On this page
The DPDP Act does not give one number for how long you may keep customer data. It gives a trigger instead: erase the data when it has done its job, unless a law says to keep it. The Rules then add three fixed points: a one-year floor for logs and related data, a three-year inactivity limit for the largest online platforms, and a 48-hour warning before an inactivity erasure.
The general rule: erase when the purpose ends
A Data Fiduciary must erase personal data when the person withdraws consent, or as soon as it is reasonable to assume the specified purpose is no longer being served, whichever comes first. The exception is retention that is necessary to comply with a law. You must also cause your Data Processor to erase any personal data you made available to it.
The Act gives its own examples. In one, a person registers on an online marketplace to sell her used car. Once the marketplace has helped conclude the sale, it must no longer retain her personal data. In another, a bank is required by the law that applies to banks to keep identity records for ten years after an account closes, so it keeps them for that period.
When a purpose is treated as ended
The Act deems a purpose to be no longer served if the person does not approach you for the performance of the purpose, and does not use any of their rights, for a period that the Rules prescribe. Different periods can be set for different classes of Data Fiduciary and different purposes. A period in which the person has not started contact with you, in person or by electronic or physical communication, counts as time in which they did not approach you.
The three-year limit for large platforms
The Rules set that period for three classes of Data Fiduciary, in the Third Schedule:

| Class | Size test | Period |
|---|---|---|
| E-commerce entity | Not less than two crore registered users in India | Three years |
| Online gaming intermediary | Not less than fifty lakh registered users in India | Three years |
| Social media intermediary | Not less than two crore registered users in India | Three years |
For these classes the personal data must be erased if the person neither approaches the Data Fiduciary for the specified purpose nor uses their rights for three years. The three years run from the date the person last approached you or used their rights, or from the commencement of the Rules, whichever is latest. The Rules start in stages, so ask counsel which date applies to you. Two uses are carved out: letting the person access their user account, and letting them access a virtual token issued by you or on your behalf, stored on your platform, that can be used to get money, goods or services.
The schedule says “e-commerce entity” means a person who owns, operates or manages a platform for e-commerce as defined in the Consumer Protection Act, 2019, but does not include a seller offering goods or services on a marketplace e-commerce entity. A business below these size tests is not covered by this particular schedule, although the general rule above still applies.
The 48-hour warning
At least forty-eight hours before the end of the period, a Data Fiduciary in those classes must tell the person that their data will be erased when the period ends. The message must say the data will stay if the person logs into their user account, starts contact with you for the specified purpose, or uses their rights.
The one-year floor for logs and related data
Separately from all of this, the Rules require a Data Fiduciary to retain personal data, the associated traffic data and other logs of the processing for a minimum of one year from the date of the processing, for the purposes in the Seventh Schedule. After that year, you must cause the personal data and logs to be erased, unless another law requires longer retention or the Government notifies it.
The Rules give two examples. A person buys an e-book and delivery completes, so the purpose is served. The platform must still keep the order details, personal data and logs of the order, payment and delivery for at least one year from the transaction, even if she deletes her account. In the second, a company hosts customer records with a cloud provider. The company must make sure the provider also keeps the data and logs for at least one year before erasure, unless another law requires a longer period.
The security safeguards in the Rules point the same way. They include keeping logs and personal data for one year so that unauthorised access can be detected and investigated, unless a law requires otherwise.
Putting it together
| Situation | What the text says |
|---|---|
| Person withdraws consent | Erase, and cause processors to erase, unless a law requires retention. |
| Purpose served, any business | Erase as soon as it is reasonable to assume the purpose is no longer served, unless a law requires retention. |
| Large e-commerce, gaming or social media platform, inactive person | Erase after three years of no contact and no use of rights, after a 48-hour warning. |
| Logs, traffic data and the personal data processed | Keep for at least one year from the processing, then erase unless another law requires more. |
| A law requires a longer period | Keep the data for as long as that law requires. |
What to write in a retention schedule
For each kind of personal data, record the purpose, the event that ends it, the law (if any) that requires a longer period, the one-year log floor, and who erases the data, including your processors. The rights article covers erasure requests, and the breach article explains why logs matter after an incident.
When this applies
The retention duties start on 13 May 2027, eighteen months after the notifications published on 13 November 2025. Check whether the Act applies to your business with the processing map.
For a small shop, app or salon, see the DPDP Act for small businesses that collect customer or lead data.
Common questions
How long can I keep customer data?
Until the person withdraws consent or it is reasonable to assume the purpose is no longer served, whichever comes first, unless a law requires you to keep it. Keep personal data, traffic data and logs of processing for at least one year, for the purposes the Rules list in the Seventh Schedule, then erase them unless another law requires longer.
Which businesses face the three-year inactivity limit?
E-commerce entities with not less than two crore registered users in India, online gaming intermediaries with not less than fifty lakh, and social media intermediaries with not less than two crore. They must erase personal data if the person has neither approached them nor used her rights for three years. The three years run from her last contact or use of rights, or from the Rules’ commencement, whichever is latest. Account access and stored virtual tokens are excluded, and a law requiring retention prevails.
Do I have to warn people before erasing their data?
The businesses above must. At least forty-eight hours before the period ends, they must tell the person the data will be erased unless she logs in, contacts them for the purpose or uses her rights.
How long must I keep logs?
At least one year from the date of the processing, for the purposes in the Seventh Schedule. After that you must erase them unless another law requires longer retention.
Does a legal duty to keep records override erasure?
Yes. The duty to erase applies unless retention is necessary for compliance with a law. The Act’s own example is a bank that must keep identity records for ten years after an account closes.
Next steps
- Check whether the DPDP Act applies to your business, free, in a few clicks
- How-to 06: Keep only as long as needed, in the toolkit
- The free duties list, every duty in plain words
In the news
- DPDP Rules 2025: Fiduciary Duties Phase In Over 18 Months
Covers retention and erasure alongside the other duties in the Rules.
- Data Deletion — A Key Compliance under the Digital Personal Data Protection Act, 2023
Legal-press view of deletion as a compliance task, relevant to a retention schedule.
- Navigating legal liabilities: Understanding DPDP execution
Question-and-answer piece from a law firm on safeguards, logs, breach reporting and retention.
Sources
Every section, rule and date above was checked against the official text on 5 Oct 2026.
Digital Personal Data Protection Act, 2023 (No. 22 of 2023)
Official text: the Digital Personal Data Protection Act, 2023 (MeitY, PDF)
- Section 8(7)Erase on withdrawal of consent or when the purpose is no longer served; cause the processor to erase; illustrations
- Section 8(8)Purpose deemed no longer served after the prescribed time without contact or use of rights
- Section 8(11)What counts as not having approached the Data Fiduciary
DPDP Rules, 2025 (G.S.R. 846(E), 13 November 2025)
- Rule 1(4)Rules 6 and 8 in force eighteen months from publication
- Rule 6(1)Safeguards, including one-year retention of logs and personal data (e)
- Rule 8Retention and erasure: classes in the Third Schedule, 48-hour notice, one-year minimum for data, traffic data and logs
- Seventh SchedulePurposes for which the one-year retention applies
- Third ScheduleE-commerce entity (two crore registered users), online gaming intermediary (fifty lakh), social media intermediary (two crore); three years
Notifications
Official text: commencement notification G.S.R. 843(E) (MeitY, PDF)
- G.S.R. 843(E), clause (c)Section 8 in force eighteen months from 13 November 2025
A drafting aid. Get legal advice for your situation. This article explains the published text of the Act and the Rules.



