schedule lists, and then erased unless another law requires longer. The Rules’ own example is an e-book platform that keeps order, payment and delivery records for at least one year even if the customer deletes her account.
What if the customer is unhappy with my answer?
She has the right to readily available means of grievance redressal and must use your grievance process before approaching the Board. You must publish a grievance response period of no more than 90 days.
Next steps
- Check whether the DPDP Act applies to your business, free, in a few clicks
- How-to 06: Keep only as long as needed, in the toolkit
- How-to 07: Answer people on time, in the toolkit
- The free duties list, every duty in plain words
In the news
- DPDP Rules 2025: Fiduciary Duties Phase In Over 18 Months
Notes the Rules’ erasure and retention provisions, the background to our invoices question.
Sources
Every section, rule and date above was checked against the official text on 6 Oct 2026.
Digital Personal Data Protection Act, 2023 (No. 22 of 2023)
Official text: the Digital Personal Data Protection Act, 2023 (MeitY, PDF)
- Section 6(6)On withdrawal of consent, cease and cause Data Processors to cease unless required or authorised by law
- Section 8(7)Erase on withdrawal of consent or when the purpose is served, unless retention is necessary for compliance with a law; cause the Data Processor to erase; bank illustration
- Section 12(1)Right to correction, completion, updating and erasure for data processed on consent
- Section 12(3)Erasure on request unless retention is necessary for the specified purpose or for compliance with a law
- Section 13(1) and (3)Right of grievance redressal; exhaust it before approaching the Board
DPDP Rules, 2025 (G.S.R. 846(E), 13 November 2025)
- Rule 1(4)Rules 3, 5 to 16 in force eighteen months from publication
- Rule 8(3)One-year minimum for personal data, traffic data and logs; e-book platform illustration
- Rule 14Publish how to make requests; grievance period of not more than ninety days
- Seventh SchedulePurposes for which the one-year retention applies
Notifications
Official text: commencement notification G.S.R. 843(E) (MeitY, PDF)
- G.S.R. 843(E), clause (c)Sections 3 to 5, 6 (except 6(9)), 7 to 17 in force eighteen months from 13 November 2025
A drafting aid. Get legal advice for your situation. This article explains the published text of the Act and the Rules.


